2 Unix SMB/CIFS implementation.
3 file opening and share modes
4 Copyright (C) Andrew Tridgell 1992-1998
5 Copyright (C) Jeremy Allison 2001-2004
6 Copyright (C) Volker Lendecke 2005
8 This program is free software; you can redistribute it and/or modify
9 it under the terms of the GNU General Public License as published by
10 the Free Software Foundation; either version 3 of the License, or
11 (at your option) any later version.
13 This program is distributed in the hope that it will be useful,
14 but WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 GNU General Public License for more details.
18 You should have received a copy of the GNU General Public License
19 along with this program. If not, see <http://www.gnu.org/licenses/>.
24 #include "smbd/globals.h"
25 #include "fake_file.h"
26 #include "librpc/gen_ndr/messaging.h"
27 #include "../librpc/gen_ndr/ndr_security.h"
29 extern const struct generic_mapping file_generic_mapping;
31 struct deferred_open_record {
32 bool delayed_for_oplocks;
36 static NTSTATUS create_file_unixpath(connection_struct *conn,
37 struct smb_request *req,
38 struct smb_filename *smb_fname,
40 uint32_t share_access,
41 uint32_t create_disposition,
42 uint32_t create_options,
43 uint32_t file_attributes,
44 uint32_t oplock_request,
45 uint64_t allocation_size,
46 uint32_t private_flags,
47 struct security_descriptor *sd,
48 struct ea_list *ea_list,
50 files_struct **result,
53 /****************************************************************************
54 SMB1 file varient of se_access_check. Never test FILE_READ_ATTRIBUTES.
55 ****************************************************************************/
57 NTSTATUS smb1_file_se_access_check(struct connection_struct *conn,
58 const struct security_descriptor *sd,
59 const struct security_token *token,
60 uint32_t access_desired,
61 uint32_t *access_granted)
65 if (get_current_uid(conn) == (uid_t)0) {
66 /* I'm sorry sir, I didn't know you were root... */
67 *access_granted = access_desired;
68 if (access_desired & SEC_FLAG_MAXIMUM_ALLOWED) {
69 *access_granted |= FILE_GENERIC_ALL;
74 return se_access_check(sd,
76 (access_desired & ~FILE_READ_ATTRIBUTES),
80 /****************************************************************************
81 Check if we have open rights.
82 ****************************************************************************/
84 NTSTATUS smbd_check_open_rights(struct connection_struct *conn,
85 const struct smb_filename *smb_fname,
87 uint32_t *access_granted)
89 /* Check if we have rights to open. */
91 struct security_descriptor *sd = NULL;
93 status = SMB_VFS_GET_NT_ACL(conn, smb_fname->base_name,
98 if (!NT_STATUS_IS_OK(status)) {
99 DEBUG(10, ("smbd_check_open_rights: Could not get acl "
101 smb_fname_str_dbg(smb_fname),
106 status = smb1_file_se_access_check(conn,
108 get_current_nttok(conn),
112 DEBUG(10,("smbd_check_open_rights: file %s requesting "
113 "0x%x returning 0x%x (%s)\n",
114 smb_fname_str_dbg(smb_fname),
115 (unsigned int)access_mask,
116 (unsigned int)*access_granted,
117 nt_errstr(status) ));
119 if (!NT_STATUS_IS_OK(status)) {
120 if (DEBUGLEVEL >= 10) {
121 DEBUG(10,("smbd_check_open_rights: acl for %s is:\n",
122 smb_fname_str_dbg(smb_fname) ));
123 NDR_PRINT_DEBUG(security_descriptor, sd);
132 /****************************************************************************
133 fd support routines - attempt to do a dos_open.
134 ****************************************************************************/
136 static NTSTATUS fd_open(struct connection_struct *conn,
141 struct smb_filename *smb_fname = fsp->fsp_name;
142 NTSTATUS status = NT_STATUS_OK;
146 * Never follow symlinks on a POSIX client. The
147 * client should be doing this.
150 if (fsp->posix_open || !lp_symlinks(SNUM(conn))) {
155 fsp->fh->fd = SMB_VFS_OPEN(conn, smb_fname, fsp, flags, mode);
156 if (fsp->fh->fd == -1) {
157 status = map_nt_error_from_unix(errno);
158 if (errno == EMFILE) {
159 static time_t last_warned = 0L;
161 if (time((time_t *) NULL) > last_warned) {
162 DEBUG(0,("Too many open files, unable "
163 "to open more! smbd's max "
165 lp_max_open_files()));
166 last_warned = time((time_t *) NULL);
172 DEBUG(10,("fd_open: name %s, flags = 0%o mode = 0%o, fd = %d. %s\n",
173 smb_fname_str_dbg(smb_fname), flags, (int)mode, fsp->fh->fd,
174 (fsp->fh->fd == -1) ? strerror(errno) : "" ));
179 /****************************************************************************
180 Close the file associated with a fsp.
181 ****************************************************************************/
183 NTSTATUS fd_close(files_struct *fsp)
187 if (fsp->fh->fd == -1) {
188 return NT_STATUS_OK; /* What we used to call a stat open. */
190 if (fsp->fh->ref_count > 1) {
191 return NT_STATUS_OK; /* Shared handle. Only close last reference. */
194 ret = SMB_VFS_CLOSE(fsp);
197 return map_nt_error_from_unix(errno);
202 /****************************************************************************
203 Change the ownership of a file to that of the parent directory.
204 Do this by fd if possible.
205 ****************************************************************************/
207 void change_file_owner_to_parent(connection_struct *conn,
208 const char *inherit_from_dir,
211 struct smb_filename *smb_fname_parent = NULL;
215 status = create_synthetic_smb_fname(talloc_tos(), inherit_from_dir,
216 NULL, NULL, &smb_fname_parent);
217 if (!NT_STATUS_IS_OK(status)) {
221 ret = SMB_VFS_STAT(conn, smb_fname_parent);
223 DEBUG(0,("change_file_owner_to_parent: failed to stat parent "
224 "directory %s. Error was %s\n",
225 smb_fname_str_dbg(smb_fname_parent),
231 ret = SMB_VFS_FCHOWN(fsp, smb_fname_parent->st.st_ex_uid, (gid_t)-1);
234 DEBUG(0,("change_file_owner_to_parent: failed to fchown "
235 "file %s to parent directory uid %u. Error "
236 "was %s\n", fsp_str_dbg(fsp),
237 (unsigned int)smb_fname_parent->st.st_ex_uid,
241 DEBUG(10,("change_file_owner_to_parent: changed new file %s to "
242 "parent directory uid %u.\n", fsp_str_dbg(fsp),
243 (unsigned int)smb_fname_parent->st.st_ex_uid));
245 TALLOC_FREE(smb_fname_parent);
248 NTSTATUS change_dir_owner_to_parent(connection_struct *conn,
249 const char *inherit_from_dir,
251 SMB_STRUCT_STAT *psbuf)
253 struct smb_filename *smb_fname_parent = NULL;
254 struct smb_filename *smb_fname_cwd = NULL;
255 char *saved_dir = NULL;
256 TALLOC_CTX *ctx = talloc_tos();
257 NTSTATUS status = NT_STATUS_OK;
260 status = create_synthetic_smb_fname(ctx, inherit_from_dir, NULL, NULL,
262 if (!NT_STATUS_IS_OK(status)) {
266 ret = SMB_VFS_STAT(conn, smb_fname_parent);
268 status = map_nt_error_from_unix(errno);
269 DEBUG(0,("change_dir_owner_to_parent: failed to stat parent "
270 "directory %s. Error was %s\n",
271 smb_fname_str_dbg(smb_fname_parent),
276 /* We've already done an lstat into psbuf, and we know it's a
277 directory. If we can cd into the directory and the dev/ino
278 are the same then we can safely chown without races as
279 we're locking the directory in place by being in it. This
280 should work on any UNIX (thanks tridge :-). JRA.
283 saved_dir = vfs_GetWd(ctx,conn);
285 status = map_nt_error_from_unix(errno);
286 DEBUG(0,("change_dir_owner_to_parent: failed to get "
287 "current working directory. Error was %s\n",
292 /* Chdir into the new path. */
293 if (vfs_ChDir(conn, fname) == -1) {
294 status = map_nt_error_from_unix(errno);
295 DEBUG(0,("change_dir_owner_to_parent: failed to change "
296 "current working directory to %s. Error "
297 "was %s\n", fname, strerror(errno) ));
301 status = create_synthetic_smb_fname(ctx, ".", NULL, NULL,
303 if (!NT_STATUS_IS_OK(status)) {
307 ret = SMB_VFS_STAT(conn, smb_fname_cwd);
309 status = map_nt_error_from_unix(errno);
310 DEBUG(0,("change_dir_owner_to_parent: failed to stat "
311 "directory '.' (%s) Error was %s\n",
312 fname, strerror(errno)));
316 /* Ensure we're pointing at the same place. */
317 if (smb_fname_cwd->st.st_ex_dev != psbuf->st_ex_dev ||
318 smb_fname_cwd->st.st_ex_ino != psbuf->st_ex_ino ||
319 smb_fname_cwd->st.st_ex_mode != psbuf->st_ex_mode ) {
320 DEBUG(0,("change_dir_owner_to_parent: "
321 "device/inode/mode on directory %s changed. "
322 "Refusing to chown !\n", fname ));
323 status = NT_STATUS_ACCESS_DENIED;
328 ret = SMB_VFS_CHOWN(conn, ".", smb_fname_parent->st.st_ex_uid,
332 status = map_nt_error_from_unix(errno);
333 DEBUG(10,("change_dir_owner_to_parent: failed to chown "
334 "directory %s to parent directory uid %u. "
335 "Error was %s\n", fname,
336 (unsigned int)smb_fname_parent->st.st_ex_uid,
341 DEBUG(10,("change_dir_owner_to_parent: changed ownership of new "
342 "directory %s to parent directory uid %u.\n",
343 fname, (unsigned int)smb_fname_parent->st.st_ex_uid ));
346 vfs_ChDir(conn,saved_dir);
348 TALLOC_FREE(smb_fname_parent);
349 TALLOC_FREE(smb_fname_cwd);
353 /****************************************************************************
355 ****************************************************************************/
357 static NTSTATUS open_file(files_struct *fsp,
358 connection_struct *conn,
359 struct smb_request *req,
360 const char *parent_dir,
363 uint32 access_mask, /* client requested access mask. */
364 uint32 open_access_mask) /* what we're actually using in the open. */
366 struct smb_filename *smb_fname = fsp->fsp_name;
367 NTSTATUS status = NT_STATUS_OK;
368 int accmode = (flags & O_ACCMODE);
369 int local_flags = flags;
370 bool file_existed = VALID_STAT(fsp->fsp_name->st);
375 /* Check permissions */
378 * This code was changed after seeing a client open request
379 * containing the open mode of (DENY_WRITE/read-only) with
380 * the 'create if not exist' bit set. The previous code
381 * would fail to open the file read only on a read-only share
382 * as it was checking the flags parameter directly against O_RDONLY,
383 * this was failing as the flags parameter was set to O_RDONLY|O_CREAT.
387 if (!CAN_WRITE(conn)) {
388 /* It's a read-only share - fail if we wanted to write. */
389 if(accmode != O_RDONLY || (flags & O_TRUNC) || (flags & O_APPEND)) {
390 DEBUG(3,("Permission denied opening %s\n",
391 smb_fname_str_dbg(smb_fname)));
392 return NT_STATUS_ACCESS_DENIED;
393 } else if(flags & O_CREAT) {
394 /* We don't want to write - but we must make sure that
395 O_CREAT doesn't create the file if we have write
396 access into the directory.
398 flags &= ~(O_CREAT|O_EXCL);
399 local_flags &= ~(O_CREAT|O_EXCL);
404 * This little piece of insanity is inspired by the
405 * fact that an NT client can open a file for O_RDONLY,
406 * but set the create disposition to FILE_EXISTS_TRUNCATE.
407 * If the client *can* write to the file, then it expects to
408 * truncate the file, even though it is opening for readonly.
409 * Quicken uses this stupid trick in backup file creation...
410 * Thanks *greatly* to "David W. Chapman Jr." <dwcjr@inethouston.net>
411 * for helping track this one down. It didn't bite us in 2.0.x
412 * as we always opened files read-write in that release. JRA.
415 if ((accmode == O_RDONLY) && ((flags & O_TRUNC) == O_TRUNC)) {
416 DEBUG(10,("open_file: truncate requested on read-only open "
417 "for file %s\n", smb_fname_str_dbg(smb_fname)));
418 local_flags = (flags & ~O_ACCMODE)|O_RDWR;
421 if ((open_access_mask & (FILE_READ_DATA|FILE_WRITE_DATA|FILE_APPEND_DATA|FILE_EXECUTE)) ||
422 (!file_existed && (local_flags & O_CREAT)) ||
423 ((local_flags & O_TRUNC) == O_TRUNC) ) {
427 * We can't actually truncate here as the file may be locked.
428 * open_file_ntcreate will take care of the truncate later. JRA.
