xref: /freebsd/sys/netsmb/smb_conn.c (revision 1e413cf93298b5b97441a21d9a50fdcd0ee9945e)
1 /*-
2  * Copyright (c) 2000-2001 Boris Popov
3  * All rights reserved.
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  * 1. Redistributions of source code must retain the above copyright
9  *    notice, this list of conditions and the following disclaimer.
10  * 2. Redistributions in binary form must reproduce the above copyright
11  *    notice, this list of conditions and the following disclaimer in the
12  *    documentation and/or other materials provided with the distribution.
13  * 3. All advertising materials mentioning features or use of this software
14  *    must display the following acknowledgement:
15  *    This product includes software developed by Boris Popov.
16  * 4. Neither the name of the author nor the names of any co-contributors
17  *    may be used to endorse or promote products derived from this software
18  *    without specific prior written permission.
19  *
20  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
21  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
22  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
23  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
24  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
25  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
26  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
27  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
28  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
29  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
30  * SUCH DAMAGE.
31  */
32 
33 /*
34  * Connection engine.
35  */
36 
37 #include <sys/cdefs.h>
38 __FBSDID("$FreeBSD$");
39 
40 #include <sys/param.h>
41 #include <sys/systm.h>
42 #include <sys/kernel.h>
43 #include <sys/malloc.h>
44 #include <sys/priv.h>
45 #include <sys/proc.h>
46 #include <sys/lock.h>
47 #include <sys/sysctl.h>
48 #include <sys/socketvar.h>
49 
50 #include <sys/iconv.h>
51 
52 #include <netsmb/smb.h>
53 #include <netsmb/smb_subr.h>
54 #include <netsmb/smb_conn.h>
55 #include <netsmb/smb_tran.h>
56 #include <netsmb/smb_trantcp.h>
57 
58 static struct smb_connobj smb_vclist;
59 static int smb_vcnext = 1;	/* next unique id for VC */
60 
61 SYSCTL_NODE(_net, OID_AUTO, smb, CTLFLAG_RW, NULL, "SMB protocol");
62 
63 MALLOC_DEFINE(M_SMBCONN, "smb_conn", "SMB connection");
64 
65 static void smb_co_init(struct smb_connobj *cp, int level, char *objname,
66 	struct thread *td);
67 static void smb_co_done(struct smb_connobj *cp);
68 static int  smb_co_lockstatus(struct smb_connobj *cp, struct thread *td);
69 
70 static int  smb_vc_disconnect(struct smb_vc *vcp);
71 static void smb_vc_free(struct smb_connobj *cp);
72 static void smb_vc_gone(struct smb_connobj *cp, struct smb_cred *scred);
73 static smb_co_free_t smb_share_free;
74 static smb_co_gone_t smb_share_gone;
75 
76 static int  smb_sysctl_treedump(SYSCTL_HANDLER_ARGS);
77 
78 SYSCTL_PROC(_net_smb, OID_AUTO, treedump, CTLFLAG_RD | CTLTYPE_OPAQUE,
79 	    NULL, 0, smb_sysctl_treedump, "S,treedump", "Requester tree");
80 
81 int
82 smb_sm_init(void)
83 {
84 
85 	smb_co_init(&smb_vclist, SMBL_SM, "smbsm", curthread);
86 	smb_co_unlock(&smb_vclist, 0, curthread);
87 	return 0;
88 }
89 
90 int
91 smb_sm_done(void)
92 {
93 
94 	/* XXX: hold the mutex */
