xref: /illumos-gate/usr/src/uts/common/fs/smbsrv/smb_server.c (revision 856399cf160942495309c59ac7a9541834573cd3)
1 /*
2  * CDDL HEADER START
3  *
4  * The contents of this file are subject to the terms of the
5  * Common Development and Distribution License (the "License").
6  * You may not use this file except in compliance with the License.
7  *
8  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
9  * or http://www.opensolaris.org/os/licensing.
10  * See the License for the specific language governing permissions
11  * and limitations under the License.
12  *
13  * When distributing Covered Code, include this CDDL HEADER in each
14  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
15  * If applicable, add the following below this CDDL HEADER, with the
16  * fields enclosed by brackets "[]" replaced with your own identifying
17  * information: Portions Copyright [yyyy] [name of copyright owner]
18  *
19  * CDDL HEADER END
20  */
21 /*
22  * Copyright (c) 2008, 2010, Oracle and/or its affiliates. All rights reserved.
23  * Copyright 2012 Nexenta Systems, Inc.  All rights reserved.
24  */
25 
26 /*
27  * General Structures Layout
28  * -------------------------
29  *
30  * This is a simplified diagram showing the relationship between most of the
31  * main structures.
32  *
33  * +-------------------+
34  * |     SMB_SERVER    |
35  * +-------------------+
36  *          |
37  *          |
38  *          v
39  * +-------------------+       +-------------------+      +-------------------+
40  * |     SESSION       |<----->|     SESSION       |......|      SESSION      |
41  * +-------------------+       +-------------------+      +-------------------+
42  *          |
43  *          |
44  *          v
45  * +-------------------+       +-------------------+      +-------------------+
46  * |       USER        |<----->|       USER        |......|       USER        |
47  * +-------------------+       +-------------------+      +-------------------+
48  *          |
49  *          |
50  *          v
51  * +-------------------+       +-------------------+      +-------------------+
52  * |       TREE        |<----->|       TREE        |......|       TREE        |
53  * +-------------------+       +-------------------+      +-------------------+
54  *      |         |
55  *      |         |
56  *      |         v
57  *      |     +-------+       +-------+      +-------+
58  *      |     | OFILE |<----->| OFILE |......| OFILE |
59  *      |     +-------+       +-------+      +-------+
60  *      |
61  *      |
62  *      v
63  *  +-------+       +------+      +------+
64  *  | ODIR  |<----->| ODIR |......| ODIR |
65  *  +-------+       +------+      +------+
66  *
67  *
68  * Module Interface Overview
69  * -------------------------
70  *
71  *
72  *	    +===================================+
73  *	    |		 smbd daemon		|
74  *	    +===================================+
75  *	      |		     |		      ^
76  *	      |		     |		      |
77  * User	      |		     |		      |
78  * -----------|--------------|----------------|--------------------------------
79  * Kernel     |		     |		      |
80  *            |		     |		      |
81  *	      |		     |		      |
82  *  +=========|==============|================|=================+
83  *  |	      v		     v		      |			|
84  *  | +-----------+ +--------------------+ +------------------+ |
85  *  | |     IO    | | Kernel Door Server | | User Door Servers|	|
86  *  | | Interface | |     Interface      | |   Interface      | |
87  *  | +-----------+ +--------------------+ +------------------+ |
88  *  |		|	     |		      ^		^	|
89  *  |		v	     v		      |		|	|    +=========+
90  *  |	     +-----------------------------------+	|	|    |	       |
91  *  |	     + SMB Server Management (this file) |<------------------|	 ZFS   |
92  *  |	     +-----------------------------------+	|	|    |	       |
93  *  |							|	|    |  Module |
94  *  |	     +-----------------------------------+	|	|    |	       |
95  *  |	     +     SMB Server Internal Layers    |------+	|    +=========+
96  *  |	     +-----------------------------------+		|
97  *  |								|
98  *  |								|
99  *  +===========================================================+
100  *
101  *
102  * Server State Machine
103  * --------------------
104  *                                  |
105  *                                  | T0
106  *                                  |
107  *                                  v
108  *                    +-----------------------------+
109  *		      |   SMB_SERVER_STATE_CREATED  |
110  *		      +-----------------------------+
111  *				    |
112  *				    | T1
113  *				    |
114  *				    v
115  *		      +-----------------------------+
116  *		      | SMB_SERVER_STATE_CONFIGURED |
117  *		      +-----------------------------+
118  *				    |
119  *				    | T2
120  *				    |
121  *				    v
122  *		      +-----------------------------+
123  *		      |  SMB_SERVER_STATE_RUNNING / |
124  *		      |  SMB_SERVER_STATE_STOPPING  |
125  *		      +-----------------------------+
126  *				    |
127  *				    | T3
128  *				    |
129  *				    v
130  *		      +-----------------------------+
131  *		      |  SMB_SERVER_STATE_DELETING  |
132  *                    +-----------------------------+
133  *				    |
134  *				    |
135  *				    |
136  *				    v
137  *
138  * States
139  * ------
140  *
141  * SMB_SERVER_STATE_CREATED
142  *
143  *    This is the state of the server just after creation.
