2 Unix SMB/CIFS implementation.
3 file opening and share modes
4 Copyright (C) Andrew Tridgell 1992-1998
5 Copyright (C) Jeremy Allison 2001-2004
6 Copyright (C) Volker Lendecke 2005
8 This program is free software; you can redistribute it and/or modify
9 it under the terms of the GNU General Public License as published by
10 the Free Software Foundation; either version 3 of the License, or
11 (at your option) any later version.
13 This program is distributed in the hope that it will be useful,
14 but WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 GNU General Public License for more details.
18 You should have received a copy of the GNU General Public License
19 along with this program. If not, see <http://www.gnu.org/licenses/>.
24 extern const struct generic_mapping file_generic_mapping;
25 extern struct current_user current_user;
26 extern userdom_struct current_user_info;
27 extern bool global_client_failed_oplock_break;
29 struct deferred_open_record {
30 bool delayed_for_oplocks;
34 /****************************************************************************
35 fd support routines - attempt to do a dos_open.
36 ****************************************************************************/
38 static NTSTATUS fd_open(struct connection_struct *conn,
44 NTSTATUS status = NT_STATUS_OK;
48 * Never follow symlinks on a POSIX client. The
49 * client should be doing this.
52 if (fsp->posix_open || !lp_symlinks(SNUM(conn))) {
57 fsp->fh->fd = SMB_VFS_OPEN(conn,fname,fsp,flags,mode);
58 if (fsp->fh->fd == -1) {
59 status = map_nt_error_from_unix(errno);
62 DEBUG(10,("fd_open: name %s, flags = 0%o mode = 0%o, fd = %d. %s\n",
63 fname, flags, (int)mode, fsp->fh->fd,
64 (fsp->fh->fd == -1) ? strerror(errno) : "" ));
69 /****************************************************************************
70 Close the file associated with a fsp.
71 ****************************************************************************/
73 NTSTATUS fd_close(files_struct *fsp)
75 if (fsp->fh->fd == -1) {
76 return NT_STATUS_OK; /* What we used to call a stat open. */
78 if (fsp->fh->ref_count > 1) {
79 return NT_STATUS_OK; /* Shared handle. Only close last reference. */
81 return fd_close_posix(fsp);
84 /****************************************************************************
85 Change the ownership of a file to that of the parent directory.
86 Do this by fd if possible.
87 ****************************************************************************/
89 static void change_file_owner_to_parent(connection_struct *conn,
90 const char *inherit_from_dir,
93 SMB_STRUCT_STAT parent_st;
96 ret = SMB_VFS_STAT(conn, inherit_from_dir, &parent_st);
98 DEBUG(0,("change_file_owner_to_parent: failed to stat parent "
99 "directory %s. Error was %s\n",
100 inherit_from_dir, strerror(errno) ));
105 ret = SMB_VFS_FCHOWN(fsp, parent_st.st_uid, (gid_t)-1);
108 DEBUG(0,("change_file_owner_to_parent: failed to fchown "
109 "file %s to parent directory uid %u. Error "
110 "was %s\n", fsp->fsp_name,
111 (unsigned int)parent_st.st_uid,
115 DEBUG(10,("change_file_owner_to_parent: changed new file %s to "
116 "parent directory uid %u.\n", fsp->fsp_name,
117 (unsigned int)parent_st.st_uid ));
120 static NTSTATUS change_dir_owner_to_parent(connection_struct *conn,
121 const char *inherit_from_dir,
123 SMB_STRUCT_STAT *psbuf)
125 char *saved_dir = NULL;
126 SMB_STRUCT_STAT sbuf;
127 SMB_STRUCT_STAT parent_st;
128 TALLOC_CTX *ctx = talloc_tos();
129 NTSTATUS status = NT_STATUS_OK;
132 ret = SMB_VFS_STAT(conn, inherit_from_dir, &parent_st);
134 status = map_nt_error_from_unix(errno);
135 DEBUG(0,("change_dir_owner_to_parent: failed to stat parent "
136 "directory %s. Error was %s\n",
137 inherit_from_dir, strerror(errno) ));
141 /* We've already done an lstat into psbuf, and we know it's a
142 directory. If we can cd into the directory and the dev/ino
143 are the same then we can safely chown without races as
144 we're locking the directory in place by being in it. This
145 should work on any UNIX (thanks tridge :-). JRA.
148 saved_dir = vfs_GetWd(ctx,conn);
150 status = map_nt_error_from_unix(errno);
151 DEBUG(0,("change_dir_owner_to_parent: failed to get "
152 "current working directory. Error was %s\n",
157 /* Chdir into the new path. */
158 if (vfs_ChDir(conn, fname) == -1) {
159 status = map_nt_error_from_unix(errno);
160 DEBUG(0,("change_dir_owner_to_parent: failed to change "
161 "current working directory to %s. Error "
162 "was %s\n", fname, strerror(errno) ));
166 if (SMB_VFS_STAT(conn,".",&sbuf) == -1) {
167 status = map_nt_error_from_unix(errno);
168 DEBUG(0,("change_dir_owner_to_parent: failed to stat "
169 "directory '.' (%s) Error was %s\n",
170 fname, strerror(errno)));
174 /* Ensure we're pointing at the same place. */
175 if (sbuf.st_dev != psbuf->st_dev ||
176 sbuf.st_ino != psbuf->st_ino ||
177 sbuf.st_mode != psbuf->st_mode ) {
178 DEBUG(0,("change_dir_owner_to_parent: "
179 "device/inode/mode on directory %s changed. "
180 "Refusing to chown !\n", fname ));
181 status = NT_STATUS_ACCESS_DENIED;
186 ret = SMB_VFS_CHOWN(conn, ".", parent_st.st_uid, (gid_t)-1);
189 status = map_nt_error_from_unix(errno);
190 DEBUG(10,("change_dir_owner_to_parent: failed to chown "
191 "directory %s to parent directory uid %u. "
192 "Error was %s\n", fname,
193 (unsigned int)parent_st.st_uid, strerror(errno) ));
197 DEBUG(10,("change_dir_owner_to_parent: changed ownership of new "
198 "directory %s to parent directory uid %u.\n",
199 fname, (unsigned int)parent_st.st_uid ));
203 vfs_ChDir(conn,saved_dir);
207 /****************************************************************************
209 ****************************************************************************/
211 static NTSTATUS open_file(files_struct *fsp,
212 connection_struct *conn,
213 struct smb_request *req,
214 const char *parent_dir,
217 SMB_STRUCT_STAT *psbuf,
220 uint32 access_mask, /* client requested access mask. */
221 uint32 open_access_mask) /* what we're actually using in the open. */
223 NTSTATUS status = NT_STATUS_OK;
224 int accmode = (flags & O_ACCMODE);
225 int local_flags = flags;
226 bool file_existed = VALID_STAT(*psbuf);
231 /* Check permissions */
234 * This code was changed after seeing a client open request
235 * containing the open mode of (DENY_WRITE/read-only) with
236 * the 'create if not exist' bit set. The previous code
237 * would fail to open the file read only on a read-only share
238 * as it was checking the flags parameter directly against O_RDONLY,
239 * this was failing as the flags parameter was set to O_RDONLY|O_CREAT.
243 if (!CAN_WRITE(conn)) {
244 /* It's a read-only share - fail if we wanted to write. */
245 if(accmode != O_RDONLY) {
246 DEBUG(3,("Permission denied opening %s\n", path));
247 return NT_STATUS_ACCESS_DENIED;
248 } else if(flags & O_CREAT) {
249 /* We don't want to write - but we must make sure that
250 O_CREAT doesn't create the file if we have write
251 access into the directory.
254 local_flags &= ~O_CREAT;
259 * This little piece of insanity is inspired by the
260 * fact that an NT client can open a file for O_RDONLY,
261 * but set the create disposition to FILE_EXISTS_TRUNCATE.
262 * If the client *can* write to the file, then it expects to
263 * truncate the file, even though it is opening for readonly.
264 * Quicken uses this stupid trick in backup file creation...
265 * Thanks *greatly* to "David W. Chapman Jr." <dwcjr@inethouston.net>
266 * for helping track this one down. It didn't bite us in 2.0.x
267 * as we always opened files read-write in that release. JRA.
270 if ((accmode == O_RDONLY) && ((flags & O_TRUNC) == O_TRUNC)) {
271 DEBUG(10,("open_file: truncate requested on read-only open "
272 "for file %s\n", path));
273 local_flags = (flags & ~O_ACCMODE)|O_RDWR;
276 if ((open_access_mask & (FILE_READ_DATA|FILE_WRITE_DATA|FILE_APPEND_DATA|FILE_EXECUTE)) ||
277 (!file_existed && (local_flags & O_CREAT)) ||
278 ((local_flags & O_TRUNC) == O_TRUNC) ) {
281 * We can't actually truncate here as the file may be locked.
282 * open_file_ntcreate will take care of the truncate later. JRA.
285 local_flags &= ~O_TRUNC;
287 #if defined(O_NONBLOCK) && defined(S_ISFIFO)
289 * We would block on opening a FIFO with no one else on the
290 * other end. Do what we used to do and add O_NONBLOCK to the
294 if (file_existed && S_ISFIFO(psbuf->st_mode)) {
295 local_flags |= O_NONBLOCK;
299 /* Don't create files with Microsoft wildcard characters. */
300 if ((local_flags & O_CREAT) && !file_existed &&
302 return NT_STATUS_OBJECT_NAME_INVALID;
305 /* Actually do the open */
306 status = fd_open(conn, path, fsp, local_flags, unx_mode);
307 if (!NT_STATUS_IS_OK(status)) {
308 DEBUG(3,("Error opening file %s (%s) (local_flags=%d) "
310 path,nt_errstr(status),local_flags,flags));
314 if ((local_flags & O_CREAT) && !file_existed) {
316 /* Inherit the ACL if required */
317 if (lp_inherit_perms(SNUM(conn))) {
318 inherit_access_acl(conn, parent_dir, path,
322 /* Change the owner if required. */
323 if (lp_inherit_owner(SNUM(conn))) {
324 change_file_owner_to_parent(conn, parent_dir,
328 notify_fname(conn, NOTIFY_ACTION_ADDED,
329 FILE_NOTIFY_CHANGE_FILE_NAME, path);
333 fsp->fh->fd = -1; /* What we used to call a stat open. */
339 if (fsp->fh->fd == -1) {
340 ret = SMB_VFS_STAT(conn, path, psbuf);
342 ret = SMB_VFS_FSTAT(fsp, psbuf);
343 /* If we have an fd, this stat should succeed. */
345 DEBUG(0,("Error doing fstat on open file %s "
346 "(%s)\n", path,strerror(errno) ));
350 /* For a non-io open, this stat failing means file not found. JRA */
352 status = map_nt_error_from_unix(errno);
359 * POSIX allows read-only opens of directories. We don't
360 * want to do this (we use a different code path for this)
361 * so catch a directory open and return an EISDIR. JRA.
364 if(S_ISDIR(psbuf->st_mode)) {
367 return NT_STATUS_FILE_IS_A_DIRECTORY;
370 fsp->mode = psbuf->st_mode;
371 fsp->file_id = vfs_file_id_from_sbuf(conn, psbuf);
372 fsp->vuid = req ? req->vuid : UID_FIELD_INVALID;
373 fsp->file_pid = req ? req->smbpid : 0;
374 fsp->can_lock = True;
375 fsp->can_read = (access_mask & (FILE_READ_DATA)) ? True : False;
376 if (!CAN_WRITE(conn)) {
377 fsp->can_write = False;
379 fsp->can_write = (access_mask & (FILE_WRITE_DATA | FILE_APPEND_DATA)) ?