95 	if (smb_vclist.co_usecount > 1) {
96 		SMBERROR("%d connections still active\n", smb_vclist.co_usecount - 1);
97 		return EBUSY;
98 	}
99 	lockmgr(&smb_vclist.co_lock, LK_DRAIN, 0, curthread);
100 	smb_co_done(&smb_vclist);
101 	return 0;
102 }
103 
104 static int
105 smb_sm_lockvclist(int flags, struct thread *td)
106 {
107 
108 	return smb_co_lock(&smb_vclist, flags | LK_CANRECURSE, td);
109 }
110 
111 static void
112 smb_sm_unlockvclist(struct thread *td)
113 {
114 
115 	smb_co_unlock(&smb_vclist, LK_RELEASE, td);
116 }
117 
118 static int
119 smb_sm_lookupint(struct smb_vcspec *vcspec, struct smb_sharespec *shspec,
120 	struct smb_cred *scred,	struct smb_vc **vcpp)
121 {
122 	struct thread *td = scred->scr_td;
123 	struct smb_connobj *scp;
124 	struct smb_vc *vcp;
125 	int exact = 1;
126 	int error;
127 
128 	vcspec->shspec = shspec;
129 	error = ENOENT;
130 	vcp = NULL;
131 	SMBCO_FOREACH(scp, &smb_vclist) {
132 		vcp = (struct smb_vc *)scp;
133 		error = smb_vc_lock(vcp, LK_EXCLUSIVE, td);
134 		if (error)
135 			continue;
136 
137 		if ((vcp->obj.co_flags & SMBV_PRIVATE) ||
138 		    !CONNADDREQ(vcp->vc_paddr, vcspec->sap) ||
139 		    strcmp(vcp->vc_username, vcspec->username) != 0)
140 			goto err1;
141 		if (vcspec->owner != SMBM_ANY_OWNER) {
142 			if (vcp->vc_uid != vcspec->owner)
143 				goto err1;
144 		} else
145 			exact = 0;
146 		if (vcspec->group != SMBM_ANY_GROUP) {
147 			if (vcp->vc_grp != vcspec->group)
148 				goto err1;
149 		} else
150 			exact = 0;
151 		if (vcspec->mode & SMBM_EXACT) {
152 			if (!exact || (vcspec->mode & SMBM_MASK) !=
153 			    vcp->vc_mode)
154 				goto err1;
155 		}
156 		if (smb_vc_access(vcp, scred, vcspec->mode) != 0)
157 			goto err1;
158 		vcspec->ssp = NULL;
159 		if (shspec) {
160 			error = (int)smb_vc_lookupshare(vcp, shspec, scred,
161 			    &vcspec->ssp);
162 			if (error)
163 				goto fail;
164 		}
165 		error = 0;
166 		break;
167 	err1:
168 		error = 1;
169 	fail:
170 		smb_vc_unlock(vcp, 0, td);
171 	}
172 	if (vcp) {
173 		smb_vc_ref(vcp);
174 		*vcpp = vcp;
175 	}
176 	return (error);
177 }
178 
179 int
180 smb_sm_lookup(struct smb_vcspec *vcspec, struct smb_sharespec *shspec,
181 	struct smb_cred *scred,	struct smb_vc **vcpp)
182 {
183 	struct thread *td = scred->scr_td;
184 	struct smb_vc *vcp;
185 	struct smb_share *ssp = NULL;
186 	int error;
187 
188 	*vcpp = vcp = NULL;
189 
190 	error = smb_sm_lockvclist(LK_EXCLUSIVE, td);
191 	if (error)
192 		return error;
193 	error = smb_sm_lookupint(vcspec, shspec, scred, vcpp);
194 	if (error == 0 || (vcspec->flags & SMBV_CREATE) == 0) {
195 		smb_sm_unlockvclist(td);
196 		return error;
197 	}
198 	error = smb_sm_lookupint(vcspec, NULL, scred, &vcp);
199 	if (error) {
200 		error = smb_vc_create(vcspec, scred, &vcp);
201 		if (error)
202 			goto out;
203 		error = smb_vc_connect(vcp, scred);
204 		if (error)
205 			goto out;
206 	}
207 	if (shspec == NULL)
208 		goto out;
209 	error = smb_share_create(vcp, shspec, scred, &ssp);
210 	if (error)
211 		goto out;
212 	error = smb_smb_treeconnect(ssp, scred);
213 	if (error == 0)
214 		vcspec->ssp = ssp;
215 	else
216 		smb_share_put(ssp, scred);
217 out:
218 	smb_sm_unlockvclist(td);
219 	if (error == 0)
220 		*vcpp = vcp;
221 	else if (vcp)
222 		smb_vc_put(vcp, scred);
223 	return error;