431 local_flags &= ~O_TRUNC;
433 #if defined(O_NONBLOCK) && defined(S_ISFIFO)
435 * We would block on opening a FIFO with no one else on the
436 * other end. Do what we used to do and add O_NONBLOCK to the
440 if (file_existed && S_ISFIFO(smb_fname->st.st_ex_mode)) {
441 local_flags |= O_NONBLOCK;
445 /* Don't create files with Microsoft wildcard characters. */
448 * wildcard characters are allowed in stream names
449 * only test the basefilename
451 wild = fsp->base_fsp->fsp_name->base_name;
453 wild = smb_fname->base_name;
455 if ((local_flags & O_CREAT) && !file_existed &&
457 return NT_STATUS_OBJECT_NAME_INVALID;
460 /* Actually do the open */
461 status = fd_open(conn, fsp, local_flags, unx_mode);
462 if (!NT_STATUS_IS_OK(status)) {
463 DEBUG(3,("Error opening file %s (%s) (local_flags=%d) "
464 "(flags=%d)\n", smb_fname_str_dbg(smb_fname),
465 nt_errstr(status),local_flags,flags));
469 if ((local_flags & O_CREAT) && !file_existed) {
471 /* Inherit the ACL if required */
472 if (lp_inherit_perms(SNUM(conn))) {
473 inherit_access_posix_acl(conn, parent_dir,
474 smb_fname->base_name,
478 /* Change the owner if required. */
479 if (lp_inherit_owner(SNUM(conn))) {
480 change_file_owner_to_parent(conn, parent_dir,
484 notify_fname(conn, NOTIFY_ACTION_ADDED,
485 FILE_NOTIFY_CHANGE_FILE_NAME,
486 smb_fname->base_name);
490 fsp->fh->fd = -1; /* What we used to call a stat open. */
492 uint32_t access_granted = 0;
494 status = smbd_check_open_rights(conn,
498 if (!NT_STATUS_IS_OK(status)) {
499 if (NT_STATUS_EQUAL(status, NT_STATUS_ACCESS_DENIED)) {
501 * On NT_STATUS_ACCESS_DENIED, access_granted
502 * contains the denied bits.
505 if ((access_mask & FILE_WRITE_ATTRIBUTES) &&
506 (access_granted & FILE_WRITE_ATTRIBUTES) &&
507 (lp_map_readonly(SNUM(conn)) ||
508 lp_map_archive(SNUM(conn)) ||
509 lp_map_hidden(SNUM(conn)) ||
510 lp_map_system(SNUM(conn)))) {
511 access_granted &= ~FILE_WRITE_ATTRIBUTES;
513 DEBUG(10,("open_file: "
522 if ((access_mask & DELETE_ACCESS) &&
523 (access_granted & DELETE_ACCESS) &&
524 can_delete_file_in_directory(conn,
526 /* Were we trying to do a stat open
527 * for delete and didn't get DELETE
528 * access (only) ? Check if the
529 * directory allows DELETE_CHILD.
531 * http://blogs.msdn.com/oldnewthing/archive/2004/06/04/148426.aspx
534 access_granted &= ~DELETE_ACCESS;
536 DEBUG(10,("open_file: "
544 if (access_granted != 0) {
545 DEBUG(10,("open_file: Access "
552 } else if (NT_STATUS_EQUAL(status, NT_STATUS_OBJECT_NAME_NOT_FOUND) &&
554 S_ISLNK(smb_fname->st.st_ex_mode)) {
555 /* This is a POSIX stat open for delete
556 * or rename on a symlink that points
558 DEBUG(10,("open_file: allowing POSIX "
559 "open on bad symlink %s\n",
563 DEBUG(10,("open_file: "
564 "smbd_check_open_rights on file "
566 smb_fname_str_dbg(smb_fname),
567 nt_errstr(status) ));
577 if (fsp->fh->fd == -1) {
578 ret = SMB_VFS_STAT(conn, smb_fname);
580 ret = SMB_VFS_FSTAT(fsp, &smb_fname->st);
581 /* If we have an fd, this stat should succeed. */
583 DEBUG(0,("Error doing fstat on open file %s "
585 smb_fname_str_dbg(smb_fname),
590 /* For a non-io open, this stat failing means file not found. JRA */
592 status = map_nt_error_from_unix(errno);
599 * POSIX allows read-only opens of directories. We don't
600 * want to do this (we use a different code path for this)
601 * so catch a directory open and return an EISDIR. JRA.
604 if(S_ISDIR(smb_fname->st.st_ex_mode)) {
607 return NT_STATUS_FILE_IS_A_DIRECTORY;
610 fsp->mode = smb_fname->st.st_ex_mode;
611 fsp->file_id = vfs_file_id_from_sbuf(conn, &smb_fname->st);
612 fsp->vuid = req ? req->vuid : UID_FIELD_INVALID;
613 fsp->file_pid = req ? req->smbpid : 0;
614 fsp->can_lock = True;
615 fsp->can_read = (access_mask & (FILE_READ_DATA)) ? True : False;
616 if (!CAN_WRITE(conn)) {
617 fsp->can_write = False;
619 fsp->can_write = (access_mask & (FILE_WRITE_DATA | FILE_APPEND_DATA)) ?
622 fsp->print_file = NULL;
623 fsp->modified = False;
624 fsp->sent_oplock_break = NO_BREAK_SENT;
625 fsp->is_directory = False;
626 if (conn->aio_write_behind_list &&
627 is_in_path(smb_fname->base_name, conn->aio_write_behind_list,
628 conn->case_sensitive)) {
629 fsp->aio_write_behind = True;
632 fsp->wcp = NULL; /* Write cache pointer. */
634 DEBUG(2,("%s opened file %s read=%s write=%s (numopen=%d)\n",
635 conn->server_info->unix_name,
636 smb_fname_str_dbg(smb_fname),
637 BOOLSTR(fsp->can_read), BOOLSTR(fsp->can_write),
638 conn->num_files_open));
644 /*******************************************************************
645 Return True if the filename is one of the special executable types.
646 ********************************************************************/
648 bool is_executable(const char *fname)
650 if ((fname = strrchr_m(fname,'.'))) {
651 if (strequal(fname,".com") ||
652 strequal(fname,".dll") ||
653 strequal(fname,".exe") ||
654 strequal(fname,".sym")) {
661 /****************************************************************************
662 Check if we can open a file with a share mode.
663 Returns True if conflict, False if not.
664 ****************************************************************************/
666 static bool share_conflict(struct share_mode_entry *entry,
670 DEBUG(10,("share_conflict: entry->access_mask = 0x%x, "
671 "entry->share_access = 0x%x, "
672 "entry->private_options = 0x%x\n",
673 (unsigned int)entry->access_mask,
674 (unsigned int)entry->share_access,
675 (unsigned int)entry->private_options));
677 DEBUG(10,("share_conflict: access_mask = 0x%x, share_access = 0x%x\n",
678 (unsigned int)access_mask, (unsigned int)share_access));
680 if ((entry->access_mask & (FILE_WRITE_DATA|
684 DELETE_ACCESS)) == 0) {
685 DEBUG(10,("share_conflict: No conflict due to "
686 "entry->access_mask = 0x%x\n",
687 (unsigned int)entry->access_mask ));
691 if ((access_mask & (FILE_WRITE_DATA|
695 DELETE_ACCESS)) == 0) {
696 DEBUG(10,("share_conflict: No conflict due to "
697 "access_mask = 0x%x\n",
698 (unsigned int)access_mask ));
702 #if 1 /* JRA TEST - Superdebug. */
703 #define CHECK_MASK(num, am, right, sa, share) \
704 DEBUG(10,("share_conflict: [%d] am (0x%x) & right (0x%x) = 0x%x\n", \
705 (unsigned int)(num), (unsigned int)(am), \
706 (unsigned int)(right), (unsigned int)(am)&(right) )); \
707 DEBUG(10,("share_conflict: [%d] sa (0x%x) & share (0x%x) = 0x%x\n", \
708 (unsigned int)(num), (unsigned int)(sa), \
709 (unsigned int)(share), (unsigned int)(sa)&(share) )); \
710 if (((am) & (right)) && !((sa) & (share))) { \
711 DEBUG(10,("share_conflict: check %d conflict am = 0x%x, right = 0x%x, \
712 sa = 0x%x, share = 0x%x\n", (num), (unsigned int)(am), (unsigned int)(right), (unsigned int)(sa), \
713 (unsigned int)(share) )); \
717 #define CHECK_MASK(num, am, right, sa, share) \
718 if (((am) & (right)) && !((sa) & (share))) { \
719 DEBUG(10,("share_conflict: check %d conflict am = 0x%x, right = 0x%x, \
720 sa = 0x%x, share = 0x%x\n", (num), (unsigned int)(am), (unsigned int)(right), (unsigned int)(sa), \
721 (unsigned int)(share) )); \
726 CHECK_MASK(1, entry->access_mask, FILE_WRITE_DATA | FILE_APPEND_DATA,
727 share_access, FILE_SHARE_WRITE);
728 CHECK_MASK(2, access_mask, FILE_WRITE_DATA | FILE_APPEND_DATA,
729 entry->share_access, FILE_SHARE_WRITE);
731 CHECK_MASK(3, entry->access_mask, FILE_READ_DATA | FILE_EXECUTE,
732 share_access, FILE_SHARE_READ);
733 CHECK_MASK(4, access_mask, FILE_READ_DATA | FILE_EXECUTE,
734 entry->share_access, FILE_SHARE_READ);
736 CHECK_MASK(5, entry->access_mask, DELETE_ACCESS,
737 share_access, FILE_SHARE_DELETE);
738 CHECK_MASK(6, access_mask, DELETE_ACCESS,
739 entry->share_access, FILE_SHARE_DELETE);
741 DEBUG(10,("share_conflict: No conflict.\n"));
745 #if defined(DEVELOPER)
746 static void validate_my_share_entries(int num,
747 struct share_mode_entry *share_entry)
751 if (!procid_is_me(&share_entry->pid)) {
755 if (is_deferred_open_entry(share_entry) &&
756 !open_was_deferred(share_entry->op_mid)) {
757 char *str = talloc_asprintf(talloc_tos(),
758 "Got a deferred entry without a request: "
760 share_mode_str(talloc_tos(), num, share_entry));
764 if (!is_valid_share_mode_entry(share_entry)) {
768 fsp = file_find_dif(smbd_server_conn, share_entry->id,
769 share_entry->share_file_id);
771 DEBUG(0,("validate_my_share_entries: PANIC : %s\n",
772 share_mode_str(talloc_tos(), num, share_entry) ));
773 smb_panic("validate_my_share_entries: Cannot match a "
774 "share entry with an open file\n");
777 if (is_deferred_open_entry(share_entry) ||
778 is_unused_share_mode_entry(share_entry)) {
782 if ((share_entry->op_type == NO_OPLOCK) &&
783 (fsp->oplock_type == FAKE_LEVEL_II_OPLOCK)) {
784 /* Someone has already written to it, but I haven't yet
789 if (((uint16)fsp->oplock_type) != share_entry->op_type) {
798 DEBUG(0,("validate_my_share_entries: PANIC : %s\n",
799 share_mode_str(talloc_tos(), num, share_entry) ));
800 str = talloc_asprintf(talloc_tos(),
801 "validate_my_share_entries: "
802 "file %s, oplock_type = 0x%x, op_type = 0x%x\n",
803 fsp->fsp_name->base_name,
804 (unsigned int)fsp->oplock_type,
805 (unsigned int)share_entry->op_type );
811 bool is_stat_open(uint32 access_mask)
813 return (access_mask &&
814 ((access_mask & ~(SYNCHRONIZE_ACCESS| FILE_READ_ATTRIBUTES|
815 FILE_WRITE_ATTRIBUTES))==0) &&
816 ((access_mask & (SYNCHRONIZE_ACCESS|FILE_READ_ATTRIBUTES|
817 FILE_WRITE_ATTRIBUTES)) != 0));
820 /****************************************************************************
821 Deal with share modes
822 Invarient: Share mode must be locked on entry and exit.
823 Returns -1 on error, or number of share modes on success (may be zero).
824 ****************************************************************************/
826 static NTSTATUS open_mode_check(connection_struct *conn,
827 struct share_mode_lock *lck,
830 uint32 create_options,
835 if(lck->num_share_modes == 0) {
839 *file_existed = True;
841 /* A delete on close prohibits everything */
843 if (lck->delete_on_close) {
844 return NT_STATUS_DELETE_PENDING;
847 if (is_stat_open(access_mask)) {
848 /* Stat open that doesn't trigger oplock breaks or share mode
849 * checks... ! JRA. */
854 * Check if the share modes will give us access.
