2009-05-28 01:28:34 +02:00
/*
Unix SMB / CIFS implementation .
Core SMB2 server
Copyright ( C ) Stefan Metzmacher 2009
This program is free software ; you can redistribute it and / or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation ; either version 3 of the License , or
( at your option ) any later version .
This program is distributed in the hope that it will be useful ,
but WITHOUT ANY WARRANTY ; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE . See the
GNU General Public License for more details .
You should have received a copy of the GNU General Public License
along with this program . If not , see < http : //www.gnu.org/licenses/>.
*/
# include "includes.h"
2011-03-22 16:57:01 +01:00
# include "smbd/smbd.h"
2009-05-28 01:28:34 +02:00
# include "smbd/globals.h"
2009-08-12 17:52:55 +02:00
# include "../libcli/smb/smb_common.h"
2011-04-28 17:38:09 +02:00
# include "../lib/util/tevent_ntstatus.h"
2011-04-29 23:32:28 +02:00
# include "rpc_server/srv_pipe_hnd.h"
2009-05-28 01:28:34 +02:00
2018-03-21 12:01:05 -07:00
# undef DBGC_CLASS
# define DBGC_CLASS DBGC_SMB2
2009-06-02 17:34:46 +02:00
static struct tevent_req * smbd_smb2_write_send ( TALLOC_CTX * mem_ctx ,
struct tevent_context * ev ,
struct smbd_smb2_request * smb2req ,
2012-06-08 11:47:05 +02:00
struct files_struct * in_fsp ,
2009-06-02 17:34:46 +02:00
DATA_BLOB in_data ,
uint64_t in_offset ,
uint32_t in_flags ) ;
static NTSTATUS smbd_smb2_write_recv ( struct tevent_req * req ,
uint32_t * out_count ) ;
static void smbd_smb2_request_write_done ( struct tevent_req * subreq ) ;
2009-05-28 01:28:34 +02:00
NTSTATUS smbd_smb2_request_process_write ( struct smbd_smb2_request * req )
{
2014-06-12 08:38:48 +02:00
struct smbXsrv_connection * xconn = req - > xconn ;
2011-09-06 14:01:43 +02:00
NTSTATUS status ;
2009-05-28 01:28:34 +02:00
const uint8_t * inbody ;
uint16_t in_data_offset ;
uint32_t in_data_length ;
DATA_BLOB in_data_buffer ;
uint64_t in_offset ;
uint64_t in_file_id_persistent ;
uint64_t in_file_id_volatile ;
2012-06-08 11:47:05 +02:00
struct files_struct * in_fsp ;
2009-05-28 01:28:34 +02:00
uint32_t in_flags ;
2013-11-18 13:45:37 +01:00
size_t in_dyn_len = 0 ;
uint8_t * in_dyn_ptr = NULL ;
2009-06-02 17:34:46 +02:00
struct tevent_req * subreq ;
2009-05-28 01:28:34 +02:00
2011-09-06 14:01:43 +02:00
status = smbd_smb2_request_verify_sizes ( req , 0x31 ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
return smbd_smb2_request_error ( req , status ) ;
2009-05-28 01:28:34 +02:00
}
2012-08-05 15:00:23 +02:00
inbody = SMBD_SMB2_IN_BODY_PTR ( req ) ;
2009-05-28 01:28:34 +02:00
in_data_offset = SVAL ( inbody , 0x02 ) ;
in_data_length = IVAL ( inbody , 0x04 ) ;
in_offset = BVAL ( inbody , 0x08 ) ;
in_file_id_persistent = BVAL ( inbody , 0x10 ) ;
in_file_id_volatile = BVAL ( inbody , 0x18 ) ;
in_flags = IVAL ( inbody , 0x2C ) ;
2012-08-05 15:00:23 +02:00
if ( in_data_offset ! = ( SMB2_HDR_BODY + SMBD_SMB2_IN_BODY_LEN ( req ) ) ) {
2009-05-28 01:28:34 +02:00
return smbd_smb2_request_error ( req , NT_STATUS_INVALID_PARAMETER ) ;
}
2013-11-18 13:45:37 +01:00
if ( req - > smb1req ! = NULL & & req - > smb1req - > unread_bytes > 0 ) {
in_dyn_ptr = NULL ;
in_dyn_len = req - > smb1req - > unread_bytes ;
} else {
in_dyn_ptr = SMBD_SMB2_IN_DYN_PTR ( req ) ;
in_dyn_len = SMBD_SMB2_IN_DYN_LEN ( req ) ;
}
if ( in_data_length > in_dyn_len ) {
2009-05-28 01:28:34 +02:00
return smbd_smb2_request_error ( req , NT_STATUS_INVALID_PARAMETER ) ;
}
/* check the max write size */
2014-05-23 10:22:34 +02:00
if ( in_data_length > xconn - > smb2 . server . max_write ) {
2010-05-05 09:42:45 -07:00
DEBUG ( 2 , ( " smbd_smb2_request_process_write : "
" client ignored max write :%s: 0x%08X: 0x%08X \n " ,
2014-05-23 10:22:34 +02:00
__location__ , in_data_length , xconn - > smb2 . server . max_write ) ) ;
2009-05-28 01:28:34 +02:00
return smbd_smb2_request_error ( req , NT_STATUS_INVALID_PARAMETER ) ;
}
2013-11-18 13:45:37 +01:00
/*
* Note : that in_dyn_ptr is NULL for the recvfile case .
