ed53ce4daf66fc6942c996e643a65db1a7cf314f
[jelmer/samba4-debian.git] / source / smb_server / smb / trans2.c
1 /* 
2    Unix SMB/CIFS implementation.
3    transaction2 handling
4    Copyright (C) Andrew Tridgell 2003
5
6    This program is free software; you can redistribute it and/or modify
7    it under the terms of the GNU General Public License as published by
8    the Free Software Foundation; either version 2 of the License, or
9    (at your option) any later version.
10    
11    This program is distributed in the hope that it will be useful,
12    but WITHOUT ANY WARRANTY; without even the implied warranty of
13    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14    GNU General Public License for more details.
15    
16    You should have received a copy of the GNU General Public License
17    along with this program; if not, write to the Free Software
18    Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
19 */
20 /*
21    This file handles the parsing of transact2 requests
22 */
23
24 #include "includes.h"
25 #include "dlinklist.h"
26 #include "smb_server/smb_server.h"
27 #include "librpc/gen_ndr/ndr_misc.h"
28 #include "ntvfs/ntvfs.h"
29 #include "libcli/raw/libcliraw.h"
30
31 #define CHECK_MIN_BLOB_SIZE(blob, size) do { \
32         if ((blob)->length < (size)) { \
33                 return NT_STATUS_INFO_LENGTH_MISMATCH; \
34         }} while (0)
35
36 /* grow the data allocation size of a trans2 reply - this guarantees
37    that requests to grow the data size later will not change the
38    pointer */
39 static BOOL trans2_grow_data_allocation(struct smbsrv_request *req, 
40                                         struct smb_trans2 *trans,
41                                         uint32_t new_size)
42 {
43         if (new_size <= trans->out.data.length) {
44                 return True;
45         }
46         trans->out.data.data = talloc_realloc(req, trans->out.data.data, 
47                                               uint8_t, new_size);
48         return (trans->out.data.data != NULL);
49 }
50
51
52 /* grow the data size of a trans2 reply */
53 static BOOL trans2_grow_data(struct smbsrv_request *req, 
54                              struct smb_trans2 *trans,
55                              uint32_t new_size)
56 {
57         if (!trans2_grow_data_allocation(req, trans, new_size)) {
58                 return False;
59         }
60         trans->out.data.length = new_size;
61         return True;
62 }
63
64 /* grow the data, zero filling any new bytes */
65 static BOOL trans2_grow_data_fill(struct smbsrv_request *req, 
66                                   struct smb_trans2 *trans,
67                                   uint32_t new_size)
68 {
69         uint32_t old_size = trans->out.data.length;
70         if (!trans2_grow_data(req, trans, new_size)) {
71                 return False;
72         }
73         if (new_size > old_size) {
74                 memset(trans->out.data.data + old_size, 0, new_size - old_size);
75         }
76         return True;
77 }
78
79
80 /* setup a trans2 reply, given the data and params sizes */
81 static void trans2_setup_reply(struct smbsrv_request *req, 
82                                struct smb_trans2 *trans,
83                                uint16_t param_size, uint16_t data_size,
84                                uint16_t setup_count)
85 {
86         trans->out.setup_count = setup_count;
87         if (setup_count != 0) {
88                 trans->out.setup = talloc_zero_array(req, uint16_t, setup_count);
89         }
90         trans->out.params = data_blob_talloc(req, NULL, param_size);
91         trans->out.data = data_blob_talloc(req, NULL, data_size);
92 }
93
94
95 /*
96   pull a string from a blob in a trans2 request
97 */
98 static size_t trans2_pull_blob_string(struct smbsrv_request *req, 
99                                       const DATA_BLOB *blob,
100                                       uint16_t offset,
101                                       const char **str,
102                                       int flags)
103 {
104         /* we use STR_NO_RANGE_CHECK because the params are allocated
105            separately in a DATA_BLOB, so we need to do our own range
106            checking */
107         if (offset >= blob->length) {
108                 *str = NULL;
109                 return 0;
110         }
111         
112         return req_pull_string(req, str, 
113                                blob->data + offset, 
114                                blob->length - offset,
115                                STR_NO_RANGE_CHECK | flags);
116 }
117
118 /*
119   push a string into the data section of a trans2 request
120   return the number of bytes consumed in the output
121 */
122 static size_t trans2_push_data_string(struct smbsrv_request *req, 
123                                       struct smb_trans2 *trans,
124                                       uint32_t len_offset,
125                                       uint32_t offset,
126                                       const WIRE_STRING *str,
127                                       int dest_len,
128                                       int flags)
129 {
130         int alignment = 0, ret = 0, pkt_len;
131
132         /* we use STR_NO_RANGE_CHECK because the params are allocated
133            separately in a DATA_BLOB, so we need to do our own range
134            checking */
135         if (!str->s || offset >= trans->out.data.length) {
136                 if (flags & STR_LEN8BIT) {
137                         SCVAL(trans->out.data.data, len_offset, 0);
138                 } else {
139                         SIVAL(trans->out.data.data, len_offset, 0);
140                 }
141                 return 0;
142         }
143
144         flags |= STR_NO_RANGE_CHECK;
145
146         if (dest_len == -1 || (dest_len > trans->out.data.length - offset)) {
147                 dest_len = trans->out.data.length - offset;
148         }
149
150         if (!(flags & (STR_ASCII|STR_UNICODE))) {
151                 flags |= (req->flags2 & FLAGS2_UNICODE_STRINGS) ? STR_UNICODE : STR_ASCII;
152         }
153
154         if ((offset&1) && (flags & STR_UNICODE) && !(flags & STR_NOALIGN)) {
155                 alignment = 1;
156                 if (dest_len > 0) {
157                         SCVAL(trans->out.data.data + offset, 0, 0);
158                         ret = push_string(trans->out.data.data + offset + 1, str->s, dest_len-1, flags);
159                 }
160         } else {
161                 ret = push_string(trans->out.data.data + offset, str->s, dest_len, flags);
162         }
163
164         /* sometimes the string needs to be terminated, but the length
165            on the wire must not include the termination! */
166         pkt_len = ret;
167
168         if ((flags & STR_LEN_NOTERM) && (flags & STR_TERMINATE)) {
169                 if ((flags & STR_UNICODE) && ret >= 2) {
170                         pkt_len = ret-2;
171                 }
172                 if ((flags & STR_ASCII) && ret >= 1) {
173                         pkt_len = ret-1;
174                 }
175         }       
176
177         if (flags & STR_LEN8BIT) {
178                 SCVAL(trans->out.data.data, len_offset, pkt_len);
179         } else {
180                 SIVAL(trans->out.data.data, len_offset, pkt_len);
181         }
182
183         return ret + alignment;
184 }
185
186 /*
187   append a string to the data section of a trans2 reply
188   len_offset points to the place in the packet where the length field
189   should go
190 */
191 static void trans2_append_data_string(struct smbsrv_request *req, 
192                                         struct smb_trans2 *trans,
193                                         const WIRE_STRING *str,
194                                         uint_t len_offset,
195                                         int flags)
196 {
197         size_t ret;
198         uint32_t offset;
199         const int max_bytes_per_char = 3;
200
201         offset = trans->out.data.length;
202         trans2_grow_data(req, trans, offset + (2+strlen_m(str->s))*max_bytes_per_char);
203         ret = trans2_push_data_string(req, trans, len_offset, offset, str, -1, flags);
204         trans2_grow_data(req, trans, offset + ret);
205 }
206
207 /*
208   align the end of the data section of a trans reply on an even boundary
209 */
210 static void trans2_align_data(struct smbsrv_request *req, struct smb_trans2 *trans)
211 {
212         if ((trans->out.data.length & 1) == 0) {
213                 return;
214         }
215         trans2_grow_data(req, trans, trans->out.data.length+1);
216         SCVAL(trans->out.data.data, trans->out.data.length-1, 0);
217 }
218
219
220 /*
221   trans2 qfsinfo implementation
222 */
223 static NTSTATUS trans2_qfsinfo(struct smbsrv_request *req, struct smb_trans2 *trans)
224 {
225         union smb_fsinfo fsinfo;
226         NTSTATUS status;
227         uint16_t level;
228         uint_t i;
229         DATA_BLOB guid_blob;
230
231         /* make sure we got enough parameters */
232         if (trans->in.params.length != 2) {
233                 return NT_STATUS_FOOBAR;
234         }
235
236         level = SVAL(trans->in.params.data, 0);
237
238         switch (level) {
239         case SMB_QFS_ALLOCATION:
240                 fsinfo.allocation.level = RAW_QFS_ALLOCATION;
241
242                 status = ntvfs_fsinfo(req, &fsinfo);
243                 if (!NT_STATUS_IS_OK(status)) {
244                         return status;
245                 }
246
247                 trans2_setup_reply(req, trans, 0, 18, 0);
248
249                 SIVAL(trans->out.data.data,  0, fsinfo.allocation.out.fs_id);
250                 SIVAL(trans->out.data.data,  4, fsinfo.allocation.out.sectors_per_unit);
251                 SIVAL(trans->out.data.data,  8, fsinfo.allocation.out.total_alloc_units);