144  *
145  * SMB_SERVER_STATE_CONFIGURED
146  *
147  *    The server has been configured.
148  *
149  * SMB_SERVER_STATE_RUNNING
150  *
151  *    The server has been started. While in this state the threads listening on
152  *    the sockets are started.
153  *
154  *    When a client establishes a connection the thread listening dispatches
155  *    a task with the new session as an argument. If the dispatch fails the new
156  *    session context is destroyed.
157  *
158  * SMB_SERVER_STATE_STOPPING
159  *
160  *    The threads listening on the NBT and TCP sockets are being terminated.
161  *
162  *
163  * Transitions
164  * -----------
165  *
166  * Transition T0
167  *
168  *    The daemon smbd triggers its creation by opening the smbsrv device. If
169  *    the zone where the daemon lives doesn't have an smb server yet it is
170  *    created.
171  *
172  *		smb_drv_open() --> smb_server_create()
173  *
174  * Transition T1
175  *
176  *    This transition occurs in smb_server_configure(). It is triggered by the
177  *    daemon through an Ioctl.
178  *
179  *	smb_drv_ioctl(SMB_IOC_CONFIG) --> smb_server_configure()
180  *
181  * Transition T2
182  *
183  *    This transition occurs in smb_server_start(). It is triggered by the
184  *    daemon through an Ioctl.
185  *
186  *	smb_drv_ioctl(SMB_IOC_START) --> smb_server_start()
187  *
188  * Transition T3
189  *
190  *    This transition occurs in smb_server_delete(). It is triggered by the
191  *    daemon when closing the smbsrv device
192  *
193  *		smb_drv_close() --> smb_server_delete()
194  *
195  * Comments
196  * --------
197  *
198  * This files assumes that there will one SMB server per zone. For now the
199  * smb server works only in global zone. There's nothing in this file preventing
200  * an smb server from being created in a non global zone. That limitation is
201  * enforced in user space.
202  */
203 
204 #include <sys/strsubr.h>
205 #include <sys/cmn_err.h>
206 #include <sys/priv.h>
207 #include <sys/socketvar.h>
208 #include <sys/zone.h>
209 #include <netinet/in.h>
210 #include <netinet/in_systm.h>
211 #include <netinet/ip.h>
212 #include <netinet/ip_icmp.h>
213 #include <netinet/ip_var.h>
214 #include <netinet/tcp.h>
215 #include <smbsrv/smb_kproto.h>
216 #include <smbsrv/string.h>
217 #include <smbsrv/netbios.h>
218 #include <smbsrv/smb_fsops.h>
219 #include <smbsrv/smb_share.h>
220 #include <smbsrv/smb_door.h>
221 #include <smbsrv/smb_kstat.h>
222 
223 extern void smb_reply_notify_change_request(smb_request_t *);
224 
225 typedef struct {
226 	smb_listener_daemon_t	*ra_listener;
227 	smb_session_t		*ra_session;
228 } smb_receiver_arg_t;
229 
230 static void smb_server_kstat_init(smb_server_t *);
231 static void smb_server_kstat_fini(smb_server_t *);
232 static void smb_server_timers(smb_thread_t *, void *);
233 static void smb_server_store_cfg(smb_server_t *, smb_ioc_cfg_t *);
234 static void smb_server_shutdown(smb_server_t *);
235 static int smb_server_fsop_start(smb_server_t *);
236 static void smb_server_fsop_stop(smb_server_t *);
237 static void smb_event_cancel(smb_server_t *, uint32_t);
238 static uint32_t smb_event_alloc_txid(void);
239 
240 static void smb_server_disconnect_share(smb_llist_t *, const char *);
241 static void smb_server_enum_users(smb_llist_t *, smb_svcenum_t *);
242 static void smb_server_enum_trees(smb_llist_t *, smb_svcenum_t *);
243 static int smb_server_session_disconnect(smb_llist_t *, const char *,
244     const char *);
245 static int smb_server_fclose(smb_llist_t *, uint32_t);
246 static int smb_server_kstat_update(kstat_t *, int);
247 static int smb_server_legacy_kstat_update(kstat_t *, int);
248 static void smb_server_listener_init(smb_server_t *, smb_listener_daemon_t *,
249     char *, in_port_t, int);
250 static void smb_server_listener_destroy(smb_listener_daemon_t *);
251 static int smb_server_listener_start(smb_listener_daemon_t *);
252 static void smb_server_listener_stop(smb_listener_daemon_t *);
253 static void smb_server_listener(smb_thread_t *, void *);
254 static void smb_server_receiver(void *);
255 static void smb_server_create_session(smb_listener_daemon_t *, ksocket_t);
256 static void smb_server_destroy_session(smb_listener_daemon_t *,
257     smb_session_t *);
258 static uint16_t smb_spool_get_fid(smb_server_t *);
259 static boolean_t smb_spool_lookup_doc_byfid(smb_server_t *, uint16_t,
260     smb_kspooldoc_t *);
261 
262 int smb_event_debug = 0;
263 
264 static smb_llist_t	smb_servers;
265 
266 kmem_cache_t		*smb_cache_request;
267 kmem_cache_t		*smb_cache_session;
268 kmem_cache_t		*smb_cache_user;
269 kmem_cache_t		*smb_cache_tree;
270 kmem_cache_t		*smb_cache_ofile;
271 kmem_cache_t		*smb_cache_odir;
272 kmem_cache_t		*smb_cache_opipe;
273 kmem_cache_t		*smb_cache_event;
274 
275 /*
276  * *****************************************************************************
277  * **************** Functions called from the device interface *****************
278  * *****************************************************************************
279  *
280  * These functions typically have to determine the relevant smb server
281  * to which the call applies.
