ef7fa40b201d7294da3e3336d6373b5f664508e8
[jelmer/samba4-debian.git] / source / smb_server / smb / trans2.c
1 /* 
2    Unix SMB/CIFS implementation.
3    transaction2 handling
4    Copyright (C) Andrew Tridgell 2003
5
6    This program is free software; you can redistribute it and/or modify
7    it under the terms of the GNU General Public License as published by
8    the Free Software Foundation; either version 2 of the License, or
9    (at your option) any later version.
10    
11    This program is distributed in the hope that it will be useful,
12    but WITHOUT ANY WARRANTY; without even the implied warranty of
13    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14    GNU General Public License for more details.
15    
16    You should have received a copy of the GNU General Public License
17    along with this program; if not, write to the Free Software
18    Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
19 */
20 /*
21    This file handles the parsing of transact2 requests
22 */
23
24 #include "includes.h"
25 #include "dlinklist.h"
26 #include "smb_server/smb_server.h"
27 #include "librpc/gen_ndr/ndr_misc.h"
28 #include "ntvfs/ntvfs.h"
29
30 #define CHECK_MIN_BLOB_SIZE(blob, size) do { \
31         if ((blob)->length < (size)) { \
32                 return NT_STATUS_INFO_LENGTH_MISMATCH; \
33         }} while (0)
34
35 /* grow the data allocation size of a trans2 reply - this guarantees
36    that requests to grow the data size later will not change the
37    pointer */
38 static BOOL trans2_grow_data_allocation(struct smbsrv_request *req, 
39                                         struct smb_trans2 *trans,
40                                         uint32_t new_size)
41 {
42         if (new_size <= trans->out.data.length) {
43                 return True;
44         }
45         trans->out.data.data = talloc_realloc(req, trans->out.data.data, 
46                                               uint8_t, new_size);
47         return (trans->out.data.data != NULL);
48 }
49
50
51 /* grow the data size of a trans2 reply */
52 static BOOL trans2_grow_data(struct smbsrv_request *req, 
53                              struct smb_trans2 *trans,
54                              uint32_t new_size)
55 {
56         if (!trans2_grow_data_allocation(req, trans, new_size)) {
57                 return False;
58         }
59         trans->out.data.length = new_size;
60         return True;
61 }
62
63 /* grow the data, zero filling any new bytes */
64 static BOOL trans2_grow_data_fill(struct smbsrv_request *req, 
65                                   struct smb_trans2 *trans,
66                                   uint32_t new_size)
67 {
68         uint32_t old_size = trans->out.data.length;
69         if (!trans2_grow_data(req, trans, new_size)) {
70                 return False;
71         }
72         if (new_size > old_size) {
73                 memset(trans->out.data.data + old_size, 0, new_size - old_size);
74         }
75         return True;
76 }
77
78
79 /* setup a trans2 reply, given the data and params sizes */
80 static void trans2_setup_reply(struct smbsrv_request *req, 
81                                struct smb_trans2 *trans,
82                                uint16_t param_size, uint16_t data_size,
83                                uint16_t setup_count)
84 {
85         trans->out.setup_count = setup_count;
86         if (setup_count != 0) {
87                 trans->out.setup = talloc_zero_array(req, uint16_t, setup_count);
88         }
89         trans->out.params = data_blob_talloc(req, NULL, param_size);
90         trans->out.data = data_blob_talloc(req, NULL, data_size);
91 }
92
93
94 /*
95   pull a string from a blob in a trans2 request
96 */
97 static size_t trans2_pull_blob_string(struct smbsrv_request *req, 
98                                       const DATA_BLOB *blob,
99                                       uint16_t offset,
100                                       const char **str,
101                                       int flags)
102 {
103         /* we use STR_NO_RANGE_CHECK because the params are allocated
104            separately in a DATA_BLOB, so we need to do our own range
105            checking */
106         if (offset >= blob->length) {
107                 *str = NULL;
108                 return 0;
109         }
110         
111         return req_pull_string(req, str, 
112                                blob->data + offset, 
113                                blob->length - offset,
114                                STR_NO_RANGE_CHECK | flags);
115 }
116
117 /*
118   push a string into the data section of a trans2 request
119   return the number of bytes consumed in the output
120 */
121 static size_t trans2_push_data_string(struct smbsrv_request *req, 
122                                       struct smb_trans2 *trans,
123                                       uint32_t len_offset,
124                                       uint32_t offset,
125                                       const WIRE_STRING *str,
126                                       int dest_len,
127                                       int flags)
128 {
129         int alignment = 0, ret = 0, pkt_len;
130
131         /* we use STR_NO_RANGE_CHECK because the params are allocated
132            separately in a DATA_BLOB, so we need to do our own range
133            checking */
134         if (!str->s || offset >= trans->out.data.length) {
135                 if (flags & STR_LEN8BIT) {
136                         SCVAL(trans->out.data.data, len_offset, 0);
137                 } else {
138                         SIVAL(trans->out.data.data, len_offset, 0);
139                 }
140                 return 0;
141         }
142
143         flags |= STR_NO_RANGE_CHECK;
144
145         if (dest_len == -1 || (dest_len > trans->out.data.length - offset)) {
146                 dest_len = trans->out.data.length - offset;
147         }
148
149         if (!(flags & (STR_ASCII|STR_UNICODE))) {
150                 flags |= (req->flags2 & FLAGS2_UNICODE_STRINGS) ? STR_UNICODE : STR_ASCII;
151         }
152
153         if ((offset&1) && (flags & STR_UNICODE) && !(flags & STR_NOALIGN)) {
154                 alignment = 1;
155                 if (dest_len > 0) {
156                         SCVAL(trans->out.data.data + offset, 0, 0);
157                         ret = push_string(trans->out.data.data + offset + 1, str->s, dest_len-1, flags);
158                 }
159         } else {
160                 ret = push_string(trans->out.data.data + offset, str->s, dest_len, flags);
161         }
162
163         /* sometimes the string needs to be terminated, but the length
164            on the wire must not include the termination! */
165         pkt_len = ret;
166
167         if ((flags & STR_LEN_NOTERM) && (flags & STR_TERMINATE)) {
168                 if ((flags & STR_UNICODE) && ret >= 2) {
169                         pkt_len = ret-2;
170                 }
171                 if ((flags & STR_ASCII) && ret >= 1) {
172                         pkt_len = ret-1;
173                 }
174         }       
175
176         if (flags & STR_LEN8BIT) {
177                 SCVAL(trans->out.data.data, len_offset, pkt_len);
178         } else {
179                 SIVAL(trans->out.data.data, len_offset, pkt_len);
180         }
181
182         return ret + alignment;
183 }
184
185 /*
186   append a string to the data section of a trans2 reply
187   len_offset points to the place in the packet where the length field
188   should go
189 */
190 static void trans2_append_data_string(struct smbsrv_request *req, 
191                                         struct smb_trans2 *trans,
192                                         const WIRE_STRING *str,
193                                         uint_t len_offset,
194                                         int flags)
195 {
196         size_t ret;
197         uint32_t offset;
198         const int max_bytes_per_char = 3;
199
200         offset = trans->out.data.length;
201         trans2_grow_data(req, trans, offset + (2+strlen_m(str->s))*max_bytes_per_char);
202         ret = trans2_push_data_string(req, trans, len_offset, offset, str, -1, flags);
203         trans2_grow_data(req, trans, offset + ret);
204 }
205
206 /*
207   align the end of the data section of a trans reply on an even boundary
208 */
209 static void trans2_align_data(struct smbsrv_request *req, struct smb_trans2 *trans)
210 {
211         if ((trans->out.data.length & 1) == 0) {
212                 return;
213         }
214         trans2_grow_data(req, trans, trans->out.data.length+1);
215         SCVAL(trans->out.data.data, trans->out.data.length-1, 0);
216 }
217
218
219 /*
220   trans2 qfsinfo implementation
221 */
222 static NTSTATUS trans2_qfsinfo(struct smbsrv_request *req, struct smb_trans2 *trans)
223 {
224         union smb_fsinfo fsinfo;
225         NTSTATUS status;
226         uint16_t level;
227         uint_t i;
228         DATA_BLOB guid_blob;
229
230         /* make sure we got enough parameters */
231         if (trans->in.params.length != 2) {
232                 return NT_STATUS_FOOBAR;
233         }
234
235         level = SVAL(trans->in.params.data, 0);
236
237         switch (level) {
238         case SMB_QFS_ALLOCATION:
239                 fsinfo.allocation.level = RAW_QFS_ALLOCATION;
240
241                 status = ntvfs_fsinfo(req, &fsinfo);
242                 if (!NT_STATUS_IS_OK(status)) {
243                         return status;
244                 }
245
246                 trans2_setup_reply(req, trans, 0, 18, 0);
247
248                 SIVAL(trans->out.data.data,  0, fsinfo.allocation.out.fs_id);
249                 SIVAL(trans->out.data.data,  4, fsinfo.allocation.out.sectors_per_unit);
250                 SIVAL(trans->out.data.data,  8, fsinfo.allocation.out.total_alloc_units);