252                 SIVAL(trans->out.data.data, 12, fsinfo.allocation.out.avail_alloc_units);
253                 SSVAL(trans->out.data.data, 16, fsinfo.allocation.out.bytes_per_sector);
254
255                 return NT_STATUS_OK;
256
257         case SMB_QFS_VOLUME:
258                 fsinfo.volume.level = RAW_QFS_VOLUME;
259
260                 status = ntvfs_fsinfo(req, &fsinfo);
261                 if (!NT_STATUS_IS_OK(status)) {
262                         return status;
263                 }
264
265                 trans2_setup_reply(req, trans, 0, 5, 0);
266
267                 SIVAL(trans->out.data.data,       0, fsinfo.volume.out.serial_number);
268                 /* w2k3 implements this incorrectly for unicode - it
269                  * leaves the last byte off the string */
270                 trans2_append_data_string(req, trans, 
271                                           &fsinfo.volume.out.volume_name, 
272                                           4, STR_LEN8BIT|STR_NOALIGN);
273
274                 return NT_STATUS_OK;
275
276         case SMB_QFS_VOLUME_INFO:
277         case SMB_QFS_VOLUME_INFORMATION:
278                 fsinfo.volume_info.level = RAW_QFS_VOLUME_INFO;
279
280                 status = ntvfs_fsinfo(req, &fsinfo);
281                 if (!NT_STATUS_IS_OK(status)) {
282                         return status;
283                 }
284
285                 trans2_setup_reply(req, trans, 0, 18, 0);
286
287                 push_nttime(trans->out.data.data, 0, fsinfo.volume_info.out.create_time);
288                 SIVAL(trans->out.data.data,       8, fsinfo.volume_info.out.serial_number);
289                 SSVAL(trans->out.data.data,      16, 0); /* padding */
290                 trans2_append_data_string(req, trans, 
291                                           &fsinfo.volume_info.out.volume_name, 
292                                           12, STR_UNICODE);
293
294                 return NT_STATUS_OK;
295
296         case SMB_QFS_SIZE_INFO:
297         case SMB_QFS_SIZE_INFORMATION:
298                 fsinfo.size_info.level = RAW_QFS_SIZE_INFO;
299
300                 status = ntvfs_fsinfo(req, &fsinfo);
301                 if (!NT_STATUS_IS_OK(status)) {
302                         return status;
303                 }
304
305                 trans2_setup_reply(req, trans, 0, 24, 0);
306
307                 SBVAL(trans->out.data.data,  0, fsinfo.size_info.out.total_alloc_units);
308                 SBVAL(trans->out.data.data,  8, fsinfo.size_info.out.avail_alloc_units);
309                 SIVAL(trans->out.data.data, 16, fsinfo.size_info.out.sectors_per_unit);
310                 SIVAL(trans->out.data.data, 20, fsinfo.size_info.out.bytes_per_sector);
311
312                 return NT_STATUS_OK;
313
314         case SMB_QFS_DEVICE_INFO:
315         case SMB_QFS_DEVICE_INFORMATION:
316                 fsinfo.device_info.level = RAW_QFS_DEVICE_INFO;
317
318                 status = ntvfs_fsinfo(req, &fsinfo);
319                 if (!NT_STATUS_IS_OK(status)) {
320                         return status;
321                 }
322                 trans2_setup_reply(req, trans, 0, 8, 0);
323                 SIVAL(trans->out.data.data,      0, fsinfo.device_info.out.device_type);
324                 SIVAL(trans->out.data.data,      4, fsinfo.device_info.out.characteristics);
325                 return NT_STATUS_OK;
326
327
328         case SMB_QFS_ATTRIBUTE_INFO:
329         case SMB_QFS_ATTRIBUTE_INFORMATION:
330                 fsinfo.attribute_info.level = RAW_QFS_ATTRIBUTE_INFO;
331
332                 status = ntvfs_fsinfo(req, &fsinfo);
333                 if (!NT_STATUS_IS_OK(status)) {
334                         return status;
335                 }
336
337                 trans2_setup_reply(req, trans, 0, 12, 0);
338
339                 SIVAL(trans->out.data.data, 0, fsinfo.attribute_info.out.fs_attr);
340                 SIVAL(trans->out.data.data, 4, fsinfo.attribute_info.out.max_file_component_length);
341                 /* this must not be null terminated or win98 gets
342                    confused!  also note that w2k3 returns this as
343                    unicode even when ascii is negotiated */
344                 trans2_append_data_string(req, trans, 
345                                           &fsinfo.attribute_info.out.fs_type,
346                                           8, STR_UNICODE);
347                 return NT_STATUS_OK;
348
349
350         case SMB_QFS_QUOTA_INFORMATION:
351                 fsinfo.quota_information.level = RAW_QFS_QUOTA_INFORMATION;
352
353                 status = ntvfs_fsinfo(req, &fsinfo);
354                 if (!NT_STATUS_IS_OK(status)) {
355                         return status;
356                 }
357
358                 trans2_setup_reply(req, trans, 0, 48, 0);
359
360                 SBVAL(trans->out.data.data,   0, fsinfo.quota_information.out.unknown[0]);
361                 SBVAL(trans->out.data.data,   8, fsinfo.quota_information.out.unknown[1]);
362                 SBVAL(trans->out.data.data,  16, fsinfo.quota_information.out.unknown[2]);
363                 SBVAL(trans->out.data.data,  24, fsinfo.quota_information.out.quota_soft);
364                 SBVAL(trans->out.data.data,  32, fsinfo.quota_information.out.quota_hard);
365                 SBVAL(trans->out.data.data,  40, fsinfo.quota_information.out.quota_flags);
366
367                 return NT_STATUS_OK;
368
369
370         case SMB_QFS_FULL_SIZE_INFORMATION:
371                 fsinfo.full_size_information.level = RAW_QFS_FULL_SIZE_INFORMATION;
372
373                 status = ntvfs_fsinfo(req, &fsinfo);
374                 if (!NT_STATUS_IS_OK(status)) {
375                         return status;
376                 }
377
378                 trans2_setup_reply(req, trans, 0, 32, 0);
379
380                 SBVAL(trans->out.data.data,  0, fsinfo.full_size_information.out.total_alloc_units);
381                 SBVAL(trans->out.data.data,  8, fsinfo.full_size_information.out.call_avail_alloc_units);
382                 SBVAL(trans->out.data.data, 16, fsinfo.full_size_information.out.actual_avail_alloc_units);
383                 SIVAL(trans->out.data.data, 24, fsinfo.full_size_information.out.sectors_per_unit);
384                 SIVAL(trans->out.data.data, 28, fsinfo.full_size_information.out.bytes_per_sector);
385
386                 return NT_STATUS_OK;
387
388         case SMB_QFS_OBJECTID_INFORMATION:
389                 fsinfo.objectid_information.level = RAW_QFS_OBJECTID_INFORMATION;
390
391                 status = ntvfs_fsinfo(req, &fsinfo);
392                 if (!NT_STATUS_IS_OK(status)) {
393                         return status;
394                 }
395
396                 trans2_setup_reply(req, trans, 0, 64, 0);
397
398                 status = ndr_push_struct_blob(&guid_blob, req, 
399                                               &fsinfo.objectid_information.out.guid,
400                                               (ndr_push_flags_fn_t)ndr_push_GUID);
401                 if (!NT_STATUS_IS_OK(status)) {
402                         return status;
403                 }
404
405                 memcpy(trans->out.data.data, guid_blob.data, guid_blob.length);
406
407                 for (i=0;i<6;i++) {
408                         SBVAL(trans->out.data.data, 16 + 8*i, fsinfo.objectid_information.out.unknown[i]);
409                 }
410                 return NT_STATUS_OK;
411         }
412
413         return NT_STATUS_INVALID_LEVEL;
414 }
415
416
417 /*
418   trans2 open implementation
419 */
420 static NTSTATUS trans2_open(struct smbsrv_request *req, struct smb_trans2 *trans)
421 {
422         union smb_open *io;
423         NTSTATUS status;
424
425         /* make sure we got enough parameters */
426         if (trans->in.params.length < 29) {
427                 return NT_STATUS_FOOBAR;
428         }
429
430         io = talloc(req, union smb_open);
431         if (io == NULL) {
432                 return NT_STATUS_NO_MEMORY;
433         }
434
435         io->t2open.level           = RAW_OPEN_T2OPEN;
436         io->t2open.in.flags        = SVAL(trans->in.params.data, VWV(0));
437         io->t2open.in.open_mode    = SVAL(trans->in.params.data, VWV(1));
438         io->t2open.in.search_attrs = SVAL(trans->in.params.data, VWV(2));
439         io->t2open.in.file_attrs   = SVAL(trans->in.params.data, VWV(3));
440         io->t2open.in.write_time   = srv_pull_dos_date(req->smb_conn, 
441                                                     trans->in.params.data + VWV(4));;
442         io->t2open.in.open_func    = SVAL(trans->in.params.data, VWV(6));
443         io->t2open.in.size         = IVAL(trans->in.params.data, VWV(7));
444         io->t2open.in.timeout      = IVAL(trans->in.params.data, VWV(9));
445         io->t2open.in.num_eas      = 0;
446         io->t2open.in.eas          = NULL;
447
448         trans2_pull_blob_string(req, &trans->in.params, 28, &io->t2open.in.fname, 0);
449
450         status = ea_pull_list(&trans->in.data, io, &io->t2open.in.num_eas, &io->t2open.in.eas);
451         if (!NT_STATUS_IS_OK(status)) {
452                 return status;
453         }
454
455         status = ntvfs_open(req, io);
456         if (!NT_STATUS_IS_OK(status)) {
457                 return status;
458         }
459
460         trans2_setup_reply(req, trans, 30, 0, 0);
461
462         SSVAL(trans->out.params.data, VWV(0), io->t2open.out.fnum);
463         SSVAL(trans->out.params.data, VWV(1), io->t2open.out.attrib);
464         srv_push_dos_date3(req->smb_conn, trans->out.params.data, 
465                            VWV(2), io->t2open.out.write_time);
466         SIVAL(trans->out.params.data, VWV(4), io->t2open.out.size);
467         SSVAL(trans->out.params.data, VWV(6), io->t2open.out.access);
468         SSVAL(trans->out.params.data, VWV(7), io->t2open.out.ftype);