282  */
283 
284 /*
285  * smb_server_g_init
286  *
287  * This function must be called from smb_drv_attach().
288  */
289 int
290 smb_server_g_init(void)
291 {
292 	int rc;
293 
294 	if ((rc = smb_vop_init()) != 0)
295 		goto errout;
296 	if ((rc = smb_fem_init()) != 0)
297 		goto errout;
298 	if ((rc = smb_oplock_init()) != 0)
299 		goto errout;
300 
301 	smb_kshare_g_init();
302 	smb_codepage_init();
303 	smb_mbc_init();		/* smb_mbc_cache */
304 	smb_net_init();		/* smb_txr_cache */
305 	smb_node_init();	/* smb_node_cache, lists */
306 	smb_sign_g_init();
307 
308 	smb_cache_request = kmem_cache_create("smb_request_cache",
309 	    sizeof (smb_request_t), 8, NULL, NULL, NULL, NULL, NULL, 0);
310 	smb_cache_session = kmem_cache_create("smb_session_cache",
311 	    sizeof (smb_session_t), 8, NULL, NULL, NULL, NULL, NULL, 0);
312 	smb_cache_user = kmem_cache_create("smb_user_cache",
313 	    sizeof (smb_user_t), 8, NULL, NULL, NULL, NULL, NULL, 0);
314 	smb_cache_tree = kmem_cache_create("smb_tree_cache",
315 	    sizeof (smb_tree_t), 8, NULL, NULL, NULL, NULL, NULL, 0);
316 	smb_cache_ofile = kmem_cache_create("smb_ofile_cache",
317 	    sizeof (smb_ofile_t), 8, NULL, NULL, NULL, NULL, NULL, 0);
318 	smb_cache_odir = kmem_cache_create("smb_odir_cache",
319 	    sizeof (smb_odir_t), 8, NULL, NULL, NULL, NULL, NULL, 0);
320 	smb_cache_opipe = kmem_cache_create("smb_opipe_cache",
321 	    sizeof (smb_opipe_t), 8, NULL, NULL, NULL, NULL, NULL, 0);
322 	smb_cache_event = kmem_cache_create("smb_event_cache",
323 	    sizeof (smb_event_t), 8, NULL, NULL, NULL, NULL, NULL, 0);
324 
325 	smb_llist_init();
326 	smb_llist_constructor(&smb_servers, sizeof (smb_server_t),
327 	    offsetof(smb_server_t, sv_lnd));
328 
329 	return (0);
330 
331 errout:
332 	smb_fem_fini();
333 	smb_vop_fini();
334 	return (rc);
335 }
336 
337 /*
338  * smb_server_g_fini
339  *
340  * This function must called from smb_drv_detach(). It will fail if servers
341  * still exist.
342  */
343 int
344 smb_server_g_fini(void)
345 {
346 
347 	if (smb_llist_get_count(&smb_servers) != 0)
348 		return (EBUSY);
349 	smb_llist_fini();
350 
351 	kmem_cache_destroy(smb_cache_request);
352 	kmem_cache_destroy(smb_cache_session);
353 	kmem_cache_destroy(smb_cache_user);
354 	kmem_cache_destroy(smb_cache_tree);
355 	kmem_cache_destroy(smb_cache_ofile);
356 	kmem_cache_destroy(smb_cache_odir);
357 	kmem_cache_destroy(smb_cache_opipe);
358 	kmem_cache_destroy(smb_cache_event);
359 
360 	smb_node_fini();
361 	smb_net_fini();
362 	smb_mbc_fini();
363 	smb_kshare_g_fini();
364 
365 	smb_oplock_fini();
366 	smb_fem_fini();
367 	smb_vop_fini();
368 
369 	smb_llist_destructor(&smb_servers);
370 
371 	return (0);
372 }
373 
374 /*
375  * smb_server_create
376  *
377  * This function will fail if there's already a server associated with the
378  * caller's zone.