224 }
225 
226 /*
227  * Common code for connection object
228  */
229 static void
230 smb_co_init(struct smb_connobj *cp, int level, char *objname, struct thread *td)
231 {
232 	SLIST_INIT(&cp->co_children);
233 	smb_sl_init(&cp->co_interlock, objname);
234 	lockinit(&cp->co_lock, PZERO, objname, 0, 0);
235 	cp->co_level = level;
236 	cp->co_usecount = 1;
237 	if (smb_co_lock(cp, LK_EXCLUSIVE, td) != 0)
238 	    panic("smb_co_init: lock failed");
239 }
240 
241 static void
242 smb_co_done(struct smb_connobj *cp)
243 {
244 	smb_sl_destroy(&cp->co_interlock);
245 	lockmgr(&cp->co_lock, LK_RELEASE, 0, curthread);
246 	lockdestroy(&cp->co_lock);
247 }
248 
249 static void
250 smb_co_gone(struct smb_connobj *cp, struct smb_cred *scred)
251 {
252 	struct smb_connobj *parent;
253 
254 	if (cp->co_gone)
255 		cp->co_gone(cp, scred);
256 	parent = cp->co_parent;
257 	if (parent) {
258 		smb_co_lock(parent, LK_EXCLUSIVE, scred->scr_td);
259 		SLIST_REMOVE(&parent->co_children, cp, smb_connobj, co_next);
260 		smb_co_put(parent, scred);
261 	}
262 	if (cp->co_free)
263 		cp->co_free(cp);
264 }
265 
266 void
267 smb_co_ref(struct smb_connobj *cp)
268 {
269 
270 	SMB_CO_LOCK(cp);
271 	cp->co_usecount++;
272 	SMB_CO_UNLOCK(cp);
273 }
274 
275 void
276 smb_co_rele(struct smb_connobj *cp, struct smb_cred *scred)
277 {
278 	struct thread *td = scred->scr_td;
279 
280 	SMB_CO_LOCK(cp);
281 	if (cp->co_usecount > 1) {
282 		cp->co_usecount--;
283 		SMB_CO_UNLOCK(cp);
284 		return;
285 	}
286 	if (cp->co_usecount == 0) {
287 		SMBERROR("negative use_count for object %d", cp->co_level);
288 		SMB_CO_UNLOCK(cp);
289 		return;
290 	}
291 	cp->co_usecount--;
292 	cp->co_flags |= SMBO_GONE;
293 
294 	lockmgr(&cp->co_lock, LK_DRAIN | LK_INTERLOCK, &cp->co_interlock, td);
295 	smb_co_gone(cp, scred);
296 }
297 
298 int
299 smb_co_get(struct smb_connobj *cp, int flags, struct smb_cred *scred)
300 {
301 	int error;
302 
303 	if ((flags & LK_INTERLOCK) == 0)
304 		SMB_CO_LOCK(cp);
305 	cp->co_usecount++;
306 	error = smb_co_lock(cp, flags | LK_INTERLOCK, scred->scr_td);
307 	if (error) {
308 		SMB_CO_LOCK(cp);
309 		cp->co_usecount--;
310 		SMB_CO_UNLOCK(cp);
311 		return error;
312 	}
313 	return 0;
314 }
315 
316 void
317 smb_co_put(struct smb_connobj *cp, struct smb_cred *scred)
318 {
319 	struct thread *td = scred->scr_td;
320 
321 	SMB_CO_LOCK(cp);
322 	if (cp->co_usecount > 1) {
323 		cp->co_usecount--;
324 	} else if (cp->co_usecount == 1) {
325 		cp->co_usecount--;
326 		cp->co_flags |= SMBO_GONE;
327 	} else {
328 		SMBERROR("negative usecount");
329 	}
330 	lockmgr(&cp->co_lock, LK_RELEASE | LK_INTERLOCK, &cp->co_interlock, td);
331 	if ((cp->co_flags & SMBO_GONE) == 0)
332 		return;
333 	lockmgr(&cp->co_lock, LK_DRAIN, NULL, td);
334 	smb_co_gone(cp, scred);
335 }
336 
337 int
338 smb_co_lockstatus(struct smb_connobj *cp, struct thread *td)
339 {
340 	return lockstatus(&cp->co_lock, td);
341 }
342 
343 int
344 smb_co_lock(struct smb_connobj *cp, int flags, struct thread *td)
345 {
346 
347 	if (cp->co_flags & SMBO_GONE)
348 		return EINVAL;
349 	if ((flags & LK_TYPE_MASK) == 0)
350 		flags |= LK_EXCLUSIVE;
351 	if (smb_co_lockstatus(cp, td) == LK_EXCLUSIVE &&
352 	    (flags & LK_CANRECURSE) == 0) {
353 		SMBERROR("recursive lock for object %d\n", cp->co_level);