469         SSVAL(trans->out.params.data, VWV(8), io->t2open.out.devstate);
470         SSVAL(trans->out.params.data, VWV(9), io->t2open.out.action);
471         SIVAL(trans->out.params.data, VWV(10), 0); /* reserved */
472         SSVAL(trans->out.params.data, VWV(12), 0); /* EaErrorOffset */
473         SIVAL(trans->out.params.data, VWV(13), 0); /* EaLength */
474
475         return status;
476 }
477
478
479 /*
480   trans2 mkdir implementation
481 */
482 static NTSTATUS trans2_mkdir(struct smbsrv_request *req, struct smb_trans2 *trans)
483 {
484         union smb_mkdir *io;
485         NTSTATUS status;
486
487         /* make sure we got enough parameters */
488         if (trans->in.params.length < 5) {
489                 return NT_STATUS_FOOBAR;
490         }
491
492         io = talloc(req, union smb_mkdir);
493         if (io == NULL) {
494                 return NT_STATUS_NO_MEMORY;
495         }
496
497         io->t2mkdir.level = RAW_MKDIR_T2MKDIR;
498         trans2_pull_blob_string(req, &trans->in.params, 4, &io->t2mkdir.in.path, 0);
499
500         status = ea_pull_list(&trans->in.data, io, 
501                               &io->t2mkdir.in.num_eas, 
502                               &io->t2mkdir.in.eas);
503         if (!NT_STATUS_IS_OK(status)) {
504                 return status;
505         }
506
507         status = ntvfs_mkdir(req, io);
508         if (!NT_STATUS_IS_OK(status)) {
509                 return status;
510         }
511
512         trans2_setup_reply(req, trans, 2, 0, 0);
513
514         SSVAL(trans->out.params.data, VWV(0), 0);
515
516         return status;
517 }
518
519 /*
520   fill in the reply from a qpathinfo or qfileinfo call
521 */
522 static NTSTATUS trans2_fileinfo_fill(struct smbsrv_request *req, struct smb_trans2 *trans,
523                                      union smb_fileinfo *st)
524 {
525         uint_t i;
526         uint32_t list_size;
527         
528         switch (st->generic.level) {
529         case RAW_FILEINFO_GENERIC:
530         case RAW_FILEINFO_GETATTR:
531         case RAW_FILEINFO_GETATTRE:
532         case RAW_FILEINFO_SEC_DESC:
533                 /* handled elsewhere */
534                 return NT_STATUS_INVALID_LEVEL;
535
536         case RAW_FILEINFO_BASIC_INFO:
537         case RAW_FILEINFO_BASIC_INFORMATION:
538                 trans2_setup_reply(req, trans, 2, 40, 0);
539
540                 SSVAL(trans->out.params.data, 0, 0);
541                 push_nttime(trans->out.data.data,  0, st->basic_info.out.create_time);
542                 push_nttime(trans->out.data.data,  8, st->basic_info.out.access_time);
543                 push_nttime(trans->out.data.data, 16, st->basic_info.out.write_time);
544                 push_nttime(trans->out.data.data, 24, st->basic_info.out.change_time);
545                 SIVAL(trans->out.data.data,       32, st->basic_info.out.attrib);
546                 SIVAL(trans->out.data.data,       36, 0); /* padding */
547                 return NT_STATUS_OK;
548
549         case RAW_FILEINFO_STANDARD:
550                 trans2_setup_reply(req, trans, 2, 22, 0);
551
552                 SSVAL(trans->out.params.data, 0, 0);
553                 srv_push_dos_date2(req->smb_conn, trans->out.data.data, 0, st->standard.out.create_time);
554                 srv_push_dos_date2(req->smb_conn, trans->out.data.data, 4, st->standard.out.access_time);
555                 srv_push_dos_date2(req->smb_conn, trans->out.data.data, 8, st->standard.out.write_time);
556                 SIVAL(trans->out.data.data,        12, st->standard.out.size);
557                 SIVAL(trans->out.data.data,        16, st->standard.out.alloc_size);
558                 SSVAL(trans->out.data.data,        20, st->standard.out.attrib);
559                 return NT_STATUS_OK;
560
561         case RAW_FILEINFO_EA_SIZE:
562                 trans2_setup_reply(req, trans, 2, 26, 0);
563
564                 SSVAL(trans->out.params.data, 0, 0);
565                 srv_push_dos_date2(req->smb_conn, trans->out.data.data, 0, st->ea_size.out.create_time);
566                 srv_push_dos_date2(req->smb_conn, trans->out.data.data, 4, st->ea_size.out.access_time);
567                 srv_push_dos_date2(req->smb_conn, trans->out.data.data, 8, st->ea_size.out.write_time);
568                 SIVAL(trans->out.data.data,        12, st->ea_size.out.size);
569                 SIVAL(trans->out.data.data,        16, st->ea_size.out.alloc_size);
570                 SSVAL(trans->out.data.data,        20, st->ea_size.out.attrib);
571                 SIVAL(trans->out.data.data,        22, st->ea_size.out.ea_size);
572                 return NT_STATUS_OK;
573
574         case RAW_FILEINFO_NETWORK_OPEN_INFORMATION:
575                 trans2_setup_reply(req, trans, 2, 56, 0);
576
577                 SSVAL(trans->out.params.data, 0, 0);
578                 push_nttime(trans->out.data.data,  0, st->network_open_information.out.create_time);
579                 push_nttime(trans->out.data.data,  8, st->network_open_information.out.access_time);
580                 push_nttime(trans->out.data.data, 16, st->network_open_information.out.write_time);
581                 push_nttime(trans->out.data.data, 24, st->network_open_information.out.change_time);
582                 SBVAL(trans->out.data.data,       32, st->network_open_information.out.alloc_size);
583                 SBVAL(trans->out.data.data,       40, st->network_open_information.out.size);
584                 SIVAL(trans->out.data.data,       48, st->network_open_information.out.attrib);
585                 SIVAL(trans->out.data.data,       52, 0); /* padding */
586                 return NT_STATUS_OK;
587
588         case RAW_FILEINFO_STANDARD_INFO:
589         case RAW_FILEINFO_STANDARD_INFORMATION:
590                 trans2_setup_reply(req, trans, 2, 24, 0);
591                 SSVAL(trans->out.params.data, 0, 0);
592                 SBVAL(trans->out.data.data,  0, st->standard_info.out.alloc_size);
593                 SBVAL(trans->out.data.data,  8, st->standard_info.out.size);
594                 SIVAL(trans->out.data.data, 16, st->standard_info.out.nlink);
595                 SCVAL(trans->out.data.data, 20, st->standard_info.out.delete_pending);
596                 SCVAL(trans->out.data.data, 21, st->standard_info.out.directory);
597                 SSVAL(trans->out.data.data, 22, 0); /* padding */
598                 return NT_STATUS_OK;
599
600         case RAW_FILEINFO_ATTRIBUTE_TAG_INFORMATION:
601                 trans2_setup_reply(req, trans, 2, 8, 0);
602                 SSVAL(trans->out.params.data, 0, 0);
603                 SIVAL(trans->out.data.data,  0, st->attribute_tag_information.out.attrib);
604                 SIVAL(trans->out.data.data,  4, st->attribute_tag_information.out.reparse_tag);
605                 return NT_STATUS_OK;
606
607         case RAW_FILEINFO_EA_INFO:
608         case RAW_FILEINFO_EA_INFORMATION:
609                 trans2_setup_reply(req, trans, 2, 4, 0);
610                 SSVAL(trans->out.params.data, 0, 0);
611                 SIVAL(trans->out.data.data,  0, st->ea_info.out.ea_size);
612                 return NT_STATUS_OK;
613
614         case RAW_FILEINFO_MODE_INFORMATION:
615                 trans2_setup_reply(req, trans, 2, 4, 0);
616                 SSVAL(trans->out.params.data, 0, 0);
617                 SIVAL(trans->out.data.data,  0, st->mode_information.out.mode);
618                 return NT_STATUS_OK;
619
620         case RAW_FILEINFO_ALIGNMENT_INFORMATION:
621                 trans2_setup_reply(req, trans, 2, 4, 0);
622                 SSVAL(trans->out.params.data, 0, 0);
623                 SIVAL(trans->out.data.data,  0, 
624                       st->alignment_information.out.alignment_requirement);
625                 return NT_STATUS_OK;
626
627         case RAW_FILEINFO_EA_LIST:
628                 list_size = ea_list_size(st->ea_list.out.num_eas,
629                                          st->ea_list.out.eas);
630                 trans2_setup_reply(req, trans, 2, list_size, 0);
631                 SSVAL(trans->out.params.data, 0, 0);
632                 ea_put_list(trans->out.data.data, 
633                             st->ea_list.out.num_eas, st->ea_list.out.eas);
634                 return NT_STATUS_OK;
635
636         case RAW_FILEINFO_ALL_EAS:
637                 list_size = ea_list_size(st->all_eas.out.num_eas,
638                                                   st->all_eas.out.eas);
639                 trans2_setup_reply(req, trans, 2, list_size, 0);
640                 SSVAL(trans->out.params.data, 0, 0);
641                 ea_put_list(trans->out.data.data, 
642                             st->all_eas.out.num_eas, st->all_eas.out.eas);
643                 return NT_STATUS_OK;
644
645         case RAW_FILEINFO_ACCESS_INFORMATION:
646                 trans2_setup_reply(req, trans, 2, 4, 0);
647                 SSVAL(trans->out.params.data, 0, 0);
648                 SIVAL(trans->out.data.data,  0, st->access_information.out.access_flags);
649                 return NT_STATUS_OK;
650
651         case RAW_FILEINFO_POSITION_INFORMATION:
652                 trans2_setup_reply(req, trans, 2, 8, 0);
653                 SSVAL(trans->out.params.data, 0, 0);
654                 SBVAL(trans->out.data.data,  0, st->position_information.out.position);
655                 return NT_STATUS_OK;
656
657         case RAW_FILEINFO_COMPRESSION_INFO:
658         case RAW_FILEINFO_COMPRESSION_INFORMATION:
659                 trans2_setup_reply(req, trans, 2, 16, 0);
660                 SSVAL(trans->out.params.data, 0, 0);
661                 SBVAL(trans->out.data.data,  0, st->compression_info.out.compressed_size);
662                 SSVAL(trans->out.data.data,  8, st->compression_info.out.format);
663                 SCVAL(trans->out.data.data, 10, st->compression_info.out.unit_shift);