251                 SIVAL(trans->out.data.data, 12, fsinfo.allocation.out.avail_alloc_units);
252                 SSVAL(trans->out.data.data, 16, fsinfo.allocation.out.bytes_per_sector);
253
254                 return NT_STATUS_OK;
255
256         case SMB_QFS_VOLUME:
257                 fsinfo.volume.level = RAW_QFS_VOLUME;
258
259                 status = ntvfs_fsinfo(req, &fsinfo);
260                 if (!NT_STATUS_IS_OK(status)) {
261                         return status;
262                 }
263
264                 trans2_setup_reply(req, trans, 0, 5, 0);
265
266                 SIVAL(trans->out.data.data,       0, fsinfo.volume.out.serial_number);
267                 /* w2k3 implements this incorrectly for unicode - it
268                  * leaves the last byte off the string */
269                 trans2_append_data_string(req, trans, 
270                                           &fsinfo.volume.out.volume_name, 
271                                           4, STR_LEN8BIT|STR_NOALIGN);
272
273                 return NT_STATUS_OK;
274
275         case SMB_QFS_VOLUME_INFO:
276         case SMB_QFS_VOLUME_INFORMATION:
277                 fsinfo.volume_info.level = RAW_QFS_VOLUME_INFO;
278
279                 status = ntvfs_fsinfo(req, &fsinfo);
280                 if (!NT_STATUS_IS_OK(status)) {
281                         return status;
282                 }
283
284                 trans2_setup_reply(req, trans, 0, 18, 0);
285
286                 push_nttime(trans->out.data.data, 0, fsinfo.volume_info.out.create_time);
287                 SIVAL(trans->out.data.data,       8, fsinfo.volume_info.out.serial_number);
288                 SSVAL(trans->out.data.data,      16, 0); /* padding */
289                 trans2_append_data_string(req, trans, 
290                                           &fsinfo.volume_info.out.volume_name, 
291                                           12, STR_UNICODE);
292
293                 return NT_STATUS_OK;
294
295         case SMB_QFS_SIZE_INFO:
296         case SMB_QFS_SIZE_INFORMATION:
297                 fsinfo.size_info.level = RAW_QFS_SIZE_INFO;
298
299                 status = ntvfs_fsinfo(req, &fsinfo);
300                 if (!NT_STATUS_IS_OK(status)) {
301                         return status;
302                 }
303
304                 trans2_setup_reply(req, trans, 0, 24, 0);
305
306                 SBVAL(trans->out.data.data,  0, fsinfo.size_info.out.total_alloc_units);
307                 SBVAL(trans->out.data.data,  8, fsinfo.size_info.out.avail_alloc_units);
308                 SIVAL(trans->out.data.data, 16, fsinfo.size_info.out.sectors_per_unit);
309                 SIVAL(trans->out.data.data, 20, fsinfo.size_info.out.bytes_per_sector);
310
311                 return NT_STATUS_OK;
312
313         case SMB_QFS_DEVICE_INFO:
314         case SMB_QFS_DEVICE_INFORMATION:
315                 fsinfo.device_info.level = RAW_QFS_DEVICE_INFO;
316
317                 status = ntvfs_fsinfo(req, &fsinfo);
318                 if (!NT_STATUS_IS_OK(status)) {
319                         return status;
320                 }
321                 trans2_setup_reply(req, trans, 0, 8, 0);
322                 SIVAL(trans->out.data.data,      0, fsinfo.device_info.out.device_type);
323                 SIVAL(trans->out.data.data,      4, fsinfo.device_info.out.characteristics);
324                 return NT_STATUS_OK;
325
326
327         case SMB_QFS_ATTRIBUTE_INFO:
328         case SMB_QFS_ATTRIBUTE_INFORMATION:
329                 fsinfo.attribute_info.level = RAW_QFS_ATTRIBUTE_INFO;
330
331                 status = ntvfs_fsinfo(req, &fsinfo);
332                 if (!NT_STATUS_IS_OK(status)) {
333                         return status;
334                 }
335
336                 trans2_setup_reply(req, trans, 0, 12, 0);
337
338                 SIVAL(trans->out.data.data, 0, fsinfo.attribute_info.out.fs_attr);
339                 SIVAL(trans->out.data.data, 4, fsinfo.attribute_info.out.max_file_component_length);
340                 /* this must not be null terminated or win98 gets
341                    confused!  also note that w2k3 returns this as
342                    unicode even when ascii is negotiated */
343                 trans2_append_data_string(req, trans, 
344                                           &fsinfo.attribute_info.out.fs_type,
345                                           8, STR_UNICODE);
346                 return NT_STATUS_OK;
347
348
349         case SMB_QFS_QUOTA_INFORMATION:
350                 fsinfo.quota_information.level = RAW_QFS_QUOTA_INFORMATION;
351
352                 status = ntvfs_fsinfo(req, &fsinfo);
353                 if (!NT_STATUS_IS_OK(status)) {
354                         return status;
355                 }
356
357                 trans2_setup_reply(req, trans, 0, 48, 0);
358
359                 SBVAL(trans->out.data.data,   0, fsinfo.quota_information.out.unknown[0]);
360                 SBVAL(trans->out.data.data,   8, fsinfo.quota_information.out.unknown[1]);
361                 SBVAL(trans->out.data.data,  16, fsinfo.quota_information.out.unknown[2]);
362                 SBVAL(trans->out.data.data,  24, fsinfo.quota_information.out.quota_soft);
363                 SBVAL(trans->out.data.data,  32, fsinfo.quota_information.out.quota_hard);
364                 SBVAL(trans->out.data.data,  40, fsinfo.quota_information.out.quota_flags);
365
366                 return NT_STATUS_OK;
367
368
369         case SMB_QFS_FULL_SIZE_INFORMATION:
370                 fsinfo.full_size_information.level = RAW_QFS_FULL_SIZE_INFORMATION;
371
372                 status = ntvfs_fsinfo(req, &fsinfo);
373                 if (!NT_STATUS_IS_OK(status)) {
374                         return status;
375                 }
376
377                 trans2_setup_reply(req, trans, 0, 32, 0);
378
379                 SBVAL(trans->out.data.data,  0, fsinfo.full_size_information.out.total_alloc_units);
380                 SBVAL(trans->out.data.data,  8, fsinfo.full_size_information.out.call_avail_alloc_units);
381                 SBVAL(trans->out.data.data, 16, fsinfo.full_size_information.out.actual_avail_alloc_units);
382                 SIVAL(trans->out.data.data, 24, fsinfo.full_size_information.out.sectors_per_unit);
383                 SIVAL(trans->out.data.data, 28, fsinfo.full_size_information.out.bytes_per_sector);
384
385                 return NT_STATUS_OK;
386
387         case SMB_QFS_OBJECTID_INFORMATION:
388                 fsinfo.objectid_information.level = RAW_QFS_OBJECTID_INFORMATION;
389
390                 status = ntvfs_fsinfo(req, &fsinfo);
391                 if (!NT_STATUS_IS_OK(status)) {
392                         return status;
393                 }
394
395                 trans2_setup_reply(req, trans, 0, 64, 0);
396
397                 status = ndr_push_struct_blob(&guid_blob, req, 
398                                               &fsinfo.objectid_information.out.guid,
399                                               (ndr_push_flags_fn_t)ndr_push_GUID);
400                 if (!NT_STATUS_IS_OK(status)) {
401                         return status;
402                 }
403
404                 memcpy(trans->out.data.data, guid_blob.data, guid_blob.length);
405
406                 for (i=0;i<6;i++) {
407                         SBVAL(trans->out.data.data, 16 + 8*i, fsinfo.objectid_information.out.unknown[i]);
408                 }
409                 return NT_STATUS_OK;
410         }
411
412         return NT_STATUS_INVALID_LEVEL;
413 }
414
415
416 /*
417   trans2 open implementation
418 */
419 static NTSTATUS trans2_open(struct smbsrv_request *req, struct smb_trans2 *trans)
420 {
421         union smb_open *io;
422         NTSTATUS status;
423
424         /* make sure we got enough parameters */
425         if (trans->in.params.length < 29) {
426                 return NT_STATUS_FOOBAR;
427         }
428
429         io = talloc(req, union smb_open);
430         if (io == NULL) {
431                 return NT_STATUS_NO_MEMORY;
432         }
433
434         io->t2open.level           = RAW_OPEN_T2OPEN;
435         io->t2open.in.flags        = SVAL(trans->in.params.data, VWV(0));
436         io->t2open.in.open_mode    = SVAL(trans->in.params.data, VWV(1));
437         io->t2open.in.search_attrs = SVAL(trans->in.params.data, VWV(2));
438         io->t2open.in.file_attrs   = SVAL(trans->in.params.data, VWV(3));
439         io->t2open.in.write_time   = srv_pull_dos_date(req->smb_conn, 
440                                                     trans->in.params.data + VWV(4));;
441         io->t2open.in.open_func    = SVAL(trans->in.params.data, VWV(6));
442         io->t2open.in.size         = IVAL(trans->in.params.data, VWV(7));
443         io->t2open.in.timeout      = IVAL(trans->in.params.data, VWV(9));
444         io->t2open.in.num_eas      = 0;
445         io->t2open.in.eas          = NULL;
446
447         trans2_pull_blob_string(req, &trans->in.params, 28, &io->t2open.in.fname, 0);
448
449         status = ea_pull_list(&trans->in.data, io, &io->t2open.in.num_eas, &io->t2open.in.eas);
450         if (!NT_STATUS_IS_OK(status)) {
451                 return status;
452         }
453
454         status = ntvfs_openfile(req, io);
455         if (!NT_STATUS_IS_OK(status)) {
456                 return status;
457         }
458
459         trans2_setup_reply(req, trans, 30, 0, 0);
460
461         SSVAL(trans->out.params.data, VWV(0), io->t2open.out.fnum);
462         SSVAL(trans->out.params.data, VWV(1), io->t2open.out.attrib);
463         srv_push_dos_date3(req->smb_conn, trans->out.params.data, 
464                            VWV(2), io->t2open.out.write_time);
465         SIVAL(trans->out.params.data, VWV(4), io->t2open.out.size);
466         SSVAL(trans->out.params.data, VWV(6), io->t2open.out.access);
467         SSVAL(trans->out.params.data, VWV(7), io->t2open.out.ftype);