382 fsp->print_file = False;
383 fsp->modified = False;
384 fsp->sent_oplock_break = NO_BREAK_SENT;
385 fsp->is_directory = False;
386 fsp->is_stat = False;
387 if (conn->aio_write_behind_list &&
388 is_in_path(path, conn->aio_write_behind_list, conn->case_sensitive)) {
389 fsp->aio_write_behind = True;
392 string_set(&fsp->fsp_name, path);
393 fsp->wcp = NULL; /* Write cache pointer. */
395 DEBUG(2,("%s opened file %s read=%s write=%s (numopen=%d)\n",
396 *current_user_info.smb_name ?
397 current_user_info.smb_name : conn->user,fsp->fsp_name,
398 BOOLSTR(fsp->can_read), BOOLSTR(fsp->can_write),
399 conn->num_files_open + 1));
405 /*******************************************************************
406 Return True if the filename is one of the special executable types.
407 ********************************************************************/
409 static bool is_executable(const char *fname)
411 if ((fname = strrchr_m(fname,'.'))) {
412 if (strequal(fname,".com") ||
413 strequal(fname,".dll") ||
414 strequal(fname,".exe") ||
415 strequal(fname,".sym")) {
422 /****************************************************************************
423 Check if we can open a file with a share mode.
424 Returns True if conflict, False if not.
425 ****************************************************************************/
427 static bool share_conflict(struct share_mode_entry *entry,
431 DEBUG(10,("share_conflict: entry->access_mask = 0x%x, "
432 "entry->share_access = 0x%x, "
433 "entry->private_options = 0x%x\n",
434 (unsigned int)entry->access_mask,
435 (unsigned int)entry->share_access,
436 (unsigned int)entry->private_options));
438 DEBUG(10,("share_conflict: access_mask = 0x%x, share_access = 0x%x\n",
439 (unsigned int)access_mask, (unsigned int)share_access));
441 if ((entry->access_mask & (FILE_WRITE_DATA|
445 DELETE_ACCESS)) == 0) {
446 DEBUG(10,("share_conflict: No conflict due to "
447 "entry->access_mask = 0x%x\n",
448 (unsigned int)entry->access_mask ));
452 if ((access_mask & (FILE_WRITE_DATA|
456 DELETE_ACCESS)) == 0) {
457 DEBUG(10,("share_conflict: No conflict due to "
458 "access_mask = 0x%x\n",
459 (unsigned int)access_mask ));
463 #if 1 /* JRA TEST - Superdebug. */
464 #define CHECK_MASK(num, am, right, sa, share) \
465 DEBUG(10,("share_conflict: [%d] am (0x%x) & right (0x%x) = 0x%x\n", \
466 (unsigned int)(num), (unsigned int)(am), \
467 (unsigned int)(right), (unsigned int)(am)&(right) )); \
468 DEBUG(10,("share_conflict: [%d] sa (0x%x) & share (0x%x) = 0x%x\n", \
469 (unsigned int)(num), (unsigned int)(sa), \
470 (unsigned int)(share), (unsigned int)(sa)&(share) )); \
471 if (((am) & (right)) && !((sa) & (share))) { \
472 DEBUG(10,("share_conflict: check %d conflict am = 0x%x, right = 0x%x, \
473 sa = 0x%x, share = 0x%x\n", (num), (unsigned int)(am), (unsigned int)(right), (unsigned int)(sa), \
474 (unsigned int)(share) )); \
478 #define CHECK_MASK(num, am, right, sa, share) \
479 if (((am) & (right)) && !((sa) & (share))) { \
480 DEBUG(10,("share_conflict: check %d conflict am = 0x%x, right = 0x%x, \
481 sa = 0x%x, share = 0x%x\n", (num), (unsigned int)(am), (unsigned int)(right), (unsigned int)(sa), \
482 (unsigned int)(share) )); \
487 CHECK_MASK(1, entry->access_mask, FILE_WRITE_DATA | FILE_APPEND_DATA,
488 share_access, FILE_SHARE_WRITE);
489 CHECK_MASK(2, access_mask, FILE_WRITE_DATA | FILE_APPEND_DATA,
490 entry->share_access, FILE_SHARE_WRITE);
492 CHECK_MASK(3, entry->access_mask, FILE_READ_DATA | FILE_EXECUTE,
493 share_access, FILE_SHARE_READ);
494 CHECK_MASK(4, access_mask, FILE_READ_DATA | FILE_EXECUTE,
495 entry->share_access, FILE_SHARE_READ);
497 CHECK_MASK(5, entry->access_mask, DELETE_ACCESS,
498 share_access, FILE_SHARE_DELETE);
499 CHECK_MASK(6, access_mask, DELETE_ACCESS,
500 entry->share_access, FILE_SHARE_DELETE);
502 DEBUG(10,("share_conflict: No conflict.\n"));
506 #if defined(DEVELOPER)
507 static void validate_my_share_entries(int num,
508 struct share_mode_entry *share_entry)
512 if (!procid_is_me(&share_entry->pid)) {
516 if (is_deferred_open_entry(share_entry) &&
517 !open_was_deferred(share_entry->op_mid)) {
518 char *str = talloc_asprintf(talloc_tos(),
519 "Got a deferred entry without a request: "
521 share_mode_str(talloc_tos(), num, share_entry));
525 if (!is_valid_share_mode_entry(share_entry)) {
529 fsp = file_find_dif(share_entry->id,
530 share_entry->share_file_id);
532 DEBUG(0,("validate_my_share_entries: PANIC : %s\n",
533 share_mode_str(talloc_tos(), num, share_entry) ));
534 smb_panic("validate_my_share_entries: Cannot match a "
535 "share entry with an open file\n");
538 if (is_deferred_open_entry(share_entry) ||
539 is_unused_share_mode_entry(share_entry)) {
543 if ((share_entry->op_type == NO_OPLOCK) &&
544 (fsp->oplock_type == FAKE_LEVEL_II_OPLOCK)) {
545 /* Someone has already written to it, but I haven't yet
550 if (((uint16)fsp->oplock_type) != share_entry->op_type) {
559 DEBUG(0,("validate_my_share_entries: PANIC : %s\n",
560 share_mode_str(talloc_tos(), num, share_entry) ));
561 str = talloc_asprintf(talloc_tos(),
562 "validate_my_share_entries: "
563 "file %s, oplock_type = 0x%x, op_type = 0x%x\n",
564 fsp->fsp_name, (unsigned int)fsp->oplock_type,
565 (unsigned int)share_entry->op_type );
571 static bool is_stat_open(uint32 access_mask)
573 return (access_mask &&
574 ((access_mask & ~(SYNCHRONIZE_ACCESS| FILE_READ_ATTRIBUTES|
575 FILE_WRITE_ATTRIBUTES))==0) &&
576 ((access_mask & (SYNCHRONIZE_ACCESS|FILE_READ_ATTRIBUTES|
577 FILE_WRITE_ATTRIBUTES)) != 0));
580 /****************************************************************************
581 Deal with share modes
582 Invarient: Share mode must be locked on entry and exit.
583 Returns -1 on error, or number of share modes on success (may be zero).
584 ****************************************************************************/
586 static NTSTATUS open_mode_check(connection_struct *conn,
588 struct share_mode_lock *lck,
591 uint32 create_options,
596 if(lck->num_share_modes == 0) {
600 *file_existed = True;
602 /* A delete on close prohibits everything */
604 if (lck->delete_on_close) {
605 return NT_STATUS_DELETE_PENDING;
608 if (is_stat_open(access_mask)) {
609 /* Stat open that doesn't trigger oplock breaks or share mode
610 * checks... ! JRA. */
615 * Check if the share modes will give us access.
618 #if defined(DEVELOPER)
619 for(i = 0; i < lck->num_share_modes; i++) {
620 validate_my_share_entries(i, &lck->share_modes[i]);
624 if (!lp_share_modes(SNUM(conn))) {
628 /* Now we check the share modes, after any oplock breaks. */
629 for(i = 0; i < lck->num_share_modes; i++) {
631 if (!is_valid_share_mode_entry(&lck->share_modes[i])) {
635 /* someone else has a share lock on it, check to see if we can
637 if (share_conflict(&lck->share_modes[i],
638 access_mask, share_access)) {
639 return NT_STATUS_SHARING_VIOLATION;
646 static bool is_delete_request(files_struct *fsp) {
647 return ((fsp->access_mask == DELETE_ACCESS) &&
648 (fsp->oplock_type == NO_OPLOCK));
652 * 1) No files open at all or internal open: Grant whatever the client wants.
654 * 2) Exclusive (or batch) oplock around: If the requested access is a delete
655 * request, break if the oplock around is a batch oplock. If it's another
656 * requested access type, break.
658 * 3) Only level2 around: Grant level2 and do nothing else.
661 static bool delay_for_oplocks(struct share_mode_lock *lck,
668 struct share_mode_entry *exclusive = NULL;
669 bool valid_entry = False;
670 bool delay_it = False;
671 bool have_level2 = False;
673 char msg[MSG_SMB_SHARE_MODE_ENTRY_SIZE];
675 if (oplock_request & INTERNAL_OPEN_ONLY) {
676 fsp->oplock_type = NO_OPLOCK;
679 if ((oplock_request & INTERNAL_OPEN_ONLY) || is_stat_open(fsp->access_mask)) {
683 for (i=0; i<lck->num_share_modes; i++) {
685 if (!is_valid_share_mode_entry(&lck->share_modes[i])) {
689 /* At least one entry is not an invalid or deferred entry. */
692 if (pass_number == 1) {
693 if (BATCH_OPLOCK_TYPE(lck->share_modes[i].op_type)) {
694 SMB_ASSERT(exclusive == NULL);
695 exclusive = &lck->share_modes[i];
698 if (EXCLUSIVE_OPLOCK_TYPE(lck->share_modes[i].op_type)) {
699 SMB_ASSERT(exclusive == NULL);
700 exclusive = &lck->share_modes[i];
704 if (lck->share_modes[i].op_type == LEVEL_II_OPLOCK) {
705 SMB_ASSERT(exclusive == NULL);
711 /* All entries are placeholders or deferred.
712 * Directly grant whatever the client wants. */
713 if (fsp->oplock_type == NO_OPLOCK) {
714 /* Store a level2 oplock, but don't tell the client */
715 fsp->oplock_type = FAKE_LEVEL_II_OPLOCK;
720 if (exclusive != NULL) { /* Found an exclusive oplock */
721 SMB_ASSERT(!have_level2);
722 delay_it = is_delete_request(fsp) ?