*/
in_data_buffer . data = in_dyn_ptr ;
2009-05-28 01:28:34 +02:00
in_data_buffer . length = in_data_length ;
2012-02-27 17:51:40 -08:00
status = smbd_smb2_request_verify_creditcharge ( req , in_data_length ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
return smbd_smb2_request_error ( req , status ) ;
}
2012-06-08 11:47:05 +02:00
in_fsp = file_fsp_smb2 ( req , in_file_id_persistent , in_file_id_volatile ) ;
if ( in_fsp = = NULL ) {
2009-05-28 01:28:34 +02:00
return smbd_smb2_request_error ( req , NT_STATUS_FILE_CLOSED ) ;
}
2018-12-27 15:18:55 +01:00
subreq = smbd_smb2_write_send ( req , req - > sconn - > ev_ctx ,
2012-06-08 11:47:05 +02:00
req , in_fsp ,
2009-06-02 17:34:46 +02:00
in_data_buffer ,
in_offset ,
in_flags ) ;
if ( subreq = = NULL ) {
return smbd_smb2_request_error ( req , NT_STATUS_NO_MEMORY ) ;
}
tevent_req_set_callback ( subreq , smbd_smb2_request_write_done , req ) ;
2009-06-09 22:34:14 +02:00
2011-11-14 15:42:55 +01:00
return smbd_smb2_request_pending_queue ( req , subreq , 500 ) ;
2009-06-02 17:34:46 +02:00
}
static void smbd_smb2_request_write_done ( struct tevent_req * subreq )
{
struct smbd_smb2_request * req = tevent_req_callback_data ( subreq ,
struct smbd_smb2_request ) ;
DATA_BLOB outbody ;
DATA_BLOB outdyn ;
2009-07-24 10:21:07 -04:00
uint32_t out_count = 0 ;
2009-06-02 17:34:46 +02:00
NTSTATUS status ;
NTSTATUS error ; /* transport error */
status = smbd_smb2_write_recv ( subreq , & out_count ) ;
TALLOC_FREE ( subreq ) ;
2009-05-28 01:28:34 +02:00
if ( ! NT_STATUS_IS_OK ( status ) ) {
2009-06-02 17:34:46 +02:00
error = smbd_smb2_request_error ( req , status ) ;
if ( ! NT_STATUS_IS_OK ( error ) ) {
2014-06-11 12:15:48 +02:00
smbd_server_connection_terminate ( req - > xconn ,
2009-06-02 17:34:46 +02:00
nt_errstr ( error ) ) ;
return ;
}
2009-06-05 14:32:27 +02:00
return ;
2009-05-28 01:28:34 +02:00
}
2013-12-04 14:59:07 +01:00
outbody = smbd_smb2_generate_outbody ( req , 0x10 ) ;
2009-05-28 01:28:34 +02:00
if ( outbody . data = = NULL ) {
2009-06-02 17:34:46 +02:00
error = smbd_smb2_request_error ( req , NT_STATUS_NO_MEMORY ) ;
if ( ! NT_STATUS_IS_OK ( error ) ) {
2014-06-11 12:15:48 +02:00
smbd_server_connection_terminate ( req - > xconn ,
2009-06-02 17:34:46 +02:00
nt_errstr ( error ) ) ;
return ;
}
2009-06-05 14:32:27 +02:00
return ;
2009-05-28 01:28:34 +02:00
}
SSVAL ( outbody . data , 0x00 , 0x10 + 1 ) ; /* struct size */
SSVAL ( outbody . data , 0x02 , 0 ) ; /* reserved */
SIVAL ( outbody . data , 0x04 , out_count ) ; /* count */
SIVAL ( outbody . data , 0x08 , 0 ) ; /* remaining */
SSVAL ( outbody . data , 0x0C , 0 ) ; /* write channel info offset */
SSVAL ( outbody . data , 0x0E , 0 ) ; /* write channel info length */
outdyn = data_blob_const ( NULL , 0 ) ;
2009-06-02 17:34:46 +02:00
error = smbd_smb2_request_done ( req , outbody , & outdyn ) ;
if ( ! NT_STATUS_IS_OK ( error ) ) {
2014-06-11 12:15:48 +02:00
smbd_server_connection_terminate ( req - > xconn , nt_errstr ( error ) ) ;
2009-06-02 17:34:46 +02:00