664                 SCVAL(trans->out.data.data, 11, st->compression_info.out.chunk_shift);
665                 SCVAL(trans->out.data.data, 12, st->compression_info.out.cluster_shift);
666                 SSVAL(trans->out.data.data, 13, 0); /* 3 bytes padding */
667                 SCVAL(trans->out.data.data, 15, 0);
668                 return NT_STATUS_OK;
669
670         case RAW_FILEINFO_IS_NAME_VALID:
671                 trans2_setup_reply(req, trans, 2, 0, 0);
672                 SSVAL(trans->out.params.data, 0, 0);
673                 return NT_STATUS_OK;
674
675         case RAW_FILEINFO_INTERNAL_INFORMATION:
676                 trans2_setup_reply(req, trans, 2, 8, 0);
677                 SSVAL(trans->out.params.data, 0, 0);
678                 SBVAL(trans->out.data.data,  0, st->internal_information.out.file_id);
679                 return NT_STATUS_OK;
680
681         case RAW_FILEINFO_ALL_INFO:
682         case RAW_FILEINFO_ALL_INFORMATION:
683                 trans2_setup_reply(req, trans, 2, 72, 0);
684
685                 SSVAL(trans->out.params.data, 0, 0);
686                 push_nttime(trans->out.data.data,  0, st->all_info.out.create_time);
687                 push_nttime(trans->out.data.data,  8, st->all_info.out.access_time);
688                 push_nttime(trans->out.data.data, 16, st->all_info.out.write_time);
689                 push_nttime(trans->out.data.data, 24, st->all_info.out.change_time);
690                 SIVAL(trans->out.data.data,       32, st->all_info.out.attrib);
691                 SIVAL(trans->out.data.data,       36, 0);
692                 SBVAL(trans->out.data.data,       40, st->all_info.out.alloc_size);
693                 SBVAL(trans->out.data.data,       48, st->all_info.out.size);
694                 SIVAL(trans->out.data.data,       56, st->all_info.out.nlink);
695                 SCVAL(trans->out.data.data,       60, st->all_info.out.delete_pending);
696                 SCVAL(trans->out.data.data,       61, st->all_info.out.directory);
697                 SSVAL(trans->out.data.data,       62, 0); /* padding */
698                 SIVAL(trans->out.data.data,       64, st->all_info.out.ea_size);
699                 trans2_append_data_string(req, trans, &st->all_info.out.fname, 
700                                           68, STR_UNICODE);
701                 return NT_STATUS_OK;
702
703         case RAW_FILEINFO_NAME_INFO:
704         case RAW_FILEINFO_NAME_INFORMATION:
705                 trans2_setup_reply(req, trans, 2, 4, 0);
706                 SSVAL(trans->out.params.data, 0, 0);
707                 trans2_append_data_string(req, trans, &st->name_info.out.fname, 0, STR_UNICODE);
708                 return NT_STATUS_OK;
709
710         case RAW_FILEINFO_ALT_NAME_INFO:
711         case RAW_FILEINFO_ALT_NAME_INFORMATION:
712                 trans2_setup_reply(req, trans, 2, 4, 0);
713                 SSVAL(trans->out.params.data, 0, 0);
714                 trans2_append_data_string(req, trans, &st->alt_name_info.out.fname, 0, STR_UNICODE);
715                 return NT_STATUS_OK;
716
717         case RAW_FILEINFO_STREAM_INFO:
718         case RAW_FILEINFO_STREAM_INFORMATION:
719                 trans2_setup_reply(req, trans, 2, 0, 0);
720
721                 SSVAL(trans->out.params.data, 0, 0);
722
723                 for (i=0;i<st->stream_info.out.num_streams;i++) {
724                         uint32_t data_size = trans->out.data.length;
725                         uint8_t *data;
726
727                         trans2_grow_data(req, trans, data_size + 24);
728                         data = trans->out.data.data + data_size;
729                         SBVAL(data,  8, st->stream_info.out.streams[i].size);
730                         SBVAL(data, 16, st->stream_info.out.streams[i].alloc_size);
731                         trans2_append_data_string(req, trans, 
732                                                   &st->stream_info.out.streams[i].stream_name, 
733                                                   data_size + 4, STR_UNICODE);
734                         if (i == st->stream_info.out.num_streams - 1) {
735                                 SIVAL(trans->out.data.data, data_size, 0);
736                         } else {
737                                 trans2_grow_data_fill(req, trans, (trans->out.data.length+7)&~7);
738                                 SIVAL(trans->out.data.data, data_size, 
739                                       trans->out.data.length - data_size);
740                         }
741                 }
742                 return NT_STATUS_OK;
743                 
744         case RAW_FILEINFO_UNIX_BASIC:
745         case RAW_FILEINFO_UNIX_LINK:
746                 return NT_STATUS_INVALID_LEVEL;
747
748         case RAW_FILEINFO_SMB2_ALL_EAS:
749         case RAW_FILEINFO_SMB2_ALL_INFORMATION:
750                 return NT_STATUS_INVALID_LEVEL;
751         }
752
753         return NT_STATUS_INVALID_LEVEL;
754 }
755
756 /*
757   trans2 qpathinfo implementation
758 */
759 static NTSTATUS trans2_qpathinfo(struct smbsrv_request *req, struct smb_trans2 *trans)
760 {
761         union smb_fileinfo st;
762         NTSTATUS status;
763         uint16_t level;
764
765         /* make sure we got enough parameters */
766         if (trans->in.params.length < 2) {
767                 return NT_STATUS_FOOBAR;
768         }
769
770         level = SVAL(trans->in.params.data, 0);
771
772         trans2_pull_blob_string(req, &trans->in.params, 6, &st.generic.in.fname, 0);
773         if (st.generic.in.fname == NULL) {
774                 return NT_STATUS_FOOBAR;
775         }
776
777         /* work out the backend level - we make it 1-1 in the header */
778         st.generic.level = (enum smb_fileinfo_level)level;
779         if (st.generic.level >= RAW_FILEINFO_GENERIC) {
780                 return NT_STATUS_INVALID_LEVEL;
781         }
782
783         if (st.generic.level == RAW_FILEINFO_EA_LIST) {
784                 status = ea_pull_name_list(&trans->in.data, req, 
785                                            &st.ea_list.in.num_names,
786                                            &st.ea_list.in.ea_names);
787                 if (!NT_STATUS_IS_OK(status)) {
788                         return status;
789                 }
790         }
791
792         /* call the backend */
793         status = ntvfs_qpathinfo(req, &st);
794         if (!NT_STATUS_IS_OK(status)) {
795                 return status;
796         }
797
798         /* fill in the reply parameters */
799         status = trans2_fileinfo_fill(req, trans, &st);
800
801         return status;
802 }
803
804
805 /*
806   trans2 qpathinfo implementation
807 */
808 static NTSTATUS trans2_qfileinfo(struct smbsrv_request *req, struct smb_trans2 *trans)
809 {
810         union smb_fileinfo st;
811         NTSTATUS status;
812         uint16_t level;
813
814         /* make sure we got enough parameters */
815         if (trans->in.params.length < 4) {
816                 return NT_STATUS_FOOBAR;
817         }
818
819         st.generic.in.fnum  = SVAL(trans->in.params.data, 0);
820         level = SVAL(trans->in.params.data, 2);
821
822         /* work out the backend level - we make it 1-1 in the header */
823         st.generic.level = (enum smb_fileinfo_level)level;
824         if (st.generic.level >= RAW_FILEINFO_GENERIC) {
825                 return NT_STATUS_INVALID_LEVEL;
826         }
827
828         if (st.generic.level == RAW_FILEINFO_EA_LIST) {
829                 status = ea_pull_name_list(&trans->in.data, req, 
830                                            &st.ea_list.in.num_names,
831                                            &st.ea_list.in.ea_names);
832                 if (!NT_STATUS_IS_OK(status)) {
833                         return status;
834                 }
835         }
836
837         /* call the backend */
838         status = ntvfs_qfileinfo(req, &st);
839         if (!NT_STATUS_IS_OK(status)) {
840                 return status;
841         }
842
843         /* fill in the reply parameters */
844         status = trans2_fileinfo_fill(req, trans, &st);
845
846         return status;
847 }
848
849
850 /*
851   parse a trans2 setfileinfo/setpathinfo data blob
852 */
853 static NTSTATUS trans2_parse_sfileinfo(struct smbsrv_request *req,
854                                        union smb_setfileinfo *st,
855                                        const DATA_BLOB *blob)
856 {
857         uint32_t len;
858
859         switch (st->generic.level) {
860         case RAW_SFILEINFO_GENERIC:
861         case RAW_SFILEINFO_SETATTR:
862         case RAW_SFILEINFO_SETATTRE:
863         case RAW_SFILEINFO_SEC_DESC:
864                 /* handled elsewhere */
865                 return NT_STATUS_INVALID_LEVEL;
866
867         case RAW_SFILEINFO_STANDARD:
868                 CHECK_MIN_BLOB_SIZE(blob, 12);
869                 st->standard.in.create_time = srv_pull_dos_date2(req->smb_conn, blob->data + 0);
870                 st->standard.in.access_time = srv_pull_dos_date2(req->smb_conn, blob->data + 4);
871                 st->standard.in.write_time  = srv_pull_dos_date2(req->smb_conn, blob->data + 8);
872                 return NT_STATUS_OK;
873
874         case RAW_SFILEINFO_EA_SET:
875                 return ea_pull_list(blob, req, 
876                                     &st->ea_set.in.num_eas, 
877                                     &st->ea_set.in.eas);
878
879         case SMB_SFILEINFO_BASIC_INFO:
880         case SMB_SFILEINFO_BASIC_INFORMATION:
881                 CHECK_MIN_BLOB_SIZE(blob, 36);
882                 st->basic_info.in.create_time = pull_nttime(blob->data,  0);
883                 st->basic_info.in.access_time = pull_nttime(blob->data,  8);
884                 st->basic_info.in.write_time =  pull_nttime(blob->data, 16);
885                 st->basic_info.in.change_time = pull_nttime(blob->data, 24);