723 BATCH_OPLOCK_TYPE(exclusive->op_type) : True;
726 if (EXCLUSIVE_OPLOCK_TYPE(fsp->oplock_type)) {
727 /* We can at most grant level2 as there are other
728 * level2 or NO_OPLOCK entries. */
729 fsp->oplock_type = LEVEL_II_OPLOCK;
732 if ((fsp->oplock_type == NO_OPLOCK) && have_level2) {
733 /* Store a level2 oplock, but don't tell the client */
734 fsp->oplock_type = FAKE_LEVEL_II_OPLOCK;
742 * Send a break message to the oplock holder and delay the open for
746 DEBUG(10, ("Sending break request to PID %s\n",
747 procid_str_static(&exclusive->pid)));
748 exclusive->op_mid = mid;
750 /* Create the message. */
751 share_mode_entry_to_message(msg, exclusive);
753 /* Add in the FORCE_OPLOCK_BREAK_TO_NONE bit in the message if set. We
754 don't want this set in the share mode struct pointed to by lck. */
756 if (oplock_request & FORCE_OPLOCK_BREAK_TO_NONE) {
757 SSVAL(msg,6,exclusive->op_type | FORCE_OPLOCK_BREAK_TO_NONE);
760 status = messaging_send_buf(smbd_messaging_context(), exclusive->pid,
761 MSG_SMB_BREAK_REQUEST,
763 MSG_SMB_SHARE_MODE_ENTRY_SIZE);
764 if (!NT_STATUS_IS_OK(status)) {
765 DEBUG(3, ("Could not send oplock break message: %s\n",
772 static bool request_timed_out(struct timeval request_time,
773 struct timeval timeout)
775 struct timeval now, end_time;
777 end_time = timeval_sum(&request_time, &timeout);
778 return (timeval_compare(&end_time, &now) < 0);
781 /****************************************************************************
782 Handle the 1 second delay in returning a SHARING_VIOLATION error.
783 ****************************************************************************/
785 static void defer_open(struct share_mode_lock *lck,
786 struct timeval request_time,
787 struct timeval timeout,
788 struct smb_request *req,
789 struct deferred_open_record *state)
795 for (i=0; i<lck->num_share_modes; i++) {
796 struct share_mode_entry *e = &lck->share_modes[i];
798 if (!is_deferred_open_entry(e)) {
802 if (procid_is_me(&e->pid) && (e->op_mid == req->mid)) {
803 DEBUG(0, ("Trying to defer an already deferred "
804 "request: mid=%d, exiting\n", req->mid));
805 exit_server("attempt to defer a deferred request");
809 /* End paranoia check */
811 DEBUG(10,("defer_open_sharing_error: time [%u.%06u] adding deferred "
812 "open entry for mid %u\n",
813 (unsigned int)request_time.tv_sec,
814 (unsigned int)request_time.tv_usec,
815 (unsigned int)req->mid));
817 if (!push_deferred_smb_message(req, request_time, timeout,
818 (char *)state, sizeof(*state))) {
819 exit_server("push_deferred_smb_message failed");
821 add_deferred_open(lck, req->mid, request_time, state->id);
824 * Push the MID of this packet on the signing queue.
825 * We only do this once, the first time we push the packet
826 * onto the deferred open queue, as this has a side effect
827 * of incrementing the response sequence number.
830 srv_defer_sign_response(req->mid);
834 /****************************************************************************
835 On overwrite open ensure that the attributes match.
836 ****************************************************************************/
838 static bool open_match_attributes(connection_struct *conn,
842 mode_t existing_unx_mode,
844 mode_t *returned_unx_mode)
846 uint32 noarch_old_dos_attr, noarch_new_dos_attr;
848 noarch_old_dos_attr = (old_dos_attr & ~FILE_ATTRIBUTE_ARCHIVE);
849 noarch_new_dos_attr = (new_dos_attr & ~FILE_ATTRIBUTE_ARCHIVE);
851 if((noarch_old_dos_attr == 0 && noarch_new_dos_attr != 0) ||
852 (noarch_old_dos_attr != 0 && ((noarch_old_dos_attr & noarch_new_dos_attr) == noarch_old_dos_attr))) {
853 *returned_unx_mode = new_unx_mode;
855 *returned_unx_mode = (mode_t)0;
858 DEBUG(10,("open_match_attributes: file %s old_dos_attr = 0x%x, "
859 "existing_unx_mode = 0%o, new_dos_attr = 0x%x "
860 "returned_unx_mode = 0%o\n",
862 (unsigned int)old_dos_attr,
863 (unsigned int)existing_unx_mode,
864 (unsigned int)new_dos_attr,
865 (unsigned int)*returned_unx_mode ));
867 /* If we're mapping SYSTEM and HIDDEN ensure they match. */
868 if (lp_map_system(SNUM(conn)) || lp_store_dos_attributes(SNUM(conn))) {
869 if ((old_dos_attr & FILE_ATTRIBUTE_SYSTEM) &&
870 !(new_dos_attr & FILE_ATTRIBUTE_SYSTEM)) {
874 if (lp_map_hidden(SNUM(conn)) || lp_store_dos_attributes(SNUM(conn))) {
875 if ((old_dos_attr & FILE_ATTRIBUTE_HIDDEN) &&
876 !(new_dos_attr & FILE_ATTRIBUTE_HIDDEN)) {
883 /****************************************************************************
884 Special FCB or DOS processing in the case of a sharing violation.
885 Try and find a duplicated file handle.
886 ****************************************************************************/
888 static files_struct *fcb_or_dos_open(connection_struct *conn,
895 uint32 create_options)
898 files_struct *dup_fsp;
900 DEBUG(5,("fcb_or_dos_open: attempting old open semantics for "
901 "file %s.\n", fname ));
903 for(fsp = file_find_di_first(id); fsp;
904 fsp = file_find_di_next(fsp)) {
906 DEBUG(10,("fcb_or_dos_open: checking file %s, fd = %d, "
907 "vuid = %u, file_pid = %u, private_options = 0x%x "
908 "access_mask = 0x%x\n", fsp->fsp_name,
909 fsp->fh->fd, (unsigned int)fsp->vuid,
910 (unsigned int)fsp->file_pid,
911 (unsigned int)fsp->fh->private_options,
912 (unsigned int)fsp->access_mask ));
914 if (fsp->fh->fd != -1 &&
916 fsp->file_pid == file_pid &&
917 (fsp->fh->private_options & (NTCREATEX_OPTIONS_PRIVATE_DENY_DOS |
918 NTCREATEX_OPTIONS_PRIVATE_DENY_FCB)) &&
919 (fsp->access_mask & FILE_WRITE_DATA) &&
920 strequal(fsp->fsp_name, fname)) {
921 DEBUG(10,("fcb_or_dos_open: file match\n"));
930 /* quite an insane set of semantics ... */
931 if (is_executable(fname) &&
932 (fsp->fh->private_options & NTCREATEX_OPTIONS_PRIVATE_DENY_DOS)) {
933 DEBUG(10,("fcb_or_dos_open: file fail due to is_executable.\n"));
937 /* We need to duplicate this fsp. */
938 if (!NT_STATUS_IS_OK(dup_file_fsp(fsp, access_mask, share_access,
939 create_options, &dup_fsp))) {
946 /****************************************************************************
947 Open a file with a share mode - old openX method - map into NTCreate.
948 ****************************************************************************/
950 bool map_open_params_to_ntcreate(const char *fname, int deny_mode, int open_func,
951 uint32 *paccess_mask,
953 uint32 *pcreate_disposition,
954 uint32 *pcreate_options)
958 uint32 create_disposition;
959 uint32 create_options = 0;
961 DEBUG(10,("map_open_params_to_ntcreate: fname = %s, deny_mode = 0x%x, "
962 "open_func = 0x%x\n",
963 fname, (unsigned int)deny_mode, (unsigned int)open_func ));
965 /* Create the NT compatible access_mask. */
966 switch (GET_OPENX_MODE(deny_mode)) {
967 case DOS_OPEN_EXEC: /* Implies read-only - used to be FILE_READ_DATA */
968 case DOS_OPEN_RDONLY:
969 access_mask = FILE_GENERIC_READ;
971 case DOS_OPEN_WRONLY:
972 access_mask = FILE_GENERIC_WRITE;
976 access_mask = FILE_GENERIC_READ|FILE_GENERIC_WRITE;
979 DEBUG(10,("map_open_params_to_ntcreate: bad open mode = 0x%x\n",
980 (unsigned int)GET_OPENX_MODE(deny_mode)));
984 /* Create the NT compatible create_disposition. */
986 case OPENX_FILE_EXISTS_FAIL|OPENX_FILE_CREATE_IF_NOT_EXIST:
987 create_disposition = FILE_CREATE;
990 case OPENX_FILE_EXISTS_OPEN:
991 create_disposition = FILE_OPEN;
994 case OPENX_FILE_EXISTS_OPEN|OPENX_FILE_CREATE_IF_NOT_EXIST:
995 create_disposition = FILE_OPEN_IF;
998 case OPENX_FILE_EXISTS_TRUNCATE:
999 create_disposition = FILE_OVERWRITE;
1002 case OPENX_FILE_EXISTS_TRUNCATE|OPENX_FILE_CREATE_IF_NOT_EXIST:
1003 create_disposition = FILE_OVERWRITE_IF;
1007 /* From samba4 - to be confirmed. */
1008 if (GET_OPENX_MODE(deny_mode) == DOS_OPEN_EXEC) {
1009 create_disposition = FILE_CREATE;
1012 DEBUG(10,("map_open_params_to_ntcreate: bad "
1013 "open_func 0x%x\n", (unsigned int)open_func));
1017 /* Create the NT compatible share modes. */
1018 switch (GET_DENY_MODE(deny_mode)) {
1020 share_mode = FILE_SHARE_NONE;
1024 share_mode = FILE_SHARE_READ;
1028 share_mode = FILE_SHARE_WRITE;
1032 share_mode = FILE_SHARE_READ|FILE_SHARE_WRITE;
1036 create_options |= NTCREATEX_OPTIONS_PRIVATE_DENY_DOS;
1037 if (is_executable(fname)) {
1038 share_mode = FILE_SHARE_READ|FILE_SHARE_WRITE;
1040 if (GET_OPENX_MODE(deny_mode) == DOS_OPEN_RDONLY) {
1041 share_mode = FILE_SHARE_READ;
1043 share_mode = FILE_SHARE_NONE;
1049 create_options |= NTCREATEX_OPTIONS_PRIVATE_DENY_FCB;
1050 share_mode = FILE_SHARE_NONE;
1054 DEBUG(10,("map_open_params_to_ntcreate: bad deny_mode 0x%x\n",
1055 (unsigned int)GET_DENY_MODE(deny_mode) ));
1059 DEBUG(10,("map_open_params_to_ntcreate: file %s, access_mask = 0x%x, "
1060 "share_mode = 0x%x, create_disposition = 0x%x, "
1061 "create_options = 0x%x\n",
1063 (unsigned int)access_mask,
1064 (unsigned int)share_mode,
1065 (unsigned int)create_disposition,
1066 (unsigned int)create_options ));
1069 *paccess_mask = access_mask;
1072 *pshare_mode = share_mode;
1074 if (pcreate_disposition) {
1075 *pcreate_disposition = create_disposition;
1077 if (pcreate_options) {
1078 *pcreate_options = create_options;
1085 static void schedule_defer_open(struct share_mode_lock *lck,
1086 struct timeval request_time,
1087 struct smb_request *req)
1089 struct deferred_open_record state;
1091 /* This is a relative time, added to the absolute
1092 request_time value to get the absolute timeout time.