468         SSVAL(trans->out.params.data, VWV(8), io->t2open.out.devstate);
469         SSVAL(trans->out.params.data, VWV(9), io->t2open.out.action);
470         SIVAL(trans->out.params.data, VWV(10), 0); /* reserved */
471         SSVAL(trans->out.params.data, VWV(12), 0); /* EaErrorOffset */
472         SIVAL(trans->out.params.data, VWV(13), 0); /* EaLength */
473
474         return status;
475 }
476
477
478 /*
479   trans2 mkdir implementation
480 */
481 static NTSTATUS trans2_mkdir(struct smbsrv_request *req, struct smb_trans2 *trans)
482 {
483         union smb_mkdir *io;
484         NTSTATUS status;
485
486         /* make sure we got enough parameters */
487         if (trans->in.params.length < 5) {
488                 return NT_STATUS_FOOBAR;
489         }
490
491         io = talloc(req, union smb_mkdir);
492         if (io == NULL) {
493                 return NT_STATUS_NO_MEMORY;
494         }
495
496         io->t2mkdir.level = RAW_MKDIR_T2MKDIR;
497         trans2_pull_blob_string(req, &trans->in.params, 4, &io->t2mkdir.in.path, 0);
498
499         status = ea_pull_list(&trans->in.data, io, 
500                               &io->t2mkdir.in.num_eas, 
501                               &io->t2mkdir.in.eas);
502         if (!NT_STATUS_IS_OK(status)) {
503                 return status;
504         }
505
506         status = ntvfs_mkdir(req, io);
507         if (!NT_STATUS_IS_OK(status)) {
508                 return status;
509         }
510
511         trans2_setup_reply(req, trans, 2, 0, 0);
512
513         SSVAL(trans->out.params.data, VWV(0), 0);
514
515         return status;
516 }
517
518 /*
519   fill in the reply from a qpathinfo or qfileinfo call
520 */
521 static NTSTATUS trans2_fileinfo_fill(struct smbsrv_request *req, struct smb_trans2 *trans,
522                                      union smb_fileinfo *st)
523 {
524         uint_t i;
525         uint32_t list_size;
526         
527         switch (st->generic.level) {
528         case RAW_FILEINFO_GENERIC:
529         case RAW_FILEINFO_GETATTR:
530         case RAW_FILEINFO_GETATTRE:
531         case RAW_FILEINFO_SEC_DESC:
532                 /* handled elsewhere */
533                 return NT_STATUS_INVALID_LEVEL;
534
535         case RAW_FILEINFO_BASIC_INFO:
536         case RAW_FILEINFO_BASIC_INFORMATION:
537                 trans2_setup_reply(req, trans, 2, 40, 0);
538
539                 SSVAL(trans->out.params.data, 0, 0);
540                 push_nttime(trans->out.data.data,  0, st->basic_info.out.create_time);
541                 push_nttime(trans->out.data.data,  8, st->basic_info.out.access_time);
542                 push_nttime(trans->out.data.data, 16, st->basic_info.out.write_time);
543                 push_nttime(trans->out.data.data, 24, st->basic_info.out.change_time);
544                 SIVAL(trans->out.data.data,       32, st->basic_info.out.attrib);
545                 SIVAL(trans->out.data.data,       36, 0); /* padding */
546                 return NT_STATUS_OK;
547
548         case RAW_FILEINFO_STANDARD:
549                 trans2_setup_reply(req, trans, 2, 22, 0);
550
551                 SSVAL(trans->out.params.data, 0, 0);
552                 srv_push_dos_date2(req->smb_conn, trans->out.data.data, 0, st->standard.out.create_time);
553                 srv_push_dos_date2(req->smb_conn, trans->out.data.data, 4, st->standard.out.access_time);
554                 srv_push_dos_date2(req->smb_conn, trans->out.data.data, 8, st->standard.out.write_time);
555                 SIVAL(trans->out.data.data,        12, st->standard.out.size);
556                 SIVAL(trans->out.data.data,        16, st->standard.out.alloc_size);
557                 SSVAL(trans->out.data.data,        20, st->standard.out.attrib);
558                 return NT_STATUS_OK;
559
560         case RAW_FILEINFO_EA_SIZE:
561                 trans2_setup_reply(req, trans, 2, 26, 0);
562
563                 SSVAL(trans->out.params.data, 0, 0);
564                 srv_push_dos_date2(req->smb_conn, trans->out.data.data, 0, st->ea_size.out.create_time);
565                 srv_push_dos_date2(req->smb_conn, trans->out.data.data, 4, st->ea_size.out.access_time);
566                 srv_push_dos_date2(req->smb_conn, trans->out.data.data, 8, st->ea_size.out.write_time);
567                 SIVAL(trans->out.data.data,        12, st->ea_size.out.size);
568                 SIVAL(trans->out.data.data,        16, st->ea_size.out.alloc_size);
569                 SSVAL(trans->out.data.data,        20, st->ea_size.out.attrib);
570                 SIVAL(trans->out.data.data,        22, st->ea_size.out.ea_size);
571                 return NT_STATUS_OK;
572
573         case RAW_FILEINFO_NETWORK_OPEN_INFORMATION:
574                 trans2_setup_reply(req, trans, 2, 56, 0);
575
576                 SSVAL(trans->out.params.data, 0, 0);
577                 push_nttime(trans->out.data.data,  0, st->network_open_information.out.create_time);
578                 push_nttime(trans->out.data.data,  8, st->network_open_information.out.access_time);
579                 push_nttime(trans->out.data.data, 16, st->network_open_information.out.write_time);
580                 push_nttime(trans->out.data.data, 24, st->network_open_information.out.change_time);
581                 SBVAL(trans->out.data.data,       32, st->network_open_information.out.alloc_size);
582                 SBVAL(trans->out.data.data,       40, st->network_open_information.out.size);
583                 SIVAL(trans->out.data.data,       48, st->network_open_information.out.attrib);
584                 SIVAL(trans->out.data.data,       52, 0); /* padding */
585                 return NT_STATUS_OK;
586
587         case RAW_FILEINFO_STANDARD_INFO:
588         case RAW_FILEINFO_STANDARD_INFORMATION:
589                 trans2_setup_reply(req, trans, 2, 24, 0);
590                 SSVAL(trans->out.params.data, 0, 0);
591                 SBVAL(trans->out.data.data,  0, st->standard_info.out.alloc_size);
592                 SBVAL(trans->out.data.data,  8, st->standard_info.out.size);
593                 SIVAL(trans->out.data.data, 16, st->standard_info.out.nlink);
594                 SCVAL(trans->out.data.data, 20, st->standard_info.out.delete_pending);
595                 SCVAL(trans->out.data.data, 21, st->standard_info.out.directory);
596                 SSVAL(trans->out.data.data, 22, 0); /* padding */
597                 return NT_STATUS_OK;
598
599         case RAW_FILEINFO_ATTRIBUTE_TAG_INFORMATION:
600                 trans2_setup_reply(req, trans, 2, 8, 0);
601                 SSVAL(trans->out.params.data, 0, 0);
602                 SIVAL(trans->out.data.data,  0, st->attribute_tag_information.out.attrib);
603                 SIVAL(trans->out.data.data,  4, st->attribute_tag_information.out.reparse_tag);
604                 return NT_STATUS_OK;
605
606         case RAW_FILEINFO_EA_INFO:
607         case RAW_FILEINFO_EA_INFORMATION:
608                 trans2_setup_reply(req, trans, 2, 4, 0);
609                 SSVAL(trans->out.params.data, 0, 0);
610                 SIVAL(trans->out.data.data,  0, st->ea_info.out.ea_size);
611                 return NT_STATUS_OK;
612
613         case RAW_FILEINFO_MODE_INFORMATION:
614                 trans2_setup_reply(req, trans, 2, 4, 0);
615                 SSVAL(trans->out.params.data, 0, 0);
616                 SIVAL(trans->out.data.data,  0, st->mode_information.out.mode);
617                 return NT_STATUS_OK;
618
619         case RAW_FILEINFO_ALIGNMENT_INFORMATION:
620                 trans2_setup_reply(req, trans, 2, 4, 0);
621                 SSVAL(trans->out.params.data, 0, 0);
622                 SIVAL(trans->out.data.data,  0, 
623                       st->alignment_information.out.alignment_requirement);
624                 return NT_STATUS_OK;
625
626         case RAW_FILEINFO_EA_LIST:
627                 list_size = ea_list_size(st->ea_list.out.num_eas,
628                                          st->ea_list.out.eas);
629                 trans2_setup_reply(req, trans, 2, list_size, 0);
630                 SSVAL(trans->out.params.data, 0, 0);
631                 ea_put_list(trans->out.data.data, 
632                             st->ea_list.out.num_eas, st->ea_list.out.eas);
633                 return NT_STATUS_OK;
634
635         case RAW_FILEINFO_ALL_EAS:
636                 list_size = ea_list_size(st->all_eas.out.num_eas,
637                                                   st->all_eas.out.eas);
638                 trans2_setup_reply(req, trans, 2, list_size, 0);
639                 SSVAL(trans->out.params.data, 0, 0);
640                 ea_put_list(trans->out.data.data, 
641                             st->all_eas.out.num_eas, st->all_eas.out.eas);
642                 return NT_STATUS_OK;
643
644         case RAW_FILEINFO_ACCESS_INFORMATION:
645                 trans2_setup_reply(req, trans, 2, 4, 0);
646                 SSVAL(trans->out.params.data, 0, 0);
647                 SIVAL(trans->out.data.data,  0, st->access_information.out.access_flags);
648                 return NT_STATUS_OK;
649
650         case RAW_FILEINFO_POSITION_INFORMATION:
651                 trans2_setup_reply(req, trans, 2, 8, 0);
652                 SSVAL(trans->out.params.data, 0, 0);
653                 SBVAL(trans->out.data.data,  0, st->position_information.out.position);
654                 return NT_STATUS_OK;
655
656         case RAW_FILEINFO_COMPRESSION_INFO:
657         case RAW_FILEINFO_COMPRESSION_INFORMATION:
658                 trans2_setup_reply(req, trans, 2, 16, 0);
659                 SSVAL(trans->out.params.data, 0, 0);
660                 SBVAL(trans->out.data.data,  0, st->compression_info.out.compressed_size);
661                 SSVAL(trans->out.data.data,  8, st->compression_info.out.format);
662                 SCVAL(trans->out.data.data, 10, st->compression_info.out.unit_shift);