886                 st->basic_info.in.attrib =      IVAL(blob->data,        32);
887                 return NT_STATUS_OK;
888
889         case SMB_SFILEINFO_DISPOSITION_INFO:
890         case SMB_SFILEINFO_DISPOSITION_INFORMATION:
891                 CHECK_MIN_BLOB_SIZE(blob, 1);
892                 st->disposition_info.in.delete_on_close = CVAL(blob->data, 0);
893                 return NT_STATUS_OK;
894
895         case SMB_SFILEINFO_ALLOCATION_INFO:
896         case SMB_SFILEINFO_ALLOCATION_INFORMATION:
897                 CHECK_MIN_BLOB_SIZE(blob, 8);
898                 st->allocation_info.in.alloc_size = BVAL(blob->data, 0);
899                 return NT_STATUS_OK;                            
900
901         case RAW_SFILEINFO_END_OF_FILE_INFO:
902         case RAW_SFILEINFO_END_OF_FILE_INFORMATION:
903                 CHECK_MIN_BLOB_SIZE(blob, 8);
904                 st->end_of_file_info.in.size = BVAL(blob->data, 0);
905                 return NT_STATUS_OK;
906
907         case RAW_SFILEINFO_RENAME_INFORMATION: {
908                 DATA_BLOB blob2;
909
910                 CHECK_MIN_BLOB_SIZE(blob, 12);
911                 st->rename_information.in.overwrite = CVAL(blob->data, 0);
912                 st->rename_information.in.root_fid  = IVAL(blob->data, 4);
913                 len                                 = IVAL(blob->data, 8);
914                 blob2.data = blob->data+12;
915                 blob2.length = MIN(blob->length, len);
916                 trans2_pull_blob_string(req, &blob2, 0, 
917                                         &st->rename_information.in.new_name, STR_UNICODE);
918                 return NT_STATUS_OK;
919         }
920
921         case RAW_SFILEINFO_POSITION_INFORMATION:
922                 CHECK_MIN_BLOB_SIZE(blob, 8);
923                 st->position_information.in.position = BVAL(blob->data, 0);
924                 return NT_STATUS_OK;
925
926         case RAW_SFILEINFO_MODE_INFORMATION:
927                 CHECK_MIN_BLOB_SIZE(blob, 4);
928                 st->mode_information.in.mode = IVAL(blob->data, 0);
929                 return NT_STATUS_OK;
930
931         case RAW_SFILEINFO_UNIX_BASIC:
932         case RAW_SFILEINFO_UNIX_LINK:
933         case RAW_SFILEINFO_UNIX_HLINK:
934         case RAW_SFILEINFO_1023:
935         case RAW_SFILEINFO_1025:
936         case RAW_SFILEINFO_1029:
937         case RAW_SFILEINFO_1032:
938         case RAW_SFILEINFO_1039:
939         case RAW_SFILEINFO_1040:
940                 return NT_STATUS_INVALID_LEVEL;
941         }
942
943         return NT_STATUS_INVALID_LEVEL;
944 }
945
946 /*
947   trans2 setfileinfo implementation
948 */
949 static NTSTATUS trans2_setfileinfo(struct smbsrv_request *req, struct smb_trans2 *trans)
950 {
951         union smb_setfileinfo st;
952         NTSTATUS status;
953         uint16_t level, fnum;
954         DATA_BLOB *blob;
955
956         /* make sure we got enough parameters */
957         if (trans->in.params.length < 4) {
958                 return NT_STATUS_FOOBAR;
959         }
960
961         fnum  = SVAL(trans->in.params.data, 0);
962         level = SVAL(trans->in.params.data, 2);
963
964         blob = &trans->in.data;
965
966         st.generic.file.fnum = fnum;
967         st.generic.level = (enum smb_setfileinfo_level)level;
968
969         status = trans2_parse_sfileinfo(req, &st, blob);
970         if (!NT_STATUS_IS_OK(status)) {
971                 return status;
972         }
973
974         status = ntvfs_setfileinfo(req, &st);
975         if (!NT_STATUS_IS_OK(status)) {
976                 return status;
977         }
978
979         trans2_setup_reply(req, trans, 2, 0, 0);
980         SSVAL(trans->out.params.data, 0, 0);
981         return NT_STATUS_OK;
982 }
983
984 /*
985   trans2 setpathinfo implementation
986 */
987 static NTSTATUS trans2_setpathinfo(struct smbsrv_request *req, struct smb_trans2 *trans)
988 {
989         union smb_setfileinfo st;
990         NTSTATUS status;
991         uint16_t level;
992         DATA_BLOB *blob;
993
994         /* make sure we got enough parameters */
995         if (trans->in.params.length < 4) {
996                 return NT_STATUS_FOOBAR;
997         }
998
999         level = SVAL(trans->in.params.data, 0);
1000         blob = &trans->in.data;
1001         st.generic.level = (enum smb_setfileinfo_level)level;
1002
1003         trans2_pull_blob_string(req, &trans->in.params, 6, &st.generic.file.fname, 0);
1004         if (st.generic.file.fname == NULL) {
1005                 return NT_STATUS_FOOBAR;
1006         }
1007
1008         status = trans2_parse_sfileinfo(req, &st, blob);
1009         if (!NT_STATUS_IS_OK(status)) {
1010                 return status;
1011         }
1012
1013         status = ntvfs_setpathinfo(req, &st);
1014         if (!NT_STATUS_IS_OK(status)) {
1015                 return status;
1016         }
1017
1018         trans2_setup_reply(req, trans, 2, 0, 0);
1019         SSVAL(trans->out.params.data, 0, 0);
1020         return NT_STATUS_OK;
1021 }
1022
1023
1024 /* a structure to encapsulate the state information about an in-progress ffirst/fnext operation */
1025 struct find_state {
1026         struct smbsrv_request *req;
1027         struct smb_trans2 *trans;
1028         enum smb_search_level level;
1029         uint16_t last_entry_offset;
1030         uint16_t flags;
1031 };
1032
1033 /*
1034   fill a single entry in a trans2 find reply 
1035 */
1036 static BOOL find_fill_info(struct smbsrv_request *req,
1037                            struct smb_trans2 *trans, 
1038                            struct find_state *state,
1039                            union smb_search_data *file)
1040 {
1041         uint8_t *data;
1042         uint_t ofs = trans->out.data.length;
1043         uint32_t ea_size;
1044
1045         switch (state->level) {
1046         case RAW_SEARCH_SEARCH:
1047         case RAW_SEARCH_FFIRST:
1048         case RAW_SEARCH_FUNIQUE:
1049         case RAW_SEARCH_GENERIC:
1050                 /* handled elsewhere */
1051                 break;
1052
1053         case RAW_SEARCH_STANDARD:
1054                 if (state->flags & FLAG_TRANS2_FIND_REQUIRE_RESUME) {
1055                         trans2_grow_data(req, trans, ofs + 27);
1056                         SIVAL(trans->out.data.data, ofs, file->standard.resume_key);
1057                         ofs += 4;
1058                 } else {
1059                         trans2_grow_data(req, trans, ofs + 23);
1060                 }
1061                 data = trans->out.data.data + ofs;
1062                 srv_push_dos_date2(req->smb_conn, data, 0, file->standard.create_time);
1063                 srv_push_dos_date2(req->smb_conn, data, 4, file->standard.access_time);
1064                 srv_push_dos_date2(req->smb_conn, data, 8, file->standard.write_time);
1065                 SIVAL(data, 12, file->standard.size);
1066                 SIVAL(data, 16, file->standard.alloc_size);
1067                 SSVAL(data, 20, file->standard.attrib);
1068                 trans2_append_data_string(req, trans, &file->standard.name, 
1069                                           ofs + 22, STR_LEN8BIT | STR_TERMINATE | STR_LEN_NOTERM);
1070                 break;
1071
1072         case RAW_SEARCH_EA_SIZE:
1073                 if (state->flags & FLAG_TRANS2_FIND_REQUIRE_RESUME) {
1074                         trans2_grow_data(req, trans, ofs + 31);
1075                         SIVAL(trans->out.data.data, ofs, file->ea_size.resume_key);
1076                         ofs += 4;
1077                 } else {
1078                         trans2_grow_data(req, trans, ofs + 27);
1079                 }
1080                 data = trans->out.data.data + ofs;
1081                 srv_push_dos_date2(req->smb_conn, data, 0, file->ea_size.create_time);
1082                 srv_push_dos_date2(req->smb_conn, data, 4, file->ea_size.access_time);
1083                 srv_push_dos_date2(req->smb_conn, data, 8, file->ea_size.write_time);
1084                 SIVAL(data, 12, file->ea_size.size);
1085                 SIVAL(data, 16, file->ea_size.alloc_size);
1086                 SSVAL(data, 20, file->ea_size.attrib);
1087                 SIVAL(data, 22, file->ea_size.ea_size);
1088                 trans2_append_data_string(req, trans, &file->ea_size.name, 
1089                                           ofs + 26, STR_LEN8BIT | STR_NOALIGN);
1090                 trans2_grow_data(req, trans, trans->out.data.length + 1);
1091                 trans->out.data.data[trans->out.data.length-1] = 0;
1092                 break;
1093
1094         case RAW_SEARCH_EA_LIST:
1095                 ea_size = ea_list_size(file->ea_list.eas.num_eas, file->ea_list.eas.eas);
1096                 if (state->flags & FLAG_TRANS2_FIND_REQUIRE_RESUME) {
1097                         if (!trans2_grow_data(req, trans, ofs + 27 + ea_size)) {
1098                                 return False;
1099                         }
1100                         SIVAL(trans->out.data.data, ofs, file->ea_list.resume_key);
1101                         ofs += 4;
1102                 } else {
1103                         if (!trans2_grow_data(req, trans, ofs + 23 + ea_size)) {
1104                                 return False;
1105                         }
1106                 }
1107                 data = trans->out.data.data + ofs;
1108                 srv_push_dos_date2(req->smb_conn, data, 0, file->ea_list.create_time);
1109                 srv_push_dos_date2(req->smb_conn, data, 4, file->ea_list.access_time);
1110                 srv_push_dos_date2(req->smb_conn, data, 8, file->ea_list.write_time);
1111                 SIVAL(data, 12, file->ea_list.size);
1112                 SIVAL(data, 16, file->ea_list.alloc_size);
1113                 SSVAL(data, 20, file->ea_list.attrib);
1114                 ea_put_list(data+22, file->ea_list.eas.num_eas, file->ea_list.eas.eas);