return ;
}
2009-05-28 01:28:34 +02:00
}
2009-06-02 17:34:46 +02:00
struct smbd_smb2_write_state {
struct smbd_smb2_request * smb2req ;
2011-11-14 09:33:22 +01:00
struct smb_request * smbreq ;
2010-06-09 17:09:11 -07:00
files_struct * fsp ;
bool write_through ;
2009-06-02 17:34:46 +02:00
uint32_t in_length ;
2010-06-09 17:09:11 -07:00
uint64_t in_offset ;
2009-06-02 17:34:46 +02:00
uint32_t out_count ;
} ;
2009-06-05 12:54:22 +02:00
static void smbd_smb2_write_pipe_done ( struct tevent_req * subreq ) ;
2012-07-13 13:39:52 +02:00
static NTSTATUS smb2_write_complete_internal ( struct tevent_req * req ,
ssize_t nwritten , int err ,
bool do_sync )
2010-06-09 17:09:11 -07:00
{
NTSTATUS status ;
struct smbd_smb2_write_state * state = tevent_req_data ( req ,
struct smbd_smb2_write_state ) ;
files_struct * fsp = state - > fsp ;
2012-03-03 07:14:35 +01:00
if ( nwritten = = - 1 ) {
2021-05-07 06:37:25 -04:00
if ( err = = EOVERFLOW & &
is_ntfs_stream_smb_fname ( fsp - > fsp_name ) ) {
status = NT_STATUS_FILE_SYSTEM_LIMITATION ;
} else {
status = map_nt_error_from_unix ( err ) ;
}
2012-03-03 07:14:35 +01:00
2012-06-14 13:28:17 +02:00
DEBUG ( 2 , ( " smb2_write failed: %s, file %s, "
2012-03-03 07:14:35 +01:00
" length=%lu offset=%lu nwritten=-1: %s \n " ,
2012-06-14 13:28:17 +02:00
fsp_fnum_dbg ( fsp ) ,
2012-03-03 07:14:35 +01:00
fsp_str_dbg ( fsp ) ,
( unsigned long ) state - > in_length ,
( unsigned long ) state - > in_offset ,
nt_errstr ( status ) ) ) ;
return status ;
}
2012-06-14 13:28:17 +02:00
DEBUG ( 3 , ( " smb2: %s, file %s, "
2010-06-09 17:09:11 -07:00
" length=%lu offset=%lu wrote=%lu \n " ,
2012-06-14 13:28:17 +02:00
fsp_fnum_dbg ( fsp ) ,
2010-06-09 17:09:11 -07:00
fsp_str_dbg ( fsp ) ,
( unsigned long ) state - > in_length ,
( unsigned long ) state - > in_offset ,
( unsigned long ) nwritten ) ) ;
if ( ( nwritten = = 0 ) & & ( state - > in_length ! = 0 ) ) {
DEBUG ( 5 , ( " smb2: write [%s] disk full \n " ,
fsp_str_dbg ( fsp ) ) ) ;
return NT_STATUS_DISK_FULL ;
}
2012-07-13 13:39:52 +02:00
if ( do_sync ) {
status = sync_file ( fsp - > conn , fsp , state - > write_through ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
DEBUG ( 5 , ( " smb2: sync_file for %s returned %s \n " ,
fsp_str_dbg ( fsp ) ,
nt_errstr ( status ) ) ) ;
return status ;
}
2010-06-09 17:09:11 -07:00
}
state - > out_count = nwritten ;
return NT_STATUS_OK ;
}
2012-07-13 13:39:52 +02:00
NTSTATUS smb2_write_complete ( struct tevent_req * req , ssize_t nwritten , int err )
{
return smb2_write_complete_internal ( req , nwritten , err , true ) ;
}
NTSTATUS smb2_write_complete_nosync ( struct tevent_req * req , ssize_t nwritten ,
int err )
{
return smb2_write_complete_internal ( req , nwritten , err , false ) ;
}
2011-11-14 09:33:22 +01:00
static bool smbd_smb2_write_cancel ( struct tevent_req * req )
{
struct smbd_smb2_write_state * state =
tevent_req_data ( req ,
struct smbd_smb2_write_state ) ;
return cancel_smb2_aio ( state - > smbreq ) ;
}
2009-06-02 17:34:46 +02:00