354 		return 0;
355 	}
356 	return lockmgr(&cp->co_lock, flags, &cp->co_interlock, td);
357 }
358 
359 void
360 smb_co_unlock(struct smb_connobj *cp, int flags, struct thread *td)
361 {
362 	(void)lockmgr(&cp->co_lock, flags | LK_RELEASE, &cp->co_interlock, td);
363 }
364 
365 static void
366 smb_co_addchild(struct smb_connobj *parent, struct smb_connobj *child)
367 {
368 	KASSERT(smb_co_lockstatus(parent, curthread) == LK_EXCLUSIVE, ("smb_co_addchild: parent not locked"));
369 	KASSERT(smb_co_lockstatus(child, curthread) == LK_EXCLUSIVE, ("smb_co_addchild: child not locked"));
370 
371 	smb_co_ref(parent);
372 	SLIST_INSERT_HEAD(&parent->co_children, child, co_next);
373 	child->co_parent = parent;
374 }
375 
376 /*
377  * Session implementation
378  */
379 
380 int
381 smb_vc_create(struct smb_vcspec *vcspec,
382 	struct smb_cred *scred, struct smb_vc **vcpp)
383 {
384 	struct smb_vc *vcp;
385 	struct thread *td = scred->scr_td;
386 	struct ucred *cred = scred->scr_cred;
387 	uid_t uid = vcspec->owner;
388 	gid_t gid = vcspec->group;
389 	uid_t realuid = cred->cr_uid;
390 	char *domain = vcspec->domain;
391 	int error, isroot;
392 
393 	isroot = smb_suser(cred) == 0;
394 	/*
395 	 * Only superuser can create VCs with different uid and gid
396 	 */
397 	if (uid != SMBM_ANY_OWNER && uid != realuid && !isroot)
398 		return EPERM;
399 	if (gid != SMBM_ANY_GROUP && !groupmember(gid, cred) && !isroot)
400 		return EPERM;
401 
402 	vcp = smb_zmalloc(sizeof(*vcp), M_SMBCONN, M_WAITOK);
403 	smb_co_init(VCTOCP(vcp), SMBL_VC, "smb_vc", td);
404 	vcp->obj.co_free = smb_vc_free;
405 	vcp->obj.co_gone = smb_vc_gone;
406 	vcp->vc_number = smb_vcnext++;
407 	vcp->vc_timo = SMB_DEFRQTIMO;
408 	vcp->vc_smbuid = SMB_UID_UNKNOWN;
409 	vcp->vc_mode = vcspec->rights & SMBM_MASK;
410 	vcp->obj.co_flags = vcspec->flags & (SMBV_PRIVATE | SMBV_SINGLESHARE);
411 	vcp->vc_tdesc = &smb_tran_nbtcp_desc;
412 	vcp->vc_seqno = 0;
413 	vcp->vc_mackey = NULL;
414 	vcp->vc_mackeylen = 0;
415 
416 	if (uid == SMBM_ANY_OWNER)
417 		uid = realuid;
418 	if (gid == SMBM_ANY_GROUP)
419 		gid = cred->cr_groups[0];
420 	vcp->vc_uid = uid;
421 	vcp->vc_grp = gid;
422 
423 	smb_sl_init(&vcp->vc_stlock, "vcstlock");
424 	error = ENOMEM;
425 
426 	vcp->vc_paddr = sodupsockaddr(vcspec->sap, M_WAITOK);
427 	if (vcp->vc_paddr == NULL)
428 		goto fail;
429 	vcp->vc_laddr = sodupsockaddr(vcspec->lap, M_WAITOK);
430 	if (vcp->vc_laddr == NULL)
431 		goto fail;
432 	vcp->vc_pass = smb_strdup(vcspec->pass);
433 	if (vcp->vc_pass == NULL)
434 		goto fail;
435 	vcp->vc_domain = smb_strdup((domain && domain[0]) ? domain :
436 	    "NODOMAIN");
437 	if (vcp->vc_domain == NULL)
438 		goto fail;
439 	vcp->vc_srvname = smb_strdup(vcspec->srvname);
440 	if (vcp->vc_srvname == NULL)
441 		goto fail;
442 	vcp->vc_username = smb_strdup(vcspec->username);
443 	if (vcp->vc_username == NULL)
444 		goto fail;
445 	error = (int)iconv_open("tolower", vcspec->localcs, &vcp->vc_tolower);
446 	if (error)
447 		goto fail;
448 	error = (int)iconv_open("toupper", vcspec->localcs, &vcp->vc_toupper);
449 	if (error)
450 		goto fail;
451 	if (vcspec->servercs[0]) {
452 		error = (int)iconv_open(vcspec->servercs, vcspec->localcs,
453 		    &vcp->vc_toserver);
454 		if (error)
455 			goto fail;
456 		error = (int)iconv_open(vcspec->localcs, vcspec->servercs,