1115                 trans2_append_data_string(req, trans, &file->ea_list.name, 
1116                                           ofs + 22 + ea_size, STR_LEN8BIT | STR_NOALIGN);
1117                 trans2_grow_data(req, trans, trans->out.data.length + 1);
1118                 trans->out.data.data[trans->out.data.length-1] = 0;
1119                 break;
1120
1121         case RAW_SEARCH_DIRECTORY_INFO:
1122                 trans2_grow_data(req, trans, ofs + 64);
1123                 data = trans->out.data.data + ofs;
1124                 SIVAL(data,          4, file->directory_info.file_index);
1125                 push_nttime(data,    8, file->directory_info.create_time);
1126                 push_nttime(data,   16, file->directory_info.access_time);
1127                 push_nttime(data,   24, file->directory_info.write_time);
1128                 push_nttime(data,   32, file->directory_info.change_time);
1129                 SBVAL(data,         40, file->directory_info.size);
1130                 SBVAL(data,         48, file->directory_info.alloc_size);
1131                 SIVAL(data,         56, file->directory_info.attrib);
1132                 trans2_append_data_string(req, trans, &file->directory_info.name, 
1133                                           ofs + 60, STR_TERMINATE_ASCII);
1134                 data = trans->out.data.data + ofs;
1135                 SIVAL(data,          0, trans->out.data.length - ofs);
1136                 break;
1137
1138         case RAW_SEARCH_FULL_DIRECTORY_INFO:
1139                 trans2_grow_data(req, trans, ofs + 68);
1140                 data = trans->out.data.data + ofs;
1141                 SIVAL(data,          4, file->full_directory_info.file_index);
1142                 push_nttime(data,    8, file->full_directory_info.create_time);
1143                 push_nttime(data,   16, file->full_directory_info.access_time);
1144                 push_nttime(data,   24, file->full_directory_info.write_time);
1145                 push_nttime(data,   32, file->full_directory_info.change_time);
1146                 SBVAL(data,         40, file->full_directory_info.size);
1147                 SBVAL(data,         48, file->full_directory_info.alloc_size);
1148                 SIVAL(data,         56, file->full_directory_info.attrib);
1149                 SIVAL(data,         64, file->full_directory_info.ea_size);
1150                 trans2_append_data_string(req, trans, &file->full_directory_info.name, 
1151                                           ofs + 60, STR_TERMINATE_ASCII);
1152                 data = trans->out.data.data + ofs;
1153                 SIVAL(data,          0, trans->out.data.length - ofs);
1154                 break;
1155
1156         case RAW_SEARCH_NAME_INFO:
1157                 trans2_grow_data(req, trans, ofs + 12);
1158                 data = trans->out.data.data + ofs;
1159                 SIVAL(data,          4, file->name_info.file_index);
1160                 trans2_append_data_string(req, trans, &file->name_info.name, 
1161                                           ofs + 8, STR_TERMINATE_ASCII);
1162                 data = trans->out.data.data + ofs;
1163                 SIVAL(data,          0, trans->out.data.length - ofs);
1164                 break;
1165
1166         case RAW_SEARCH_BOTH_DIRECTORY_INFO:
1167                 trans2_grow_data(req, trans, ofs + 94);
1168                 data = trans->out.data.data + ofs;
1169                 SIVAL(data,          4, file->both_directory_info.file_index);
1170                 push_nttime(data,    8, file->both_directory_info.create_time);
1171                 push_nttime(data,   16, file->both_directory_info.access_time);
1172                 push_nttime(data,   24, file->both_directory_info.write_time);
1173                 push_nttime(data,   32, file->both_directory_info.change_time);
1174                 SBVAL(data,         40, file->both_directory_info.size);
1175                 SBVAL(data,         48, file->both_directory_info.alloc_size);
1176                 SIVAL(data,         56, file->both_directory_info.attrib);
1177                 SIVAL(data,         64, file->both_directory_info.ea_size);
1178                 SCVAL(data,         69, 0); /* reserved */
1179                 memset(data+70,0,24);
1180                 trans2_push_data_string(req, trans, 
1181                                         68 + ofs, 70 + ofs, 
1182                                         &file->both_directory_info.short_name, 
1183                                         24, STR_UNICODE | STR_LEN8BIT);
1184                 trans2_append_data_string(req, trans, &file->both_directory_info.name, 
1185                                           ofs + 60, STR_TERMINATE_ASCII);
1186                 trans2_align_data(req, trans);
1187                 data = trans->out.data.data + ofs;
1188                 SIVAL(data,          0, trans->out.data.length - ofs);
1189                 break;
1190
1191         case RAW_SEARCH_ID_FULL_DIRECTORY_INFO:
1192                 trans2_grow_data(req, trans, ofs + 80);
1193                 data = trans->out.data.data + ofs;
1194                 SIVAL(data,          4, file->id_full_directory_info.file_index);
1195                 push_nttime(data,    8, file->id_full_directory_info.create_time);
1196                 push_nttime(data,   16, file->id_full_directory_info.access_time);
1197                 push_nttime(data,   24, file->id_full_directory_info.write_time);
1198                 push_nttime(data,   32, file->id_full_directory_info.change_time);
1199                 SBVAL(data,         40, file->id_full_directory_info.size);
1200                 SBVAL(data,         48, file->id_full_directory_info.alloc_size);
1201                 SIVAL(data,         56, file->id_full_directory_info.attrib);
1202                 SIVAL(data,         64, file->id_full_directory_info.ea_size);
1203                 SIVAL(data,         68, 0); /* padding */
1204                 SBVAL(data,         72, file->id_full_directory_info.file_id);
1205                 trans2_append_data_string(req, trans, &file->id_full_directory_info.name, 
1206                                           ofs + 60, STR_TERMINATE_ASCII);
1207                 data = trans->out.data.data + ofs;
1208                 SIVAL(data,          0, trans->out.data.length - ofs);
1209                 break;
1210
1211         case RAW_SEARCH_ID_BOTH_DIRECTORY_INFO:
1212                 trans2_grow_data(req, trans, ofs + 104);
1213                 data = trans->out.data.data + ofs;
1214                 SIVAL(data,          4, file->id_both_directory_info.file_index);
1215                 push_nttime(data,    8, file->id_both_directory_info.create_time);
1216                 push_nttime(data,   16, file->id_both_directory_info.access_time);
1217                 push_nttime(data,   24, file->id_both_directory_info.write_time);
1218                 push_nttime(data,   32, file->id_both_directory_info.change_time);
1219                 SBVAL(data,         40, file->id_both_directory_info.size);
1220                 SBVAL(data,         48, file->id_both_directory_info.alloc_size);
1221                 SIVAL(data,         56, file->id_both_directory_info.attrib);
1222                 SIVAL(data,         64, file->id_both_directory_info.ea_size);
1223                 SCVAL(data,         69, 0); /* reserved */
1224                 memset(data+70,0,26);
1225                 trans2_push_data_string(req, trans, 
1226                                         68 + ofs, 70 + ofs, 
1227                                         &file->id_both_directory_info.short_name, 
1228                                         24, STR_UNICODE | STR_LEN8BIT);
1229                 SBVAL(data,         96, file->id_both_directory_info.file_id);
1230                 trans2_append_data_string(req, trans, &file->id_both_directory_info.name, 
1231                                           ofs + 60, STR_TERMINATE_ASCII);
1232                 data = trans->out.data.data + ofs;
1233                 SIVAL(data,          0, trans->out.data.length - ofs);
1234                 break;
1235         }
1236
1237         return True;
1238 }
1239
1240 /* callback function for trans2 findfirst/findnext */
1241 static BOOL find_callback(void *private, union smb_search_data *file)
1242 {
1243         struct find_state *state = (struct find_state *)private;
1244         struct smb_trans2 *trans = state->trans;
1245         uint_t old_length;
1246
1247         old_length = trans->out.data.length;
1248
1249         if (!find_fill_info(state->req, trans, state, file) ||
1250             trans->out.data.length > trans->in.max_data) {
1251                 /* restore the old length and tell the backend to stop */
1252                 trans2_grow_data(state->req, trans, old_length);
1253                 return False;
1254         }
1255
1256         state->last_entry_offset = old_length;  
1257         return True;
1258 }
1259
1260
1261 /*
1262   trans2 findfirst implementation
1263 */
1264 static NTSTATUS trans2_findfirst(struct smbsrv_request *req, struct smb_trans2 *trans)
1265 {
1266         union smb_search_first search;
1267         NTSTATUS status;
1268         uint16_t level;
1269         uint8_t *param;
1270         struct find_state state;
1271
1272         /* make sure we got all the parameters */
1273         if (trans->in.params.length < 14) {
1274                 return NT_STATUS_FOOBAR;
1275         }
1276
1277         search.t2ffirst.in.search_attrib = SVAL(trans->in.params.data, 0);
1278         search.t2ffirst.in.max_count     = SVAL(trans->in.params.data, 2);
1279         search.t2ffirst.in.flags         = SVAL(trans->in.params.data, 4);
1280         level                            = SVAL(trans->in.params.data, 6);
1281         search.t2ffirst.in.storage_type  = IVAL(trans->in.params.data, 8);