1093 Note that if this is the second or greater time we enter
1094 this codepath for this particular request mid then
1095 request_time is left as the absolute time of the *first*
1096 time this request mid was processed. This is what allows
1097 the request to eventually time out. */
1099 struct timeval timeout;
1101 /* Normally the smbd we asked should respond within
1102 * OPLOCK_BREAK_TIMEOUT seconds regardless of whether
1103 * the client did, give twice the timeout as a safety
1104 * measure here in case the other smbd is stuck
1105 * somewhere else. */
1107 timeout = timeval_set(OPLOCK_BREAK_TIMEOUT*2, 0);
1109 /* Nothing actually uses state.delayed_for_oplocks
1110 but it's handy to differentiate in debug messages
1111 between a 30 second delay due to oplock break, and
1112 a 1 second delay for share mode conflicts. */
1114 state.delayed_for_oplocks = True;
1117 if (!request_timed_out(request_time, timeout)) {
1118 defer_open(lck, request_time, timeout, req, &state);
1122 /****************************************************************************
1123 Open a file with a share mode.
1124 ****************************************************************************/
1126 NTSTATUS open_file_ntcreate(connection_struct *conn,
1127 struct smb_request *req,
1129 SMB_STRUCT_STAT *psbuf,
1130 uint32 access_mask, /* access bits (FILE_READ_DATA etc.) */
1131 uint32 share_access, /* share constants (FILE_SHARE_READ etc) */
1132 uint32 create_disposition, /* FILE_OPEN_IF etc. */
1133 uint32 create_options, /* options such as delete on close. */
1134 uint32 new_dos_attributes, /* attributes used for new file. */
1135 int oplock_request, /* internal Samba oplock codes. */
1136 /* Information (FILE_EXISTS etc.) */
1138 files_struct **result)
1142 bool file_existed = VALID_STAT(*psbuf);
1143 bool def_acl = False;
1144 bool posix_open = False;
1145 bool new_file_created = False;
1147 NTSTATUS fsp_open = NT_STATUS_ACCESS_DENIED;
1148 files_struct *fsp = NULL;
1149 mode_t new_unx_mode = (mode_t)0;
1150 mode_t unx_mode = (mode_t)0;
1152 uint32 existing_dos_attributes = 0;
1153 struct pending_message_list *pml = NULL;
1154 struct timeval request_time = timeval_zero();
1155 struct share_mode_lock *lck = NULL;
1156 uint32 open_access_mask = access_mask;
1160 const char *newname;
1164 if (conn->printer) {
1166 * Printers are handled completely differently.
1167 * Most of the passed parameters are ignored.
1171 *pinfo = FILE_WAS_CREATED;
1174 DEBUG(10, ("open_file_ntcreate: printer open fname=%s\n", fname));
1176 return print_fsp_open(conn, fname, result);
1179 if (!parent_dirname_talloc(talloc_tos(), fname, &parent_dir,
1181 return NT_STATUS_NO_MEMORY;
1184 if (new_dos_attributes & FILE_FLAG_POSIX_SEMANTICS) {
1186 unx_mode = (mode_t)(new_dos_attributes & ~FILE_FLAG_POSIX_SEMANTICS);
1187 new_dos_attributes = 0;
1189 /* We add aARCH to this as this mode is only used if the file is
1191 unx_mode = unix_mode(conn, new_dos_attributes | aARCH, fname,
1195 DEBUG(10, ("open_file_ntcreate: fname=%s, dos_attrs=0x%x "
1196 "access_mask=0x%x share_access=0x%x "
1197 "create_disposition = 0x%x create_options=0x%x "
1198 "unix mode=0%o oplock_request=%d\n",
1199 fname, new_dos_attributes, access_mask, share_access,
1200 create_disposition, create_options, unx_mode,
1203 if ((req == NULL) && ((oplock_request & INTERNAL_OPEN_ONLY) == 0)) {
1204 DEBUG(0, ("No smb request but not an internal only open!\n"));
1205 return NT_STATUS_INTERNAL_ERROR;
1209 * Only non-internal opens can be deferred at all
1213 && ((pml = get_open_deferred_message(req->mid)) != NULL)) {
1214 struct deferred_open_record *state =
1215 (struct deferred_open_record *)pml->private_data.data;
1217 /* Remember the absolute time of the original
1218 request with this mid. We'll use it later to
1219 see if this has timed out. */
1221 request_time = pml->request_time;
1223 /* Remove the deferred open entry under lock. */
1224 lck = get_share_mode_lock(talloc_tos(), state->id, NULL, NULL);
1226 DEBUG(0, ("could not get share mode lock\n"));
1228 del_deferred_open_entry(lck, req->mid);
1232 /* Ensure we don't reprocess this message. */
1233 remove_deferred_open_smb_message(req->mid);
1236 status = check_name(conn, fname);
1237 if (!NT_STATUS_IS_OK(status)) {
1242 new_dos_attributes &= SAMBA_ATTRIBUTES_MASK;
1244 existing_dos_attributes = dos_mode(conn, fname, psbuf);
1248 /* ignore any oplock requests if oplocks are disabled */
1249 if (!lp_oplocks(SNUM(conn)) || global_client_failed_oplock_break ||
1250 IS_VETO_OPLOCK_PATH(conn, fname)) {
1251 /* Mask off everything except the private Samba bits. */
1252 oplock_request &= SAMBA_PRIVATE_OPLOCK_MASK;
1255 /* this is for OS/2 long file names - say we don't support them */
1256 if (!lp_posix_pathnames() && strstr(fname,".+,;=[].")) {
1257 /* OS/2 Workplace shell fix may be main code stream in a later
1259 DEBUG(5,("open_file_ntcreate: OS/2 long filenames are not "
1261 if (use_nt_status()) {
1262 return NT_STATUS_OBJECT_NAME_NOT_FOUND;
1264 return NT_STATUS_DOS(ERRDOS, ERRcannotopen);
1267 switch( create_disposition ) {
1269 * Currently we're using FILE_SUPERSEDE as the same as
1270 * FILE_OVERWRITE_IF but they really are
1271 * different. FILE_SUPERSEDE deletes an existing file
1272 * (requiring delete access) then recreates it.
1274 case FILE_SUPERSEDE:
1275 /* If file exists replace/overwrite. If file doesn't
1277 flags2 |= (O_CREAT | O_TRUNC);
1280 case FILE_OVERWRITE_IF:
1281 /* If file exists replace/overwrite. If file doesn't
1283 flags2 |= (O_CREAT | O_TRUNC);
1287 /* If file exists open. If file doesn't exist error. */
1288 if (!file_existed) {
1289 DEBUG(5,("open_file_ntcreate: FILE_OPEN "
1290 "requested for file %s and file "
1291 "doesn't exist.\n", fname ));
1293 return NT_STATUS_OBJECT_NAME_NOT_FOUND;
1297 case FILE_OVERWRITE:
1298 /* If file exists overwrite. If file doesn't exist
1300 if (!file_existed) {
1301 DEBUG(5,("open_file_ntcreate: FILE_OVERWRITE "
1302 "requested for file %s and file "
1303 "doesn't exist.\n", fname ));
1305 return NT_STATUS_OBJECT_NAME_NOT_FOUND;
1311 /* If file exists error. If file doesn't exist
1314 DEBUG(5,("open_file_ntcreate: FILE_CREATE "
1315 "requested for file %s and file "
1316 "already exists.\n", fname ));
1317 if (S_ISDIR(psbuf->st_mode)) {
1322 return map_nt_error_from_unix(errno);
1324 flags2 |= (O_CREAT|O_EXCL);
1328 /* If file exists open. If file doesn't exist
1334 return NT_STATUS_INVALID_PARAMETER;
1337 /* We only care about matching attributes on file exists and
1340 if (!posix_open && file_existed && ((create_disposition == FILE_OVERWRITE) ||
1341 (create_disposition == FILE_OVERWRITE_IF))) {
1342 if (!open_match_attributes(conn, fname,
1343 existing_dos_attributes,
1344 new_dos_attributes, psbuf->st_mode,
1345 unx_mode, &new_unx_mode)) {
1346 DEBUG(5,("open_file_ntcreate: attributes missmatch "
1347 "for file %s (%x %x) (0%o, 0%o)\n",
1348 fname, existing_dos_attributes,
1350 (unsigned int)psbuf->st_mode,
1351 (unsigned int)unx_mode ));
1353 return NT_STATUS_ACCESS_DENIED;
1357 /* This is a nasty hack - must fix... JRA. */
1358 if (access_mask == MAXIMUM_ALLOWED_ACCESS) {
1359 open_access_mask = access_mask = FILE_GENERIC_ALL;
1363 * Convert GENERIC bits to specific bits.
1366 se_map_generic(&access_mask, &file_generic_mapping);
1367 open_access_mask = access_mask;
1369 if (flags2 & O_TRUNC) {
1370 open_access_mask |= FILE_WRITE_DATA; /* This will cause oplock breaks. */
1373 DEBUG(10, ("open_file_ntcreate: fname=%s, after mapping "
1374 "access_mask=0x%x\n", fname, access_mask ));
1377 * Note that we ignore the append flag as append does not
1378 * mean the same thing under DOS and Unix.
1381 if (access_mask & (FILE_WRITE_DATA | FILE_APPEND_DATA)) {
1382 /* DENY_DOS opens are always underlying read-write on the
1383 file handle, no matter what the requested access mask
1385 if ((create_options & NTCREATEX_OPTIONS_PRIVATE_DENY_DOS) ||
1386 access_mask & (FILE_READ_ATTRIBUTES|FILE_READ_DATA|FILE_READ_EA|FILE_EXECUTE)) {
1396 * Currently we only look at FILE_WRITE_THROUGH for create options.
1400 if ((create_options & FILE_WRITE_THROUGH) && lp_strict_sync(SNUM(conn))) {
1405 if (posix_open && (access_mask & FILE_APPEND_DATA)) {
1409 if (!posix_open && !CAN_WRITE(conn)) {
1411 * We should really return a permission denied error if either
1412 * O_CREAT or O_TRUNC are set, but for compatibility with
1413 * older versions of Samba we just AND them out.
1415 flags2 &= ~(O_CREAT|O_TRUNC);
1419 * Ensure we can't write on a read-only share or file.