457 		    &vcp->vc_tolocal);
458 		if (error)
459 			goto fail;
460 	}
461 	error = (int)smb_iod_create(vcp);
462 	if (error)
463 		goto fail;
464 	*vcpp = vcp;
465 	smb_co_addchild(&smb_vclist, VCTOCP(vcp));
466 	return (0);
467 
468  fail:
469 	smb_vc_put(vcp, scred);
470 	return (error);
471 }
472 
473 static void
474 smb_vc_free(struct smb_connobj *cp)
475 {
476 	struct smb_vc *vcp = CPTOVC(cp);
477 
478 	if (vcp->vc_iod)
479 		smb_iod_destroy(vcp->vc_iod);
480 	SMB_STRFREE(vcp->vc_username);
481 	SMB_STRFREE(vcp->vc_srvname);
482 	SMB_STRFREE(vcp->vc_pass);
483 	SMB_STRFREE(vcp->vc_domain);
484 	if (vcp->vc_mackey)
485 		free(vcp->vc_mackey, M_SMBTEMP);
486 	if (vcp->vc_paddr)
487 		free(vcp->vc_paddr, M_SONAME);
488 	if (vcp->vc_laddr)
489 		free(vcp->vc_laddr, M_SONAME);
490 	if (vcp->vc_tolower)
491 		iconv_close(vcp->vc_tolower);
492 	if (vcp->vc_toupper)
493 		iconv_close(vcp->vc_toupper);
494 	if (vcp->vc_tolocal)
495 		iconv_close(vcp->vc_tolocal);
496 	if (vcp->vc_toserver)
497 		iconv_close(vcp->vc_toserver);
498 	smb_co_done(VCTOCP(vcp));
499 	smb_sl_destroy(&vcp->vc_stlock);
500 	free(vcp, M_SMBCONN);
501 }
502 
503 /*
504  * Called when use count of VC dropped to zero.
505  * VC should be locked on enter with LK_DRAIN.
506  */
507 static void
508 smb_vc_gone(struct smb_connobj *cp, struct smb_cred *scred)
509 {
510 	struct smb_vc *vcp = CPTOVC(cp);
511 
512 	smb_vc_disconnect(vcp);
513 }
514 
515 void
516 smb_vc_ref(struct smb_vc *vcp)
517 {
518 	smb_co_ref(VCTOCP(vcp));
519 }
520 
521 void
522 smb_vc_rele(struct smb_vc *vcp, struct smb_cred *scred)
523 {
524 	smb_co_rele(VCTOCP(vcp), scred);
525 }
526 
527 int
528 smb_vc_get(struct smb_vc *vcp, int flags, struct smb_cred *scred)
529 {
530 	return smb_co_get(VCTOCP(vcp), flags, scred);
531 }
532 
533 void
534 smb_vc_put(struct smb_vc *vcp, struct smb_cred *scred)
535 {
536 	smb_co_put(VCTOCP(vcp), scred);
537 }
538 
539 int
540 smb_vc_lock(struct smb_vc *vcp, int flags, struct thread *td)
541 {
542 	return smb_co_lock(VCTOCP(vcp), flags, td);
543 }
544 
545 void
546 smb_vc_unlock(struct smb_vc *vcp, int flags, struct thread *td)
547 {
548 	smb_co_unlock(VCTOCP(vcp), flags, td);
549 }
550 
551 int
552 smb_vc_access(struct smb_vc *vcp, struct smb_cred *scred, mode_t mode)
553 {
554 	struct ucred *cred = scred->scr_cred;
555 
556 	if (smb_suser(cred) == 0 || cred->cr_uid == vcp->vc_uid)
557 		return 0;
558 	mode >>= 3;
559 	if (!groupmember(vcp->vc_grp, cred))
560 		mode >>= 3;
561 	return (vcp->vc_mode & mode) == mode ? 0 : EACCES;
562 }
563 
564 static int
565 smb_vc_cmpshare(struct smb_share *ssp, struct smb_sharespec *dp)
566 {
567 	int exact = 1;
568 
569 	if (strcmp(ssp->ss_name, dp->name) != 0)
570 		return 1;
571 	if (dp->owner != SMBM_ANY_OWNER) {
572 		if (ssp->ss_uid != dp->owner)
573 			return 1;
574 	} else
575 		exact = 0;
576 	if (dp->group != SMBM_ANY_GROUP) {
577 		if (ssp->ss_grp != dp->group)
578 			return 1;
579 	} else
580 		exact = 0;
581 
582 	if (dp->mode & SMBM_EXACT) {
583 		if (!exact)
584 			return 1;
585 		return (dp->mode & SMBM_MASK) == ssp->ss_mode ? 0 : 1;
586 	}
587 	if (smb_share_access(ssp, dp->scred, dp->mode) != 0)
588 		return 1;
589 	return 0;
590 }
591 
592 /*
593  * Lookup share in the given VC. Share referenced and locked on return.