static struct tevent_req * smbd_smb2_write_send ( TALLOC_CTX * mem_ctx ,
struct tevent_context * ev ,
struct smbd_smb2_request * smb2req ,
2012-06-08 11:47:05 +02:00
struct files_struct * fsp ,
2009-06-02 17:34:46 +02:00
DATA_BLOB in_data ,
uint64_t in_offset ,
uint32_t in_flags )
2009-05-28 01:28:34 +02:00
{
NTSTATUS status ;
2010-06-09 17:09:11 -07:00
struct tevent_req * req = NULL ;
struct smbd_smb2_write_state * state = NULL ;
struct smb_request * smbreq = NULL ;
2012-03-27 11:09:05 +02:00
connection_struct * conn = smb2req - > tcon - > compat ;
2009-05-28 01:28:34 +02:00
ssize_t nwritten ;
struct lock_struct lock ;
2009-06-02 17:34:46 +02:00
req = tevent_req_create ( mem_ctx , & state ,
struct smbd_smb2_write_state ) ;
if ( req = = NULL ) {
return NULL ;
}
state - > smb2req = smb2req ;
2015-05-06 10:42:29 +02:00
if ( smb2req - > xconn - > protocol > = PROTOCOL_SMB3_02 ) {
if ( in_flags & SMB2_WRITEFLAG_WRITE_UNBUFFERED ) {
state - > write_through = true ;
}
}
2011-09-06 13:38:32 +02:00
if ( in_flags & SMB2_WRITEFLAG_WRITE_THROUGH ) {
2010-06-09 17:09:11 -07:00
state - > write_through = true ;
}
2009-06-02 17:34:46 +02:00
state - > in_length = in_data . length ;
2017-10-05 15:59:23 +02:00
state - > in_offset = in_offset ;
2009-06-02 17:34:46 +02:00
state - > out_count = 0 ;
2012-06-14 13:28:17 +02:00
DEBUG ( 10 , ( " smbd_smb2_write: %s - %s \n " ,
fsp_str_dbg ( fsp ) , fsp_fnum_dbg ( fsp ) ) ) ;
2009-05-28 01:28:34 +02:00
2009-06-02 17:34:46 +02:00
smbreq = smbd_smb2_fake_smb_request ( smb2req ) ;
if ( tevent_req_nomem ( smbreq , req ) ) {
return tevent_req_post ( req , ev ) ;
2009-05-28 01:28:34 +02:00
}
2011-11-14 09:33:22 +01:00
state - > smbreq = smbreq ;
2009-05-28 01:28:34 +02:00
2010-06-09 17:09:11 -07:00
state - > fsp = fsp ;
2009-06-05 12:54:22 +02:00
if ( IS_IPC ( smbreq - > conn ) ) {
2010-06-09 17:09:11 -07:00
struct tevent_req * subreq = NULL ;
2009-06-05 12:54:22 +02:00
if ( ! fsp_is_np ( fsp ) ) {
tevent_req_nterror ( req , NT_STATUS_FILE_CLOSED ) ;
return tevent_req_post ( req , ev ) ;
}
2011-12-12 13:47:56 +01:00
subreq = np_write_send ( state , ev ,
2009-06-05 12:54:22 +02:00
fsp - > fake_file_handle ,
in_data . data ,
in_data . length ) ;
if ( tevent_req_nomem ( subreq , req ) ) {
return tevent_req_post ( req , ev ) ;
}
tevent_req_set_callback ( subreq ,
smbd_smb2_write_pipe_done ,
req ) ;
return req ;
2009-06-02 17:34:46 +02:00
}
2009-06-05 12:54:22 +02:00
if ( ! CHECK_WRITE ( fsp ) ) {
tevent_req_nterror ( req , NT_STATUS_ACCESS_DENIED ) ;
2009-06-02 17:34:46 +02:00
return tevent_req_post ( req , ev ) ;
2009-05-28 01:28:34 +02:00
}
2010-06-10 13:20:37 -07:00
/* Try and do an asynchronous write. */
status = schedule_aio_smb2_write ( conn ,
smbreq ,
fsp ,
in_offset ,
in_data ,
state - > write_through ) ;
if ( NT_STATUS_IS_OK ( status ) ) {
/*
2011-11-14 09:33:22 +01:00
* Doing an async write , allow this
* request to be canceled
2010-06-10 13:20:37 -07:00
*/
2011-11-14 09:33:22 +01:00
tevent_req_set_cancel_fn ( req , smbd_smb2_write_cancel ) ;