857 #if defined(DEVELOPER)
858 for(i = 0; i < lck->num_share_modes; i++) {
859 validate_my_share_entries(i, &lck->share_modes[i]);
863 if (!lp_share_modes(SNUM(conn))) {
867 /* Now we check the share modes, after any oplock breaks. */
868 for(i = 0; i < lck->num_share_modes; i++) {
870 if (!is_valid_share_mode_entry(&lck->share_modes[i])) {
874 /* someone else has a share lock on it, check to see if we can
876 if (share_conflict(&lck->share_modes[i],
877 access_mask, share_access)) {
878 return NT_STATUS_SHARING_VIOLATION;
885 static bool is_delete_request(files_struct *fsp) {
886 return ((fsp->access_mask == DELETE_ACCESS) &&
887 (fsp->oplock_type == NO_OPLOCK));
891 * Send a break message to the oplock holder and delay the open for
895 static NTSTATUS send_break_message(files_struct *fsp,
896 struct share_mode_entry *exclusive,
901 char msg[MSG_SMB_SHARE_MODE_ENTRY_SIZE];
903 DEBUG(10, ("Sending break request to PID %s\n",
904 procid_str_static(&exclusive->pid)));
905 exclusive->op_mid = mid;
907 /* Create the message. */
908 share_mode_entry_to_message(msg, exclusive);
910 /* Add in the FORCE_OPLOCK_BREAK_TO_NONE bit in the message if set. We
911 don't want this set in the share mode struct pointed to by lck. */
913 if (oplock_request & FORCE_OPLOCK_BREAK_TO_NONE) {
914 SSVAL(msg,OP_BREAK_MSG_OP_TYPE_OFFSET,
915 exclusive->op_type | FORCE_OPLOCK_BREAK_TO_NONE);
918 status = messaging_send_buf(fsp->conn->sconn->msg_ctx, exclusive->pid,
919 MSG_SMB_BREAK_REQUEST,
921 MSG_SMB_SHARE_MODE_ENTRY_SIZE);
922 if (!NT_STATUS_IS_OK(status)) {
923 DEBUG(3, ("Could not send oplock break message: %s\n",
931 * 1) No files open at all or internal open: Grant whatever the client wants.
933 * 2) Exclusive (or batch) oplock around: If the requested access is a delete
934 * request, break if the oplock around is a batch oplock. If it's another
935 * requested access type, break.
937 * 3) Only level2 around: Grant level2 and do nothing else.
940 static bool delay_for_oplocks(struct share_mode_lock *lck,
947 struct share_mode_entry *exclusive = NULL;
948 bool valid_entry = false;
949 bool have_level2 = false;
950 bool have_a_none_oplock = false;
951 bool allow_level2 = (global_client_caps & CAP_LEVEL_II_OPLOCKS) &&
952 lp_level2_oplocks(SNUM(fsp->conn));
954 if (oplock_request & INTERNAL_OPEN_ONLY) {
955 fsp->oplock_type = NO_OPLOCK;
958 if ((oplock_request & INTERNAL_OPEN_ONLY) || is_stat_open(fsp->access_mask)) {
962 for (i=0; i<lck->num_share_modes; i++) {
964 if (!is_valid_share_mode_entry(&lck->share_modes[i])) {
968 /* At least one entry is not an invalid or deferred entry. */
971 if (pass_number == 1) {
972 if (BATCH_OPLOCK_TYPE(lck->share_modes[i].op_type)) {
973 SMB_ASSERT(exclusive == NULL);
974 exclusive = &lck->share_modes[i];
977 if (EXCLUSIVE_OPLOCK_TYPE(lck->share_modes[i].op_type)) {
978 SMB_ASSERT(exclusive == NULL);
979 exclusive = &lck->share_modes[i];
983 if (LEVEL_II_OPLOCK_TYPE(lck->share_modes[i].op_type)) {
984 SMB_ASSERT(exclusive == NULL);
988 if (lck->share_modes[i].op_type == NO_OPLOCK) {
989 have_a_none_oplock = true;
993 if (exclusive != NULL) { /* Found an exclusive oplock */
994 bool delay_it = is_delete_request(fsp) ?
995 BATCH_OPLOCK_TYPE(exclusive->op_type) : true;
996 SMB_ASSERT(!have_level2);
998 send_break_message(fsp, exclusive, mid, oplock_request);
1004 * Match what was requested (fsp->oplock_type) with
1005 * what was found in the existing share modes.
1009 /* All entries are placeholders or deferred.
1010 * Directly grant whatever the client wants. */
1011 if (fsp->oplock_type == NO_OPLOCK) {
1012 /* Store a level2 oplock, but don't tell the client */
1013 fsp->oplock_type = FAKE_LEVEL_II_OPLOCK;
1015 } else if (have_a_none_oplock) {
1016 fsp->oplock_type = NO_OPLOCK;
1017 } else if (have_level2) {
1018 if (fsp->oplock_type == NO_OPLOCK ||
1019 fsp->oplock_type == FAKE_LEVEL_II_OPLOCK) {
1020 /* Store a level2 oplock, but don't tell the client */
1021 fsp->oplock_type = FAKE_LEVEL_II_OPLOCK;
1023 fsp->oplock_type = LEVEL_II_OPLOCK;
1026 /* This case can never happen. */
1031 * Don't grant level2 to clients that don't want them
1032 * or if we've turned them off.
1034 if (fsp->oplock_type == LEVEL_II_OPLOCK && !allow_level2) {
1035 fsp->oplock_type = FAKE_LEVEL_II_OPLOCK;
1038 DEBUG(10,("delay_for_oplocks: oplock type 0x%x on file %s\n",
1039 fsp->oplock_type, fsp_str_dbg(fsp)));
1045 bool request_timed_out(struct timeval request_time,
1046 struct timeval timeout)
1048 struct timeval now, end_time;
1050 end_time = timeval_sum(&request_time, &timeout);
1051 return (timeval_compare(&end_time, &now) < 0);
1054 /****************************************************************************
1055 Handle the 1 second delay in returning a SHARING_VIOLATION error.
1056 ****************************************************************************/
1058 static void defer_open(struct share_mode_lock *lck,
1059 struct timeval request_time,
1060 struct timeval timeout,
1061 struct smb_request *req,
1062 struct deferred_open_record *state)
1066 /* Paranoia check */
1068 for (i=0; i<lck->num_share_modes; i++) {
1069 struct share_mode_entry *e = &lck->share_modes[i];
1071 if (!is_deferred_open_entry(e)) {
1075 if (procid_is_me(&e->pid) && (e->op_mid == req->mid)) {
1076 DEBUG(0, ("Trying to defer an already deferred "
1077 "request: mid=%llu, exiting\n",
1078 (unsigned long long)req->mid));
1079 exit_server("attempt to defer a deferred request");
1083 /* End paranoia check */
1085 DEBUG(10,("defer_open_sharing_error: time [%u.%06u] adding deferred "
1086 "open entry for mid %llu\n",
1087 (unsigned int)request_time.tv_sec,
1088 (unsigned int)request_time.tv_usec,
1089 (unsigned long long)req->mid));
1091 if (!push_deferred_open_message_smb(req, request_time, timeout,
1092 state->id, (char *)state, sizeof(*state))) {
1093 exit_server("push_deferred_open_message_smb failed");
1095 add_deferred_open(lck, req->mid, request_time,
1096 sconn_server_id(req->sconn), state->id);
1100 /****************************************************************************
1101 On overwrite open ensure that the attributes match.
1102 ****************************************************************************/
1104 bool open_match_attributes(connection_struct *conn,
1105 uint32 old_dos_attr,
1106 uint32 new_dos_attr,
1107 mode_t existing_unx_mode,
1108 mode_t new_unx_mode,
1109 mode_t *returned_unx_mode)
1111 uint32 noarch_old_dos_attr, noarch_new_dos_attr;
1113 noarch_old_dos_attr = (old_dos_attr & ~FILE_ATTRIBUTE_ARCHIVE);
1114 noarch_new_dos_attr = (new_dos_attr & ~FILE_ATTRIBUTE_ARCHIVE);
1116 if((noarch_old_dos_attr == 0 && noarch_new_dos_attr != 0) ||
1117 (noarch_old_dos_attr != 0 && ((noarch_old_dos_attr & noarch_new_dos_attr) == noarch_old_dos_attr))) {
1118 *returned_unx_mode = new_unx_mode;
1120 *returned_unx_mode = (mode_t)0;
1123 DEBUG(10,("open_match_attributes: old_dos_attr = 0x%x, "
1124 "existing_unx_mode = 0%o, new_dos_attr = 0x%x "
1125 "returned_unx_mode = 0%o\n",
1126 (unsigned int)old_dos_attr,
1127 (unsigned int)existing_unx_mode,
1128 (unsigned int)new_dos_attr,
1129 (unsigned int)*returned_unx_mode ));
1131 /* If we're mapping SYSTEM and HIDDEN ensure they match. */
1132 if (lp_map_system(SNUM(conn)) || lp_store_dos_attributes(SNUM(conn))) {
1133 if ((old_dos_attr & FILE_ATTRIBUTE_SYSTEM) &&
1134 !(new_dos_attr & FILE_ATTRIBUTE_SYSTEM)) {
1138 if (lp_map_hidden(SNUM(conn)) || lp_store_dos_attributes(SNUM(conn))) {
1139 if ((old_dos_attr & FILE_ATTRIBUTE_HIDDEN) &&
1140 !(new_dos_attr & FILE_ATTRIBUTE_HIDDEN)) {
1147 /****************************************************************************
1148 Special FCB or DOS processing in the case of a sharing violation.
1149 Try and find a duplicated file handle.
1150 ****************************************************************************/
1152 NTSTATUS fcb_or_dos_open(struct smb_request *req,
1153 connection_struct *conn,
1154 files_struct *fsp_to_dup_into,
1155 const struct smb_filename *smb_fname,
1160 uint32 share_access,
1161 uint32 create_options)
1165 DEBUG(5,("fcb_or_dos_open: attempting old open semantics for "
1166 "file %s.\n", smb_fname_str_dbg(smb_fname)));
1168 for(fsp = file_find_di_first(conn->sconn, id); fsp;
1169 fsp = file_find_di_next(fsp)) {
1171 DEBUG(10,("fcb_or_dos_open: checking file %s, fd = %d, "
1172 "vuid = %u, file_pid = %u, private_options = 0x%x "
1173 "access_mask = 0x%x\n", fsp_str_dbg(fsp),
1174 fsp->fh->fd, (unsigned int)fsp->vuid,
1175 (unsigned int)fsp->file_pid,
1176 (unsigned int)fsp->fh->private_options,
1177 (unsigned int)fsp->access_mask ));
1179 if (fsp->fh->fd != -1 &&
1180 fsp->vuid == vuid &&
1181 fsp->file_pid == file_pid &&
1182 (fsp->fh->private_options & (NTCREATEX_OPTIONS_PRIVATE_DENY_DOS |
1183 NTCREATEX_OPTIONS_PRIVATE_DENY_FCB)) &&
1184 (fsp->access_mask & FILE_WRITE_DATA) &&
1185 strequal(fsp->fsp_name->base_name, smb_fname->base_name) &&
1186 strequal(fsp->fsp_name->stream_name,
1187 smb_fname->stream_name)) {
1188 DEBUG(10,("fcb_or_dos_open: file match\n"));
1194 return NT_STATUS_NOT_FOUND;
1197 /* quite an insane set of semantics ... */
1198 if (is_executable(smb_fname->base_name) &&
1199 (fsp->fh->private_options & NTCREATEX_OPTIONS_PRIVATE_DENY_DOS)) {
1200 DEBUG(10,("fcb_or_dos_open: file fail due to is_executable.\n"));
1201 return NT_STATUS_INVALID_PARAMETER;
1204 /* We need to duplicate this fsp. */
1205 return dup_file_fsp(req, fsp, access_mask, share_access,
1206 create_options, fsp_to_dup_into);
1209 /****************************************************************************