663                 SCVAL(trans->out.data.data, 11, st->compression_info.out.chunk_shift);
664                 SCVAL(trans->out.data.data, 12, st->compression_info.out.cluster_shift);
665                 SSVAL(trans->out.data.data, 13, 0); /* 3 bytes padding */
666                 SCVAL(trans->out.data.data, 15, 0);
667                 return NT_STATUS_OK;
668
669         case RAW_FILEINFO_IS_NAME_VALID:
670                 trans2_setup_reply(req, trans, 2, 0, 0);
671                 SSVAL(trans->out.params.data, 0, 0);
672                 return NT_STATUS_OK;
673
674         case RAW_FILEINFO_INTERNAL_INFORMATION:
675                 trans2_setup_reply(req, trans, 2, 8, 0);
676                 SSVAL(trans->out.params.data, 0, 0);
677                 SBVAL(trans->out.data.data,  0, st->internal_information.out.file_id);
678                 return NT_STATUS_OK;
679
680         case RAW_FILEINFO_ALL_INFO:
681         case RAW_FILEINFO_ALL_INFORMATION:
682                 trans2_setup_reply(req, trans, 2, 72, 0);
683
684                 SSVAL(trans->out.params.data, 0, 0);
685                 push_nttime(trans->out.data.data,  0, st->all_info.out.create_time);
686                 push_nttime(trans->out.data.data,  8, st->all_info.out.access_time);
687                 push_nttime(trans->out.data.data, 16, st->all_info.out.write_time);
688                 push_nttime(trans->out.data.data, 24, st->all_info.out.change_time);
689                 SIVAL(trans->out.data.data,       32, st->all_info.out.attrib);
690                 SIVAL(trans->out.data.data,       36, 0);
691                 SBVAL(trans->out.data.data,       40, st->all_info.out.alloc_size);
692                 SBVAL(trans->out.data.data,       48, st->all_info.out.size);
693                 SIVAL(trans->out.data.data,       56, st->all_info.out.nlink);
694                 SCVAL(trans->out.data.data,       60, st->all_info.out.delete_pending);
695                 SCVAL(trans->out.data.data,       61, st->all_info.out.directory);
696                 SSVAL(trans->out.data.data,       62, 0); /* padding */
697                 SIVAL(trans->out.data.data,       64, st->all_info.out.ea_size);
698                 trans2_append_data_string(req, trans, &st->all_info.out.fname, 
699                                           68, STR_UNICODE);
700                 return NT_STATUS_OK;
701
702         case RAW_FILEINFO_NAME_INFO:
703         case RAW_FILEINFO_NAME_INFORMATION:
704                 trans2_setup_reply(req, trans, 2, 4, 0);
705                 SSVAL(trans->out.params.data, 0, 0);
706                 trans2_append_data_string(req, trans, &st->name_info.out.fname, 0, STR_UNICODE);
707                 return NT_STATUS_OK;
708
709         case RAW_FILEINFO_ALT_NAME_INFO:
710         case RAW_FILEINFO_ALT_NAME_INFORMATION:
711                 trans2_setup_reply(req, trans, 2, 4, 0);
712                 SSVAL(trans->out.params.data, 0, 0);
713                 trans2_append_data_string(req, trans, &st->alt_name_info.out.fname, 0, STR_UNICODE);
714                 return NT_STATUS_OK;
715
716         case RAW_FILEINFO_STREAM_INFO:
717         case RAW_FILEINFO_STREAM_INFORMATION:
718                 trans2_setup_reply(req, trans, 2, 0, 0);
719
720                 SSVAL(trans->out.params.data, 0, 0);
721
722                 for (i=0;i<st->stream_info.out.num_streams;i++) {
723                         uint32_t data_size = trans->out.data.length;
724                         uint8_t *data;
725
726                         trans2_grow_data(req, trans, data_size + 24);
727                         data = trans->out.data.data + data_size;
728                         SBVAL(data,  8, st->stream_info.out.streams[i].size);
729                         SBVAL(data, 16, st->stream_info.out.streams[i].alloc_size);
730                         trans2_append_data_string(req, trans, 
731                                                   &st->stream_info.out.streams[i].stream_name, 
732                                                   data_size + 4, STR_UNICODE);
733                         if (i == st->stream_info.out.num_streams - 1) {
734                                 SIVAL(trans->out.data.data, data_size, 0);
735                         } else {
736                                 trans2_grow_data_fill(req, trans, (trans->out.data.length+7)&~7);
737                                 SIVAL(trans->out.data.data, data_size, 
738                                       trans->out.data.length - data_size);
739                         }
740                 }
741                 return NT_STATUS_OK;
742                 
743         case RAW_FILEINFO_UNIX_BASIC:
744         case RAW_FILEINFO_UNIX_LINK:
745                 return NT_STATUS_INVALID_LEVEL;
746
747         case RAW_FILEINFO_SMB2_ALL_EAS:
748         case RAW_FILEINFO_SMB2_ALL_INFORMATION:
749                 return NT_STATUS_INVALID_LEVEL;
750         }
751
752         return NT_STATUS_INVALID_LEVEL;
753 }
754
755 /*
756   trans2 qpathinfo implementation
757 */
758 static NTSTATUS trans2_qpathinfo(struct smbsrv_request *req, struct smb_trans2 *trans)
759 {
760         union smb_fileinfo st;
761         NTSTATUS status;
762         uint16_t level;
763
764         /* make sure we got enough parameters */
765         if (trans->in.params.length < 2) {
766                 return NT_STATUS_FOOBAR;
767         }
768
769         level = SVAL(trans->in.params.data, 0);
770
771         trans2_pull_blob_string(req, &trans->in.params, 6, &st.generic.in.fname, 0);
772         if (st.generic.in.fname == NULL) {
773                 return NT_STATUS_FOOBAR;
774         }
775
776         /* work out the backend level - we make it 1-1 in the header */
777         st.generic.level = (enum smb_fileinfo_level)level;
778         if (st.generic.level >= RAW_FILEINFO_GENERIC) {
779                 return NT_STATUS_INVALID_LEVEL;
780         }
781
782         if (st.generic.level == RAW_FILEINFO_EA_LIST) {
783                 status = ea_pull_name_list(&trans->in.data, req, 
784                                            &st.ea_list.in.num_names,
785                                            &st.ea_list.in.ea_names);
786                 if (!NT_STATUS_IS_OK(status)) {
787                         return status;
788                 }
789         }
790
791         /* call the backend */
792         status = ntvfs_qpathinfo(req, &st);
793         if (!NT_STATUS_IS_OK(status)) {
794                 return status;
795         }
796
797         /* fill in the reply parameters */
798         status = trans2_fileinfo_fill(req, trans, &st);
799
800         return status;
801 }
802
803
804 /*
805   trans2 qpathinfo implementation
806 */
807 static NTSTATUS trans2_qfileinfo(struct smbsrv_request *req, struct smb_trans2 *trans)
808 {
809         union smb_fileinfo st;
810         NTSTATUS status;
811         uint16_t level;
812
813         /* make sure we got enough parameters */
814         if (trans->in.params.length < 4) {
815                 return NT_STATUS_FOOBAR;
816         }
817
818         st.generic.in.fnum  = SVAL(trans->in.params.data, 0);
819         level = SVAL(trans->in.params.data, 2);
820
821         /* work out the backend level - we make it 1-1 in the header */
822         st.generic.level = (enum smb_fileinfo_level)level;
823         if (st.generic.level >= RAW_FILEINFO_GENERIC) {
824                 return NT_STATUS_INVALID_LEVEL;
825         }
826
827         if (st.generic.level == RAW_FILEINFO_EA_LIST) {
828                 status = ea_pull_name_list(&trans->in.data, req, 
829                                            &st.ea_list.in.num_names,
830                                            &st.ea_list.in.ea_names);
831                 if (!NT_STATUS_IS_OK(status)) {
832                         return status;
833                 }
834         }
835
836         /* call the backend */
837         status = ntvfs_qfileinfo(req, &st);
838         if (!NT_STATUS_IS_OK(status)) {
839                 return status;
840         }
841
842         /* fill in the reply parameters */
843         status = trans2_fileinfo_fill(req, trans, &st);
844
845         return status;
846 }
847
848
849 /*
850   parse a trans2 setfileinfo/setpathinfo data blob
851 */
852 static NTSTATUS trans2_parse_sfileinfo(struct smbsrv_request *req,
853                                        union smb_setfileinfo *st,
854                                        const DATA_BLOB *blob)
855 {
856         uint32_t len;
857
858         switch (st->generic.level) {
859         case RAW_SFILEINFO_GENERIC:
860         case RAW_SFILEINFO_SETATTR:
861         case RAW_SFILEINFO_SETATTRE:
862         case RAW_SFILEINFO_SEC_DESC:
863                 /* handled elsewhere */
864                 return NT_STATUS_INVALID_LEVEL;
865
866         case RAW_SFILEINFO_STANDARD:
867                 CHECK_MIN_BLOB_SIZE(blob, 12);
868                 st->standard.in.create_time = srv_pull_dos_date2(req->smb_conn, blob->data + 0);
869                 st->standard.in.access_time = srv_pull_dos_date2(req->smb_conn, blob->data + 4);
870                 st->standard.in.write_time  = srv_pull_dos_date2(req->smb_conn, blob->data + 8);
871                 return NT_STATUS_OK;
872
873         case RAW_SFILEINFO_EA_SET:
874                 return ea_pull_list(blob, req, 
875                                     &st->ea_set.in.num_eas, 
876                                     &st->ea_set.in.eas);
877
878         case SMB_SFILEINFO_BASIC_INFO:
879         case SMB_SFILEINFO_BASIC_INFORMATION:
880                 CHECK_MIN_BLOB_SIZE(blob, 36);
881                 st->basic_info.in.create_time = pull_nttime(blob->data,  0);
882                 st->basic_info.in.access_time = pull_nttime(blob->data,  8);
883                 st->basic_info.in.write_time =  pull_nttime(blob->data, 16);