2010-06-10 13:20:37 -07:00
return req ;
}
if ( ! NT_STATUS_EQUAL ( status , NT_STATUS_RETRY ) ) {
/* Real error in setting up aio. Fail. */
2012-07-13 08:38:07 +02:00
tevent_req_nterror ( req , status ) ;
2010-06-10 13:20:37 -07:00
return tevent_req_post ( req , ev ) ;
}
/* Fallback to synchronous. */
2009-05-28 01:28:34 +02:00
init_strict_lock_struct ( fsp ,
2012-06-08 17:51:47 +02:00
fsp - > op - > global - > open_persistent_id ,
2009-05-28 01:28:34 +02:00
in_offset ,
in_data . length ,
WRITE_LOCK ,
2021-11-16 15:00:03 -08:00
lp_posix_cifsu_locktype ( fsp ) ,
2009-05-28 01:28:34 +02:00
& lock ) ;
2017-07-09 14:34:10 +02:00
if ( ! SMB_VFS_STRICT_LOCK_CHECK ( conn , fsp , & lock ) ) {
2009-06-02 17:34:46 +02:00
tevent_req_nterror ( req , NT_STATUS_FILE_LOCK_CONFLICT ) ;
return tevent_req_post ( req , ev ) ;
2009-05-28 01:28:34 +02:00
}
2013-11-18 13:45:37 +01:00
/*
* Note : in_data . data is NULL for the recvfile case .
*/
2009-05-28 01:28:34 +02:00
nwritten = write_file ( smbreq , fsp ,
( const char * ) in_data . data ,
in_offset ,
in_data . length ) ;
2010-06-09 17:09:11 -07:00
status = smb2_write_complete ( req , nwritten , errno ) ;
2010-03-31 17:40:30 -07:00
2010-06-09 17:09:11 -07:00
DEBUG ( 10 , ( " smb2: write on "
" file %s, offset %.0f, requested %u, written = %u \n " ,
fsp_str_dbg ( fsp ) ,
( double ) in_offset ,
( unsigned int ) in_data . length ,
( unsigned int ) nwritten ) ) ;
2009-05-28 01:28:34 +02:00
if ( ! NT_STATUS_IS_OK ( status ) ) {
2009-06-02 17:34:46 +02:00
tevent_req_nterror ( req , status ) ;
2010-06-09 17:09:11 -07:00
} else {
/* Success. */
tevent_req_done ( req ) ;
2009-05-28 01:28:34 +02:00
}
2009-06-02 17:34:46 +02:00
return tevent_req_post ( req , ev ) ;
}
2009-06-05 12:54:22 +02:00
static void smbd_smb2_write_pipe_done ( struct tevent_req * subreq )
{
struct tevent_req * req = tevent_req_callback_data ( subreq ,
struct tevent_req ) ;
struct smbd_smb2_write_state * state = tevent_req_data ( req ,
struct smbd_smb2_write_state ) ;
NTSTATUS status ;
ssize_t nwritten = - 1 ;
status = np_write_recv ( subreq , & nwritten ) ;
TALLOC_FREE ( subreq ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
2012-05-23 15:24:01 +02:00
NTSTATUS old = status ;
status = nt_status_np_pipe ( old ) ;
2009-06-05 12:54:22 +02:00
tevent_req_nterror ( req , status ) ;
return ;
}
if ( ( nwritten = = 0 & & state - > in_length ! = 0 ) | | ( nwritten < 0 ) ) {
tevent_req_nterror ( req , NT_STATUS_ACCESS_DENIED ) ;
return ;
}
state - > out_count = nwritten ;
tevent_req_done ( req ) ;
}
2009-06-02 17:34:46 +02:00
static NTSTATUS smbd_smb2_write_recv ( struct tevent_req * req ,
uint32_t * out_count )
{
NTSTATUS status ;
struct smbd_smb2_write_state * state = tevent_req_data ( req ,
struct smbd_smb2_write_state ) ;
if ( tevent_req_is_nterror ( req , & status ) ) {
tevent_req_received ( req ) ;
return status ;
}
* out_count = state - > out_count ;
tevent_req_received ( req ) ;
2009-05-28 01:28:34 +02:00
return NT_STATUS_OK ;
}