1210 Open a file with a share mode - old openX method - map into NTCreate.
1211 ****************************************************************************/
1213 bool map_open_params_to_ntcreate(const struct smb_filename *smb_fname,
1214 int deny_mode, int open_func,
1215 uint32 *paccess_mask,
1216 uint32 *pshare_mode,
1217 uint32 *pcreate_disposition,
1218 uint32 *pcreate_options,
1219 uint32_t *pprivate_flags)
1223 uint32 create_disposition;
1224 uint32 create_options = FILE_NON_DIRECTORY_FILE;
1225 uint32_t private_flags = 0;
1227 DEBUG(10,("map_open_params_to_ntcreate: fname = %s, deny_mode = 0x%x, "
1228 "open_func = 0x%x\n",
1229 smb_fname_str_dbg(smb_fname), (unsigned int)deny_mode,
1230 (unsigned int)open_func ));
1232 /* Create the NT compatible access_mask. */
1233 switch (GET_OPENX_MODE(deny_mode)) {
1234 case DOS_OPEN_EXEC: /* Implies read-only - used to be FILE_READ_DATA */
1235 case DOS_OPEN_RDONLY:
1236 access_mask = FILE_GENERIC_READ;
1238 case DOS_OPEN_WRONLY:
1239 access_mask = FILE_GENERIC_WRITE;
1243 access_mask = FILE_GENERIC_READ|FILE_GENERIC_WRITE;
1246 DEBUG(10,("map_open_params_to_ntcreate: bad open mode = 0x%x\n",
1247 (unsigned int)GET_OPENX_MODE(deny_mode)));
1251 /* Create the NT compatible create_disposition. */
1252 switch (open_func) {
1253 case OPENX_FILE_EXISTS_FAIL|OPENX_FILE_CREATE_IF_NOT_EXIST:
1254 create_disposition = FILE_CREATE;
1257 case OPENX_FILE_EXISTS_OPEN:
1258 create_disposition = FILE_OPEN;
1261 case OPENX_FILE_EXISTS_OPEN|OPENX_FILE_CREATE_IF_NOT_EXIST:
1262 create_disposition = FILE_OPEN_IF;
1265 case OPENX_FILE_EXISTS_TRUNCATE:
1266 create_disposition = FILE_OVERWRITE;
1269 case OPENX_FILE_EXISTS_TRUNCATE|OPENX_FILE_CREATE_IF_NOT_EXIST:
1270 create_disposition = FILE_OVERWRITE_IF;
1274 /* From samba4 - to be confirmed. */
1275 if (GET_OPENX_MODE(deny_mode) == DOS_OPEN_EXEC) {
1276 create_disposition = FILE_CREATE;
1279 DEBUG(10,("map_open_params_to_ntcreate: bad "
1280 "open_func 0x%x\n", (unsigned int)open_func));
1284 /* Create the NT compatible share modes. */
1285 switch (GET_DENY_MODE(deny_mode)) {
1287 share_mode = FILE_SHARE_NONE;
1291 share_mode = FILE_SHARE_READ;
1295 share_mode = FILE_SHARE_WRITE;
1299 share_mode = FILE_SHARE_READ|FILE_SHARE_WRITE;
1303 private_flags |= NTCREATEX_OPTIONS_PRIVATE_DENY_DOS;
1304 if (is_executable(smb_fname->base_name)) {
1305 share_mode = FILE_SHARE_READ|FILE_SHARE_WRITE;
1307 if (GET_OPENX_MODE(deny_mode) == DOS_OPEN_RDONLY) {
1308 share_mode = FILE_SHARE_READ;
1310 share_mode = FILE_SHARE_NONE;
1316 private_flags |= NTCREATEX_OPTIONS_PRIVATE_DENY_FCB;
1317 share_mode = FILE_SHARE_NONE;
1321 DEBUG(10,("map_open_params_to_ntcreate: bad deny_mode 0x%x\n",
1322 (unsigned int)GET_DENY_MODE(deny_mode) ));
1326 DEBUG(10,("map_open_params_to_ntcreate: file %s, access_mask = 0x%x, "
1327 "share_mode = 0x%x, create_disposition = 0x%x, "
1328 "create_options = 0x%x private_flags = 0x%x\n",
1329 smb_fname_str_dbg(smb_fname),
1330 (unsigned int)access_mask,
1331 (unsigned int)share_mode,
1332 (unsigned int)create_disposition,
1333 (unsigned int)create_options,
1334 (unsigned int)private_flags));
1337 *paccess_mask = access_mask;
1340 *pshare_mode = share_mode;
1342 if (pcreate_disposition) {
1343 *pcreate_disposition = create_disposition;
1345 if (pcreate_options) {
1346 *pcreate_options = create_options;
1348 if (pprivate_flags) {
1349 *pprivate_flags = private_flags;
1356 static void schedule_defer_open(struct share_mode_lock *lck,
1357 struct timeval request_time,
1358 struct smb_request *req)
1360 struct deferred_open_record state;
1362 /* This is a relative time, added to the absolute
1363 request_time value to get the absolute timeout time.
1364 Note that if this is the second or greater time we enter
1365 this codepath for this particular request mid then
1366 request_time is left as the absolute time of the *first*
1367 time this request mid was processed. This is what allows
1368 the request to eventually time out. */
1370 struct timeval timeout;
1372 /* Normally the smbd we asked should respond within
1373 * OPLOCK_BREAK_TIMEOUT seconds regardless of whether
1374 * the client did, give twice the timeout as a safety
1375 * measure here in case the other smbd is stuck
1376 * somewhere else. */
1378 timeout = timeval_set(OPLOCK_BREAK_TIMEOUT*2, 0);
1380 /* Nothing actually uses state.delayed_for_oplocks
1381 but it's handy to differentiate in debug messages
1382 between a 30 second delay due to oplock break, and
1383 a 1 second delay for share mode conflicts. */
1385 state.delayed_for_oplocks = True;
1388 if (!request_timed_out(request_time, timeout)) {
1389 defer_open(lck, request_time, timeout, req, &state);
1393 /****************************************************************************
1394 Work out what access_mask to use from what the client sent us.
1395 ****************************************************************************/
1397 static NTSTATUS calculate_access_mask(connection_struct *conn,
1398 const struct smb_filename *smb_fname,
1400 uint32_t access_mask,
1401 uint32_t *access_mask_out)
1406 * Convert GENERIC bits to specific bits.
1409 se_map_generic(&access_mask, &file_generic_mapping);
1411 /* Calculate MAXIMUM_ALLOWED_ACCESS if requested. */
1412 if (access_mask & MAXIMUM_ALLOWED_ACCESS) {
1415 struct security_descriptor *sd;
1416 uint32_t access_granted = 0;
1418 status = SMB_VFS_GET_NT_ACL(conn, smb_fname->base_name,
1423 if (!NT_STATUS_IS_OK(status)) {
1424 DEBUG(10, ("calculate_access_mask: Could not get acl "
1426 smb_fname_str_dbg(smb_fname),
1427 nt_errstr(status)));
1428 return NT_STATUS_ACCESS_DENIED;
1431 status = smb1_file_se_access_check(conn,
1433 get_current_nttok(conn),
1439 if (!NT_STATUS_IS_OK(status)) {
1440 DEBUG(10, ("calculate_access_mask: Access denied on "
1441 "file %s: when calculating maximum access\n",
1442 smb_fname_str_dbg(smb_fname)));
1443 return NT_STATUS_ACCESS_DENIED;
1446 access_mask = access_granted;
1448 access_mask = FILE_GENERIC_ALL;
1452 *access_mask_out = access_mask;
1453 return NT_STATUS_OK;
1456 /****************************************************************************
1457 Remove the deferred open entry under lock.
1458 ****************************************************************************/
1460 void remove_deferred_open_entry(struct file_id id, uint64_t mid,
1461 struct server_id pid)
1463 struct share_mode_lock *lck = get_share_mode_lock(talloc_tos(), id,
1466 DEBUG(0, ("could not get share mode lock\n"));
1468 del_deferred_open_entry(lck, mid, pid);
1473 /****************************************************************************
1474 Open a file with a share mode. Passed in an already created files_struct *.
1475 ****************************************************************************/
1477 static NTSTATUS open_file_ntcreate(connection_struct *conn,
1478 struct smb_request *req,
1479 uint32 access_mask, /* access bits (FILE_READ_DATA etc.) */
1480 uint32 share_access, /* share constants (FILE_SHARE_READ etc) */
1481 uint32 create_disposition, /* FILE_OPEN_IF etc. */
1482 uint32 create_options, /* options such as delete on close. */
1483 uint32 new_dos_attributes, /* attributes used for new file. */
1484 int oplock_request, /* internal Samba oplock codes. */
1485 /* Information (FILE_EXISTS etc.) */
1486 uint32_t private_flags, /* Samba specific flags. */
1490 struct smb_filename *smb_fname = fsp->fsp_name;
1493 bool file_existed = VALID_STAT(smb_fname->st);
1494 bool def_acl = False;
1495 bool posix_open = False;
1496 bool new_file_created = False;
1497 bool clear_ads = false;
1499 NTSTATUS fsp_open = NT_STATUS_ACCESS_DENIED;
1500 mode_t new_unx_mode = (mode_t)0;
1501 mode_t unx_mode = (mode_t)0;
1503 uint32 existing_dos_attributes = 0;
1504 struct timeval request_time = timeval_zero();
1505 struct share_mode_lock *lck = NULL;
1506 uint32 open_access_mask = access_mask;
1512 if (conn->printer) {
1514 * Printers are handled completely differently.
1515 * Most of the passed parameters are ignored.
1519 *pinfo = FILE_WAS_CREATED;
1522 DEBUG(10, ("open_file_ntcreate: printer open fname=%s\n",
1523 smb_fname_str_dbg(smb_fname)));
1526 DEBUG(0,("open_file_ntcreate: printer open without "
1527 "an SMB request!\n"));
1528 return NT_STATUS_INTERNAL_ERROR;
1531 return print_spool_open(fsp, smb_fname->base_name,
1535 if (!parent_dirname(talloc_tos(), smb_fname->base_name, &parent_dir,
1537 return NT_STATUS_NO_MEMORY;
1540 if (new_dos_attributes & FILE_FLAG_POSIX_SEMANTICS) {
1542 unx_mode = (mode_t)(new_dos_attributes & ~FILE_FLAG_POSIX_SEMANTICS);
1543 new_dos_attributes = 0;
1545 /* We add aARCH to this as this mode is only used if the file is
1547 unx_mode = unix_mode(conn, new_dos_attributes | aARCH,
1548 smb_fname, parent_dir);
1551 DEBUG(10, ("open_file_ntcreate: fname=%s, dos_attrs=0x%x "
1552 "access_mask=0x%x share_access=0x%x "
1553 "create_disposition = 0x%x create_options=0x%x "
1554 "unix mode=0%o oplock_request=%d private_flags = 0x%x\n",
1555 smb_fname_str_dbg(smb_fname), new_dos_attributes,
1556 access_mask, share_access, create_disposition,
1557 create_options, (unsigned int)unx_mode, oplock_request,
1558 (unsigned int)private_flags));
1560 if ((req == NULL) && ((oplock_request & INTERNAL_OPEN_ONLY) == 0)) {
1561 DEBUG(0, ("No smb request but not an internal only open!\n"));
1562 return NT_STATUS_INTERNAL_ERROR;
1566 * Only non-internal opens can be deferred at all
1571 if (get_deferred_open_message_state(req,
1575 struct deferred_open_record *state = (struct deferred_open_record *)ptr;
1576 /* Remember the absolute time of the original
1577 request with this mid. We'll use it later to
1578 see if this has timed out. */
1580 /* Remove the deferred open entry under lock. */
1581 remove_deferred_open_entry(
1582 state->id, req->mid,
1583 sconn_server_id(req->sconn));
1585 /* Ensure we don't reprocess this message. */
1586 remove_deferred_open_message_smb(req->mid);
1590 status = check_name(conn, smb_fname->base_name);
1591 if (!NT_STATUS_IS_OK(status)) {
1596 new_dos_attributes &= SAMBA_ATTRIBUTES_MASK;
1598 existing_dos_attributes = dos_mode(conn, smb_fname);
1602 /* ignore any oplock requests if oplocks are disabled */
1603 if (!lp_oplocks(SNUM(conn)) ||
1604 IS_VETO_OPLOCK_PATH(conn, smb_fname->base_name)) {
1605 /* Mask off everything except the private Samba bits. */
1606 oplock_request &= SAMBA_PRIVATE_OPLOCK_MASK;
1609 /* this is for OS/2 long file names - say we don't support them */
1610 if (!lp_posix_pathnames() && strstr(smb_fname->base_name,".+,;=[].")) {
1611 /* OS/2 Workplace shell fix may be main code stream in a later
1613 DEBUG(5,("open_file_ntcreate: OS/2 long filenames are not "
1615 if (use_nt_status()) {
1616 return NT_STATUS_OBJECT_NAME_NOT_FOUND;
1618 return NT_STATUS_DOS(ERRDOS, ERRcannotopen);
1621 switch( create_disposition ) {
1623 * Currently we're using FILE_SUPERSEDE as the same as
1624 * FILE_OVERWRITE_IF but they really are
1625 * different. FILE_SUPERSEDE deletes an existing file
1626 * (requiring delete access) then recreates it.
1628 case FILE_SUPERSEDE:
1629 /* If file exists replace/overwrite. If file doesn't
1631 flags2 |= (O_CREAT | O_TRUNC);
1635 case FILE_OVERWRITE_IF:
1636 /* If file exists replace/overwrite. If file doesn't
1638 flags2 |= (O_CREAT | O_TRUNC);
1643 /* If file exists open. If file doesn't exist error. */
1644 if (!file_existed) {
1645 DEBUG(5,("open_file_ntcreate: FILE_OPEN "
1646 "requested for file %s and file "
1648 smb_fname_str_dbg(smb_fname)));
1650 return NT_STATUS_OBJECT_NAME_NOT_FOUND;
1654 case FILE_OVERWRITE:
1655 /* If file exists overwrite. If file doesn't exist
1657 if (!file_existed) {
1658 DEBUG(5,("open_file_ntcreate: FILE_OVERWRITE "
1659 "requested for file %s and file "
1661 smb_fname_str_dbg(smb_fname) ));
1663 return NT_STATUS_OBJECT_NAME_NOT_FOUND;
1670 /* If file exists error. If file doesn't exist
1673 DEBUG(5,("open_file_ntcreate: FILE_CREATE "
1674 "requested for file %s and file "
1675 "already exists.\n",
1676 smb_fname_str_dbg(smb_fname)));
1677 if (S_ISDIR(smb_fname->st.st_ex_mode)) {
1682 return map_nt_error_from_unix(errno);
1684 flags2 |= (O_CREAT|O_EXCL);
1688 /* If file exists open. If file doesn't exist
1694 return NT_STATUS_INVALID_PARAMETER;
1697 /* We only care about matching attributes on file exists and
1700 if (!posix_open && file_existed && ((create_disposition == FILE_OVERWRITE) ||
1701 (create_disposition == FILE_OVERWRITE_IF))) {
1702 if (!open_match_attributes(conn, existing_dos_attributes,
1704 smb_fname->st.st_ex_mode,
1705 unx_mode, &new_unx_mode)) {
1706 DEBUG(5,("open_file_ntcreate: attributes missmatch "
1707 "for file %s (%x %x) (0%o, 0%o)\n",
1708 smb_fname_str_dbg(smb_fname),
1709 existing_dos_attributes,
1711 (unsigned int)smb_fname->st.st_ex_mode,
1712 (unsigned int)unx_mode ));
1714 return NT_STATUS_ACCESS_DENIED;
1718 status = calculate_access_mask(conn, smb_fname, file_existed,
1721 if (!NT_STATUS_IS_OK(status)) {
1722 DEBUG(10, ("open_file_ntcreate: calculate_access_mask "
1723 "on file %s returned %s\n",
1724 smb_fname_str_dbg(smb_fname), nt_errstr(status)));
1728 open_access_mask = access_mask;
1730 if ((flags2 & O_TRUNC) || (oplock_request & FORCE_OPLOCK_BREAK_TO_NONE)) {
1731 open_access_mask |= FILE_WRITE_DATA; /* This will cause oplock breaks. */
1734 DEBUG(10, ("open_file_ntcreate: fname=%s, after mapping "
1735 "access_mask=0x%x\n", smb_fname_str_dbg(smb_fname),
1739 * Note that we ignore the append flag as append does not
1740 * mean the same thing under DOS and Unix.