884                 st->basic_info.in.change_time = pull_nttime(blob->data, 24);
885                 st->basic_info.in.attrib =      IVAL(blob->data,        32);
886                 return NT_STATUS_OK;
887
888         case SMB_SFILEINFO_DISPOSITION_INFO:
889         case SMB_SFILEINFO_DISPOSITION_INFORMATION:
890                 CHECK_MIN_BLOB_SIZE(blob, 1);
891                 st->disposition_info.in.delete_on_close = CVAL(blob->data, 0);
892                 return NT_STATUS_OK;
893
894         case SMB_SFILEINFO_ALLOCATION_INFO:
895         case SMB_SFILEINFO_ALLOCATION_INFORMATION:
896                 CHECK_MIN_BLOB_SIZE(blob, 8);
897                 st->allocation_info.in.alloc_size = BVAL(blob->data, 0);
898                 return NT_STATUS_OK;                            
899
900         case RAW_SFILEINFO_END_OF_FILE_INFO:
901         case RAW_SFILEINFO_END_OF_FILE_INFORMATION:
902                 CHECK_MIN_BLOB_SIZE(blob, 8);
903                 st->end_of_file_info.in.size = BVAL(blob->data, 0);
904                 return NT_STATUS_OK;
905
906         case RAW_SFILEINFO_RENAME_INFORMATION: {
907                 DATA_BLOB blob2;
908
909                 CHECK_MIN_BLOB_SIZE(blob, 12);
910                 st->rename_information.in.overwrite = CVAL(blob->data, 0);
911                 st->rename_information.in.root_fid  = IVAL(blob->data, 4);
912                 len                                 = IVAL(blob->data, 8);
913                 blob2.data = blob->data+12;
914                 blob2.length = MIN(blob->length, len);
915                 trans2_pull_blob_string(req, &blob2, 0, 
916                                         &st->rename_information.in.new_name, STR_UNICODE);
917                 return NT_STATUS_OK;
918         }
919
920         case RAW_SFILEINFO_POSITION_INFORMATION:
921                 CHECK_MIN_BLOB_SIZE(blob, 8);
922                 st->position_information.in.position = BVAL(blob->data, 0);
923                 return NT_STATUS_OK;
924
925         case RAW_SFILEINFO_MODE_INFORMATION:
926                 CHECK_MIN_BLOB_SIZE(blob, 4);
927                 st->mode_information.in.mode = IVAL(blob->data, 0);
928                 return NT_STATUS_OK;
929
930         case RAW_SFILEINFO_UNIX_BASIC:
931         case RAW_SFILEINFO_UNIX_LINK:
932         case RAW_SFILEINFO_UNIX_HLINK:
933         case RAW_SFILEINFO_1023:
934         case RAW_SFILEINFO_1025:
935         case RAW_SFILEINFO_1029:
936         case RAW_SFILEINFO_1032:
937         case RAW_SFILEINFO_1039:
938         case RAW_SFILEINFO_1040:
939                 return NT_STATUS_INVALID_LEVEL;
940         }
941
942         return NT_STATUS_INVALID_LEVEL;
943 }
944
945 /*
946   trans2 setfileinfo implementation
947 */
948 static NTSTATUS trans2_setfileinfo(struct smbsrv_request *req, struct smb_trans2 *trans)
949 {
950         union smb_setfileinfo st;
951         NTSTATUS status;
952         uint16_t level, fnum;
953         DATA_BLOB *blob;
954
955         /* make sure we got enough parameters */
956         if (trans->in.params.length < 4) {
957                 return NT_STATUS_FOOBAR;
958         }
959
960         fnum  = SVAL(trans->in.params.data, 0);
961         level = SVAL(trans->in.params.data, 2);
962
963         blob = &trans->in.data;
964
965         st.generic.file.fnum = fnum;
966         st.generic.level = (enum smb_setfileinfo_level)level;
967
968         status = trans2_parse_sfileinfo(req, &st, blob);
969         if (!NT_STATUS_IS_OK(status)) {
970                 return status;
971         }
972
973         status = ntvfs_setfileinfo(req, &st);
974         if (!NT_STATUS_IS_OK(status)) {
975                 return status;
976         }
977
978         trans2_setup_reply(req, trans, 2, 0, 0);
979         SSVAL(trans->out.params.data, 0, 0);
980         return NT_STATUS_OK;
981 }
982
983 /*
984   trans2 setpathinfo implementation
985 */
986 static NTSTATUS trans2_setpathinfo(struct smbsrv_request *req, struct smb_trans2 *trans)
987 {
988         union smb_setfileinfo st;
989         NTSTATUS status;
990         uint16_t level;
991         DATA_BLOB *blob;
992
993         /* make sure we got enough parameters */
994         if (trans->in.params.length < 4) {
995                 return NT_STATUS_FOOBAR;
996         }
997
998         level = SVAL(trans->in.params.data, 0);
999         blob = &trans->in.data;
1000         st.generic.level = (enum smb_setfileinfo_level)level;
1001
1002         trans2_pull_blob_string(req, &trans->in.params, 6, &st.generic.file.fname, 0);
1003         if (st.generic.file.fname == NULL) {
1004                 return NT_STATUS_FOOBAR;
1005         }
1006
1007         status = trans2_parse_sfileinfo(req, &st, blob);
1008         if (!NT_STATUS_IS_OK(status)) {
1009                 return status;
1010         }
1011
1012         status = ntvfs_setpathinfo(req, &st);
1013         if (!NT_STATUS_IS_OK(status)) {
1014                 return status;
1015         }
1016
1017         trans2_setup_reply(req, trans, 2, 0, 0);
1018         SSVAL(trans->out.params.data, 0, 0);
1019         return NT_STATUS_OK;
1020 }
1021
1022
1023 /* a structure to encapsulate the state information about an in-progress ffirst/fnext operation */
1024 struct find_state {
1025         struct smbsrv_request *req;
1026         struct smb_trans2 *trans;
1027         enum smb_search_level level;
1028         uint16_t last_entry_offset;
1029         uint16_t flags;
1030 };
1031
1032 /*
1033   fill a single entry in a trans2 find reply 
1034 */
1035 static BOOL find_fill_info(struct smbsrv_request *req,
1036                            struct smb_trans2 *trans, 
1037                            struct find_state *state,
1038                            union smb_search_data *file)
1039 {
1040         uint8_t *data;
1041         uint_t ofs = trans->out.data.length;
1042         uint32_t ea_size;
1043
1044         switch (state->level) {
1045         case RAW_SEARCH_SEARCH:
1046         case RAW_SEARCH_FFIRST:
1047         case RAW_SEARCH_FUNIQUE:
1048         case RAW_SEARCH_GENERIC:
1049                 /* handled elsewhere */
1050                 break;
1051
1052         case RAW_SEARCH_STANDARD:
1053                 if (state->flags & FLAG_TRANS2_FIND_REQUIRE_RESUME) {
1054                         trans2_grow_data(req, trans, ofs + 27);
1055                         SIVAL(trans->out.data.data, ofs, file->standard.resume_key);
1056                         ofs += 4;
1057                 } else {
1058                         trans2_grow_data(req, trans, ofs + 23);
1059                 }
1060                 data = trans->out.data.data + ofs;
1061                 srv_push_dos_date2(req->smb_conn, data, 0, file->standard.create_time);
1062                 srv_push_dos_date2(req->smb_conn, data, 4, file->standard.access_time);
1063                 srv_push_dos_date2(req->smb_conn, data, 8, file->standard.write_time);
1064                 SIVAL(data, 12, file->standard.size);
1065                 SIVAL(data, 16, file->standard.alloc_size);
1066                 SSVAL(data, 20, file->standard.attrib);
1067                 trans2_append_data_string(req, trans, &file->standard.name, 
1068                                           ofs + 22, STR_LEN8BIT | STR_TERMINATE | STR_LEN_NOTERM);
1069                 break;
1070
1071         case RAW_SEARCH_EA_SIZE:
1072                 if (state->flags & FLAG_TRANS2_FIND_REQUIRE_RESUME) {
1073                         trans2_grow_data(req, trans, ofs + 31);
1074                         SIVAL(trans->out.data.data, ofs, file->ea_size.resume_key);
1075                         ofs += 4;
1076                 } else {
1077                         trans2_grow_data(req, trans, ofs + 27);
1078                 }
1079                 data = trans->out.data.data + ofs;
1080                 srv_push_dos_date2(req->smb_conn, data, 0, file->ea_size.create_time);
1081                 srv_push_dos_date2(req->smb_conn, data, 4, file->ea_size.access_time);
1082                 srv_push_dos_date2(req->smb_conn, data, 8, file->ea_size.write_time);
1083                 SIVAL(data, 12, file->ea_size.size);
1084                 SIVAL(data, 16, file->ea_size.alloc_size);
1085                 SSVAL(data, 20, file->ea_size.attrib);
1086                 SIVAL(data, 22, file->ea_size.ea_size);
1087                 trans2_append_data_string(req, trans, &file->ea_size.name, 
1088                                           ofs + 26, STR_LEN8BIT | STR_NOALIGN);
1089                 trans2_grow_data(req, trans, trans->out.data.length + 1);
1090                 trans->out.data.data[trans->out.data.length-1] = 0;
1091                 break;
1092
1093         case RAW_SEARCH_EA_LIST:
1094                 ea_size = ea_list_size(file->ea_list.eas.num_eas, file->ea_list.eas.eas);
1095                 if (state->flags & FLAG_TRANS2_FIND_REQUIRE_RESUME) {
1096                         if (!trans2_grow_data(req, trans, ofs + 27 + ea_size)) {
1097                                 return False;
1098                         }
1099                         SIVAL(trans->out.data.data, ofs, file->ea_list.resume_key);
1100                         ofs += 4;
1101                 } else {
1102                         if (!trans2_grow_data(req, trans, ofs + 23 + ea_size)) {
1103                                 return False;
1104                         }
1105                 }
1106                 data = trans->out.data.data + ofs;
1107                 srv_push_dos_date2(req->smb_conn, data, 0, file->ea_list.create_time);
1108                 srv_push_dos_date2(req->smb_conn, data, 4, file->ea_list.access_time);
1109                 srv_push_dos_date2(req->smb_conn, data, 8, file->ea_list.write_time);
1110                 SIVAL(data, 12, file->ea_list.size);
1111                 SIVAL(data, 16, file->ea_list.alloc_size);
1112                 SSVAL(data, 20, file->ea_list.attrib);
