2 Unix SMB/CIFS implementation.
3 service (connection) handling
4 Copyright (C) Andrew Tridgell 1992-2003
6 This program is free software; you can redistribute it and/or modify
7 it under the terms of the GNU General Public License as published by
8 the Free Software Foundation; either version 2 of the License, or
9 (at your option) any later version.
11 This program is distributed in the hope that it will be useful,
12 but WITHOUT ANY WARRANTY; without even the implied warranty of
13 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 GNU General Public License for more details.
16 You should have received a copy of the GNU General Public License
17 along with this program; if not, write to the Free Software
18 Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
24 /****************************************************************************
25 Add a home service. Returns the new service number or -1 if fail.
26 ****************************************************************************/
27 int add_home_service(const char *service, const char *username, const char *homedir)
31 if (!service || !homedir)
34 if ((iHomeService = lp_servicenumber(HOMES_NAME)) < 0)
38 * If this is a winbindd provided username, remove
39 * the domain component before adding the service.
40 * Log a warning if the "path=" parameter does not
45 const char *p = strchr(service,*lp_winbind_separator());
47 /* We only want the 'user' part of the string */
53 if (!lp_add_home(service, iHomeService, username, homedir)) {
57 return lp_servicenumber(service);
63 * Find a service entry. service is always in dos codepage.
65 * @param service is modified (to canonical form??)
67 static int find_service(const char *service)
71 iService = lp_servicenumber(service);
73 /* now handle the special case of a home directory */
75 char *phome_dir = get_user_home_dir(service);
79 * Try mapping the servicename, it may
80 * be a Windows to unix mapped user name.
83 if (map_username(service))
84 phome_dir = get_user_home_dir(service);
88 DEBUG(3,("checking for home directory %s gave %s\n",service,
89 phome_dir?phome_dir:"(NULL)"));
91 iService = add_home_service(service,service /* 'username' */, phome_dir);
94 /* If we still don't have a service, attempt to add it as a printer. */
98 if ((iPrinterService = lp_servicenumber(PRINTERS_NAME)) >= 0) {
101 DEBUG(3,("checking whether %s is a valid printer name...\n", service));
102 pszTemp = lp_printcapname();
103 if ((pszTemp != NULL) && pcap_printername_ok(service, pszTemp)) {
104 DEBUG(3,("%s is a valid printer name\n", service));
105 DEBUG(3,("adding %s as a printer service\n", service));
106 lp_add_printer(service, iPrinterService);
107 iService = lp_servicenumber(service);
109 DEBUG(0,("failed to add %s as a printer service!\n", service));
111 DEBUG(3,("%s is not a valid printer name\n", service));
116 /* Check for default vfs service? Unsure whether to implement this */
117 if (iService == -1) {
120 /* just possibly it's a default service? */
121 if (iService == -1) {
122 char *pdefservice = lp_defaultservice();
123 if (pdefservice && *pdefservice &&
124 !strequal(pdefservice,service) &&
125 !strstr(service,"..")) {
127 * We need to do a local copy here as lp_defaultservice()
128 * returns one of the rotating lp_string buffers that
129 * could get overwritten by the recursive find_service() call
130 * below. Fix from Josef Hinteregger <joehtg@joehtg.co.at>.
133 pstrcpy(defservice, pdefservice);
134 iService = find_service(defservice);
136 /* REWRITE: all_string_sub(service, "_","/",0); */
137 iService = lp_add_service(service, iService);
142 if (iService >= 0 && !VALID_SNUM(iService)) {
143 DEBUG(0,("Invalid snum %d for %s\n",iService, service));
147 if (iService == -1) {
148 DEBUG(3,("find_service() failed to find service %s\n", service));
155 /****************************************************************************
156 Make a connection, given the snum to connect to, and the vuser of the
157 connecting user if appropriate.
158 ****************************************************************************/
159 static NTSTATUS make_connection_snum(struct request_context *req,
160 int snum, enum ntvfs_type type,
164 struct tcon_context *conn;
167 conn = conn_new(req->smb);
169 DEBUG(0,("Couldn't find free connection.\n"));
170 return NT_STATUS_INSUFFICIENT_RESOURCES;
174 conn->service = snum;
178 * New code to check if there's a share security descripter
179 * added from NT server manager. This is done after the
180 * smb.conf checks are done as we need a uid and token. JRA.