379  */
380 int
381 smb_server_create(void)
382 {
383 	zoneid_t	zid;
384 	smb_server_t	*sv;
385 
386 	zid = getzoneid();
387 
388 	smb_llist_enter(&smb_servers, RW_WRITER);
389 	sv = smb_llist_head(&smb_servers);
390 	while (sv) {
391 		SMB_SERVER_VALID(sv);
392 		if (sv->sv_zid == zid) {
393 			smb_llist_exit(&smb_servers);
394 			return (EPERM);
395 		}
396 		sv = smb_llist_next(&smb_servers, sv);
397 	}
398 
399 	sv = kmem_zalloc(sizeof (smb_server_t), KM_SLEEP);
400 
401 	sv->sv_magic = SMB_SERVER_MAGIC;
402 	sv->sv_state = SMB_SERVER_STATE_CREATED;
403 	sv->sv_zid = zid;
404 	sv->sv_pid = curproc->p_pid;
405 
406 	mutex_init(&sv->sv_mutex, NULL, MUTEX_DEFAULT, NULL);
407 	cv_init(&sv->sv_cv, NULL, CV_DEFAULT, NULL);
408 	cv_init(&sv->sp_info.sp_cv, NULL, CV_DEFAULT, NULL);
409 
410 	smb_llist_constructor(&sv->sv_opipe_list, sizeof (smb_opipe_t),
411 	    offsetof(smb_opipe_t, p_lnd));
412 
413 	smb_llist_constructor(&sv->sv_event_list, sizeof (smb_event_t),
414 	    offsetof(smb_event_t, se_lnd));
415 
416 	smb_llist_constructor(&sv->sp_info.sp_list, sizeof (smb_kspooldoc_t),
417 	    offsetof(smb_kspooldoc_t, sd_lnd));
418 
419 	smb_llist_constructor(&sv->sp_info.sp_fidlist,
420 	    sizeof (smb_spoolfid_t), offsetof(smb_spoolfid_t, sf_lnd));
421 
422 	sv->sv_disp_stats = kmem_zalloc(SMB_COM_NUM *
423 	    sizeof (smb_disp_stats_t), KM_SLEEP);
424 
425 	smb_thread_init(&sv->si_thread_timers, "smb_timers",
426 	    smb_server_timers, sv, smbsrv_timer_pri);
427 
428 	smb_srqueue_init(&sv->sv_srqueue);
429 
430 	smb_kdoor_init(sv);
431 	smb_kshare_init(sv);
432 	smb_opipe_door_init(sv);
433 	smb_server_kstat_init(sv);
434 
435 	smb_threshold_init(&sv->sv_ssetup_ct, SMB_SSETUP_CMD,
436 	    smb_ssetup_threshold, smb_ssetup_timeout);
437 	smb_threshold_init(&sv->sv_tcon_ct, SMB_TCON_CMD,
438 	    smb_tcon_threshold, smb_tcon_timeout);
439 	smb_threshold_init(&sv->sv_opipe_ct, SMB_OPIPE_CMD,
440 	    smb_opipe_threshold, smb_opipe_timeout);
441 
442 	smb_llist_insert_tail(&smb_servers, sv);
443 	smb_llist_exit(&smb_servers);
444 
445 	return (0);
446 }
447 
448 /*
449  * smb_server_delete
450  *
451  * This function will delete the server passed in. It will make sure that all
452  * activity associated that server has ceased before destroying it.
453  */
454 int
455 smb_server_delete(void)
456 {
457 	smb_server_t	*sv;
458 	int		rc;
459 
460 	rc = smb_server_lookup(&sv);
461 	if (rc != 0)
462 		return (rc);
463 
464 	mutex_enter(&sv->sv_mutex);
465 	switch (sv->sv_state) {
466 	case SMB_SERVER_STATE_RUNNING:
467 		sv->sv_state = SMB_SERVER_STATE_STOPPING;
468 		mutex_exit(&sv->sv_mutex);
469 		smb_server_shutdown(sv);
470 		mutex_enter(&sv->sv_mutex);
471 		cv_broadcast(&sv->sp_info.sp_cv);
472 		sv->sv_state = SMB_SERVER_STATE_DELETING;
473 		break;
474 	case SMB_SERVER_STATE_STOPPING:
475 		sv->sv_state = SMB_SERVER_STATE_DELETING;
476 		break;
477 	case SMB_SERVER_STATE_CONFIGURED:
478 	case SMB_SERVER_STATE_CREATED:
479 		sv->sv_state = SMB_SERVER_STATE_DELETING;
480 		break;
481 	default:
482 		SMB_SERVER_STATE_VALID(sv->sv_state);
483 		mutex_exit(&sv->sv_mutex);
484 		smb_server_release(sv);
485 		return (ENOTTY);
486 	}
487 
488 	ASSERT(sv->sv_state == SMB_SERVER_STATE_DELETING);
489 
490 	sv->sv_refcnt--;
491 	while (sv->sv_refcnt)
492 		cv_wait(&sv->sv_cv, &sv->sv_mutex);
493 
494 	mutex_exit(&sv->sv_mutex);
495 
496 	smb_llist_enter(&smb_servers, RW_WRITER);
497 	smb_llist_remove(&smb_servers, sv);
498 	smb_llist_exit(&smb_servers);
499 
500 	smb_threshold_fini(&sv->sv_ssetup_ct);
501 	smb_threshold_fini(&sv->sv_tcon_ct);
502 	smb_threshold_fini(&sv->sv_opipe_ct);
503 
504 	smb_server_listener_destroy(&sv->sv_nbt_daemon);
505 	smb_server_listener_destroy(&sv->sv_tcp_daemon);
506 	rw_destroy(&sv->sv_cfg_lock);
507 	smb_server_kstat_fini(sv);
508 	smb_opipe_door_fini(sv);
509 	smb_kshare_fini(sv);
510 	smb_kdoor_fini(sv);