1743 if ((access_mask & (FILE_WRITE_DATA | FILE_APPEND_DATA)) ||
1744 (oplock_request & FORCE_OPLOCK_BREAK_TO_NONE)) {
1745 /* DENY_DOS opens are always underlying read-write on the
1746 file handle, no matter what the requested access mask
1748 if ((private_flags & NTCREATEX_OPTIONS_PRIVATE_DENY_DOS) ||
1749 access_mask & (FILE_READ_ATTRIBUTES|FILE_READ_DATA|FILE_READ_EA|FILE_EXECUTE)) {
1759 * Currently we only look at FILE_WRITE_THROUGH for create options.
1763 if ((create_options & FILE_WRITE_THROUGH) && lp_strict_sync(SNUM(conn))) {
1768 if (posix_open && (access_mask & FILE_APPEND_DATA)) {
1772 if (!posix_open && !CAN_WRITE(conn)) {
1774 * We should really return a permission denied error if either
1775 * O_CREAT or O_TRUNC are set, but for compatibility with
1776 * older versions of Samba we just AND them out.
1778 flags2 &= ~(O_CREAT|O_TRUNC);
1782 * Ensure we can't write on a read-only share or file.
1785 if (flags != O_RDONLY && file_existed &&
1786 (!CAN_WRITE(conn) || IS_DOS_READONLY(existing_dos_attributes))) {
1787 DEBUG(5,("open_file_ntcreate: write access requested for "
1788 "file %s on read only %s\n",
1789 smb_fname_str_dbg(smb_fname),
1790 !CAN_WRITE(conn) ? "share" : "file" ));
1792 return NT_STATUS_ACCESS_DENIED;
1795 fsp->file_id = vfs_file_id_from_sbuf(conn, &smb_fname->st);
1796 fsp->share_access = share_access;
1797 fsp->fh->private_options = private_flags;
1798 fsp->access_mask = open_access_mask; /* We change this to the
1799 * requested access_mask after
1800 * the open is done. */
1801 fsp->posix_open = posix_open;
1803 /* Ensure no SAMBA_PRIVATE bits can be set. */
1804 fsp->oplock_type = (oplock_request & ~SAMBA_PRIVATE_OPLOCK_MASK);
1806 if (timeval_is_zero(&request_time)) {
1807 request_time = fsp->open_time;
1811 struct timespec old_write_time = smb_fname->st.st_ex_mtime;
1812 id = vfs_file_id_from_sbuf(conn, &smb_fname->st);
1814 lck = get_share_mode_lock(talloc_tos(), id,
1816 smb_fname, &old_write_time);
1819 DEBUG(0, ("Could not get share mode lock\n"));
1820 return NT_STATUS_SHARING_VIOLATION;
1823 /* First pass - send break only on batch oplocks. */
1825 && delay_for_oplocks(lck, fsp, req->mid, 1,
1827 schedule_defer_open(lck, request_time, req);
1829 return NT_STATUS_SHARING_VIOLATION;
1832 /* Use the client requested access mask here, not the one we
1834 status = open_mode_check(conn, lck, access_mask, share_access,
1835 create_options, &file_existed);
1837 if (NT_STATUS_IS_OK(status)) {
1838 /* We might be going to allow this open. Check oplock
1840 /* Second pass - send break for both batch or
1841 * exclusive oplocks. */
1843 && delay_for_oplocks(lck, fsp, req->mid, 2,
1845 schedule_defer_open(lck, request_time, req);
1847 return NT_STATUS_SHARING_VIOLATION;
1851 if (NT_STATUS_EQUAL(status, NT_STATUS_DELETE_PENDING)) {
1852 /* DELETE_PENDING is not deferred for a second */
1857 if (!NT_STATUS_IS_OK(status)) {
1858 uint32 can_access_mask;
1859 bool can_access = True;
1861 SMB_ASSERT(NT_STATUS_EQUAL(status, NT_STATUS_SHARING_VIOLATION));
1863 /* Check if this can be done with the deny_dos and fcb
1866 (NTCREATEX_OPTIONS_PRIVATE_DENY_DOS|
1867 NTCREATEX_OPTIONS_PRIVATE_DENY_FCB)) {
1869 DEBUG(0, ("DOS open without an SMB "
1872 return NT_STATUS_INTERNAL_ERROR;
1875 /* Use the client requested access mask here,
1876 * not the one we open with. */
1877 status = fcb_or_dos_open(req,
1888 if (NT_STATUS_IS_OK(status)) {
1891 *pinfo = FILE_WAS_OPENED;
1893 return NT_STATUS_OK;
1898 * This next line is a subtlety we need for
1899 * MS-Access. If a file open will fail due to share
1900 * permissions and also for security (access) reasons,
1901 * we need to return the access failed error, not the
1902 * share error. We can't open the file due to kernel
1903 * oplock deadlock (it's possible we failed above on
1904 * the open_mode_check()) so use a userspace check.
1907 if (flags & O_RDWR) {
1908 can_access_mask = FILE_READ_DATA|FILE_WRITE_DATA;
1909 } else if (flags & O_WRONLY) {
1910 can_access_mask = FILE_WRITE_DATA;
1912 can_access_mask = FILE_READ_DATA;
1915 if (((can_access_mask & FILE_WRITE_DATA) &&
1916 !CAN_WRITE(conn)) ||
1917 !can_access_file_data(conn, smb_fname,
1923 * If we're returning a share violation, ensure we
1924 * cope with the braindead 1 second delay.
1927 if (!(oplock_request & INTERNAL_OPEN_ONLY) &&
1928 lp_defer_sharing_violations()) {
1929 struct timeval timeout;
1930 struct deferred_open_record state;
1933 /* this is a hack to speed up torture tests
1935 timeout_usecs = lp_parm_int(SNUM(conn),
1936 "smbd","sharedelay",
1937 SHARING_VIOLATION_USEC_WAIT);
1939 /* This is a relative time, added to the absolute
1940 request_time value to get the absolute timeout time.
1941 Note that if this is the second or greater time we enter
1942 this codepath for this particular request mid then
1943 request_time is left as the absolute time of the *first*
1944 time this request mid was processed. This is what allows
1945 the request to eventually time out. */
1947 timeout = timeval_set(0, timeout_usecs);
1949 /* Nothing actually uses state.delayed_for_oplocks
1950 but it's handy to differentiate in debug messages
1951 between a 30 second delay due to oplock break, and
1952 a 1 second delay for share mode conflicts. */
1954 state.delayed_for_oplocks = False;
1958 && !request_timed_out(request_time,
1960 defer_open(lck, request_time, timeout,
1968 * We have detected a sharing violation here
1969 * so return the correct error code
1971 status = NT_STATUS_SHARING_VIOLATION;
1973 status = NT_STATUS_ACCESS_DENIED;
1979 * We exit this block with the share entry *locked*.....
1983 SMB_ASSERT(!file_existed || (lck != NULL));
1986 * Ensure we pay attention to default ACLs on directories if required.
1989 if ((flags2 & O_CREAT) && lp_inherit_acls(SNUM(conn)) &&
1990 (def_acl = directory_has_default_acl(conn, parent_dir))) {
1994 DEBUG(4,("calling open_file with flags=0x%X flags2=0x%X mode=0%o, "
1995 "access_mask = 0x%x, open_access_mask = 0x%x\n",
1996 (unsigned int)flags, (unsigned int)flags2,
1997 (unsigned int)unx_mode, (unsigned int)access_mask,
1998 (unsigned int)open_access_mask));
2001 * open_file strips any O_TRUNC flags itself.
2004 fsp_open = open_file(fsp, conn, req, parent_dir,
2005 flags|flags2, unx_mode, access_mask,
2008 if (!NT_STATUS_IS_OK(fsp_open)) {
2015 if (!file_existed) {
2016 struct timespec old_write_time = smb_fname->st.st_ex_mtime;
2018 * Deal with the race condition where two smbd's detect the
2019 * file doesn't exist and do the create at the same time. One
2020 * of them will win and set a share mode, the other (ie. this
2021 * one) should check if the requested share mode for this
2022 * create is allowed.
2026 * Now the file exists and fsp is successfully opened,
2027 * fsp->dev and fsp->inode are valid and should replace the
2028 * dev=0,inode=0 from a non existent file. Spotted by
2029 * Nadav Danieli <nadavd@exanet.com>. JRA.
2034 lck = get_share_mode_lock(talloc_tos(), id,
2036 smb_fname, &old_write_time);
2039 DEBUG(0, ("open_file_ntcreate: Could not get share "
2040 "mode lock for %s\n",
2041 smb_fname_str_dbg(smb_fname)));
2043 return NT_STATUS_SHARING_VIOLATION;
2046 /* First pass - send break only on batch oplocks. */
2048 && delay_for_oplocks(lck, fsp, req->mid, 1,
2050 schedule_defer_open(lck, request_time, req);
2053 return NT_STATUS_SHARING_VIOLATION;
2056 status = open_mode_check(conn, lck, access_mask, share_access,
2057 create_options, &file_existed);
2059 if (NT_STATUS_IS_OK(status)) {
2060 /* We might be going to allow this open. Check oplock
2062 /* Second pass - send break for both batch or
2063 * exclusive oplocks. */
2065 && delay_for_oplocks(lck, fsp, req->mid, 2,
2067 schedule_defer_open(lck, request_time, req);
2070 return NT_STATUS_SHARING_VIOLATION;
2074 if (!NT_STATUS_IS_OK(status)) {
2075 struct deferred_open_record state;
2079 state.delayed_for_oplocks = False;
2082 /* Do it all over again immediately. In the second
2083 * round we will find that the file existed and handle
2084 * the DELETE_PENDING and FCB cases correctly. No need
2085 * to duplicate the code here. Essentially this is a
2086 * "goto top of this function", but don't tell
2090 defer_open(lck, request_time, timeval_zero(),
2098 * We exit this block with the share entry *locked*.....
2103 SMB_ASSERT(lck != NULL);
2105 /* Delete streams if create_disposition requires it */
2106 if (file_existed && clear_ads &&
2107 !is_ntfs_stream_smb_fname(smb_fname)) {
2108 status = delete_all_streams(conn, smb_fname->base_name);
2109 if (!NT_STATUS_IS_OK(status)) {
2116 /* note that we ignore failure for the following. It is
2117 basically a hack for NFS, and NFS will never set one of
2118 these only read them. Nobody but Samba can ever set a deny
2119 mode and we have already checked our more authoritative
2120 locking database for permission to set this deny mode. If
2121 the kernel refuses the operations then the kernel is wrong.
2122 note that GPFS supports it as well - jmcd */
2124 if (fsp->fh->fd != -1) {
2126 ret_flock = SMB_VFS_KERNEL_FLOCK(fsp, share_access, access_mask);
2127 if(ret_flock == -1 ){
2132 return NT_STATUS_SHARING_VIOLATION;
2137 * At this point onwards, we can guarentee that the share entry
2138 * is locked, whether we created the file or not, and that the
2139 * deny mode is compatible with all current opens.
2143 * If requested, truncate the file.