1113                 ea_put_list(data+22, file->ea_list.eas.num_eas, file->ea_list.eas.eas);
1114                 trans2_append_data_string(req, trans, &file->ea_list.name, 
1115                                           ofs + 22 + ea_size, STR_LEN8BIT | STR_NOALIGN);
1116                 trans2_grow_data(req, trans, trans->out.data.length + 1);
1117                 trans->out.data.data[trans->out.data.length-1] = 0;
1118                 break;
1119
1120         case RAW_SEARCH_DIRECTORY_INFO:
1121                 trans2_grow_data(req, trans, ofs + 64);
1122                 data = trans->out.data.data + ofs;
1123                 SIVAL(data,          4, file->directory_info.file_index);
1124                 push_nttime(data,    8, file->directory_info.create_time);
1125                 push_nttime(data,   16, file->directory_info.access_time);
1126                 push_nttime(data,   24, file->directory_info.write_time);
1127                 push_nttime(data,   32, file->directory_info.change_time);
1128                 SBVAL(data,         40, file->directory_info.size);
1129                 SBVAL(data,         48, file->directory_info.alloc_size);
1130                 SIVAL(data,         56, file->directory_info.attrib);
1131                 trans2_append_data_string(req, trans, &file->directory_info.name, 
1132                                           ofs + 60, STR_TERMINATE_ASCII);
1133                 data = trans->out.data.data + ofs;
1134                 SIVAL(data,          0, trans->out.data.length - ofs);
1135                 break;
1136
1137         case RAW_SEARCH_FULL_DIRECTORY_INFO:
1138                 trans2_grow_data(req, trans, ofs + 68);
1139                 data = trans->out.data.data + ofs;
1140                 SIVAL(data,          4, file->full_directory_info.file_index);
1141                 push_nttime(data,    8, file->full_directory_info.create_time);
1142                 push_nttime(data,   16, file->full_directory_info.access_time);
1143                 push_nttime(data,   24, file->full_directory_info.write_time);
1144                 push_nttime(data,   32, file->full_directory_info.change_time);
1145                 SBVAL(data,         40, file->full_directory_info.size);
1146                 SBVAL(data,         48, file->full_directory_info.alloc_size);
1147                 SIVAL(data,         56, file->full_directory_info.attrib);
1148                 SIVAL(data,         64, file->full_directory_info.ea_size);
1149                 trans2_append_data_string(req, trans, &file->full_directory_info.name, 
1150                                           ofs + 60, STR_TERMINATE_ASCII);
1151                 data = trans->out.data.data + ofs;
1152                 SIVAL(data,          0, trans->out.data.length - ofs);
1153                 break;
1154
1155         case RAW_SEARCH_NAME_INFO:
1156                 trans2_grow_data(req, trans, ofs + 12);
1157                 data = trans->out.data.data + ofs;
1158                 SIVAL(data,          4, file->name_info.file_index);
1159                 trans2_append_data_string(req, trans, &file->name_info.name, 
1160                                           ofs + 8, STR_TERMINATE_ASCII);
1161                 data = trans->out.data.data + ofs;
1162                 SIVAL(data,          0, trans->out.data.length - ofs);
1163                 break;
1164
1165         case RAW_SEARCH_BOTH_DIRECTORY_INFO:
1166                 trans2_grow_data(req, trans, ofs + 94);
1167                 data = trans->out.data.data + ofs;
1168                 SIVAL(data,          4, file->both_directory_info.file_index);
1169                 push_nttime(data,    8, file->both_directory_info.create_time);
1170                 push_nttime(data,   16, file->both_directory_info.access_time);
1171                 push_nttime(data,   24, file->both_directory_info.write_time);
1172                 push_nttime(data,   32, file->both_directory_info.change_time);
1173                 SBVAL(data,         40, file->both_directory_info.size);
1174                 SBVAL(data,         48, file->both_directory_info.alloc_size);
1175                 SIVAL(data,         56, file->both_directory_info.attrib);
1176                 SIVAL(data,         64, file->both_directory_info.ea_size);
1177                 SCVAL(data,         69, 0); /* reserved */
1178                 memset(data+70,0,24);
1179                 trans2_push_data_string(req, trans, 
1180                                         68 + ofs, 70 + ofs, 
1181                                         &file->both_directory_info.short_name, 
1182                                         24, STR_UNICODE | STR_LEN8BIT);
1183                 trans2_append_data_string(req, trans, &file->both_directory_info.name, 
1184                                           ofs + 60, STR_TERMINATE_ASCII);
1185                 trans2_align_data(req, trans);
1186                 data = trans->out.data.data + ofs;
1187                 SIVAL(data,          0, trans->out.data.length - ofs);
1188                 break;
1189
1190         case RAW_SEARCH_ID_FULL_DIRECTORY_INFO:
1191                 trans2_grow_data(req, trans, ofs + 80);
1192                 data = trans->out.data.data + ofs;
1193                 SIVAL(data,          4, file->id_full_directory_info.file_index);
1194                 push_nttime(data,    8, file->id_full_directory_info.create_time);
1195                 push_nttime(data,   16, file->id_full_directory_info.access_time);
1196                 push_nttime(data,   24, file->id_full_directory_info.write_time);
1197                 push_nttime(data,   32, file->id_full_directory_info.change_time);
1198                 SBVAL(data,         40, file->id_full_directory_info.size);
1199                 SBVAL(data,         48, file->id_full_directory_info.alloc_size);
1200                 SIVAL(data,         56, file->id_full_directory_info.attrib);
1201                 SIVAL(data,         64, file->id_full_directory_info.ea_size);
1202                 SIVAL(data,         68, 0); /* padding */
1203                 SBVAL(data,         72, file->id_full_directory_info.file_id);
1204                 trans2_append_data_string(req, trans, &file->id_full_directory_info.name, 
1205                                           ofs + 60, STR_TERMINATE_ASCII);
1206                 data = trans->out.data.data + ofs;
1207                 SIVAL(data,          0, trans->out.data.length - ofs);
1208                 break;
1209
1210         case RAW_SEARCH_ID_BOTH_DIRECTORY_INFO:
1211                 trans2_grow_data(req, trans, ofs + 104);
1212                 data = trans->out.data.data + ofs;
1213                 SIVAL(data,          4, file->id_both_directory_info.file_index);
1214                 push_nttime(data,    8, file->id_both_directory_info.create_time);
1215                 push_nttime(data,   16, file->id_both_directory_info.access_time);
1216                 push_nttime(data,   24, file->id_both_directory_info.write_time);
1217                 push_nttime(data,   32, file->id_both_directory_info.change_time);
1218                 SBVAL(data,         40, file->id_both_directory_info.size);
1219                 SBVAL(data,         48, file->id_both_directory_info.alloc_size);
1220                 SIVAL(data,         56, file->id_both_directory_info.attrib);
1221                 SIVAL(data,         64, file->id_both_directory_info.ea_size);
1222                 SCVAL(data,         69, 0); /* reserved */
1223                 memset(data+70,0,26);
1224                 trans2_push_data_string(req, trans, 
1225                                         68 + ofs, 70 + ofs, 
1226                                         &file->id_both_directory_info.short_name, 
1227                                         24, STR_UNICODE | STR_LEN8BIT);
1228                 SBVAL(data,         96, file->id_both_directory_info.file_id);
1229                 trans2_append_data_string(req, trans, &file->id_both_directory_info.name, 
1230                                           ofs + 60, STR_TERMINATE_ASCII);
1231                 data = trans->out.data.data + ofs;
1232                 SIVAL(data,          0, trans->out.data.length - ofs);
1233                 break;
1234         }
1235
1236         return True;
1237 }
1238
1239 /* callback function for trans2 findfirst/findnext */
1240 static BOOL find_callback(void *private, union smb_search_data *file)
1241 {
1242         struct find_state *state = (struct find_state *)private;
1243         struct smb_trans2 *trans = state->trans;
1244         uint_t old_length;
1245
1246         old_length = trans->out.data.length;
1247
1248         if (!find_fill_info(state->req, trans, state, file) ||
1249             trans->out.data.length > trans->in.max_data) {
1250                 /* restore the old length and tell the backend to stop */
1251                 trans2_grow_data(state->req, trans, old_length);
1252                 return False;
1253         }
1254
1255         state->last_entry_offset = old_length;  
1256         return True;
1257 }
1258
1259
1260 /*
1261   trans2 findfirst implementation
1262 */
1263 static NTSTATUS trans2_findfirst(struct smbsrv_request *req, struct smb_trans2 *trans)
1264 {
1265         union smb_search_first search;
1266         NTSTATUS status;
1267         uint16_t level;
1268         uint8_t *param;
1269         struct find_state state;
1270
1271         /* make sure we got all the parameters */
1272         if (trans->in.params.length < 14) {
1273                 return NT_STATUS_FOOBAR;
1274         }
1275
1276         search.t2ffirst.in.search_attrib = SVAL(trans->in.params.data, 0);
1277         search.t2ffirst.in.max_count     = SVAL(trans->in.params.data, 2);
1278         search.t2ffirst.in.flags         = SVAL(trans->in.params.data, 4);
1279         level                            = SVAL(trans->in.params.data, 6);