511 	smb_llist_destructor(&sv->sv_opipe_list);
512 	smb_llist_destructor(&sv->sv_event_list);
513 
514 	kmem_free(sv->sv_disp_stats,
515 	    SMB_COM_NUM * sizeof (smb_disp_stats_t));
516 
517 	smb_srqueue_destroy(&sv->sv_srqueue);
518 	smb_thread_destroy(&sv->si_thread_timers);
519 
520 	mutex_destroy(&sv->sv_mutex);
521 	cv_destroy(&sv->sv_cv);
522 	sv->sv_magic = 0;
523 	kmem_free(sv, sizeof (smb_server_t));
524 
525 	return (0);
526 }
527 
528 /*
529  * smb_server_configure
530  */
531 int
532 smb_server_configure(smb_ioc_cfg_t *ioc)
533 {
534 	int		rc = 0;
535 	smb_server_t	*sv;
536 
537 	rc = smb_server_lookup(&sv);
538 	if (rc)
539 		return (rc);
540 
541 	mutex_enter(&sv->sv_mutex);
542 	switch (sv->sv_state) {
543 	case SMB_SERVER_STATE_CREATED:
544 		smb_server_store_cfg(sv, ioc);
545 		sv->sv_state = SMB_SERVER_STATE_CONFIGURED;
546 		break;
547 
548 	case SMB_SERVER_STATE_CONFIGURED:
549 		smb_server_store_cfg(sv, ioc);
550 		break;
551 
552 	case SMB_SERVER_STATE_RUNNING:
553 	case SMB_SERVER_STATE_STOPPING:
554 		rw_enter(&sv->sv_cfg_lock, RW_WRITER);
555 		smb_server_store_cfg(sv, ioc);
556 		rw_exit(&sv->sv_cfg_lock);
557 		break;
558 
559 	default:
560 		SMB_SERVER_STATE_VALID(sv->sv_state);
561 		rc = EFAULT;
562 		break;
563 	}
564 	mutex_exit(&sv->sv_mutex);
565 
566 	smb_server_release(sv);
567 
568 	return (rc);
569 }
570 
571 /*
572  * smb_server_start
573  */
574 int
575 smb_server_start(smb_ioc_start_t *ioc)
576 {
577 	int		rc = 0;
578 	int		family;
579 	smb_server_t	*sv;
580 
581 	rc = smb_server_lookup(&sv);
582 	if (rc)
583 		return (rc);
584 
585 	mutex_enter(&sv->sv_mutex);
586 	switch (sv->sv_state) {
587 	case SMB_SERVER_STATE_CONFIGURED:
588 
589 		if ((rc = smb_server_fsop_start(sv)) != 0)
590 			break;
591 
592 		if ((rc = smb_kshare_start(sv)) != 0)
593 			break;
594 
595 		sv->sv_worker_pool = taskq_create_proc("smb_workers",
596 		    sv->sv_cfg.skc_maxworkers, smbsrv_worker_pri,
597 		    sv->sv_cfg.skc_maxworkers, INT_MAX,
598 		    curzone->zone_zsched, TASKQ_DYNAMIC);
599 
600 		sv->sv_receiver_pool = taskq_create_proc("smb_receivers",
601 		    sv->sv_cfg.skc_maxconnections, smbsrv_receive_pri,
602 		    sv->sv_cfg.skc_maxconnections, INT_MAX,
603 		    curzone->zone_zsched, TASKQ_DYNAMIC);
604 
605 		sv->sv_session = smb_session_create(NULL, 0, sv, 0);
606 
607 		if (sv->sv_worker_pool == NULL || sv->sv_session == NULL) {
608 			rc = ENOMEM;
609 			break;
610 		}
611 
612 		ASSERT(sv->sv_lmshrd == NULL);
613 		sv->sv_lmshrd = smb_kshare_door_init(ioc->lmshrd);
614 		if (sv->sv_lmshrd == NULL)
615 			break;
616 		if (rc = smb_kdoor_open(sv, ioc->udoor)) {
617 			cmn_err(CE_WARN, "Cannot open smbd door");
618 			break;
619 		}
620 		if (rc = smb_opipe_door_open(sv, ioc->opipe)) {
621 			cmn_err(CE_WARN, "Cannot open opipe door");
622 			break;
623 		}
624 		if (rc = smb_thread_start(&sv->si_thread_timers))
625 			break;
626 
627 		family = AF_INET;
628 		smb_server_listener_init(sv, &sv->sv_nbt_daemon,
629 		    "smb_nbt_listener", IPPORT_NETBIOS_SSN, family);
630 		if (sv->sv_cfg.skc_ipv6_enable)
631 			family = AF_INET6;
632 		smb_server_listener_init(sv, &sv->sv_tcp_daemon,
633 		    "smb_tcp_listener", IPPORT_SMB, family);
634 		rc = smb_server_listener_start(&sv->sv_nbt_daemon);
635 		if (rc != 0)
636 			break;
637 		rc = smb_server_listener_start(&sv->sv_tcp_daemon);
638 		if (rc != 0)
639 			break;
640 
641 		sv->sv_state = SMB_SERVER_STATE_RUNNING;
642 		sv->sv_start_time = gethrtime();
643 		mutex_exit(&sv->sv_mutex);
644 		smb_server_release(sv);
645 		smb_export_start(sv);
646 		return (0);
647 	default:
648 		SMB_SERVER_STATE_VALID(sv->sv_state);
649 		mutex_exit(&sv->sv_mutex);
650 		smb_server_release(sv);
651 		return (ENOTTY);
652 	}
653 
654 	mutex_exit(&sv->sv_mutex);
655 	smb_server_shutdown(sv);
656 	smb_server_release(sv);
657 	return (rc);
658 }
659 
660 /*
661  * An smbd is shutting down.