1282
1283         trans2_pull_blob_string(req, &trans->in.params, 12, &search.t2ffirst.in.pattern, 0);
1284         if (search.t2ffirst.in.pattern == NULL) {
1285                 return NT_STATUS_FOOBAR;
1286         }
1287
1288         search.t2ffirst.level = (enum smb_search_level)level;
1289         if (search.t2ffirst.level >= RAW_SEARCH_GENERIC) {
1290                 return NT_STATUS_INVALID_LEVEL;
1291         }
1292
1293         if (search.t2ffirst.level == RAW_SEARCH_EA_LIST) {
1294                 status = ea_pull_name_list(&trans->in.data, req,
1295                                            &search.t2ffirst.in.num_names, 
1296                                            &search.t2ffirst.in.ea_names);
1297                 if (!NT_STATUS_IS_OK(status)) {
1298                         return status;
1299                 }
1300         }
1301
1302         /* setup the private state structure that the backend will
1303            give us in the callback */
1304         state.req = req;
1305         state.trans = trans;
1306         state.level = search.t2ffirst.level;
1307         state.last_entry_offset = 0;
1308         state.flags = search.t2ffirst.in.flags;
1309
1310         /* setup for just a header in the reply */
1311         trans2_setup_reply(req, trans, 10, 0, 0);
1312
1313         /* call the backend */
1314         status = ntvfs_search_first(req, &search, &state, find_callback);
1315         if (!NT_STATUS_IS_OK(status)) {
1316                 trans2_setup_reply(req, trans, 0, 0, 0);
1317                 return status;
1318         }
1319
1320         /* fill in the findfirst reply header */
1321         param = trans->out.params.data;
1322         SSVAL(param, VWV(0), search.t2ffirst.out.handle);
1323         SSVAL(param, VWV(1), search.t2ffirst.out.count);
1324         SSVAL(param, VWV(2), search.t2ffirst.out.end_of_search);
1325         SSVAL(param, VWV(3), 0);
1326         SSVAL(param, VWV(4), state.last_entry_offset);
1327
1328         return NT_STATUS_OK;
1329 }
1330
1331
1332 /*
1333   trans2 findnext implementation
1334 */
1335 static NTSTATUS trans2_findnext(struct smbsrv_request *req, struct smb_trans2 *trans)
1336 {
1337         union smb_search_next search;
1338         NTSTATUS status;
1339         uint16_t level;
1340         uint8_t *param;
1341         struct find_state state;
1342
1343         /* make sure we got all the parameters */
1344         if (trans->in.params.length < 12) {
1345                 return NT_STATUS_FOOBAR;
1346         }
1347
1348         search.t2fnext.in.handle        = SVAL(trans->in.params.data, 0);
1349         search.t2fnext.in.max_count     = SVAL(trans->in.params.data, 2);
1350         level                           = SVAL(trans->in.params.data, 4);
1351         search.t2fnext.in.resume_key    = IVAL(trans->in.params.data, 6);
1352         search.t2fnext.in.flags         = SVAL(trans->in.params.data, 10);
1353
1354         trans2_pull_blob_string(req, &trans->in.params, 12, &search.t2fnext.in.last_name, 0);
1355         if (search.t2fnext.in.last_name == NULL) {
1356                 return NT_STATUS_FOOBAR;
1357         }
1358
1359         search.t2fnext.level = (enum smb_search_level)level;
1360         if (search.t2fnext.level >= RAW_SEARCH_GENERIC) {
1361                 return NT_STATUS_INVALID_LEVEL;
1362         }
1363
1364         if (search.t2fnext.level == RAW_SEARCH_EA_LIST) {
1365                 status = ea_pull_name_list(&trans->in.data, req,
1366                                            &search.t2fnext.in.num_names, 
1367                                            &search.t2fnext.in.ea_names);
1368                 if (!NT_STATUS_IS_OK(status)) {
1369                         return status;
1370                 }
1371         }
1372
1373         /* setup the private state structure that the backend will give us in the callback */
1374         state.req = req;
1375         state.trans = trans;
1376         state.level = search.t2fnext.level;
1377         state.last_entry_offset = 0;
1378         state.flags = search.t2fnext.in.flags;
1379
1380         /* setup for just a header in the reply */
1381         trans2_setup_reply(req, trans, 8, 0, 0);
1382
1383         /* call the backend */
1384         status = ntvfs_search_next(req, &search, &state, find_callback);
1385         if (!NT_STATUS_IS_OK(status)) {
1386                 return status;
1387         }
1388
1389         /* fill in the findfirst reply header */
1390         param = trans->out.params.data;
1391         SSVAL(param, VWV(0), search.t2fnext.out.count);
1392         SSVAL(param, VWV(1), search.t2fnext.out.end_of_search);
1393         SSVAL(param, VWV(2), 0);
1394         SSVAL(param, VWV(3), state.last_entry_offset);
1395         
1396         return NT_STATUS_OK;
1397 }
1398
1399
1400 /*
1401   backend for trans2 requests
1402 */
1403 static NTSTATUS trans2_backend(struct smbsrv_request *req, struct smb_trans2 *trans)
1404 {
1405         NTSTATUS status;
1406
1407         /* direct trans2 pass thru */
1408         status = ntvfs_trans2(req, trans);
1409         if (!NT_STATUS_EQUAL(NT_STATUS_NOT_IMPLEMENTED, status)) {
1410                 return status;
1411         }
1412
1413         /* must have at least one setup word */
1414         if (trans->in.setup_count < 1) {
1415                 return NT_STATUS_FOOBAR;
1416         }
1417
1418         /* the trans2 command is in setup[0] */
1419         switch (trans->in.setup[0]) {
1420         case TRANSACT2_FINDFIRST:
1421                 return trans2_findfirst(req, trans);
1422         case TRANSACT2_FINDNEXT:
1423                 return trans2_findnext(req, trans);
1424         case TRANSACT2_QPATHINFO:
1425                 return trans2_qpathinfo(req, trans);
1426         case TRANSACT2_QFILEINFO:
1427                 return trans2_qfileinfo(req, trans);
1428         case TRANSACT2_SETFILEINFO:
1429                 return trans2_setfileinfo(req, trans);
1430         case TRANSACT2_SETPATHINFO:
1431                 return trans2_setpathinfo(req, trans);
1432         case TRANSACT2_QFSINFO:
1433                 return trans2_qfsinfo(req, trans);
1434         case TRANSACT2_OPEN:
1435                 return trans2_open(req, trans);
1436         case TRANSACT2_MKDIR:
1437                 return trans2_mkdir(req, trans);
1438         }
1439
1440         /* an unknown trans2 command */
1441         return NT_STATUS_FOOBAR;
1442 }
1443
1444
1445 /*
1446   send a continue request
1447 */
1448 static void reply_trans_continue(struct smbsrv_request *req, uint8_t command, 
1449                                  struct smb_trans2 *trans)
1450 {
1451         struct smbsrv_trans_partial *tp;
1452         int count;
1453
1454         /* make sure they don't flood us */
1455         for (count=0,tp=req->smb_conn->trans_partial;tp;tp=tp->next) count++;
1456         if (count > 100) {
1457                 smbsrv_send_error(req, NT_STATUS_INSUFFICIENT_RESOURCES);
1458                 return;
1459         }
1460
1461         tp = talloc(req, struct smbsrv_trans_partial);
1462
1463         tp->req = talloc_reference(tp, req);
1464         tp->trans = trans;
1465         tp->command = command;
1466
1467         DLIST_ADD(req->smb_conn->trans_partial, tp);
1468
1469         /* send a 'please continue' reply */
1470         smbsrv_setup_reply(req, 0, 0);
1471         smbsrv_send_reply(req);
1472 }
1473
1474
1475 /*
1476   answer a reconstructed trans request
1477 */
1478 static void reply_trans_complete(struct smbsrv_request *req, uint8_t command, 
1479                                  struct smb_trans2 *trans)
1480 {
1481         uint16_t params_left, data_left;
1482         uint8_t *params, *data;
1483         NTSTATUS status;
1484         int i;
1485
1486         /* its a full request, give it to the backend */
1487         if (command == SMBtrans) {
1488                 status = ntvfs_trans(req, trans);
1489         } else {
1490                 status = trans2_backend(req, trans);
1491         }
1492
1493         if (NT_STATUS_IS_ERR(status)) {
1494                 smbsrv_send_error(req, status);
1495                 return;
1496         }
1497
1498         params_left = trans->out.params.length;
1499         data_left   = trans->out.data.length;
1500         params      = trans->out.params.data;
1501         data        = trans->out.data.data;
1502
1503         smbsrv_setup_reply(req, 10 + trans->out.setup_count, 0);
1504
1505         if (!NT_STATUS_IS_OK(status)) {
1506                 smbsrv_setup_error(req, status);
1507         }
1508
1509         /* we need to divide up the reply into chunks that fit into
1510            the negotiated buffer size */
1511         do {
1512                 uint16_t this_data, this_param, max_bytes;
1513                 uint_t align1 = 1, align2 = (params_left ? 2 : 0);
1514                 struct smbsrv_request *this_req;
1515
1516                 max_bytes = req_max_data(req) - (align1 + align2);
1517
1518                 this_param = params_left;
1519                 if (this_param > max_bytes) {
1520                         this_param = max_bytes;
1521                 }
1522                 max_bytes -= this_param;
1523
1524                 this_data = data_left;
1525                 if (this_data > max_bytes) {
1526                         this_data = max_bytes;
1527                 }
1528
1529                 /* don't destroy unless this is the last chunk */
1530                 if (params_left - this_param != 0 || 
1531                     data_left - this_data != 0) {
1532                         this_req = smbsrv_setup_secondary_request(req);
1533                 } else {
1534                         this_req = req;
1535                 }
1536
1537                 req_grow_data(this_req, this_param + this_data + (align1 + align2));
1538
1539                 SSVAL(this_req->out.vwv, VWV(0), trans->out.params.length);