594  * VC expected to be locked on entry and will be left locked on exit.
595  */
596 int
597 smb_vc_lookupshare(struct smb_vc *vcp, struct smb_sharespec *dp,
598 	struct smb_cred *scred,	struct smb_share **sspp)
599 {
600 	struct thread *td = scred->scr_td;
601 	struct smb_connobj *scp = NULL;
602 	struct smb_share *ssp = NULL;
603 	int error;
604 
605 	*sspp = NULL;
606 	dp->scred = scred;
607 	SMBCO_FOREACH(scp, VCTOCP(vcp)) {
608 		ssp = (struct smb_share *)scp;
609 		error = smb_share_lock(ssp, LK_EXCLUSIVE, td);
610 		if (error)
611 			continue;
612 		if (smb_vc_cmpshare(ssp, dp) == 0)
613 			break;
614 		smb_share_unlock(ssp, 0, td);
615 	}
616 	if (ssp) {
617 		smb_share_ref(ssp);
618 		*sspp = ssp;
619 		error = 0;
620 	} else
621 		error = ENOENT;
622 	return error;
623 }
624 
625 int
626 smb_vc_connect(struct smb_vc *vcp, struct smb_cred *scred)
627 {
628 
629 	return smb_iod_request(vcp->vc_iod, SMBIOD_EV_CONNECT | SMBIOD_EV_SYNC, NULL);
630 }
631 
632 /*
633  * Destroy VC to server, invalidate shares linked with it.
634  * Transport should be locked on entry.
635  */
636 int
637 smb_vc_disconnect(struct smb_vc *vcp)
638 {
639 
640 	smb_iod_request(vcp->vc_iod, SMBIOD_EV_DISCONNECT | SMBIOD_EV_SYNC, NULL);
641 	return 0;
642 }
643 
644 static char smb_emptypass[] = "";
645 
646 const char *
647 smb_vc_getpass(struct smb_vc *vcp)
648 {
649 	if (vcp->vc_pass)
650 		return vcp->vc_pass;
651 	return smb_emptypass;
652 }
653 
654 static int
655 smb_vc_getinfo(struct smb_vc *vcp, struct smb_vc_info *vip)
656 {
657 	bzero(vip, sizeof(struct smb_vc_info));
658 	vip->itype = SMB_INFO_VC;
659 	vip->usecount = vcp->obj.co_usecount;
660 	vip->uid = vcp->vc_uid;
661 	vip->gid = vcp->vc_grp;
662 	vip->mode = vcp->vc_mode;
663 	vip->flags = vcp->obj.co_flags;
664 	vip->sopt = vcp->vc_sopt;
665 	vip->iodstate = vcp->vc_iod->iod_state;
666 	bzero(&vip->sopt.sv_skey, sizeof(vip->sopt.sv_skey));
667 	snprintf(vip->srvname, sizeof(vip->srvname), "%s", vcp->vc_srvname);
668 	snprintf(vip->vcname, sizeof(vip->vcname), "%s", vcp->vc_username);
669 	return 0;
670 }
671 
672 u_short
673 smb_vc_nextmid(struct smb_vc *vcp)
674 {
675 	u_short r;
676 
677 	SMB_CO_LOCK(&vcp->obj);
678 	r = vcp->vc_mid++;
679 	SMB_CO_UNLOCK(&vcp->obj);
680 	return r;
681 }
682 
683 /*
684  * Share implementation
685  */
686 /*
687  * Allocate share structure and attach it to the given VC
688  * Connection expected to be locked on entry. Share will be returned
689  * in locked state.