662  */
663 int
664 smb_server_stop(void)
665 {
666 	smb_server_t	*sv;
667 	int		rc;
668 
669 	if ((rc = smb_server_lookup(&sv)) != 0)
670 		return (rc);
671 
672 	mutex_enter(&sv->sv_mutex);
673 	switch (sv->sv_state) {
674 	case SMB_SERVER_STATE_RUNNING:
675 		sv->sv_state = SMB_SERVER_STATE_STOPPING;
676 		mutex_exit(&sv->sv_mutex);
677 		smb_server_shutdown(sv);
678 		mutex_enter(&sv->sv_mutex);
679 		cv_broadcast(&sv->sp_info.sp_cv);
680 		break;
681 	default:
682 		SMB_SERVER_STATE_VALID(sv->sv_state);
683 		break;
684 	}
685 	mutex_exit(&sv->sv_mutex);
686 
687 	smb_server_release(sv);
688 	return (0);
689 }
690 
691 boolean_t
692 smb_server_is_stopping(smb_server_t *sv)
693 {
694 	boolean_t	status;
695 
696 	SMB_SERVER_VALID(sv);
697 
698 	mutex_enter(&sv->sv_mutex);
699 
700 	switch (sv->sv_state) {
701 	case SMB_SERVER_STATE_STOPPING:
702 	case SMB_SERVER_STATE_DELETING:
703 		status = B_TRUE;
704 		break;
705 	default:
706 		status = B_FALSE;
707 		break;
708 	}
709 
710 	mutex_exit(&sv->sv_mutex);
711 	return (status);
712 }
713 
714 void
715 smb_server_cancel_event(smb_server_t *sv, uint32_t txid)
716 {
717 	smb_event_cancel(sv, txid);
718 }
719 
720 int
721 smb_server_notify_event(smb_ioc_event_t *ioc)
722 {
723 	smb_server_t	*sv;
724 	int		rc;
725 
726 	if ((rc = smb_server_lookup(&sv)) == 0) {
727 		smb_event_notify(sv, ioc->txid);
728 		smb_server_release(sv);
729 	}
730 
731 	return (rc);
732 }
733 
734 /*
735  * smb_server_spooldoc
736  *
737  * Waits for print file close broadcast.
738  * Gets the head of the fid list,
739  * then searches the spooldoc list and returns
740  * this info via the ioctl to user land.
741  *
742  * rc - 0 success
743  */
744 
745 int
746 smb_server_spooldoc(smb_ioc_spooldoc_t *ioc)
747 {
748 	smb_server_t	*sv;
749 	int		rc;
750 	smb_kspooldoc_t *spdoc;
751 	uint16_t	fid;
752 
753 	if ((rc = smb_server_lookup(&sv)) != 0)
754 		return (rc);
755 
756 	if (sv->sv_cfg.skc_print_enable == 0) {
757 		rc = ENOTTY;
758 		goto out;
759 	}
760 
761 	mutex_enter(&sv->sv_mutex);
762 	for (;;) {
763 		if (sv->sv_state != SMB_SERVER_STATE_RUNNING) {
764 			rc = ECANCELED;
765 			break;
766 		}
767 		if ((fid = smb_spool_get_fid(sv)) != 0) {
768 			rc = 0;
769 			break;
770 		}
771 		if (cv_wait_sig(&sv->sp_info.sp_cv, &sv->sv_mutex) == 0) {
772 			rc = EINTR;
773 			break;
774 		}
775 	}
776 	mutex_exit(&sv->sv_mutex);
777 	if (rc != 0)
778 		goto out;
779 
780 	spdoc = kmem_zalloc(sizeof (*spdoc), KM_SLEEP);
781 	if (smb_spool_lookup_doc_byfid(sv, fid, spdoc)) {
782 		ioc->spool_num = spdoc->sd_spool_num;
783 		ioc->ipaddr = spdoc->sd_ipaddr;
784 		(void) strlcpy(ioc->path, spdoc->sd_path,
785 		    MAXPATHLEN);
786 		(void) strlcpy(ioc->username,
787 		    spdoc->sd_username, MAXNAMELEN);
788 	} else {
789 		/* Did not find that print job. */
790 		rc = EAGAIN;
791 	}
792 	kmem_free(spdoc, sizeof (*spdoc));
793 
794 out:
795 	smb_server_release(sv);
796 	return (rc);
797 }
798 
799 int
800 smb_server_set_gmtoff(smb_ioc_gmt_t *ioc)
801 {
802 	int		rc;
803 	smb_server_t	*sv;
804 
805 	if ((rc = smb_server_lookup(&sv)) == 0) {
806 		sv->si_gmtoff = ioc->offset;
807 		smb_server_release(sv);
808 	}
809 
810 	return (rc);
811 }
812 
813 int
814 smb_server_numopen(smb_ioc_opennum_t *ioc)
815 {
816 	smb_server_t	*sv;
817 	int		rc;
818 
819 	if ((rc = smb_server_lookup(&sv)) == 0) {
820 		ioc->open_users = sv->sv_users;
821 		ioc->open_trees = sv->sv_trees;
822 		ioc->open_files = sv->sv_files + sv->sv_pipes;
823 		smb_server_release(sv);
824 	}
825 	return (rc);
826 }
827 
828 /*
829  * Enumerate objects within the server.  The svcenum provides the
830  * enumeration context, i.e. what the caller want to get back.