184 if (!share_access_check(req, conn, snum, SA_RIGHT_FILE_WRITE_DATA)) {
185 if (!share_access_check(req, conn, snum, SA_RIGHT_FILE_READ_DATA)) {
186 /* No access, read or write. */
187 DEBUG(0,( "make_connection: connection to %s denied due to security descriptor.\n",
188 lp_servicename(snum)));
189 conn_free(req->smb, conn);
190 return NT_STATUS_ACCESS_DENIED;
192 conn->read_only = True;
196 /* check number of connections */
197 if (!claim_connection(conn,
198 lp_servicename(SNUM(conn)),
199 lp_max_connections(SNUM(conn)),
201 DEBUG(1,("too many connections - rejected\n"));
202 conn_free(req->smb, conn);
203 return NT_STATUS_INSUFFICIENT_RESOURCES;
206 /* init ntvfs function pointers */
207 status = ntvfs_init_connection(req);
208 if (!NT_STATUS_IS_OK(status)) {
209 DEBUG(0, ("ntvfs_init_connection failed for service %s\n", lp_servicename(SNUM(conn))));
210 conn_free(req->smb, conn);
214 /* Invoke NTVFS connection hook */
215 if (conn->ntvfs_ops->connect) {
216 status = conn->ntvfs_ops->connect(req, lp_servicename(snum));
217 if (!NT_STATUS_IS_OK(status)) {
218 DEBUG(0,("make_connection: NTVFS make connection failed!\n"));
219 conn_free(req->smb, conn);
227 /****************************************************************************
228 Make a connection to a service.
231 ****************************************************************************/
232 static NTSTATUS make_connection(struct request_context *req,
233 const char *service, DATA_BLOB password,
234 const char *dev, uint16 vuid)
237 enum ntvfs_type type;
238 const char *type_str;
240 /* the service might be of the form \\SERVER\SHARE. Should we put
241 the server name we get from this somewhere? */
242 if (strncmp(service, "\\\\", 2) == 0) {
243 char *p = strchr(service+2, '\\');
249 snum = find_service(service);
252 DEBUG(0,("%s couldn't find service %s\n",
253 sub_get_remote_machine(), service));
254 return NT_STATUS_BAD_NETWORK_NAME;
257 /* work out what sort of connection this is */
258 if (strcmp(lp_fstype(snum), "IPC") == 0) {
261 } else if (lp_print_ok(snum)) {
269 if (strcmp(dev, "?????") != 0 && strcasecmp(type_str, dev) != 0) {
270 /* the client gave us the wrong device type */
271 return NT_STATUS_BAD_DEVICE_TYPE;
274 return make_connection_snum(req, snum, type, password, dev);
277 /****************************************************************************
279 ****************************************************************************/
280 void close_cnum(struct tcon_context *conn)
282 DEBUG(3, ("%s (%s) closed connection to service %s\n",
283 sub_get_remote_machine(),conn->smb->socket.client_addr,
284 lp_servicename(SNUM(conn))));
286 yield_connection(conn, lp_servicename(SNUM(conn)));
288 /* tell the ntvfs backend that we are disconnecting */
289 conn->ntvfs_ops->disconnect(conn);
291 conn_free(conn->smb, conn);
297 backend for tree connect call
299 NTSTATUS tcon_backend(struct request_context *req, union smb_tcon *con)
303 /* can only do bare tcon in share level security */
304 if (req->user_ctx == NULL && lp_security() != SEC_SHARE) {
305 return NT_STATUS_ACCESS_DENIED;
308 if (con->generic.level == RAW_TCON_TCON) {
310 password = data_blob(con->tcon.in.password, strlen(con->tcon.in.password) + 1);
312 status = make_connection(req, con->tcon.in.service, password, con->tcon.in.dev, req->user_ctx->vuid);
314 if (!NT_STATUS_IS_OK(status)) {
318 con->tcon.out.max_xmit = req->smb->negotiate.max_recv;
319 con->tcon.out.cnum = req->conn->cnum;
324 status = make_connection(req, con->tconx.in.path, con->tconx.in.password,
325 con->tconx.in.device, req->user_ctx->vuid);
326 if (!NT_STATUS_IS_OK(status)) {
330 con->tconx.out.cnum = req->conn->cnum;
331 con->tconx.out.dev_type = talloc_strdup(req->mem_ctx, req->conn->dev_type);
332 con->tconx.out.fs_type = talloc_strdup(req->mem_ctx, req->conn->fs_type);
333 con->tconx.out.options = SMB_SUPPORT_SEARCH_BITS | (lp_csc_policy(req->conn->service) << 2);
334 if (lp_msdfs_root(req->conn->service) && lp_host_msdfs()) {
335 con->tconx.out.options |= SMB_SHARE_IN_DFS;