690  */
691 int
692 smb_share_create(struct smb_vc *vcp, struct smb_sharespec *shspec,
693 	struct smb_cred *scred, struct smb_share **sspp)
694 {
695 	struct smb_share *ssp;
696 	struct thread *td = scred->scr_td;
697 	struct ucred *cred = scred->scr_cred;
698 	uid_t realuid = cred->cr_uid;
699 	uid_t uid = shspec->owner;
700 	gid_t gid = shspec->group;
701 	int error, isroot;
702 
703 	isroot = smb_suser(cred) == 0;
704 	/*
705 	 * Only superuser can create shares with different uid and gid
706 	 */
707 	if (uid != SMBM_ANY_OWNER && uid != realuid && !isroot)
708 		return EPERM;
709 	if (gid != SMBM_ANY_GROUP && !groupmember(gid, cred) && !isroot)
710 		return EPERM;
711 	error = smb_vc_lookupshare(vcp, shspec, scred, &ssp);
712 	if (!error) {
713 		smb_share_put(ssp, scred);
714 		return EEXIST;
715 	}
716 	if (uid == SMBM_ANY_OWNER)
717 		uid = realuid;
718 	if (gid == SMBM_ANY_GROUP)
719 		gid = cred->cr_groups[0];
720 	ssp = smb_zmalloc(sizeof(*ssp), M_SMBCONN, M_WAITOK);
721 	smb_co_init(SSTOCP(ssp), SMBL_SHARE, "smbss", td);
722 	ssp->obj.co_free = smb_share_free;
723 	ssp->obj.co_gone = smb_share_gone;
724 	smb_sl_init(&ssp->ss_stlock, "ssstlock");
725 	ssp->ss_name = smb_strdup(shspec->name);
726 	if (shspec->pass && shspec->pass[0])
727 		ssp->ss_pass = smb_strdup(shspec->pass);
728 	ssp->ss_type = shspec->stype;
729 	ssp->ss_tid = SMB_TID_UNKNOWN;
730 	ssp->ss_uid = uid;
731 	ssp->ss_grp = gid;
732 	ssp->ss_mode = shspec->rights & SMBM_MASK;
733 	smb_co_addchild(VCTOCP(vcp), SSTOCP(ssp));
734 	*sspp = ssp;
735 	return 0;
736 }
737 
738 static void
739 smb_share_free(struct smb_connobj *cp)
740 {
741 	struct smb_share *ssp = CPTOSS(cp);
742 
743 	SMB_STRFREE(ssp->ss_name);
744 	SMB_STRFREE(ssp->ss_pass);
745 	smb_sl_destroy(&ssp->ss_stlock);
746 	smb_co_done(SSTOCP(ssp));
747 	free(ssp, M_SMBCONN);
748 }
749 
750 static void
751 smb_share_gone(struct smb_connobj *cp, struct smb_cred *scred)
752 {
753 	struct smb_share *ssp = CPTOSS(cp);
754 
755 	smb_smb_treedisconnect(ssp, scred);
756 }
757 
758 void
759 smb_share_ref(struct smb_share *ssp)
760 {
761 	smb_co_ref(SSTOCP(ssp));
762 }
763 
764 void
765 smb_share_rele(struct smb_share *ssp, struct smb_cred *scred)
766 {
767 	smb_co_rele(SSTOCP(ssp), scred);
768 }
769 
770 int
771 smb_share_get(struct smb_share *ssp, int flags, struct smb_cred *scred)
772 {
773 	return smb_co_get(SSTOCP(ssp), flags, scred);
774 }
775 
776 void
777 smb_share_put(struct smb_share *ssp, struct smb_cred *scred)
778 {
779 	smb_co_put(SSTOCP(ssp), scred);
780 }
781 
782 int
783 smb_share_lock(struct smb_share *ssp, int flags, struct thread *td)
784 {
785 	return smb_co_lock(SSTOCP(ssp), flags, td);
786 }
787 
788 void
789 smb_share_unlock(struct smb_share *ssp, int flags, struct thread *td)
790 {
791 	smb_co_unlock(SSTOCP(ssp), flags, td);
792 }
793 
794 int