1422 if (flags != O_RDONLY && file_existed &&
1423 (!CAN_WRITE(conn) || IS_DOS_READONLY(existing_dos_attributes))) {
1424 DEBUG(5,("open_file_ntcreate: write access requested for "
1425 "file %s on read only %s\n",
1426 fname, !CAN_WRITE(conn) ? "share" : "file" ));
1428 return NT_STATUS_ACCESS_DENIED;
1431 status = file_new(conn, &fsp);
1432 if(!NT_STATUS_IS_OK(status)) {
1436 fsp->file_id = vfs_file_id_from_sbuf(conn, psbuf);
1437 fsp->share_access = share_access;
1438 fsp->fh->private_options = create_options;
1439 fsp->access_mask = open_access_mask; /* We change this to the
1440 * requested access_mask after
1441 * the open is done. */
1442 fsp->posix_open = posix_open;
1444 /* Ensure no SAMBA_PRIVATE bits can be set. */
1445 fsp->oplock_type = (oplock_request & ~SAMBA_PRIVATE_OPLOCK_MASK);
1447 if (timeval_is_zero(&request_time)) {
1448 request_time = fsp->open_time;
1452 id = vfs_file_id_from_sbuf(conn, psbuf);
1454 lck = get_share_mode_lock(talloc_tos(), id,
1460 DEBUG(0, ("Could not get share mode lock\n"));
1461 return NT_STATUS_SHARING_VIOLATION;
1464 /* First pass - send break only on batch oplocks. */
1466 && delay_for_oplocks(lck, fsp, req->mid, 1,
1468 schedule_defer_open(lck, request_time, req);
1471 return NT_STATUS_SHARING_VIOLATION;
1474 /* Use the client requested access mask here, not the one we
1476 status = open_mode_check(conn, fname, lck,
1477 access_mask, share_access,
1478 create_options, &file_existed);
1480 if (NT_STATUS_IS_OK(status)) {
1481 /* We might be going to allow this open. Check oplock
1483 /* Second pass - send break for both batch or
1484 * exclusive oplocks. */
1486 && delay_for_oplocks(lck, fsp, req->mid, 2,
1488 schedule_defer_open(lck, request_time, req);
1491 return NT_STATUS_SHARING_VIOLATION;
1495 if (NT_STATUS_EQUAL(status, NT_STATUS_DELETE_PENDING)) {
1496 /* DELETE_PENDING is not deferred for a second */
1502 if (!NT_STATUS_IS_OK(status)) {
1503 uint32 can_access_mask;
1504 bool can_access = True;
1506 SMB_ASSERT(NT_STATUS_EQUAL(status, NT_STATUS_SHARING_VIOLATION));
1508 /* Check if this can be done with the deny_dos and fcb
1510 if (create_options &
1511 (NTCREATEX_OPTIONS_PRIVATE_DENY_DOS|
1512 NTCREATEX_OPTIONS_PRIVATE_DENY_FCB)) {
1513 files_struct *fsp_dup;
1516 DEBUG(0, ("DOS open without an SMB "
1520 return NT_STATUS_INTERNAL_ERROR;
1523 /* Use the client requested access mask here,
1524 * not the one we open with. */
1525 fsp_dup = fcb_or_dos_open(conn, fname, id,
1536 *pinfo = FILE_WAS_OPENED;
1538 conn->num_files_open++;
1540 return NT_STATUS_OK;
1545 * This next line is a subtlety we need for
1546 * MS-Access. If a file open will fail due to share
1547 * permissions and also for security (access) reasons,
1548 * we need to return the access failed error, not the
1549 * share error. We can't open the file due to kernel
1550 * oplock deadlock (it's possible we failed above on
1551 * the open_mode_check()) so use a userspace check.
1554 if (flags & O_RDWR) {
1555 can_access_mask = FILE_READ_DATA|FILE_WRITE_DATA;
1556 } else if (flags & O_WRONLY) {
1557 can_access_mask = FILE_WRITE_DATA;
1559 can_access_mask = FILE_READ_DATA;
1562 if (((can_access_mask & FILE_WRITE_DATA) && !CAN_WRITE(conn)) ||
1563 !can_access_file(conn,fname,psbuf,can_access_mask)) {
1568 * If we're returning a share violation, ensure we
1569 * cope with the braindead 1 second delay.
1572 if (!(oplock_request & INTERNAL_OPEN_ONLY) &&
1573 lp_defer_sharing_violations()) {
1574 struct timeval timeout;
1575 struct deferred_open_record state;
1578 /* this is a hack to speed up torture tests
1580 timeout_usecs = lp_parm_int(SNUM(conn),
1581 "smbd","sharedelay",
1582 SHARING_VIOLATION_USEC_WAIT);
1584 /* This is a relative time, added to the absolute
1585 request_time value to get the absolute timeout time.
1586 Note that if this is the second or greater time we enter
1587 this codepath for this particular request mid then
1588 request_time is left as the absolute time of the *first*
1589 time this request mid was processed. This is what allows
1590 the request to eventually time out. */
1592 timeout = timeval_set(0, timeout_usecs);
1594 /* Nothing actually uses state.delayed_for_oplocks
1595 but it's handy to differentiate in debug messages
1596 between a 30 second delay due to oplock break, and
1597 a 1 second delay for share mode conflicts. */
1599 state.delayed_for_oplocks = False;
1603 && !request_timed_out(request_time,
1605 defer_open(lck, request_time, timeout,
1613 * We have detected a sharing violation here
1614 * so return the correct error code
1616 status = NT_STATUS_SHARING_VIOLATION;
1618 status = NT_STATUS_ACCESS_DENIED;
1625 * We exit this block with the share entry *locked*.....
1629 SMB_ASSERT(!file_existed || (lck != NULL));
1632 * Ensure we pay attention to default ACLs on directories if required.
1635 if ((flags2 & O_CREAT) && lp_inherit_acls(SNUM(conn)) &&
1636 (def_acl = directory_has_default_acl(conn, parent_dir))) {
1640 DEBUG(4,("calling open_file with flags=0x%X flags2=0x%X mode=0%o, "
1641 "access_mask = 0x%x, open_access_mask = 0x%x\n",
1642 (unsigned int)flags, (unsigned int)flags2,
1643 (unsigned int)unx_mode, (unsigned int)access_mask,
1644 (unsigned int)open_access_mask));
1647 * open_file strips any O_TRUNC flags itself.
1650 fsp_open = open_file(fsp, conn, req, parent_dir, newname, fname, psbuf,
1651 flags|flags2, unx_mode, access_mask,
1654 if (!NT_STATUS_IS_OK(fsp_open)) {
1662 if (!file_existed) {
1665 * Deal with the race condition where two smbd's detect the
1666 * file doesn't exist and do the create at the same time. One
1667 * of them will win and set a share mode, the other (ie. this
1668 * one) should check if the requested share mode for this
1669 * create is allowed.
1673 * Now the file exists and fsp is successfully opened,
1674 * fsp->dev and fsp->inode are valid and should replace the
1675 * dev=0,inode=0 from a non existent file. Spotted by
1676 * Nadav Danieli <nadavd@exanet.com>. JRA.
1681 lck = get_share_mode_lock(talloc_tos(), id,
1686 DEBUG(0, ("open_file_ntcreate: Could not get share "
1687 "mode lock for %s\n", fname));
1690 return NT_STATUS_SHARING_VIOLATION;
1693 /* First pass - send break only on batch oplocks. */
1695 && delay_for_oplocks(lck, fsp, req->mid, 1,
1697 schedule_defer_open(lck, request_time, req);
1701 return NT_STATUS_SHARING_VIOLATION;
1704 status = open_mode_check(conn, fname, lck,
1705 access_mask, share_access,
1706 create_options, &file_existed);
1708 if (NT_STATUS_IS_OK(status)) {
1709 /* We might be going to allow this open. Check oplock
1711 /* Second pass - send break for both batch or
1712 * exclusive oplocks. */
1714 && delay_for_oplocks(lck, fsp, req->mid, 2,
1716 schedule_defer_open(lck, request_time, req);
1720 return NT_STATUS_SHARING_VIOLATION;
1724 if (!NT_STATUS_IS_OK(status)) {
1725 struct deferred_open_record state;
1730 state.delayed_for_oplocks = False;
1733 /* Do it all over again immediately. In the second
1734 * round we will find that the file existed and handle
1735 * the DELETE_PENDING and FCB cases correctly. No need
1736 * to duplicate the code here. Essentially this is a
1737 * "goto top of this function", but don't tell
1741 defer_open(lck, request_time, timeval_zero(),
1749 * We exit this block with the share entry *locked*.....
1754 SMB_ASSERT(lck != NULL);
1756 /* note that we ignore failure for the following. It is
1757 basically a hack for NFS, and NFS will never set one of
1758 these only read them. Nobody but Samba can ever set a deny
1759 mode and we have already checked our more authoritative
1760 locking database for permission to set this deny mode. If
1761 the kernel refuses the operations then the kernel is wrong.
1762 note that GPFS supports it as well - jmcd */
1764 if (fsp->fh->fd != -1) {
1765 ret_flock = SMB_VFS_KERNEL_FLOCK(fsp, share_access);
1766 if(ret_flock == -1 ){
1772 return NT_STATUS_SHARING_VIOLATION;
1777 * At this point onwards, we can guarentee that the share entry
1778 * is locked, whether we created the file or not, and that the
1779 * deny mode is compatible with all current opens.
1783 * If requested, truncate the file.
1786 if (flags2&O_TRUNC) {
1788 * We are modifing the file after open - update the stat
1791 if ((SMB_VFS_FTRUNCATE(fsp, 0) == -1) ||
1792 (SMB_VFS_FSTAT(fsp, psbuf)==-1)) {
1793 status = map_nt_error_from_unix(errno);
1801 /* Record the options we were opened with. */
1802 fsp->share_access = share_access;
1803 fsp->fh->private_options = create_options;
1804 fsp->access_mask = access_mask;
1807 /* stat opens on existing files don't get oplocks. */
1808 if (is_stat_open(open_access_mask)) {
1809 fsp->oplock_type = NO_OPLOCK;
1812 if (!(flags2 & O_TRUNC)) {
1813 info = FILE_WAS_OPENED;
1815 info = FILE_WAS_OVERWRITTEN;
1818 info = FILE_WAS_CREATED;
1826 * Setup the oplock info in both the shared memory and
1830 if ((fsp->oplock_type != NO_OPLOCK) &&
1831 (fsp->oplock_type != FAKE_LEVEL_II_OPLOCK)) {
1832 if (!set_file_oplock(fsp, fsp->oplock_type)) {
1833 /* Could not get the kernel oplock */
1834 fsp->oplock_type = NO_OPLOCK;
1838 if (info == FILE_WAS_OVERWRITTEN || info == FILE_WAS_CREATED || info == FILE_WAS_SUPERSEDED) {
1839 new_file_created = True;
1842 set_share_mode(lck, fsp, current_user.ut.uid, 0, fsp->oplock_type, new_file_created);
1844 /* Handle strange delete on close create semantics. */
1845 if ((create_options & FILE_DELETE_ON_CLOSE)
1846 && (is_ntfs_stream_name(fname)
1847 || can_set_initial_delete_on_close(lck))) {
1848 status = can_set_delete_on_close(fsp, True, new_dos_attributes);
1850 if (!NT_STATUS_IS_OK(status)) {
1851 /* Remember to delete the mode we just added. */
1852 del_share_mode(lck, fsp);
1858 /* Note that here we set the *inital* delete on close flag,
1859 not the regular one. The magic gets handled in close. */
1860 fsp->initial_delete_on_close = True;
1863 if (new_file_created) {
1864 /* Files should be initially set as archive */
1865 if (lp_map_archive(SNUM(conn)) ||
1866 lp_store_dos_attributes(SNUM(conn))) {
1868 SMB_STRUCT_STAT tmp_sbuf;
1869 SET_STAT_INVALID(tmp_sbuf);
1870 if (file_set_dosmode(
1872 new_dos_attributes | aARCH,
1873 &tmp_sbuf, parent_dir,
1875 unx_mode = tmp_sbuf.st_mode;
1882 * Take care of inherited ACLs on created files - if default ACL not
1886 if (!posix_open && !file_existed && !def_acl) {
1888 int saved_errno = errno; /* We might get ENOSYS in the next
1891 if (SMB_VFS_FCHMOD_ACL(fsp, unx_mode) == -1 &&
1893 errno = saved_errno; /* Ignore ENOSYS */
1896 } else if (new_unx_mode) {
1900 /* Attributes need changing. File already existed. */
1903 int saved_errno = errno; /* We might get ENOSYS in the
1905 ret = SMB_VFS_FCHMOD_ACL(fsp, new_unx_mode);
1907 if (ret == -1 && errno == ENOSYS) {
1908 errno = saved_errno; /* Ignore ENOSYS */
1910 DEBUG(5, ("open_file_ntcreate: reset "
1911 "attributes of file %s to 0%o\n",
1912 fname, (unsigned int)new_unx_mode));
1913 ret = 0; /* Don't do the fchmod below. */
1918 (SMB_VFS_FCHMOD(fsp, new_unx_mode) == -1))
1919 DEBUG(5, ("open_file_ntcreate: failed to reset "
1920 "attributes of file %s to 0%o\n",
1921 fname, (unsigned int)new_unx_mode));
1924 /* If this is a successful open, we must remove any deferred open
1927 del_deferred_open_entry(lck, req->mid);
1931 conn->num_files_open++;
1934 return NT_STATUS_OK;
1937 /****************************************************************************
1938 Open a file for for write to ensure that we can fchmod it.
1939 ****************************************************************************/
1941 NTSTATUS open_file_fchmod(connection_struct *conn, const char *fname,
1942 SMB_STRUCT_STAT *psbuf, files_struct **result)
1944 files_struct *fsp = NULL;
1947 if (!VALID_STAT(*psbuf)) {
1948 return NT_STATUS_INVALID_PARAMETER;
1951 status = file_new(conn, &fsp);
1952 if(!NT_STATUS_IS_OK(status)) {
1956 /* note! we must use a non-zero desired access or we don't get
1957 a real file descriptor. Oh what a twisted web we weave. */
1958 status = open_file(fsp, conn, NULL, NULL, NULL, fname, psbuf, O_WRONLY,
1959 0, FILE_WRITE_DATA, FILE_WRITE_DATA);
1962 * This is not a user visible file open.