2146 if (file_existed && (flags2&O_TRUNC)) {
2148 * We are modifing the file after open - update the stat
2151 if ((SMB_VFS_FTRUNCATE(fsp, 0) == -1) ||
2152 (SMB_VFS_FSTAT(fsp, &smb_fname->st)==-1)) {
2153 status = map_nt_error_from_unix(errno);
2161 * According to Samba4, SEC_FILE_READ_ATTRIBUTE is always granted,
2163 fsp->access_mask = access_mask | FILE_READ_ATTRIBUTES;
2166 /* stat opens on existing files don't get oplocks. */
2167 if (is_stat_open(open_access_mask)) {
2168 fsp->oplock_type = NO_OPLOCK;
2171 if (!(flags2 & O_TRUNC)) {
2172 info = FILE_WAS_OPENED;
2174 info = FILE_WAS_OVERWRITTEN;
2177 info = FILE_WAS_CREATED;
2185 * Setup the oplock info in both the shared memory and
2189 if (!set_file_oplock(fsp, fsp->oplock_type)) {
2190 /* Could not get the kernel oplock */
2191 fsp->oplock_type = NO_OPLOCK;
2194 if (info == FILE_WAS_OVERWRITTEN || info == FILE_WAS_CREATED || info == FILE_WAS_SUPERSEDED) {
2195 new_file_created = True;
2198 set_share_mode(lck, fsp, get_current_uid(conn), 0,
2201 /* Handle strange delete on close create semantics. */
2202 if (create_options & FILE_DELETE_ON_CLOSE) {
2204 status = can_set_delete_on_close(fsp, new_dos_attributes);
2206 if (!NT_STATUS_IS_OK(status)) {
2207 /* Remember to delete the mode we just added. */
2208 del_share_mode(lck, fsp);
2213 /* Note that here we set the *inital* delete on close flag,
2214 not the regular one. The magic gets handled in close. */
2215 fsp->initial_delete_on_close = True;
2218 if (new_file_created) {
2219 /* Files should be initially set as archive */
2220 if (lp_map_archive(SNUM(conn)) ||
2221 lp_store_dos_attributes(SNUM(conn))) {
2223 if (file_set_dosmode(conn, smb_fname,
2224 new_dos_attributes | aARCH,
2225 parent_dir, true) == 0) {
2226 unx_mode = smb_fname->st.st_ex_mode;
2233 * Take care of inherited ACLs on created files - if default ACL not
2237 if (!posix_open && !file_existed && !def_acl) {
2239 int saved_errno = errno; /* We might get ENOSYS in the next
2242 if (SMB_VFS_FCHMOD_ACL(fsp, unx_mode) == -1 &&
2244 errno = saved_errno; /* Ignore ENOSYS */
2247 } else if (new_unx_mode) {
2251 /* Attributes need changing. File already existed. */
2254 int saved_errno = errno; /* We might get ENOSYS in the
2256 ret = SMB_VFS_FCHMOD_ACL(fsp, new_unx_mode);
2258 if (ret == -1 && errno == ENOSYS) {
2259 errno = saved_errno; /* Ignore ENOSYS */
2261 DEBUG(5, ("open_file_ntcreate: reset "
2262 "attributes of file %s to 0%o\n",
2263 smb_fname_str_dbg(smb_fname),
2264 (unsigned int)new_unx_mode));
2265 ret = 0; /* Don't do the fchmod below. */
2270 (SMB_VFS_FCHMOD(fsp, new_unx_mode) == -1))
2271 DEBUG(5, ("open_file_ntcreate: failed to reset "
2272 "attributes of file %s to 0%o\n",
2273 smb_fname_str_dbg(smb_fname),
2274 (unsigned int)new_unx_mode));
2277 /* If this is a successful open, we must remove any deferred open
2280 del_deferred_open_entry(lck, req->mid,
2281 sconn_server_id(req->sconn));
2285 return NT_STATUS_OK;
2289 /****************************************************************************
2290 Open a file for for write to ensure that we can fchmod it.
2291 ****************************************************************************/
2293 NTSTATUS open_file_fchmod(struct smb_request *req, connection_struct *conn,
2294 struct smb_filename *smb_fname,
2295 files_struct **result)
2297 files_struct *fsp = NULL;
2300 if (!VALID_STAT(smb_fname->st)) {
2301 return NT_STATUS_INVALID_PARAMETER;
2304 status = file_new(req, conn, &fsp);
2305 if(!NT_STATUS_IS_OK(status)) {
2309 status = SMB_VFS_CREATE_FILE(
2312 0, /* root_dir_fid */
2313 smb_fname, /* fname */
2314 FILE_WRITE_DATA, /* access_mask */
2315 (FILE_SHARE_READ | FILE_SHARE_WRITE | /* share_access */
2317 FILE_OPEN, /* create_disposition*/
2318 0, /* create_options */
2319 0, /* file_attributes */
2320 0, /* oplock_request */
2321 0, /* allocation_size */
2322 0, /* private_flags */
2329 * This is not a user visible file open.
2330 * Don't set a share mode.
2333 if (!NT_STATUS_IS_OK(status)) {
2334 file_free(req, fsp);
2339 return NT_STATUS_OK;
2342 /****************************************************************************
2343 Close the fchmod file fd - ensure no locks are lost.
2344 ****************************************************************************/
2346 NTSTATUS close_file_fchmod(struct smb_request *req, files_struct *fsp)
2348 NTSTATUS status = fd_close(fsp);
2349 file_free(req, fsp);
2353 static NTSTATUS mkdir_internal(connection_struct *conn,
2354 struct smb_filename *smb_dname,
2355 uint32 file_attributes)
2360 bool posix_open = false;
2362 if(!CAN_WRITE(conn)) {
2363 DEBUG(5,("mkdir_internal: failing create on read-only share "
2364 "%s\n", lp_servicename(SNUM(conn))));
2365 return NT_STATUS_ACCESS_DENIED;
2368 status = check_name(conn, smb_dname->base_name);
2369 if (!NT_STATUS_IS_OK(status)) {
2373 if (!parent_dirname(talloc_tos(), smb_dname->base_name, &parent_dir,
2375 return NT_STATUS_NO_MEMORY;
2378 if (file_attributes & FILE_FLAG_POSIX_SEMANTICS) {
2380 mode = (mode_t)(file_attributes & ~FILE_FLAG_POSIX_SEMANTICS);
2382 mode = unix_mode(conn, aDIR, smb_dname, parent_dir);
2385 if (SMB_VFS_MKDIR(conn, smb_dname->base_name, mode) != 0) {
2386 return map_nt_error_from_unix(errno);
2389 /* Ensure we're checking for a symlink here.... */
2390 /* We don't want to get caught by a symlink racer. */
2392 if (SMB_VFS_LSTAT(conn, smb_dname) == -1) {
2393 DEBUG(2, ("Could not stat directory '%s' just created: %s\n",
2394 smb_fname_str_dbg(smb_dname), strerror(errno)));
2395 return map_nt_error_from_unix(errno);
2398 if (!S_ISDIR(smb_dname->st.st_ex_mode)) {
2399 DEBUG(0, ("Directory just '%s' created is not a directory\n",
2400 smb_fname_str_dbg(smb_dname)));
2401 return NT_STATUS_ACCESS_DENIED;
2404 if (lp_store_dos_attributes(SNUM(conn))) {
2406 file_set_dosmode(conn, smb_dname,
2407 file_attributes | aDIR,
2412 if (lp_inherit_perms(SNUM(conn))) {
2413 inherit_access_posix_acl(conn, parent_dir,
2414 smb_dname->base_name, mode);
2419 * Check if high bits should have been set,
2420 * then (if bits are missing): add them.
2421 * Consider bits automagically set by UNIX, i.e. SGID bit from parent
2424 if ((mode & ~(S_IRWXU|S_IRWXG|S_IRWXO)) &&
2425 (mode & ~smb_dname->st.st_ex_mode)) {
2426 SMB_VFS_CHMOD(conn, smb_dname->base_name,
2427 (smb_dname->st.st_ex_mode |
2428 (mode & ~smb_dname->st.st_ex_mode)));
2432 /* Change the owner if required. */
2433 if (lp_inherit_owner(SNUM(conn))) {
2434 change_dir_owner_to_parent(conn, parent_dir,
2435 smb_dname->base_name,
2439 notify_fname(conn, NOTIFY_ACTION_ADDED, FILE_NOTIFY_CHANGE_DIR_NAME,
2440 smb_dname->base_name);
2442 return NT_STATUS_OK;
2445 /****************************************************************************
2446 Open a directory from an NT SMB call.
2447 ****************************************************************************/
2449 static NTSTATUS open_directory(connection_struct *conn,
2450 struct smb_request *req,
2451 struct smb_filename *smb_dname,
2453 uint32 share_access,
2454 uint32 create_disposition,
2455 uint32 create_options,
2456 uint32 file_attributes,
2458 files_struct **result)
2460 files_struct *fsp = NULL;
2461 bool dir_existed = VALID_STAT(smb_dname->st) ? True : False;
2462 struct share_mode_lock *lck = NULL;
2464 struct timespec mtimespec;
2467 SMB_ASSERT(!is_ntfs_stream_smb_fname(smb_dname));
2469 DEBUG(5,("open_directory: opening directory %s, access_mask = 0x%x, "
2470 "share_access = 0x%x create_options = 0x%x, "
2471 "create_disposition = 0x%x, file_attributes = 0x%x\n",
2472 smb_fname_str_dbg(smb_dname),
2473 (unsigned int)access_mask,
2474 (unsigned int)share_access,
2475 (unsigned int)create_options,
2476 (unsigned int)create_disposition,
2477 (unsigned int)file_attributes));
2479 if (!(file_attributes & FILE_FLAG_POSIX_SEMANTICS) &&
2480 (conn->fs_capabilities & FILE_NAMED_STREAMS) &&
2481 is_ntfs_stream_smb_fname(smb_dname)) {
2482 DEBUG(2, ("open_directory: %s is a stream name!\n",
2483 smb_fname_str_dbg(smb_dname)));
2484 return NT_STATUS_NOT_A_DIRECTORY;
2487 status = calculate_access_mask(conn, smb_dname, dir_existed,
2488 access_mask, &access_mask);
2489 if (!NT_STATUS_IS_OK(status)) {
2490 DEBUG(10, ("open_directory: calculate_access_mask "
2491 "on file %s returned %s\n",
2492 smb_fname_str_dbg(smb_dname),
2493 nt_errstr(status)));
2497 /* We need to support SeSecurityPrivilege for this. */
2498 if (access_mask & SEC_FLAG_SYSTEM_SECURITY) {
2499 DEBUG(10, ("open_directory: open on %s "
2500 "failed - SEC_FLAG_SYSTEM_SECURITY denied.\n",
2501 smb_fname_str_dbg(smb_dname)));
2502 return NT_STATUS_PRIVILEGE_NOT_HELD;
2505 switch( create_disposition ) {
2508 info = FILE_WAS_OPENED;
2511 * We want to follow symlinks here.
2514 if (SMB_VFS_STAT(conn, smb_dname) != 0) {
2515 return map_nt_error_from_unix(errno);
2522 /* If directory exists error. If directory doesn't
2525 status = mkdir_internal(conn, smb_dname,
2528 if (!NT_STATUS_IS_OK(status)) {
2529 DEBUG(2, ("open_directory: unable to create "
2530 "%s. Error was %s\n",
2531 smb_fname_str_dbg(smb_dname),
2532 nt_errstr(status)));
2536 info = FILE_WAS_CREATED;
2541 * If directory exists open. If directory doesn't
2545 status = mkdir_internal(conn, smb_dname,
2548 if (NT_STATUS_IS_OK(status)) {
2549 info = FILE_WAS_CREATED;
2552 if (NT_STATUS_EQUAL(status,
2553 NT_STATUS_OBJECT_NAME_COLLISION)) {
2554 info = FILE_WAS_OPENED;
2555 status = NT_STATUS_OK;
2560 case FILE_SUPERSEDE:
2561 case FILE_OVERWRITE:
2562 case FILE_OVERWRITE_IF:
2564 DEBUG(5,("open_directory: invalid create_disposition "
2565 "0x%x for directory %s\n",
2566 (unsigned int)create_disposition,
2567 smb_fname_str_dbg(smb_dname)));
2568 return NT_STATUS_INVALID_PARAMETER;
2571 if(!S_ISDIR(smb_dname->st.st_ex_mode)) {
2572 DEBUG(5,("open_directory: %s is not a directory !\n",
2573 smb_fname_str_dbg(smb_dname)));
2574 return NT_STATUS_NOT_A_DIRECTORY;
2577 if (info == FILE_WAS_OPENED) {
2578 uint32_t access_granted = 0;
2579 status = smbd_check_open_rights(conn, smb_dname, access_mask,
2582 /* Were we trying to do a directory open
2583 * for delete and didn't get DELETE
2584 * access (only) ? Check if the
2585 * directory allows DELETE_CHILD.
2587 * http://blogs.msdn.com/oldnewthing/archive/2004/06/04/148426.aspx
2590 if ((NT_STATUS_EQUAL(status, NT_STATUS_ACCESS_DENIED) &&
2591 (access_mask & DELETE_ACCESS) &&
2592 (access_granted == DELETE_ACCESS) &&
2593 can_delete_file_in_directory(conn, smb_dname))) {
2594 DEBUG(10,("open_directory: overrode ACCESS_DENIED "
2595 "on directory %s\n",
2596 smb_fname_str_dbg(smb_dname)));
2597 status = NT_STATUS_OK;
2600 if (!NT_STATUS_IS_OK(status)) {
2601 DEBUG(10, ("open_directory: smbd_check_open_rights on "
2602 "file %s failed with %s\n",
2603 smb_fname_str_dbg(smb_dname),
2604 nt_errstr(status)));
2609 status = file_new(req, conn, &fsp);
2610 if(!NT_STATUS_IS_OK(status)) {
2615 * Setup the files_struct for it.