1280         search.t2ffirst.in.storage_type  = IVAL(trans->in.params.data, 8);
1281
1282         trans2_pull_blob_string(req, &trans->in.params, 12, &search.t2ffirst.in.pattern, 0);
1283         if (search.t2ffirst.in.pattern == NULL) {
1284                 return NT_STATUS_FOOBAR;
1285         }
1286
1287         search.t2ffirst.level = (enum smb_search_level)level;
1288         if (search.t2ffirst.level >= RAW_SEARCH_GENERIC) {
1289                 return NT_STATUS_INVALID_LEVEL;
1290         }
1291
1292         if (search.t2ffirst.level == RAW_SEARCH_EA_LIST) {
1293                 status = ea_pull_name_list(&trans->in.data, req,
1294                                            &search.t2ffirst.in.num_names, 
1295                                            &search.t2ffirst.in.ea_names);
1296                 if (!NT_STATUS_IS_OK(status)) {
1297                         return status;
1298                 }
1299         }
1300
1301         /* setup the private state structure that the backend will
1302            give us in the callback */
1303         state.req = req;
1304         state.trans = trans;
1305         state.level = search.t2ffirst.level;
1306         state.last_entry_offset = 0;
1307         state.flags = search.t2ffirst.in.flags;
1308
1309         /* setup for just a header in the reply */
1310         trans2_setup_reply(req, trans, 10, 0, 0);
1311
1312         /* call the backend */
1313         status = ntvfs_search_first(req, &search, &state, find_callback);
1314         if (!NT_STATUS_IS_OK(status)) {
1315                 trans2_setup_reply(req, trans, 0, 0, 0);
1316                 return status;
1317         }
1318
1319         /* fill in the findfirst reply header */
1320         param = trans->out.params.data;
1321         SSVAL(param, VWV(0), search.t2ffirst.out.handle);
1322         SSVAL(param, VWV(1), search.t2ffirst.out.count);
1323         SSVAL(param, VWV(2), search.t2ffirst.out.end_of_search);
1324         SSVAL(param, VWV(3), 0);
1325         SSVAL(param, VWV(4), state.last_entry_offset);
1326
1327         return NT_STATUS_OK;
1328 }
1329
1330
1331 /*
1332   trans2 findnext implementation
1333 */
1334 static NTSTATUS trans2_findnext(struct smbsrv_request *req, struct smb_trans2 *trans)
1335 {
1336         union smb_search_next search;
1337         NTSTATUS status;
1338         uint16_t level;
1339         uint8_t *param;
1340         struct find_state state;
1341
1342         /* make sure we got all the parameters */
1343         if (trans->in.params.length < 12) {
1344                 return NT_STATUS_FOOBAR;
1345         }
1346
1347         search.t2fnext.in.handle        = SVAL(trans->in.params.data, 0);
1348         search.t2fnext.in.max_count     = SVAL(trans->in.params.data, 2);
1349         level                           = SVAL(trans->in.params.data, 4);
1350         search.t2fnext.in.resume_key    = IVAL(trans->in.params.data, 6);
1351         search.t2fnext.in.flags         = SVAL(trans->in.params.data, 10);
1352
1353         trans2_pull_blob_string(req, &trans->in.params, 12, &search.t2fnext.in.last_name, 0);
1354         if (search.t2fnext.in.last_name == NULL) {
1355                 return NT_STATUS_FOOBAR;
1356         }
1357
1358         search.t2fnext.level = (enum smb_search_level)level;
1359         if (search.t2fnext.level >= RAW_SEARCH_GENERIC) {
1360                 return NT_STATUS_INVALID_LEVEL;
1361         }
1362
1363         if (search.t2fnext.level == RAW_SEARCH_EA_LIST) {
1364                 status = ea_pull_name_list(&trans->in.data, req,
1365                                            &search.t2fnext.in.num_names, 
1366                                            &search.t2fnext.in.ea_names);
1367                 if (!NT_STATUS_IS_OK(status)) {
1368                         return status;
1369                 }
1370         }
1371
1372         /* setup the private state structure that the backend will give us in the callback */
1373         state.req = req;
1374         state.trans = trans;
1375         state.level = search.t2fnext.level;
1376         state.last_entry_offset = 0;
1377         state.flags = search.t2fnext.in.flags;
1378
1379         /* setup for just a header in the reply */
1380         trans2_setup_reply(req, trans, 8, 0, 0);
1381
1382         /* call the backend */
1383         status = ntvfs_search_next(req, &search, &state, find_callback);
1384         if (!NT_STATUS_IS_OK(status)) {
1385                 return status;
1386         }
1387
1388         /* fill in the findfirst reply header */
1389         param = trans->out.params.data;
1390         SSVAL(param, VWV(0), search.t2fnext.out.count);
1391         SSVAL(param, VWV(1), search.t2fnext.out.end_of_search);
1392         SSVAL(param, VWV(2), 0);
1393         SSVAL(param, VWV(3), state.last_entry_offset);
1394         
1395         return NT_STATUS_OK;
1396 }
1397
1398
1399 /*
1400   backend for trans2 requests
1401 */
1402 static NTSTATUS trans2_backend(struct smbsrv_request *req, struct smb_trans2 *trans)
1403 {
1404         NTSTATUS status;
1405
1406         /* direct trans2 pass thru */
1407         status = ntvfs_trans2(req, trans);
1408         if (!NT_STATUS_EQUAL(NT_STATUS_NOT_IMPLEMENTED, status)) {
1409                 return status;
1410         }
1411
1412         /* must have at least one setup word */
1413         if (trans->in.setup_count < 1) {
1414                 return NT_STATUS_FOOBAR;
1415         }
1416
1417         /* the trans2 command is in setup[0] */
1418         switch (trans->in.setup[0]) {
1419         case TRANSACT2_FINDFIRST:
1420                 return trans2_findfirst(req, trans);
1421         case TRANSACT2_FINDNEXT:
1422                 return trans2_findnext(req, trans);
1423         case TRANSACT2_QPATHINFO:
1424                 return trans2_qpathinfo(req, trans);
1425         case TRANSACT2_QFILEINFO:
1426                 return trans2_qfileinfo(req, trans);
1427         case TRANSACT2_SETFILEINFO:
1428                 return trans2_setfileinfo(req, trans);
1429         case TRANSACT2_SETPATHINFO:
1430                 return trans2_setpathinfo(req, trans);
1431         case TRANSACT2_QFSINFO:
1432                 return trans2_qfsinfo(req, trans);
1433         case TRANSACT2_OPEN:
1434                 return trans2_open(req, trans);
1435         case TRANSACT2_MKDIR:
1436                 return trans2_mkdir(req, trans);
1437         }
1438
1439         /* an unknown trans2 command */
1440         return NT_STATUS_FOOBAR;
1441 }
1442
1443
1444 /*
1445   send a continue request
1446 */
1447 static void reply_trans_continue(struct smbsrv_request *req, uint8_t command, 
1448                                  struct smb_trans2 *trans)
1449 {
1450         struct smbsrv_trans_partial *tp;
1451         int count;
1452
1453         /* make sure they don't flood us */
1454         for (count=0,tp=req->smb_conn->trans_partial;tp;tp=tp->next) count++;
1455         if (count > 100) {
1456                 req_reply_error(req, NT_STATUS_INSUFFICIENT_RESOURCES);
1457                 return;
1458         }
1459
1460         tp = talloc(req, struct smbsrv_trans_partial);
1461
1462         tp->req = talloc_reference(tp, req);
1463         tp->trans = trans;
1464         tp->command = command;
1465
1466         DLIST_ADD(req->smb_conn->trans_partial, tp);
1467
1468         /* send a 'please continue' reply */
1469         req_setup_reply(req, 0, 0);
1470         req_send_reply(req);
1471 }
1472
1473
1474 /*
1475   answer a reconstructed trans request
1476 */
1477 static void reply_trans_complete(struct smbsrv_request *req, uint8_t command, 
1478                                  struct smb_trans2 *trans)
1479 {
1480         uint16_t params_left, data_left;
1481         uint8_t *params, *data;
1482         NTSTATUS status;
1483         int i;
1484
1485         /* its a full request, give it to the backend */
1486         if (command == SMBtrans) {
1487                 status = ntvfs_trans(req, trans);
1488         } else {
1489                 status = trans2_backend(req, trans);
1490         }
1491
1492         if (NT_STATUS_IS_ERR(status)) {
1493                 req_reply_error(req, status);
1494                 return;
1495         }
1496
1497         params_left = trans->out.params.length;
1498         data_left   = trans->out.data.length;
1499         params      = trans->out.params.data;
1500         data        = trans->out.data.data;
1501
1502         req_setup_reply(req, 10 + trans->out.setup_count, 0);
1503
1504         if (!NT_STATUS_IS_OK(status)) {
1505                 req_setup_error(req, status);
1506         }
1507
1508         /* we need to divide up the reply into chunks that fit into
1509            the negotiated buffer size */
1510         do {
1511                 uint16_t this_data, this_param, max_bytes;
1512                 uint_t align1 = 1, align2 = (params_left ? 2 : 0);
1513                 struct smbsrv_request *this_req;
1514
1515                 max_bytes = req_max_data(req) - (align1 + align2);
1516
1517                 this_param = params_left;
1518                 if (this_param > max_bytes) {
1519                         this_param = max_bytes;
1520                 }
1521                 max_bytes -= this_param;
1522
1523                 this_data = data_left;
1524                 if (this_data > max_bytes) {
1525                         this_data = max_bytes;
1526                 }
1527
1528                 /* don't destroy unless this is the last chunk */
1529                 if (params_left - this_param != 0 || 
1530                     data_left - this_data != 0) {
1531                         this_req = req_setup_secondary(req);
1532                 } else {
1533                         this_req = req;
1534                 }
1535
1536                 req_grow_data(this_req, this_param + this_data + (align1 + align2));
1537