1540                 SSVAL(this_req->out.vwv, VWV(1), trans->out.data.length);
1541                 SSVAL(this_req->out.vwv, VWV(2), 0);
1542
1543                 SSVAL(this_req->out.vwv, VWV(3), this_param);
1544                 SSVAL(this_req->out.vwv, VWV(4), align1 + PTR_DIFF(this_req->out.data, this_req->out.hdr));
1545                 SSVAL(this_req->out.vwv, VWV(5), PTR_DIFF(params, trans->out.params.data));
1546
1547                 SSVAL(this_req->out.vwv, VWV(6), this_data);
1548                 SSVAL(this_req->out.vwv, VWV(7), align1 + align2 + 
1549                       PTR_DIFF(this_req->out.data + this_param, this_req->out.hdr));
1550                 SSVAL(this_req->out.vwv, VWV(8), PTR_DIFF(data, trans->out.data.data));
1551
1552                 SSVAL(this_req->out.vwv, VWV(9), trans->out.setup_count);
1553                 for (i=0;i<trans->out.setup_count;i++) {
1554                         SSVAL(this_req->out.vwv, VWV(10+i), trans->out.setup[i]);
1555                 }
1556
1557                 memset(this_req->out.data, 0, align1);
1558                 if (this_param != 0) {
1559                         memcpy(this_req->out.data + align1, params, this_param);
1560                 }
1561                 memset(this_req->out.data+this_param+align1, 0, align2);
1562                 if (this_data != 0) {
1563                         memcpy(this_req->out.data+this_param+align1+align2, data, this_data);
1564                 }
1565
1566                 params_left -= this_param;
1567                 data_left -= this_data;
1568                 params += this_param;
1569                 data += this_data;
1570
1571                 smbsrv_send_reply(this_req);
1572         } while (params_left != 0 || data_left != 0);
1573 }
1574
1575
1576 /*
1577   Reply to an SMBtrans or SMBtrans2 request
1578 */
1579 static void reply_trans_generic(struct smbsrv_request *req, uint8_t command)
1580 {
1581         struct smb_trans2 *trans;
1582         int i;
1583         uint16_t param_ofs, data_ofs;
1584         uint16_t param_count, data_count;
1585         uint16_t param_total, data_total;
1586
1587         trans = talloc(req, struct smb_trans2);
1588         if (trans == NULL) {
1589                 smbsrv_send_error(req, NT_STATUS_NO_MEMORY);
1590                 return;
1591         }
1592
1593         /* parse request */
1594         if (req->in.wct < 14) {
1595                 smbsrv_send_error(req, NT_STATUS_INVALID_PARAMETER);
1596                 return;
1597         }
1598
1599         param_total           = SVAL(req->in.vwv, VWV(0));
1600         data_total            = SVAL(req->in.vwv, VWV(1));
1601         trans->in.max_param   = SVAL(req->in.vwv, VWV(2));
1602         trans->in.max_data    = SVAL(req->in.vwv, VWV(3));
1603         trans->in.max_setup   = CVAL(req->in.vwv, VWV(4));
1604         trans->in.flags       = SVAL(req->in.vwv, VWV(5));
1605         trans->in.timeout     = IVAL(req->in.vwv, VWV(6));
1606         param_count           = SVAL(req->in.vwv, VWV(9));
1607         param_ofs             = SVAL(req->in.vwv, VWV(10));
1608         data_count            = SVAL(req->in.vwv, VWV(11));
1609         data_ofs              = SVAL(req->in.vwv, VWV(12));
1610         trans->in.setup_count = CVAL(req->in.vwv, VWV(13));
1611
1612         if (req->in.wct != 14 + trans->in.setup_count) {
1613                 smbsrv_send_error(req, NT_STATUS_DOS(ERRSRV, ERRerror));
1614                 return;
1615         }
1616
1617         /* parse out the setup words */
1618         trans->in.setup = talloc_array(req, uint16_t, trans->in.setup_count);
1619         if (trans->in.setup_count && !trans->in.setup) {
1620                 smbsrv_send_error(req, NT_STATUS_NO_MEMORY);
1621                 return;
1622         }
1623         for (i=0;i<trans->in.setup_count;i++) {
1624                 trans->in.setup[i] = SVAL(req->in.vwv, VWV(14+i));
1625         }
1626
1627         if (command == SMBtrans) {
1628                 req_pull_string(req, &trans->in.trans_name, req->in.data, -1, STR_TERMINATE);
1629         }
1630
1631         if (!req_pull_blob(req, req->in.hdr + param_ofs, param_count, &trans->in.params) ||
1632             !req_pull_blob(req, req->in.hdr + data_ofs, data_count, &trans->in.data)) {
1633                 smbsrv_send_error(req, NT_STATUS_FOOBAR);
1634                 return;
1635         }
1636
1637         /* is it a partial request? if so, then send a 'send more' message */
1638         if (param_total > param_count || data_total > data_count) {
1639                 reply_trans_continue(req, command, trans);
1640                 return;
1641         }
1642
1643         reply_trans_complete(req, command, trans);
1644 }
1645
1646
1647 /*
1648   Reply to an SMBtranss2 request
1649 */
1650 static void reply_transs_generic(struct smbsrv_request *req, uint8_t command)
1651 {
1652         struct smbsrv_trans_partial *tp;
1653         struct smb_trans2 *trans = NULL;
1654         uint16_t param_ofs, data_ofs;
1655         uint16_t param_count, data_count;
1656         uint16_t param_disp, data_disp;
1657         uint16_t param_total, data_total;
1658         DATA_BLOB params, data;
1659
1660         for (tp=req->smb_conn->trans_partial;tp;tp=tp->next) {
1661                 if (tp->command == command &&
1662                     SVAL(tp->req->in.hdr, HDR_MID) == SVAL(req->in.hdr, HDR_MID)) {
1663                         break;
1664                 }
1665         }
1666
1667         if (tp == NULL) {
1668                 smbsrv_send_error(req, NT_STATUS_INVALID_PARAMETER);
1669                 return;
1670         }
1671
1672         trans = tp->trans;
1673
1674         /* parse request */
1675         if (req->in.wct < 8) {
1676                 smbsrv_send_error(req, NT_STATUS_INVALID_PARAMETER);
1677                 return;
1678         }
1679
1680         param_total           = SVAL(req->in.vwv, VWV(0));
1681         data_total            = SVAL(req->in.vwv, VWV(1));
1682         param_count           = SVAL(req->in.vwv, VWV(2));
1683         param_ofs             = SVAL(req->in.vwv, VWV(3));
1684         param_disp            = SVAL(req->in.vwv, VWV(4));
1685         data_count            = SVAL(req->in.vwv, VWV(5));
1686         data_ofs              = SVAL(req->in.vwv, VWV(6));
1687         data_disp             = SVAL(req->in.vwv, VWV(7));
1688
1689         if (!req_pull_blob(req, req->in.hdr + param_ofs, param_count, &params) ||
1690             !req_pull_blob(req, req->in.hdr + data_ofs, data_count, &data)) {
1691                 smbsrv_send_error(req, NT_STATUS_INVALID_PARAMETER);
1692                 return;
1693         }
1694
1695         /* only allow contiguous requests */
1696         if ((param_count != 0 &&
1697              param_disp != trans->in.params.length) ||
1698             (data_count != 0 && 
1699              data_disp != trans->in.data.length)) {
1700                 smbsrv_send_error(req, NT_STATUS_INVALID_PARAMETER);
1701                 return;         
1702         }
1703
1704         /* add to the existing request */
1705         if (param_count != 0) {
1706                 trans->in.params.data = talloc_realloc(trans, 
1707                                                          trans->in.params.data, 
1708                                                          uint8_t, 
1709                                                          param_disp + param_count);
1710                 if (trans->in.params.data == NULL) {
1711                         goto failed;
1712                 }
1713                 trans->in.params.length = param_disp + param_count;
1714         }
1715
1716         if (data_count != 0) {
1717                 trans->in.data.data = talloc_realloc(trans, 
1718                                                        trans->in.data.data, 
1719                                                        uint8_t, 
1720                                                        data_disp + data_count);
1721                 if (trans->in.data.data == NULL) {
1722                         goto failed;
1723                 }
1724                 trans->in.data.length = data_disp + data_count;
1725         }
1726
1727         memcpy(trans->in.params.data + param_disp, params.data, params.length);
1728         memcpy(trans->in.data.data + data_disp, data.data, data.length);
1729
1730         /* the sequence number of the reply is taken from the last secondary
1731            response */
1732         tp->req->seq_num = req->seq_num;
1733
1734         /* we don't reply to Transs2 requests */
1735         talloc_free(req);
1736
1737         if (trans->in.params.length == param_total &&
1738             trans->in.data.length == data_total) {
1739                 /* its now complete */
1740                 DLIST_REMOVE(tp->req->smb_conn->trans_partial, tp);
1741                 reply_trans_complete(tp->req, command, trans);
1742         }
1743         return;
1744
1745 failed: 
1746         smbsrv_send_error(tp->req, NT_STATUS_NO_MEMORY);
1747         DLIST_REMOVE(req->smb_conn->trans_partial, tp);
1748         talloc_free(req);
1749         talloc_free(tp);
1750 }
1751
1752
1753 /*
1754   Reply to an SMBtrans2
1755 */
1756 void smbsrv_reply_trans2(struct smbsrv_request *req)
1757 {
1758         reply_trans_generic(req, SMBtrans2);
1759 }
1760
1761 /*
1762   Reply to an SMBtrans
1763 */
1764 void smbsrv_reply_trans(struct smbsrv_request *req)
1765 {
1766         reply_trans_generic(req, SMBtrans);
1767 }
1768
1769 /*
1770   Reply to an SMBtranss request
1771 */
1772 void smbsrv_reply_transs(struct smbsrv_request *req)
1773 {
1774         reply_transs_generic(req, SMBtrans);
1775 }
1776
1777 /*
1778   Reply to an SMBtranss2 request
1779 */
1780 void smbsrv_reply_transs2(struct smbsrv_request *req)
1781 {
1782         reply_transs_generic(req, SMBtrans2);
1783 }