2618 fsp->mode = smb_dname->st.st_ex_mode;
2619 fsp->file_id = vfs_file_id_from_sbuf(conn, &smb_dname->st);
2620 fsp->vuid = req ? req->vuid : UID_FIELD_INVALID;
2621 fsp->file_pid = req ? req->smbpid : 0;
2622 fsp->can_lock = False;
2623 fsp->can_read = False;
2624 fsp->can_write = False;
2626 fsp->share_access = share_access;
2627 fsp->fh->private_options = 0;
2629 * According to Samba4, SEC_FILE_READ_ATTRIBUTE is always granted,
2631 fsp->access_mask = access_mask | FILE_READ_ATTRIBUTES;
2632 fsp->print_file = NULL;
2633 fsp->modified = False;
2634 fsp->oplock_type = NO_OPLOCK;
2635 fsp->sent_oplock_break = NO_BREAK_SENT;
2636 fsp->is_directory = True;
2637 fsp->posix_open = (file_attributes & FILE_FLAG_POSIX_SEMANTICS) ? True : False;
2638 status = fsp_set_smb_fname(fsp, smb_dname);
2639 if (!NT_STATUS_IS_OK(status)) {
2643 mtimespec = smb_dname->st.st_ex_mtime;
2645 lck = get_share_mode_lock(talloc_tos(), fsp->file_id,
2646 conn->connectpath, smb_dname, &mtimespec);
2649 DEBUG(0, ("open_directory: Could not get share mode lock for "
2650 "%s\n", smb_fname_str_dbg(smb_dname)));
2651 file_free(req, fsp);
2652 return NT_STATUS_SHARING_VIOLATION;
2655 status = open_mode_check(conn, lck, access_mask, share_access,
2656 create_options, &dir_existed);
2658 if (!NT_STATUS_IS_OK(status)) {
2660 file_free(req, fsp);
2664 set_share_mode(lck, fsp, get_current_uid(conn), 0, NO_OPLOCK);
2666 /* For directories the delete on close bit at open time seems
2667 always to be honored on close... See test 19 in Samba4 BASE-DELETE. */
2668 if (create_options & FILE_DELETE_ON_CLOSE) {
2669 status = can_set_delete_on_close(fsp, 0);
2670 if (!NT_STATUS_IS_OK(status) && !NT_STATUS_EQUAL(status, NT_STATUS_DIRECTORY_NOT_EMPTY)) {
2672 file_free(req, fsp);
2676 if (NT_STATUS_IS_OK(status)) {
2677 /* Note that here we set the *inital* delete on close flag,
2678 not the regular one. The magic gets handled in close. */
2679 fsp->initial_delete_on_close = True;
2690 return NT_STATUS_OK;
2693 NTSTATUS create_directory(connection_struct *conn, struct smb_request *req,
2694 struct smb_filename *smb_dname)
2699 status = SMB_VFS_CREATE_FILE(
2702 0, /* root_dir_fid */
2703 smb_dname, /* fname */
2704 FILE_READ_ATTRIBUTES, /* access_mask */
2705 FILE_SHARE_NONE, /* share_access */
2706 FILE_CREATE, /* create_disposition*/
2707 FILE_DIRECTORY_FILE, /* create_options */
2708 FILE_ATTRIBUTE_DIRECTORY, /* file_attributes */
2709 0, /* oplock_request */
2710 0, /* allocation_size */
2711 0, /* private_flags */
2717 if (NT_STATUS_IS_OK(status)) {
2718 close_file(req, fsp, NORMAL_CLOSE);
2724 /****************************************************************************
2725 Receive notification that one of our open files has been renamed by another
2727 ****************************************************************************/
2729 void msg_file_was_renamed(struct messaging_context *msg,
2732 struct server_id server_id,
2736 char *frm = (char *)data->data;
2738 const char *sharepath;
2739 const char *base_name;
2740 const char *stream_name;
2741 struct smb_filename *smb_fname = NULL;
2742 size_t sp_len, bn_len;
2745 if (data->data == NULL
2746 || data->length < MSG_FILE_RENAMED_MIN_SIZE + 2) {
2747 DEBUG(0, ("msg_file_was_renamed: Got invalid msg len %d\n",
2748 (int)data->length));
2752 /* Unpack the message. */
2753 pull_file_id_24(frm, &id);
2754 sharepath = &frm[24];
2755 sp_len = strlen(sharepath);
2756 base_name = sharepath + sp_len + 1;
2757 bn_len = strlen(base_name);
2758 stream_name = sharepath + sp_len + 1 + bn_len + 1;
2760 /* stream_name must always be NULL if there is no stream. */
2761 if (stream_name[0] == '\0') {
2765 status = create_synthetic_smb_fname(talloc_tos(), base_name,
2766 stream_name, NULL, &smb_fname);
2767 if (!NT_STATUS_IS_OK(status)) {
2771 DEBUG(10,("msg_file_was_renamed: Got rename message for sharepath %s, new name %s, "
2773 sharepath, smb_fname_str_dbg(smb_fname),
2774 file_id_string_tos(&id)));
2776 for(fsp = file_find_di_first(smbd_server_conn, id); fsp;
2777 fsp = file_find_di_next(fsp)) {
2778 if (memcmp(fsp->conn->connectpath, sharepath, sp_len) == 0) {
2780 DEBUG(10,("msg_file_was_renamed: renaming file fnum %d from %s -> %s\n",
2781 fsp->fnum, fsp_str_dbg(fsp),
2782 smb_fname_str_dbg(smb_fname)));
2783 status = fsp_set_smb_fname(fsp, smb_fname);
2784 if (!NT_STATUS_IS_OK(status)) {
2789 /* Now we have the complete path we can work out if this is
2790 actually within this share and adjust newname accordingly. */
2791 DEBUG(10,("msg_file_was_renamed: share mismatch (sharepath %s "
2792 "not sharepath %s) "
2793 "fnum %d from %s -> %s\n",
2794 fsp->conn->connectpath,
2798 smb_fname_str_dbg(smb_fname)));
2802 TALLOC_FREE(smb_fname);
2807 * If a main file is opened for delete, all streams need to be checked for
2808 * !FILE_SHARE_DELETE. Do this by opening with DELETE_ACCESS.
2809 * If that works, delete them all by setting the delete on close and close.
2812 NTSTATUS open_streams_for_delete(connection_struct *conn,
2815 struct stream_struct *stream_info;
2816 files_struct **streams;
2818 unsigned int num_streams;
2819 TALLOC_CTX *frame = talloc_stackframe();
2822 status = SMB_VFS_STREAMINFO(conn, NULL, fname, talloc_tos(),
2823 &num_streams, &stream_info);
2825 if (NT_STATUS_EQUAL(status, NT_STATUS_NOT_IMPLEMENTED)
2826 || NT_STATUS_EQUAL(status, NT_STATUS_OBJECT_NAME_NOT_FOUND)) {
2827 DEBUG(10, ("no streams around\n"));
2829 return NT_STATUS_OK;
2832 if (!NT_STATUS_IS_OK(status)) {
2833 DEBUG(10, ("SMB_VFS_STREAMINFO failed: %s\n",
2834 nt_errstr(status)));
2838 DEBUG(10, ("open_streams_for_delete found %d streams\n",
2841 if (num_streams == 0) {
2843 return NT_STATUS_OK;
2846 streams = TALLOC_ARRAY(talloc_tos(), files_struct *, num_streams);
2847 if (streams == NULL) {
2848 DEBUG(0, ("talloc failed\n"));
2849 status = NT_STATUS_NO_MEMORY;
2853 for (i=0; i<num_streams; i++) {
2854 struct smb_filename *smb_fname = NULL;
2856 if (strequal(stream_info[i].name, "::$DATA")) {
2861 status = create_synthetic_smb_fname(talloc_tos(), fname,
2862 stream_info[i].name,
2864 if (!NT_STATUS_IS_OK(status)) {
2868 if (SMB_VFS_STAT(conn, smb_fname) == -1) {
2869 DEBUG(10, ("Unable to stat stream: %s\n",
2870 smb_fname_str_dbg(smb_fname)));
2873 status = SMB_VFS_CREATE_FILE(
2876 0, /* root_dir_fid */
2877 smb_fname, /* fname */
2878 DELETE_ACCESS, /* access_mask */
2879 (FILE_SHARE_READ | /* share_access */
2880 FILE_SHARE_WRITE | FILE_SHARE_DELETE),
2881 FILE_OPEN, /* create_disposition*/
2882 0, /* create_options */
2883 FILE_ATTRIBUTE_NORMAL, /* file_attributes */
2884 0, /* oplock_request */
2885 0, /* allocation_size */
2886 NTCREATEX_OPTIONS_PRIVATE_STREAM_DELETE, /* private_flags */
2889 &streams[i], /* result */
2892 if (!NT_STATUS_IS_OK(status)) {
2893 DEBUG(10, ("Could not open stream %s: %s\n",
2894 smb_fname_str_dbg(smb_fname),
2895 nt_errstr(status)));
2897 TALLOC_FREE(smb_fname);
2900 TALLOC_FREE(smb_fname);
2904 * don't touch the variable "status" beyond this point :-)
2907 for (i -= 1 ; i >= 0; i--) {
2908 if (streams[i] == NULL) {
2912 DEBUG(10, ("Closing stream # %d, %s\n", i,
2913 fsp_str_dbg(streams[i])));
2914 close_file(NULL, streams[i], NORMAL_CLOSE);
2923 * Wrapper around open_file_ntcreate and open_directory
2926 static NTSTATUS create_file_unixpath(connection_struct *conn,
2927 struct smb_request *req,
2928 struct smb_filename *smb_fname,
2929 uint32_t access_mask,
2930 uint32_t share_access,
2931 uint32_t create_disposition,
2932 uint32_t create_options,
2933 uint32_t file_attributes,
2934 uint32_t oplock_request,
2935 uint64_t allocation_size,
2936 uint32_t private_flags,
2937 struct security_descriptor *sd,
2938 struct ea_list *ea_list,
2940 files_struct **result,
2943 int info = FILE_WAS_OPENED;
2944 files_struct *base_fsp = NULL;
2945 files_struct *fsp = NULL;
2948 DEBUG(10,("create_file_unixpath: access_mask = 0x%x "
2949 "file_attributes = 0x%x, share_access = 0x%x, "
2950 "create_disposition = 0x%x create_options = 0x%x "
2951 "oplock_request = 0x%x private_flags = 0x%x "
2952 "ea_list = 0x%p, sd = 0x%p, "
2954 (unsigned int)access_mask,
2955 (unsigned int)file_attributes,
2956 (unsigned int)share_access,
2957 (unsigned int)create_disposition,
2958 (unsigned int)create_options,
2959 (unsigned int)oplock_request,
2960 (unsigned int)private_flags,
2961 ea_list, sd, smb_fname_str_dbg(smb_fname)));
2963 if (create_options & FILE_OPEN_BY_FILE_ID) {
2964 status = NT_STATUS_NOT_SUPPORTED;
2968 if (create_options & NTCREATEX_OPTIONS_INVALID_PARAM_MASK) {
2969 status = NT_STATUS_INVALID_PARAMETER;
2974 oplock_request |= INTERNAL_OPEN_ONLY;
2977 if ((conn->fs_capabilities & FILE_NAMED_STREAMS)
2978 && (access_mask & DELETE_ACCESS)
2979 && !is_ntfs_stream_smb_fname(smb_fname)) {
2981 * We can't open a file with DELETE access if any of the
2982 * streams is open without FILE_SHARE_DELETE
2984 status = open_streams_for_delete(conn, smb_fname->base_name);
2986 if (!NT_STATUS_IS_OK(status)) {
2991 /* This is the correct thing to do (check every time) but can_delete
2992 * is expensive (it may have to read the parent directory
2993 * permissions). So for now we're not doing it unless we have a strong
2994 * hint the client is really going to delete this file. If the client
2995 * is forcing FILE_CREATE let the filesystem take care of the
2998 /* Setting FILE_SHARE_DELETE is the hint. */
3000 if (lp_acl_check_permissions(SNUM(conn))
3001 && (create_disposition != FILE_CREATE)
3002 && (share_access & FILE_SHARE_DELETE)
3003 && (access_mask & DELETE_ACCESS)
3004 && (!(can_delete_file_in_directory(conn, smb_fname) ||
3005 can_access_file_acl(conn, smb_fname, DELETE_ACCESS)))) {
3006 status = NT_STATUS_ACCESS_DENIED;
3007 DEBUG(10,("create_file_unixpath: open file %s "
3008 "for delete ACCESS_DENIED\n",
3009 smb_fname_str_dbg(smb_fname)));
3014 /* We need to support SeSecurityPrivilege for this. */
3015 if ((access_mask & SEC_FLAG_SYSTEM_SECURITY) &&
3016 !user_has_privileges(current_user.nt_user_token,
3018 status = NT_STATUS_PRIVILEGE_NOT_HELD;
3022 /* We need to support SeSecurityPrivilege for this. */
3023 if (access_mask & SEC_FLAG_SYSTEM_SECURITY) {
3024 status = NT_STATUS_PRIVILEGE_NOT_HELD;
3027 /* Don't allow a SACL set from an NTtrans create until we
3028 * support SeSecurityPrivilege. */
3029 if (!VALID_STAT(smb_fname->st) &&
3030 lp_nt_acl_support(SNUM(conn)) &&
3031 sd && (sd->sacl != NULL)) {
3032 status = NT_STATUS_PRIVILEGE_NOT_HELD;
3037 if ((conn->fs_capabilities & FILE_NAMED_STREAMS)
3038 && is_ntfs_stream_smb_fname(smb_fname)
3039 && (!(private_flags & NTCREATEX_OPTIONS_PRIVATE_STREAM_DELETE))) {
3040 uint32 base_create_disposition;
3041 struct smb_filename *smb_fname_base = NULL;
3043 if (create_options & FILE_DIRECTORY_FILE) {
3044 status = NT_STATUS_NOT_A_DIRECTORY;
3048 switch (create_disposition) {
3050 base_create_disposition = FILE_OPEN;
3053 base_create_disposition = FILE_OPEN_IF;
3057 /* Create an smb_filename with stream_name == NULL. */
3058 status = create_synthetic_smb_fname(talloc_tos(),
3059 smb_fname->base_name,
3062 if (!NT_STATUS_IS_OK(status)) {
3066 if (SMB_VFS_STAT(conn, smb_fname_base) == -1) {
3067 DEBUG(10, ("Unable to stat stream: %s\n",
3068 smb_fname_str_dbg(smb_fname_base)));
3071 /* Open the base file. */
3072 status = create_file_unixpath(conn, NULL, smb_fname_base, 0,
3075 | FILE_SHARE_DELETE,
3076 base_create_disposition,
3077 0, 0, 0, 0, 0, NULL, NULL,
3079 TALLOC_FREE(smb_fname_base);
3081 if (!NT_STATUS_IS_OK(status)) {
3082 DEBUG(10, ("create_file_unixpath for base %s failed: "
3083 "%s\n", smb_fname->base_name,
3084 nt_errstr(status)));
3087 /* we don't need to low level fd */
3092 * If it's a request for a directory open, deal with it separately.