831  */
832 int
833 smb_server_enum(smb_ioc_svcenum_t *ioc)
834 {
835 	smb_svcenum_t	*svcenum = &ioc->svcenum;
836 	smb_server_t	*sv;
837 	int		rc;
838 
839 	if ((rc = smb_server_lookup(&sv)) != 0)
840 		return (rc);
841 
842 	svcenum->se_bavail = svcenum->se_buflen;
843 	svcenum->se_bused = 0;
844 	svcenum->se_nitems = 0;
845 
846 	switch (svcenum->se_type) {
847 	case SMB_SVCENUM_TYPE_USER:
848 		smb_server_enum_users(&sv->sv_nbt_daemon.ld_session_list,
849 		    svcenum);
850 		smb_server_enum_users(&sv->sv_tcp_daemon.ld_session_list,
851 		    svcenum);
852 		break;
853 	case SMB_SVCENUM_TYPE_TREE:
854 	case SMB_SVCENUM_TYPE_FILE:
855 		smb_server_enum_trees(&sv->sv_nbt_daemon.ld_session_list,
856 		    svcenum);
857 		smb_server_enum_trees(&sv->sv_tcp_daemon.ld_session_list,
858 		    svcenum);
859 		break;
860 	default:
861 		rc = EINVAL;
862 	}
863 
864 	smb_server_release(sv);
865 	return (rc);
866 }
867 
868 /*
869  * Look for sessions to disconnect by client and user name.
870  */
871 int
872 smb_server_session_close(smb_ioc_session_t *ioc)
873 {
874 	smb_llist_t	*ll;
875 	smb_server_t	*sv;
876 	int		nbt_cnt;
877 	int		tcp_cnt;
878 	int		rc;
879 
880 	if ((rc = smb_server_lookup(&sv)) != 0)
881 		return (rc);
882 
883 	ll = &sv->sv_nbt_daemon.ld_session_list;
884 	nbt_cnt = smb_server_session_disconnect(ll, ioc->client, ioc->username);
885 
886 	ll = &sv->sv_tcp_daemon.ld_session_list;
887 	tcp_cnt = smb_server_session_disconnect(ll, ioc->client, ioc->username);
888 
889 	smb_server_release(sv);
890 
891 	if ((nbt_cnt == 0) && (tcp_cnt == 0))
892 		return (ENOENT);
893 	return (0);
894 }
895 
896 /*
897  * Close a file by uniqid.
898  */
899 int
900 smb_server_file_close(smb_ioc_fileid_t *ioc)
901 {
902 	uint32_t	uniqid = ioc->uniqid;
903 	smb_llist_t	*ll;
904 	smb_server_t	*sv;
905 	int		rc;
906 
907 	if ((rc = smb_server_lookup(&sv)) != 0)
908 		return (rc);
909 
910 	ll = &sv->sv_nbt_daemon.ld_session_list;
911 	rc = smb_server_fclose(ll, uniqid);
912 
913 	if (rc == ENOENT) {
914 		ll = &sv->sv_tcp_daemon.ld_session_list;
915 		rc = smb_server_fclose(ll, uniqid);
916 	}
917 
918 	smb_server_release(sv);
919 	return (rc);
920 }
921 
922 /*
923  * These functions determine the relevant smb server to which the call apply.
924  */
925 
926 uint32_t
927 smb_server_get_session_count(smb_server_t *sv)
928 {
929 	uint32_t	counter = 0;
930 
931 	counter = smb_llist_get_count(&sv->sv_nbt_daemon.ld_session_list);
932 	counter += smb_llist_get_count(&sv->sv_tcp_daemon.ld_session_list);
933 
934 	return (counter);
935 }
936 
937 /*
938  * Gets the vnode of the specified share path.
939  *
940  * A hold on the returned vnode pointer is taken so the caller
941  * must call VN_RELE.