1963 * Don't set a share mode and don't increment
1964 * the conn->num_files_open.
1967 if (!NT_STATUS_IS_OK(status)) {
1973 return NT_STATUS_OK;
1976 /****************************************************************************
1977 Close the fchmod file fd - ensure no locks are lost.
1978 ****************************************************************************/
1980 NTSTATUS close_file_fchmod(files_struct *fsp)
1982 NTSTATUS status = fd_close(fsp);
1987 static NTSTATUS mkdir_internal(connection_struct *conn,
1989 uint32 file_attributes,
1990 SMB_STRUCT_STAT *psbuf)
1994 const char *dirname;
1996 bool posix_open = false;
1998 if(!CAN_WRITE(conn)) {
1999 DEBUG(5,("mkdir_internal: failing create on read-only share "
2000 "%s\n", lp_servicename(SNUM(conn))));
2001 return NT_STATUS_ACCESS_DENIED;
2004 status = check_name(conn, name);
2005 if (!NT_STATUS_IS_OK(status)) {
2009 if (!parent_dirname_talloc(talloc_tos(), name, &parent_dir,
2011 return NT_STATUS_NO_MEMORY;
2014 if (file_attributes & FILE_FLAG_POSIX_SEMANTICS) {
2016 mode = (mode_t)(file_attributes & ~FILE_FLAG_POSIX_SEMANTICS);
2018 mode = unix_mode(conn, aDIR, name, parent_dir);
2021 if (SMB_VFS_MKDIR(conn, name, mode) != 0) {
2022 return map_nt_error_from_unix(errno);
2025 /* Ensure we're checking for a symlink here.... */
2026 /* We don't want to get caught by a symlink racer. */
2028 if (SMB_VFS_LSTAT(conn, name, psbuf) == -1) {
2029 DEBUG(2, ("Could not stat directory '%s' just created: %s\n",
2030 name, strerror(errno)));
2031 return map_nt_error_from_unix(errno);
2034 if (!S_ISDIR(psbuf->st_mode)) {
2035 DEBUG(0, ("Directory just '%s' created is not a directory\n",
2037 return NT_STATUS_ACCESS_DENIED;
2040 if (lp_store_dos_attributes(SNUM(conn))) {
2042 file_set_dosmode(conn, name,
2043 file_attributes | aDIR, NULL,
2049 if (lp_inherit_perms(SNUM(conn))) {
2050 inherit_access_acl(conn, parent_dir, name, mode);
2053 if (!(file_attributes & FILE_FLAG_POSIX_SEMANTICS)) {
2055 * Check if high bits should have been set,
2056 * then (if bits are missing): add them.
2057 * Consider bits automagically set by UNIX, i.e. SGID bit from parent
2060 if (mode & ~(S_IRWXU|S_IRWXG|S_IRWXO) && (mode & ~psbuf->st_mode)) {
2061 SMB_VFS_CHMOD(conn, name,
2062 psbuf->st_mode | (mode & ~psbuf->st_mode));
2066 /* Change the owner if required. */
2067 if (lp_inherit_owner(SNUM(conn))) {
2068 change_dir_owner_to_parent(conn, parent_dir, name, psbuf);
2071 notify_fname(conn, NOTIFY_ACTION_ADDED, FILE_NOTIFY_CHANGE_DIR_NAME,
2074 return NT_STATUS_OK;
2077 /****************************************************************************
2078 Open a directory from an NT SMB call.
2079 ****************************************************************************/
2081 NTSTATUS open_directory(connection_struct *conn,
2082 struct smb_request *req,
2084 SMB_STRUCT_STAT *psbuf,
2086 uint32 share_access,
2087 uint32 create_disposition,
2088 uint32 create_options,
2089 uint32 file_attributes,
2091 files_struct **result)
2093 files_struct *fsp = NULL;
2094 bool dir_existed = VALID_STAT(*psbuf) ? True : False;
2095 struct share_mode_lock *lck = NULL;
2099 DEBUG(5,("open_directory: opening directory %s, access_mask = 0x%x, "
2100 "share_access = 0x%x create_options = 0x%x, "
2101 "create_disposition = 0x%x, file_attributes = 0x%x\n",
2103 (unsigned int)access_mask,
2104 (unsigned int)share_access,
2105 (unsigned int)create_options,
2106 (unsigned int)create_disposition,
2107 (unsigned int)file_attributes));
2109 if (!(file_attributes & FILE_FLAG_POSIX_SEMANTICS) && is_ntfs_stream_name(fname)) {
2110 DEBUG(2, ("open_directory: %s is a stream name!\n", fname));
2111 return NT_STATUS_NOT_A_DIRECTORY;
2114 switch( create_disposition ) {
2117 info = FILE_WAS_OPENED;
2120 * We want to follow symlinks here.
2123 if (SMB_VFS_STAT(conn, fname, psbuf) != 0) {
2124 return map_nt_error_from_unix(errno);
2131 /* If directory exists error. If directory doesn't
2134 status = mkdir_internal(conn,
2139 if (!NT_STATUS_IS_OK(status)) {
2140 DEBUG(2, ("open_directory: unable to create "
2141 "%s. Error was %s\n", fname,
2142 nt_errstr(status)));
2146 info = FILE_WAS_CREATED;
2151 * If directory exists open. If directory doesn't
2155 status = mkdir_internal(conn,
2160 if (NT_STATUS_IS_OK(status)) {
2161 info = FILE_WAS_CREATED;
2164 if (NT_STATUS_EQUAL(status,
2165 NT_STATUS_OBJECT_NAME_COLLISION)) {
2166 info = FILE_WAS_OPENED;
2167 status = NT_STATUS_OK;
2172 case FILE_SUPERSEDE:
2173 case FILE_OVERWRITE:
2174 case FILE_OVERWRITE_IF:
2176 DEBUG(5,("open_directory: invalid create_disposition "
2177 "0x%x for directory %s\n",
2178 (unsigned int)create_disposition, fname));
2179 return NT_STATUS_INVALID_PARAMETER;
2182 if(!S_ISDIR(psbuf->st_mode)) {
2183 DEBUG(5,("open_directory: %s is not a directory !\n",
2185 return NT_STATUS_NOT_A_DIRECTORY;
2188 status = file_new(conn, &fsp);
2189 if(!NT_STATUS_IS_OK(status)) {
2194 * Setup the files_struct for it.
2197 fsp->mode = psbuf->st_mode;
2198 fsp->file_id = vfs_file_id_from_sbuf(conn, psbuf);
2199 fsp->vuid = req ? req->vuid : UID_FIELD_INVALID;
2200 fsp->file_pid = req ? req->smbpid : 0;
2201 fsp->can_lock = False;
2202 fsp->can_read = False;
2203 fsp->can_write = False;
2205 fsp->share_access = share_access;
2206 fsp->fh->private_options = create_options;
2207 fsp->access_mask = access_mask;
2209 fsp->print_file = False;
2210 fsp->modified = False;
2211 fsp->oplock_type = NO_OPLOCK;
2212 fsp->sent_oplock_break = NO_BREAK_SENT;
2213 fsp->is_directory = True;
2214 fsp->is_stat = False;
2215 fsp->posix_open = (file_attributes & FILE_FLAG_POSIX_SEMANTICS) ? True : False;
2217 string_set(&fsp->fsp_name,fname);
2219 lck = get_share_mode_lock(talloc_tos(), fsp->file_id,
2224 DEBUG(0, ("open_directory: Could not get share mode lock for %s\n", fname));
2226 return NT_STATUS_SHARING_VIOLATION;
2229 status = open_mode_check(conn, fname, lck,
2230 access_mask, share_access,
2231 create_options, &dir_existed);
2233 if (!NT_STATUS_IS_OK(status)) {
2239 set_share_mode(lck, fsp, current_user.ut.uid, 0, NO_OPLOCK, True);
2241 /* For directories the delete on close bit at open time seems
2242 always to be honored on close... See test 19 in Samba4 BASE-DELETE. */
2243 if (create_options & FILE_DELETE_ON_CLOSE) {
2244 status = can_set_delete_on_close(fsp, True, 0);
2245 if (!NT_STATUS_IS_OK(status) && !NT_STATUS_EQUAL(status, NT_STATUS_DIRECTORY_NOT_EMPTY)) {
2251 if (NT_STATUS_IS_OK(status)) {
2252 /* Note that here we set the *inital* delete on close flag,
2253 not the regular one. The magic gets handled in close. */
2254 fsp->initial_delete_on_close = True;
2264 conn->num_files_open++;
2267 return NT_STATUS_OK;
2270 NTSTATUS create_directory(connection_struct *conn, struct smb_request *req, const char *directory)
2273 SMB_STRUCT_STAT sbuf;
2276 SET_STAT_INVALID(sbuf);
2278 status = open_directory(conn, req, directory, &sbuf,
2279 FILE_READ_ATTRIBUTES, /* Just a stat open */
2280 FILE_SHARE_NONE, /* Ignored for stat opens */
2283 FILE_ATTRIBUTE_DIRECTORY,
2287 if (NT_STATUS_IS_OK(status)) {
2288 close_file(fsp, NORMAL_CLOSE);
2294 /****************************************************************************
2295 Open a pseudo-file (no locking checks - a 'stat' open).
2296 ****************************************************************************/
2298 NTSTATUS open_file_stat(connection_struct *conn, struct smb_request *req,
2299 const char *fname, SMB_STRUCT_STAT *psbuf,
2300 files_struct **result)
2302 files_struct *fsp = NULL;
2305 if (!VALID_STAT(*psbuf)) {
2306 return NT_STATUS_INVALID_PARAMETER;
2309 /* Can't 'stat' open directories. */
2310 if(S_ISDIR(psbuf->st_mode)) {
2311 return NT_STATUS_FILE_IS_A_DIRECTORY;
2314 status = file_new(conn, &fsp);
2315 if(!NT_STATUS_IS_OK(status)) {
2319 DEBUG(5,("open_file_stat: 'opening' file %s\n", fname));
2322 * Setup the files_struct for it.