3095 if (create_options & FILE_DIRECTORY_FILE) {
3097 if (create_options & FILE_NON_DIRECTORY_FILE) {
3098 status = NT_STATUS_INVALID_PARAMETER;
3102 /* Can't open a temp directory. IFS kit test. */
3103 if (!(file_attributes & FILE_FLAG_POSIX_SEMANTICS) &&
3104 (file_attributes & FILE_ATTRIBUTE_TEMPORARY)) {
3105 status = NT_STATUS_INVALID_PARAMETER;
3110 * We will get a create directory here if the Win32
3111 * app specified a security descriptor in the
3112 * CreateDirectory() call.
3116 status = open_directory(
3117 conn, req, smb_fname, access_mask, share_access,
3118 create_disposition, create_options, file_attributes,
3123 * Ordinary file case.
3126 status = file_new(req, conn, &fsp);
3127 if(!NT_STATUS_IS_OK(status)) {
3131 status = fsp_set_smb_fname(fsp, smb_fname);
3132 if (!NT_STATUS_IS_OK(status)) {
3137 * We're opening the stream element of a base_fsp
3138 * we already opened. Set up the base_fsp pointer.
3141 fsp->base_fsp = base_fsp;
3144 status = open_file_ntcreate(conn,
3156 if(!NT_STATUS_IS_OK(status)) {
3157 file_free(req, fsp);
3161 if (NT_STATUS_EQUAL(status, NT_STATUS_FILE_IS_A_DIRECTORY)) {
3163 /* A stream open never opens a directory */
3166 status = NT_STATUS_FILE_IS_A_DIRECTORY;
3171 * Fail the open if it was explicitly a non-directory
3175 if (create_options & FILE_NON_DIRECTORY_FILE) {
3176 status = NT_STATUS_FILE_IS_A_DIRECTORY;
3181 status = open_directory(
3182 conn, req, smb_fname, access_mask,
3183 share_access, create_disposition,
3184 create_options, file_attributes,
3189 if (!NT_STATUS_IS_OK(status)) {
3193 fsp->base_fsp = base_fsp;
3196 * According to the MS documentation, the only time the security
3197 * descriptor is applied to the opened file is iff we *created* the
3198 * file; an existing file stays the same.
3200 * Also, it seems (from observation) that you can open the file with
3201 * any access mask but you can still write the sd. We need to override
3202 * the granted access before we call set_sd
3203 * Patch for bug #2242 from Tom Lackemann <cessnatomny@yahoo.com>.
3206 if ((sd != NULL) && (info == FILE_WAS_CREATED)
3207 && lp_nt_acl_support(SNUM(conn))) {
3209 uint32_t sec_info_sent;
3210 uint32_t saved_access_mask = fsp->access_mask;
3212 sec_info_sent = get_sec_info(sd);
3214 fsp->access_mask = FILE_GENERIC_ALL;
3216 /* Convert all the generic bits. */
3217 security_acl_map_generic(sd->dacl, &file_generic_mapping);
3218 security_acl_map_generic(sd->sacl, &file_generic_mapping);
3220 if (sec_info_sent & (SECINFO_OWNER|
3224 status = SMB_VFS_FSET_NT_ACL(fsp, sec_info_sent, sd);
3227 fsp->access_mask = saved_access_mask;
3229 if (!NT_STATUS_IS_OK(status)) {
3234 if ((ea_list != NULL) &&
3235 ((info == FILE_WAS_CREATED) || (info == FILE_WAS_OVERWRITTEN))) {
3236 status = set_ea(conn, fsp, fsp->fsp_name, ea_list);
3237 if (!NT_STATUS_IS_OK(status)) {
3242 if (!fsp->is_directory && S_ISDIR(fsp->fsp_name->st.st_ex_mode)) {
3243 status = NT_STATUS_ACCESS_DENIED;
3247 /* Save the requested allocation size. */
3248 if ((info == FILE_WAS_CREATED) || (info == FILE_WAS_OVERWRITTEN)) {
3250 && (allocation_size > fsp->fsp_name->st.st_ex_size)) {
3251 fsp->initial_allocation_size = smb_roundup(
3252 fsp->conn, allocation_size);
3253 if (fsp->is_directory) {
3254 /* Can't set allocation size on a directory. */
3255 status = NT_STATUS_ACCESS_DENIED;
3258 if (vfs_allocate_file_space(
3259 fsp, fsp->initial_allocation_size) == -1) {
3260 status = NT_STATUS_DISK_FULL;
3264 fsp->initial_allocation_size = smb_roundup(
3265 fsp->conn, (uint64_t)fsp->fsp_name->st.st_ex_size);
3269 DEBUG(10, ("create_file_unixpath: info=%d\n", info));
3272 if (pinfo != NULL) {
3276 smb_fname->st = fsp->fsp_name->st;
3278 return NT_STATUS_OK;
3281 DEBUG(10, ("create_file_unixpath: %s\n", nt_errstr(status)));
3284 if (base_fsp && fsp->base_fsp == base_fsp) {
3286 * The close_file below will close
3291 close_file(req, fsp, ERROR_CLOSE);
3294 if (base_fsp != NULL) {
3295 close_file(req, base_fsp, ERROR_CLOSE);
3302 * Calculate the full path name given a relative fid.
3304 NTSTATUS get_relative_fid_filename(connection_struct *conn,
3305 struct smb_request *req,
3306 uint16_t root_dir_fid,
3307 struct smb_filename *smb_fname)
3309 files_struct *dir_fsp;
3310 char *parent_fname = NULL;
3311 char *new_base_name = NULL;
3314 if (root_dir_fid == 0 || !smb_fname) {
3315 status = NT_STATUS_INTERNAL_ERROR;
3319 dir_fsp = file_fsp(req, root_dir_fid);
3321 if (dir_fsp == NULL) {
3322 status = NT_STATUS_INVALID_HANDLE;
3326 if (is_ntfs_stream_smb_fname(dir_fsp->fsp_name)) {
3327 status = NT_STATUS_INVALID_HANDLE;
3331 if (!dir_fsp->is_directory) {
3334 * Check to see if this is a mac fork of some kind.
3337 if ((conn->fs_capabilities & FILE_NAMED_STREAMS) &&
3338 is_ntfs_stream_smb_fname(smb_fname)) {
3339 status = NT_STATUS_OBJECT_PATH_NOT_FOUND;
3344 we need to handle the case when we get a
3345 relative open relative to a file and the
3346 pathname is blank - this is a reopen!
3347 (hint from demyn plantenberg)
3350 status = NT_STATUS_INVALID_HANDLE;
3354 if (ISDOT(dir_fsp->fsp_name->base_name)) {
3356 * We're at the toplevel dir, the final file name
3357 * must not contain ./, as this is filtered out
3358 * normally by srvstr_get_path and unix_convert
3359 * explicitly rejects paths containing ./.
3361 parent_fname = talloc_strdup(talloc_tos(), "");
3362 if (parent_fname == NULL) {
3363 status = NT_STATUS_NO_MEMORY;
3367 size_t dir_name_len = strlen(dir_fsp->fsp_name->base_name);
3370 * Copy in the base directory name.
3373 parent_fname = TALLOC_ARRAY(talloc_tos(), char,
3375 if (parent_fname == NULL) {
3376 status = NT_STATUS_NO_MEMORY;
3379 memcpy(parent_fname, dir_fsp->fsp_name->base_name,
3383 * Ensure it ends in a '/'.
3384 * We used TALLOC_SIZE +2 to add space for the '/'.
3388 && (parent_fname[dir_name_len-1] != '\\')
3389 && (parent_fname[dir_name_len-1] != '/')) {
3390 parent_fname[dir_name_len] = '/';
3391 parent_fname[dir_name_len+1] = '\0';
3395 new_base_name = talloc_asprintf(smb_fname, "%s%s", parent_fname,
3396 smb_fname->base_name);
3397 if (new_base_name == NULL) {
3398 status = NT_STATUS_NO_MEMORY;
3402 TALLOC_FREE(smb_fname->base_name);
3403 smb_fname->base_name = new_base_name;
3404 status = NT_STATUS_OK;
3407 TALLOC_FREE(parent_fname);
3411 NTSTATUS create_file_default(connection_struct *conn,
3412 struct smb_request *req,
3413 uint16_t root_dir_fid,
3414 struct smb_filename *smb_fname,
3415 uint32_t access_mask,
3416 uint32_t share_access,
3417 uint32_t create_disposition,
3418 uint32_t create_options,
3419 uint32_t file_attributes,
3420 uint32_t oplock_request,
3421 uint64_t allocation_size,
3422 uint32_t private_flags,
3423 struct security_descriptor *sd,
3424 struct ea_list *ea_list,
3425 files_struct **result,
3428 int info = FILE_WAS_OPENED;
3429 files_struct *fsp = NULL;
3431 bool stream_name = false;
3433 DEBUG(10,("create_file: access_mask = 0x%x "
3434 "file_attributes = 0x%x, share_access = 0x%x, "
3435 "create_disposition = 0x%x create_options = 0x%x "
3436 "oplock_request = 0x%x "
3437 "private_flags = 0x%x "
3438 "root_dir_fid = 0x%x, ea_list = 0x%p, sd = 0x%p, "
3440 (unsigned int)access_mask,
3441 (unsigned int)file_attributes,
3442 (unsigned int)share_access,
3443 (unsigned int)create_disposition,
3444 (unsigned int)create_options,
3445 (unsigned int)oplock_request,
3446 (unsigned int)private_flags,
3447 (unsigned int)root_dir_fid,
3448 ea_list, sd, smb_fname_str_dbg(smb_fname)));
3451 * Calculate the filename from the root_dir_if if necessary.
3454 if (root_dir_fid != 0) {
3455 status = get_relative_fid_filename(conn, req, root_dir_fid,
3457 if (!NT_STATUS_IS_OK(status)) {
3463 * Check to see if this is a mac fork of some kind.
3466 stream_name = is_ntfs_stream_smb_fname(smb_fname);
3468 enum FAKE_FILE_TYPE fake_file_type;
3470 fake_file_type = is_fake_file(smb_fname);
3472 if (fake_file_type != FAKE_FILE_TYPE_NONE) {
3475 * Here we go! support for changing the disk quotas
3478 * We need to fake up to open this MAGIC QUOTA file
3479 * and return a valid FID.
3481 * w2k close this file directly after openening xp
3482 * also tries a QUERY_FILE_INFO on the file and then
3485 status = open_fake_file(req, conn, req->vuid,
3486 fake_file_type, smb_fname,
3488 if (!NT_STATUS_IS_OK(status)) {
3492 ZERO_STRUCT(smb_fname->st);
3496 if (!(conn->fs_capabilities & FILE_NAMED_STREAMS)) {
3497 status = NT_STATUS_OBJECT_NAME_NOT_FOUND;
3502 /* All file access must go through check_name() */
3504 status = check_name(conn, smb_fname->base_name);
3505 if (!NT_STATUS_IS_OK(status)) {
3509 if (stream_name && is_ntfs_default_stream_smb_fname(smb_fname)) {
3511 smb_fname->stream_name = NULL;
3512 /* We have to handle this error here. */
3513 if (create_options & FILE_DIRECTORY_FILE) {
3514 status = NT_STATUS_NOT_A_DIRECTORY;
3517 if (lp_posix_pathnames()) {
3518 ret = SMB_VFS_LSTAT(conn, smb_fname);
3520 ret = SMB_VFS_STAT(conn, smb_fname);
3523 if (ret == 0 && VALID_STAT_OF_DIR(smb_fname->st)) {
3524 status = NT_STATUS_FILE_IS_A_DIRECTORY;
3529 status = create_file_unixpath(
3530 conn, req, smb_fname, access_mask, share_access,
3531 create_disposition, create_options, file_attributes,
3532 oplock_request, allocation_size, private_flags,
3536 if (!NT_STATUS_IS_OK(status)) {
3541 DEBUG(10, ("create_file: info=%d\n", info));
3544 if (pinfo != NULL) {
3547 return NT_STATUS_OK;
3550 DEBUG(10, ("create_file: %s\n", nt_errstr(status)));
3553 close_file(req, fsp, ERROR_CLOSE);