1538                 SSVAL(this_req->out.vwv, VWV(0), trans->out.params.length);
1539                 SSVAL(this_req->out.vwv, VWV(1), trans->out.data.length);
1540                 SSVAL(this_req->out.vwv, VWV(2), 0);
1541
1542                 SSVAL(this_req->out.vwv, VWV(3), this_param);
1543                 SSVAL(this_req->out.vwv, VWV(4), align1 + PTR_DIFF(this_req->out.data, this_req->out.hdr));
1544                 SSVAL(this_req->out.vwv, VWV(5), PTR_DIFF(params, trans->out.params.data));
1545
1546                 SSVAL(this_req->out.vwv, VWV(6), this_data);
1547                 SSVAL(this_req->out.vwv, VWV(7), align1 + align2 + 
1548                       PTR_DIFF(this_req->out.data + this_param, this_req->out.hdr));
1549                 SSVAL(this_req->out.vwv, VWV(8), PTR_DIFF(data, trans->out.data.data));
1550
1551                 SSVAL(this_req->out.vwv, VWV(9), trans->out.setup_count);
1552                 for (i=0;i<trans->out.setup_count;i++) {
1553                         SSVAL(this_req->out.vwv, VWV(10+i), trans->out.setup[i]);
1554                 }
1555
1556                 memset(this_req->out.data, 0, align1);
1557                 if (this_param != 0) {
1558                         memcpy(this_req->out.data + align1, params, this_param);
1559                 }
1560                 memset(this_req->out.data+this_param+align1, 0, align2);
1561                 if (this_data != 0) {
1562                         memcpy(this_req->out.data+this_param+align1+align2, data, this_data);
1563                 }
1564
1565                 params_left -= this_param;
1566                 data_left -= this_data;
1567                 params += this_param;
1568                 data += this_data;
1569
1570                 req_send_reply(this_req);
1571         } while (params_left != 0 || data_left != 0);
1572 }
1573
1574
1575 /*
1576   Reply to an SMBtrans or SMBtrans2 request
1577 */
1578 void reply_trans_generic(struct smbsrv_request *req, uint8_t command)
1579 {
1580         struct smb_trans2 *trans;
1581         int i;
1582         uint16_t param_ofs, data_ofs;
1583         uint16_t param_count, data_count;
1584         uint16_t param_total, data_total;
1585
1586         trans = talloc(req, struct smb_trans2);
1587         if (trans == NULL) {
1588                 req_reply_error(req, NT_STATUS_NO_MEMORY);
1589                 return;
1590         }
1591
1592         /* parse request */
1593         if (req->in.wct < 14) {
1594                 req_reply_error(req, NT_STATUS_INVALID_PARAMETER);
1595                 return;
1596         }
1597
1598         param_total           = SVAL(req->in.vwv, VWV(0));
1599         data_total            = SVAL(req->in.vwv, VWV(1));
1600         trans->in.max_param   = SVAL(req->in.vwv, VWV(2));
1601         trans->in.max_data    = SVAL(req->in.vwv, VWV(3));
1602         trans->in.max_setup   = CVAL(req->in.vwv, VWV(4));
1603         trans->in.flags       = SVAL(req->in.vwv, VWV(5));
1604         trans->in.timeout     = IVAL(req->in.vwv, VWV(6));
1605         param_count           = SVAL(req->in.vwv, VWV(9));
1606         param_ofs             = SVAL(req->in.vwv, VWV(10));
1607         data_count            = SVAL(req->in.vwv, VWV(11));
1608         data_ofs              = SVAL(req->in.vwv, VWV(12));
1609         trans->in.setup_count = CVAL(req->in.vwv, VWV(13));
1610
1611         if (req->in.wct != 14 + trans->in.setup_count) {
1612                 req_reply_dos_error(req, ERRSRV, ERRerror);
1613                 return;
1614         }
1615
1616         /* parse out the setup words */
1617         trans->in.setup = talloc_array(req, uint16_t, trans->in.setup_count);
1618         if (trans->in.setup_count && !trans->in.setup) {
1619                 req_reply_error(req, NT_STATUS_NO_MEMORY);
1620                 return;
1621         }
1622         for (i=0;i<trans->in.setup_count;i++) {
1623                 trans->in.setup[i] = SVAL(req->in.vwv, VWV(14+i));
1624         }
1625
1626         if (command == SMBtrans) {
1627                 req_pull_string(req, &trans->in.trans_name, req->in.data, -1, STR_TERMINATE);
1628         }
1629
1630         if (!req_pull_blob(req, req->in.hdr + param_ofs, param_count, &trans->in.params) ||
1631             !req_pull_blob(req, req->in.hdr + data_ofs, data_count, &trans->in.data)) {
1632                 req_reply_error(req, NT_STATUS_FOOBAR);
1633                 return;
1634         }
1635
1636         /* is it a partial request? if so, then send a 'send more' message */
1637         if (param_total > param_count || data_total > data_count) {
1638                 reply_trans_continue(req, command, trans);
1639                 return;
1640         }
1641
1642         reply_trans_complete(req, command, trans);
1643 }
1644
1645
1646 /*
1647   Reply to an SMBtranss2 request
1648 */
1649 static void reply_transs_generic(struct smbsrv_request *req, uint8_t command)
1650 {
1651         struct smbsrv_trans_partial *tp;
1652         struct smb_trans2 *trans = NULL;
1653         uint16_t param_ofs, data_ofs;
1654         uint16_t param_count, data_count;
1655         uint16_t param_disp, data_disp;
1656         uint16_t param_total, data_total;
1657         DATA_BLOB params, data;
1658
1659         for (tp=req->smb_conn->trans_partial;tp;tp=tp->next) {
1660                 if (tp->command == command &&
1661                     SVAL(tp->req->in.hdr, HDR_MID) == SVAL(req->in.hdr, HDR_MID)) {
1662                         break;
1663                 }
1664         }
1665
1666         if (tp == NULL) {
1667                 req_reply_error(req, NT_STATUS_INVALID_PARAMETER);
1668                 return;
1669         }
1670
1671         trans = tp->trans;
1672
1673         /* parse request */
1674         if (req->in.wct < 8) {
1675                 req_reply_error(req, NT_STATUS_INVALID_PARAMETER);
1676                 return;
1677         }
1678
1679         param_total           = SVAL(req->in.vwv, VWV(0));
1680         data_total            = SVAL(req->in.vwv, VWV(1));
1681         param_count           = SVAL(req->in.vwv, VWV(2));
1682         param_ofs             = SVAL(req->in.vwv, VWV(3));
1683         param_disp            = SVAL(req->in.vwv, VWV(4));
1684         data_count            = SVAL(req->in.vwv, VWV(5));
1685         data_ofs              = SVAL(req->in.vwv, VWV(6));
1686         data_disp             = SVAL(req->in.vwv, VWV(7));
1687
1688         if (!req_pull_blob(req, req->in.hdr + param_ofs, param_count, &params) ||
1689             !req_pull_blob(req, req->in.hdr + data_ofs, data_count, &data)) {
1690                 req_reply_error(req, NT_STATUS_INVALID_PARAMETER);
1691                 return;
1692         }
1693
1694         /* only allow contiguous requests */
1695         if ((param_count != 0 &&
1696              param_disp != trans->in.params.length) ||
1697             (data_count != 0 && 
1698              data_disp != trans->in.data.length)) {
1699                 req_reply_error(req, NT_STATUS_INVALID_PARAMETER);
1700                 return;         
1701         }
1702
1703         /* add to the existing request */
1704         if (param_count != 0) {
1705                 trans->in.params.data = talloc_realloc(trans, 
1706                                                          trans->in.params.data, 
1707                                                          uint8_t, 
1708                                                          param_disp + param_count);
1709                 if (trans->in.params.data == NULL) {
1710                         goto failed;
1711                 }
1712                 trans->in.params.length = param_disp + param_count;
1713         }
1714
1715         if (data_count != 0) {
1716                 trans->in.data.data = talloc_realloc(trans, 
1717                                                        trans->in.data.data, 
1718                                                        uint8_t, 
1719                                                        data_disp + data_count);
1720                 if (trans->in.data.data == NULL) {
1721                         goto failed;
1722                 }
1723                 trans->in.data.length = data_disp + data_count;
1724         }
1725
1726         memcpy(trans->in.params.data + param_disp, params.data, params.length);
1727         memcpy(trans->in.data.data + data_disp, data.data, data.length);
1728
1729         /* the sequence number of the reply is taken from the last secondary
1730            response */
1731         tp->req->seq_num = req->seq_num;
1732
1733         /* we don't reply to Transs2 requests */
1734         talloc_free(req);
1735
1736         if (trans->in.params.length == param_total &&
1737             trans->in.data.length == data_total) {
1738                 /* its now complete */
1739                 DLIST_REMOVE(tp->req->smb_conn->trans_partial, tp);
1740                 reply_trans_complete(tp->req, command, trans);
1741         }
1742         return;
1743
1744 failed: 
1745         req_reply_error(tp->req, NT_STATUS_NO_MEMORY);
1746         DLIST_REMOVE(req->smb_conn->trans_partial, tp);
1747         talloc_free(req);
1748         talloc_free(tp);
1749 }
1750
1751
1752 /*
1753   Reply to an SMBtrans2
1754 */
1755 void reply_trans2(struct smbsrv_request *req)
1756 {
1757         reply_trans_generic(req, SMBtrans2);
1758 }
1759
1760 /*
1761   Reply to an SMBtrans
1762 */
1763 void reply_trans(struct smbsrv_request *req)
1764 {
1765         reply_trans_generic(req, SMBtrans);
1766 }
1767
1768 /*
1769   Reply to an SMBtranss request
1770 */
1771 void reply_transs(struct smbsrv_request *req)
1772 {
1773         reply_transs_generic(req, SMBtrans);
1774 }
1775
1776 /*
1777   Reply to an SMBtranss2 request
1778 */
1779 void reply_transs2(struct smbsrv_request *req)
1780 {
1781         reply_transs_generic(req, SMBtrans2);
1782 }
1783