2325 fsp->mode = psbuf->st_mode;
2326 fsp->file_id = vfs_file_id_from_sbuf(conn, psbuf);
2327 fsp->vuid = req ? req->vuid : UID_FIELD_INVALID;
2328 fsp->file_pid = req ? req->smbpid : 0;
2329 fsp->can_lock = False;
2330 fsp->can_read = False;
2331 fsp->can_write = False;
2332 fsp->print_file = False;
2333 fsp->modified = False;
2334 fsp->oplock_type = NO_OPLOCK;
2335 fsp->sent_oplock_break = NO_BREAK_SENT;
2336 fsp->is_directory = False;
2337 fsp->is_stat = True;
2338 string_set(&fsp->fsp_name,fname);
2340 conn->num_files_open++;
2343 return NT_STATUS_OK;
2346 /****************************************************************************
2347 Receive notification that one of our open files has been renamed by another
2349 ****************************************************************************/
2351 void msg_file_was_renamed(struct messaging_context *msg,
2354 struct server_id server_id,
2358 char *frm = (char *)data->data;
2360 const char *sharepath;
2361 const char *newname;
2364 if (data->data == NULL
2365 || data->length < MSG_FILE_RENAMED_MIN_SIZE + 2) {
2366 DEBUG(0, ("msg_file_was_renamed: Got invalid msg len %d\n",
2367 (int)data->length));
2371 /* Unpack the message. */
2372 pull_file_id_16(frm, &id);
2373 sharepath = &frm[16];
2374 newname = sharepath + strlen(sharepath) + 1;
2375 sp_len = strlen(sharepath);
2377 DEBUG(10,("msg_file_was_renamed: Got rename message for sharepath %s, new name %s, "
2379 sharepath, newname, file_id_string_tos(&id)));
2381 for(fsp = file_find_di_first(id); fsp; fsp = file_find_di_next(fsp)) {
2382 if (memcmp(fsp->conn->connectpath, sharepath, sp_len) == 0) {
2383 DEBUG(10,("msg_file_was_renamed: renaming file fnum %d from %s -> %s\n",
2384 fsp->fnum, fsp->fsp_name, newname ));
2385 string_set(&fsp->fsp_name, newname);
2388 /* Now we have the complete path we can work out if this is
2389 actually within this share and adjust newname accordingly. */
2390 DEBUG(10,("msg_file_was_renamed: share mismatch (sharepath %s "
2391 "not sharepath %s) "
2392 "fnum %d from %s -> %s\n",
2393 fsp->conn->connectpath,
2402 struct case_semantics_state {
2403 connection_struct *conn;
2404 bool case_sensitive;
2406 bool short_case_preserve;
2409 /****************************************************************************
2410 Restore case semantics.
2411 ****************************************************************************/
2412 static int restore_case_semantics(struct case_semantics_state *state)
2414 state->conn->case_sensitive = state->case_sensitive;
2415 state->conn->case_preserve = state->case_preserve;
2416 state->conn->short_case_preserve = state->short_case_preserve;
2420 /****************************************************************************
2421 Save case semantics.
2422 ****************************************************************************/
2423 static struct case_semantics_state *set_posix_case_semantics(TALLOC_CTX *mem_ctx,
2424 connection_struct *conn)
2426 struct case_semantics_state *result;
2428 if (!(result = talloc(mem_ctx, struct case_semantics_state))) {
2429 DEBUG(0, ("talloc failed\n"));
2433 result->conn = conn;
2434 result->case_sensitive = conn->case_sensitive;
2435 result->case_preserve = conn->case_preserve;
2436 result->short_case_preserve = conn->short_case_preserve;
2439 conn->case_sensitive = True;
2440 conn->case_preserve = True;
2441 conn->short_case_preserve = True;
2443 talloc_set_destructor(result, restore_case_semantics);
2449 * If a main file is opened for delete, all streams need to be checked for
2450 * !FILE_SHARE_DELETE. Do this by opening with DELETE_ACCESS.
2451 * If that works, delete them all by setting the delete on close and close.
2454 static NTSTATUS open_streams_for_delete(connection_struct *conn,
2457 struct stream_struct *stream_info;
2458 files_struct **streams;
2460 unsigned int num_streams;
2461 TALLOC_CTX *frame = talloc_stackframe();
2464 status = SMB_VFS_STREAMINFO(conn, NULL, fname, talloc_tos(),
2465 &num_streams, &stream_info);
2467 if (NT_STATUS_EQUAL(status, NT_STATUS_NOT_IMPLEMENTED)
2468 || NT_STATUS_EQUAL(status, NT_STATUS_OBJECT_NAME_NOT_FOUND)) {
2469 DEBUG(10, ("no streams around\n"));
2471 return NT_STATUS_OK;
2474 if (!NT_STATUS_IS_OK(status)) {
2475 DEBUG(10, ("SMB_VFS_STREAMINFO failed: %s\n",
2476 nt_errstr(status)));
2480 DEBUG(10, ("open_streams_for_delete found %d streams\n",
2483 if (num_streams == 0) {
2485 return NT_STATUS_OK;
2488 streams = TALLOC_ARRAY(talloc_tos(), files_struct *, num_streams);
2489 if (streams == NULL) {
2490 DEBUG(0, ("talloc failed\n"));
2491 status = NT_STATUS_NO_MEMORY;
2495 for (i=0; i<num_streams; i++) {
2498 if (strequal(stream_info[i].name, "::$DATA")) {
2503 streamname = talloc_asprintf(talloc_tos(), "%s%s", fname,
2504 stream_info[i].name);
2506 if (streamname == NULL) {
2507 DEBUG(0, ("talloc_aprintf failed\n"));
2508 status = NT_STATUS_NO_MEMORY;
2512 status = create_file_unixpath
2515 streamname, /* fname */
2516 DELETE_ACCESS, /* access_mask */
2517 FILE_SHARE_READ | FILE_SHARE_WRITE
2518 | FILE_SHARE_DELETE, /* share_access */
2519 FILE_OPEN, /* create_disposition*/
2520 NTCREATEX_OPTIONS_PRIVATE_STREAM_DELETE, /* create_options */
2521 FILE_ATTRIBUTE_NORMAL, /* file_attributes */
2522 0, /* oplock_request */
2523 0, /* allocation_size */
2526 &streams[i], /* result */
2530 TALLOC_FREE(streamname);
2532 if (!NT_STATUS_IS_OK(status)) {
2533 DEBUG(10, ("Could not open stream %s: %s\n",
2534 streamname, nt_errstr(status)));
2540 * don't touch the variable "status" beyond this point :-)
2543 for (i -= 1 ; i >= 0; i--) {
2544 if (streams[i] == NULL) {
2548 DEBUG(10, ("Closing stream # %d, %s\n", i,
2549 streams[i]->fsp_name));
2550 close_file(streams[i], NORMAL_CLOSE);
2559 * Wrapper around open_file_ntcreate and open_directory
2562 NTSTATUS create_file_unixpath(connection_struct *conn,
2563 struct smb_request *req,
2565 uint32_t access_mask,
2566 uint32_t share_access,
2567 uint32_t create_disposition,
2568 uint32_t create_options,
2569 uint32_t file_attributes,
2570 uint32_t oplock_request,
2571 SMB_BIG_UINT allocation_size,
2572 struct security_descriptor *sd,
2573 struct ea_list *ea_list,
2575 files_struct **result,
2577 SMB_STRUCT_STAT *psbuf)
2579 SMB_STRUCT_STAT sbuf;
2580 int info = FILE_WAS_OPENED;
2581 files_struct *base_fsp = NULL;
2582 files_struct *fsp = NULL;
2585 DEBUG(10,("create_file_unixpath: access_mask = 0x%x "
2586 "file_attributes = 0x%x, share_access = 0x%x, "
2587 "create_disposition = 0x%x create_options = 0x%x "
2588 "oplock_request = 0x%x ea_list = 0x%p, sd = 0x%p, "
2590 (unsigned int)access_mask,
2591 (unsigned int)file_attributes,
2592 (unsigned int)share_access,
2593 (unsigned int)create_disposition,
2594 (unsigned int)create_options,
2595 (unsigned int)oplock_request,
2596 ea_list, sd, fname));
2598 if (create_options & FILE_OPEN_BY_FILE_ID) {
2599 status = NT_STATUS_NOT_SUPPORTED;
2604 oplock_request |= INTERNAL_OPEN_ONLY;
2607 if (psbuf != NULL) {
2611 if (SMB_VFS_STAT(conn, fname, &sbuf) == -1) {
2612 SET_STAT_INVALID(sbuf);
2616 if ((conn->fs_capabilities & FILE_NAMED_STREAMS)
2617 && (access_mask & DELETE_ACCESS)
2618 && !is_ntfs_stream_name(fname)) {
2620 * We can't open a file with DELETE access if any of the
2621 * streams is open without FILE_SHARE_DELETE
2623 status = open_streams_for_delete(conn, fname);
2625 if (!NT_STATUS_IS_OK(status)) {
2630 /* This is the correct thing to do (check every time) but can_delete
2631 * is expensive (it may have to read the parent directory
2632 * permissions). So for now we're not doing it unless we have a strong
2633 * hint the client is really going to delete this file. If the client
2634 * is forcing FILE_CREATE let the filesystem take care of the
2637 /* Setting FILE_SHARE_DELETE is the hint. */
2639 if (lp_acl_check_permissions(SNUM(conn))
2640 && (create_disposition != FILE_CREATE)
2641 && (share_access & FILE_SHARE_DELETE)
2642 && (access_mask & DELETE_ACCESS)
2643 && (((dos_mode(conn, fname, &sbuf) & FILE_ATTRIBUTE_READONLY)
2644 && !lp_delete_readonly(SNUM(conn)))
2645 || !can_delete_file_in_directory(conn, fname))) {
2646 status = NT_STATUS_ACCESS_DENIED;
2651 /* We need to support SeSecurityPrivilege for this. */
2652 if ((access_mask & SEC_RIGHT_SYSTEM_SECURITY) &&
2653 !user_has_privileges(current_user.nt_user_token,
2655 status = NT_STATUS_PRIVILEGE_NOT_HELD;
2660 if ((conn->fs_capabilities & FILE_NAMED_STREAMS)
2661 && is_ntfs_stream_name(fname)
2662 && (!(create_options & NTCREATEX_OPTIONS_PRIVATE_STREAM_DELETE))) {
2664 uint32 base_create_disposition;
2666 if (create_options & FILE_DIRECTORY_FILE) {
2667 status = NT_STATUS_NOT_A_DIRECTORY;
2671 status = split_ntfs_stream_name(talloc_tos(), fname,
2673 if (!NT_STATUS_IS_OK(status)) {
2674 DEBUG(10, ("split_ntfs_stream_name failed: %s\n",
2675 nt_errstr(status)));
2679 SMB_ASSERT(!is_ntfs_stream_name(base)); /* paranoia.. */
2681 switch (create_disposition) {
2683 base_create_disposition = FILE_OPEN;
2686 base_create_disposition = FILE_OPEN_IF;
2690 status = create_file_unixpath(conn, NULL, base, 0,
2693 | FILE_SHARE_DELETE,
2694 base_create_disposition,
2695 0, 0, 0, 0, NULL, NULL,
2696 &base_fsp, NULL, NULL);
2697 if (!NT_STATUS_IS_OK(status)) {
2698 DEBUG(10, ("create_file_unixpath for base %s failed: "
2699 "%s\n", base, nt_errstr(status)));
2705 * If it's a request for a directory open, deal with it separately.