795 smb_share_access(struct smb_share *ssp, struct smb_cred *scred, mode_t mode)
796 {
797 	struct ucred *cred = scred->scr_cred;
798 
799 	if (smb_suser(cred) == 0 || cred->cr_uid == ssp->ss_uid)
800 		return 0;
801 	mode >>= 3;
802 	if (!groupmember(ssp->ss_grp, cred))
803 		mode >>= 3;
804 	return (ssp->ss_mode & mode) == mode ? 0 : EACCES;
805 }
806 
807 void
808 smb_share_invalidate(struct smb_share *ssp)
809 {
810 	ssp->ss_tid = SMB_TID_UNKNOWN;
811 }
812 
813 int
814 smb_share_valid(struct smb_share *ssp)
815 {
816 	return ssp->ss_tid != SMB_TID_UNKNOWN &&
817 	    ssp->ss_vcgenid == SSTOVC(ssp)->vc_genid;
818 }
819 
820 const char*
821 smb_share_getpass(struct smb_share *ssp)
822 {
823 	struct smb_vc *vcp;
824 
825 	if (ssp->ss_pass)
826 		return ssp->ss_pass;
827 	vcp = SSTOVC(ssp);
828 	if (vcp->vc_pass)
829 		return vcp->vc_pass;
830 	return smb_emptypass;
831 }
832 
833 static int
834 smb_share_getinfo(struct smb_share *ssp, struct smb_share_info *sip)
835 {
836 	bzero(sip, sizeof(struct smb_share_info));
837 	sip->itype = SMB_INFO_SHARE;
838 	sip->usecount = ssp->obj.co_usecount;
839 	sip->tid  = ssp->ss_tid;
840 	sip->type= ssp->ss_type;
841 	sip->uid = ssp->ss_uid;
842 	sip->gid = ssp->ss_grp;
843 	sip->mode= ssp->ss_mode;
844 	sip->flags = ssp->obj.co_flags;
845 	snprintf(sip->sname, sizeof(sip->sname), "%s", ssp->ss_name);
846 	return 0;
847 }
848 
849 /*
850  * Dump an entire tree into sysctl call
851  */
852 static int
853 smb_sysctl_treedump(SYSCTL_HANDLER_ARGS)
854 {
855 	struct thread *td = req->td;
856 	struct smb_cred scred;
857 	struct smb_connobj *scp1, *scp2;
858 	struct smb_vc *vcp;
859 	struct smb_share *ssp;
860 	struct smb_vc_info vci;
861 	struct smb_share_info ssi;
862 	int error, itype;
863 
864 	smb_makescred(&scred, td, td->td_ucred);
865 	error = sysctl_wire_old_buffer(req, 0);
866 	if (error)
867 		return (error);
868 	error = smb_sm_lockvclist(LK_SHARED, td);
869 	if (error)
870 		return error;
871 	SMBCO_FOREACH(scp1, &smb_vclist) {
872 		vcp = (struct smb_vc *)scp1;
873 		error = smb_vc_lock(vcp, LK_SHARED, td);
874 		if (error)
875 			continue;
876 		smb_vc_getinfo(vcp, &vci);
877 		error = SYSCTL_OUT(req, &vci, sizeof(struct smb_vc_info));
878 		if (error) {
879 			smb_vc_unlock(vcp, 0, td);
880 			break;
881 		}
882 		SMBCO_FOREACH(scp2, VCTOCP(vcp)) {
883 			ssp = (struct smb_share *)scp2;
884 			error = smb_share_lock(ssp, LK_SHARED, td);
885 			if (error) {
886 				error = 0;
887 				continue;
888 			}
889 			smb_share_getinfo(ssp, &ssi);
890 			smb_share_unlock(ssp, 0, td);
891 			error = SYSCTL_OUT(req, &ssi, sizeof(struct smb_share_info));
892 			if (error)
893 				break;
894 		}
895 		smb_vc_unlock(vcp, 0, td);
896 		if (error)
897 			break;
898 	}
899 	if (!error) {
900 		itype = SMB_INFO_NONE;
901 		error = SYSCTL_OUT(req, &itype, sizeof(itype));
902 	}
903 	smb_sm_unlockvclist(td);
904 	return error;
905 }
906