2708 if (create_options & FILE_DIRECTORY_FILE) {
2710 if (create_options & FILE_NON_DIRECTORY_FILE) {
2711 status = NT_STATUS_INVALID_PARAMETER;
2715 /* Can't open a temp directory. IFS kit test. */
2716 if (file_attributes & FILE_ATTRIBUTE_TEMPORARY) {
2717 status = NT_STATUS_INVALID_PARAMETER;
2722 * We will get a create directory here if the Win32
2723 * app specified a security descriptor in the
2724 * CreateDirectory() call.
2728 status = open_directory(
2729 conn, req, fname, &sbuf, access_mask, share_access,
2730 create_disposition, create_options, file_attributes,
2735 * Ordinary file case.
2738 status = open_file_ntcreate(
2739 conn, req, fname, &sbuf, access_mask, share_access,
2740 create_disposition, create_options, file_attributes,
2741 oplock_request, &info, &fsp);
2743 if (NT_STATUS_EQUAL(status, NT_STATUS_FILE_IS_A_DIRECTORY)) {
2746 * Fail the open if it was explicitly a non-directory
2750 if (create_options & FILE_NON_DIRECTORY_FILE) {
2751 status = NT_STATUS_FILE_IS_A_DIRECTORY;
2756 status = open_directory(
2757 conn, req, fname, &sbuf, access_mask,
2758 share_access, create_disposition,
2759 create_options, file_attributes,
2764 if (!NT_STATUS_IS_OK(status)) {
2769 * According to the MS documentation, the only time the security
2770 * descriptor is applied to the opened file is iff we *created* the
2771 * file; an existing file stays the same.
2773 * Also, it seems (from observation) that you can open the file with
2774 * any access mask but you can still write the sd. We need to override
2775 * the granted access before we call set_sd
2776 * Patch for bug #2242 from Tom Lackemann <cessnatomny@yahoo.com>.
2779 if ((sd != NULL) && (info == FILE_WAS_CREATED)
2780 && lp_nt_acl_support(SNUM(conn))) {
2782 uint32_t sec_info_sent = ALL_SECURITY_INFORMATION;
2783 uint32_t saved_access_mask = fsp->access_mask;
2785 if (sd->owner_sid == NULL) {
2786 sec_info_sent &= ~OWNER_SECURITY_INFORMATION;
2788 if (sd->group_sid == NULL) {
2789 sec_info_sent &= ~GROUP_SECURITY_INFORMATION;
2791 if (sd->sacl == NULL) {
2792 sec_info_sent &= ~SACL_SECURITY_INFORMATION;
2794 if (sd->dacl == NULL) {
2795 sec_info_sent &= ~DACL_SECURITY_INFORMATION;
2798 fsp->access_mask = FILE_GENERIC_ALL;
2800 status = SMB_VFS_FSET_NT_ACL(fsp, sec_info_sent, sd);
2802 fsp->access_mask = saved_access_mask;
2804 if (!NT_STATUS_IS_OK(status)) {
2809 if ((ea_list != NULL) && (info == FILE_WAS_CREATED)) {
2810 status = set_ea(conn, fsp, fname, ea_list);
2811 if (!NT_STATUS_IS_OK(status)) {
2816 if (!fsp->is_directory && S_ISDIR(sbuf.st_mode)) {
2817 status = NT_STATUS_ACCESS_DENIED;
2821 /* Save the requested allocation size. */
2822 if ((info == FILE_WAS_CREATED) || (info == FILE_WAS_OVERWRITTEN)) {
2824 && (allocation_size > sbuf.st_size)) {
2825 fsp->initial_allocation_size = smb_roundup(
2826 fsp->conn, allocation_size);
2827 if (fsp->is_directory) {
2828 /* Can't set allocation size on a directory. */
2829 status = NT_STATUS_ACCESS_DENIED;
2832 if (vfs_allocate_file_space(
2833 fsp, fsp->initial_allocation_size) == -1) {
2834 status = NT_STATUS_DISK_FULL;
2838 fsp->initial_allocation_size = smb_roundup(
2839 fsp->conn, (SMB_BIG_UINT)sbuf.st_size);
2843 DEBUG(10, ("create_file: info=%d\n", info));
2846 * Set fsp->base_fsp late enough that we can't "goto fail" anymore. In
2847 * the fail: branch we call close_file(fsp, ERROR_CLOSE) which would
2848 * also close fsp->base_fsp which we have to also do explicitly in
2849 * this routine here, as not in all "goto fail:" we have the fsp set
2850 * up already to be initialized with the base_fsp.
2853 fsp->base_fsp = base_fsp;
2856 if (pinfo != NULL) {
2859 if (psbuf != NULL) {
2860 if ((fsp->fh == NULL) || (fsp->fh->fd == -1)) {
2864 SMB_VFS_FSTAT(fsp, psbuf);
2867 return NT_STATUS_OK;
2870 DEBUG(10, ("create_file: %s\n", nt_errstr(status)));
2873 close_file(fsp, ERROR_CLOSE);
2876 if (base_fsp != NULL) {
2877 close_file(base_fsp, ERROR_CLOSE);
2883 NTSTATUS create_file(connection_struct *conn,
2884 struct smb_request *req,
2885 uint16_t root_dir_fid,
2887 uint32_t access_mask,
2888 uint32_t share_access,
2889 uint32_t create_disposition,
2890 uint32_t create_options,
2891 uint32_t file_attributes,
2892 uint32_t oplock_request,
2893 SMB_BIG_UINT allocation_size,
2894 struct security_descriptor *sd,
2895 struct ea_list *ea_list,
2897 files_struct **result,
2899 SMB_STRUCT_STAT *psbuf)
2901 struct case_semantics_state *case_state = NULL;
2902 SMB_STRUCT_STAT sbuf;
2903 int info = FILE_WAS_OPENED;
2904 files_struct *fsp = NULL;
2907 DEBUG(10,("create_file: access_mask = 0x%x "
2908 "file_attributes = 0x%x, share_access = 0x%x, "
2909 "create_disposition = 0x%x create_options = 0x%x "
2910 "oplock_request = 0x%x "
2911 "root_dir_fid = 0x%x, ea_list = 0x%p, sd = 0x%p, "
2913 (unsigned int)access_mask,
2914 (unsigned int)file_attributes,
2915 (unsigned int)share_access,
2916 (unsigned int)create_disposition,
2917 (unsigned int)create_options,
2918 (unsigned int)oplock_request,
2919 (unsigned int)root_dir_fid,
2920 ea_list, sd, fname));
2923 * Get the file name.
2926 if (root_dir_fid != 0) {
2928 * This filename is relative to a directory fid.
2930 char *parent_fname = NULL;
2931 files_struct *dir_fsp = file_fsp(root_dir_fid);
2933 if (dir_fsp == NULL) {
2934 status = NT_STATUS_INVALID_HANDLE;
2938 if (!dir_fsp->is_directory) {
2941 * Check to see if this is a mac fork of some kind.
2944 if (is_ntfs_stream_name(fname)) {
2945 status = NT_STATUS_OBJECT_PATH_NOT_FOUND;
2950 we need to handle the case when we get a
2951 relative open relative to a file and the
2952 pathname is blank - this is a reopen!
2953 (hint from demyn plantenberg)
2956 status = NT_STATUS_INVALID_HANDLE;
2960 if (ISDOT(dir_fsp->fsp_name)) {
2962 * We're at the toplevel dir, the final file name
2963 * must not contain ./, as this is filtered out
2964 * normally by srvstr_get_path and unix_convert
2965 * explicitly rejects paths containing ./.
2967 parent_fname = talloc_strdup(talloc_tos(), "");
2968 if (parent_fname == NULL) {
2969 status = NT_STATUS_NO_MEMORY;
2973 size_t dir_name_len = strlen(dir_fsp->fsp_name);
2976 * Copy in the base directory name.
2979 parent_fname = TALLOC_ARRAY(talloc_tos(), char,
2981 if (parent_fname == NULL) {
2982 status = NT_STATUS_NO_MEMORY;
2985 memcpy(parent_fname, dir_fsp->fsp_name,
2989 * Ensure it ends in a '/'.
2990 * We used TALLOC_SIZE +2 to add space for the '/'.
2994 && (parent_fname[dir_name_len-1] != '\\')
2995 && (parent_fname[dir_name_len-1] != '/')) {
2996 parent_fname[dir_name_len] = '/';
2997 parent_fname[dir_name_len+1] = '\0';
3001 fname = talloc_asprintf(talloc_tos(), "%s%s", parent_fname,
3003 if (fname == NULL) {
3004 status = NT_STATUS_NO_MEMORY;
3010 * Check to see if this is a mac fork of some kind.
3013 if (is_ntfs_stream_name(fname)) {
3014 enum FAKE_FILE_TYPE fake_file_type;
3016 fake_file_type = is_fake_file(fname);
3018 if (fake_file_type != FAKE_FILE_TYPE_NONE) {
3021 * Here we go! support for changing the disk quotas
3024 * We need to fake up to open this MAGIC QUOTA file
3025 * and return a valid FID.
3027 * w2k close this file directly after openening xp
3028 * also tries a QUERY_FILE_INFO on the file and then
3031 status = open_fake_file(conn, fake_file_type, fname,
3033 if (!NT_STATUS_IS_OK(status)) {
3042 if ((req != NULL) && (req->flags2 & FLAGS2_DFS_PATHNAMES)) {
3043 char *resolved_fname;
3045 status = resolve_dfspath(talloc_tos(), conn, true, fname,
3048 if (!NT_STATUS_IS_OK(status)) {
3050 * For PATH_NOT_COVERED we had
3051 * reply_botherror(req, NT_STATUS_PATH_NOT_COVERED,
3052 * ERRSRV, ERRbadpath);
3053 * Need to fix in callers
3057 fname = resolved_fname;
3061 * Check if POSIX semantics are wanted.
3064 if (file_attributes & FILE_FLAG_POSIX_SEMANTICS) {
3065 case_state = set_posix_case_semantics(talloc_tos(), conn);
3066 file_attributes &= ~FILE_FLAG_POSIX_SEMANTICS;
3070 char *converted_fname;
3072 SET_STAT_INVALID(sbuf);
3074 status = unix_convert(talloc_tos(), conn, fname, False,
3075 &converted_fname, NULL, &sbuf);
3076 if (!NT_STATUS_IS_OK(status)) {
3079 fname = converted_fname;
3082 TALLOC_FREE(case_state);
3084 /* All file access must go through check_name() */
3086 status = check_name(conn, fname);
3087 if (!NT_STATUS_IS_OK(status)) {
3091 status = create_file_unixpath(
3092 conn, req, fname, access_mask, share_access,
3093 create_disposition, create_options, file_attributes,
3094 oplock_request, allocation_size, sd, ea_list,
3095 &fsp, &info, &sbuf);
3097 if (!NT_STATUS_IS_OK(status)) {
3102 DEBUG(10, ("create_file: info=%d\n", info));
3105 if (pinfo != NULL) {
3108 if (psbuf != NULL) {
3111 return NT_STATUS_OK;
3114 DEBUG(10, ("create_file: %s\n", nt_errstr(status)));
3117 close_file(fsp, ERROR_CLOSE);