942  */
943 int
944 smb_server_sharevp(smb_server_t *sv, const char *shr_path, vnode_t **vp)
945 {
946 	smb_request_t	*sr;
947 	smb_node_t	*fnode = NULL;
948 	smb_node_t	*dnode;
949 	char		last_comp[MAXNAMELEN];
950 	int		rc = 0;
951 
952 	ASSERT(shr_path);
953 
954 	mutex_enter(&sv->sv_mutex);
955 	switch (sv->sv_state) {
956 	case SMB_SERVER_STATE_RUNNING:
957 		break;
958 	default:
959 		mutex_exit(&sv->sv_mutex);
960 		return (ENOTACTIVE);
961 	}
962 	mutex_exit(&sv->sv_mutex);
963 
964 	if ((sr = smb_request_alloc(sv->sv_session, 0)) == NULL) {
965 		return (ENOMEM);
966 	}
967 	sr->user_cr = zone_kcred();
968 
969 	rc = smb_pathname_reduce(sr, sr->user_cr, shr_path,
970 	    NULL, NULL, &dnode, last_comp);
971 
972 	if (rc == 0) {
973 		rc = smb_fsop_lookup(sr, sr->user_cr, SMB_FOLLOW_LINKS,
974 		    sv->si_root_smb_node, dnode, last_comp, &fnode);
975 		smb_node_release(dnode);
976 	}
977 
978 	smb_request_free(sr);
979 
980 	if (rc != 0)
981 		return (rc);
982 
983 	ASSERT(fnode->vp && fnode->vp->v_vfsp);
984 
985 	VN_HOLD(fnode->vp);
986 	*vp = fnode->vp;
987 
988 	smb_node_release(fnode);
989 
990 	return (0);
991 }
992 
993 
994 /*
995  * This is a special interface that will be utilized by ZFS to cause a share to
996  * be added/removed.
997  *
998  * arg is either a lmshare_info_t or share_name from userspace.
999  * It will need to be copied into the kernel.   It is lmshare_info_t
1000  * for add operations and share_name for delete operations.
1001  */
1002 int
1003 smb_server_share(void *arg, boolean_t add_share)
1004 {
1005 	smb_server_t	*sv;
1006 	int		rc;
1007 
1008 	if ((rc = smb_server_lookup(&sv)) == 0) {
1009 		mutex_enter(&sv->sv_mutex);
1010 		switch (sv->sv_state) {
1011 		case SMB_SERVER_STATE_RUNNING:
1012 			mutex_exit(&sv->sv_mutex);
1013 			(void) smb_kshare_upcall(sv->sv_lmshrd, arg, add_share);
1014 			break;
1015 		default:
1016 			mutex_exit(&sv->sv_mutex);
1017 			break;
1018 		}
1019 		smb_server_release(sv);
1020 	}
1021 
1022 	return (rc);
1023 }
1024 
1025 int
1026 smb_server_unshare(const char *sharename)
1027 {
1028 	smb_server_t	*sv;
1029 	smb_llist_t	*ll;
1030 	int		rc;
1031 
1032 	if ((rc = smb_server_lookup(&sv)))
1033 		return (rc);
1034 
1035 	mutex_enter(&sv->sv_mutex);
1036 	switch (sv->sv_state) {
1037 	case SMB_SERVER_STATE_RUNNING:
1038 	case SMB_SERVER_STATE_STOPPING:
1039 		break;
1040 	default:
1041 		mutex_exit(&sv->sv_mutex);
1042 		smb_server_release(sv);
1043 		return (ENOTACTIVE);
1044 	}
1045 	mutex_exit(&sv->sv_mutex);
1046 
1047 	ll = &sv->sv_nbt_daemon.ld_session_list;
1048 	smb_server_disconnect_share(ll, sharename);
1049 
1050 	ll = &sv->sv_tcp_daemon.ld_session_list;
1051 	smb_server_disconnect_share(ll, sharename);
1052 
1053 	smb_server_release(sv);
1054 	return (0);
1055 }
1056 
1057 /*
1058  * Disconnect the specified share.
1059  * Typically called when a share has been removed.
1060  */
1061 static void
1062 smb_server_disconnect_share(smb_llist_t *ll, const char *sharename)
1063 {
1064 	smb_session_t	*session;
1065 
1066 	smb_llist_enter(ll, RW_READER);
1067 
1068 	session = smb_llist_head(ll);
1069 	while (session) {
1070 		SMB_SESSION_VALID(session);
1071 		smb_rwx_rwenter(&session->s_lock, RW_READER);
1072 		switch (session->s_state) {
1073 		case SMB_SESSION_STATE_NEGOTIATED:
1074 		case SMB_SESSION_STATE_OPLOCK_BREAKING:
1075 		case SMB_SESSION_STATE_WRITE_RAW_ACTIVE:
1076 			smb_session_disconnect_share(session, sharename);
1077 			break;
1078 		default:
1079 			break;
1080 		}
1081 		smb_rwx_rwexit(&session->s_lock);
1082 		session = smb_llist_next(ll, session);
1083 	}
1084 
1085 	smb_llist_exit(ll);
1086 }
1087 
1088 /*
1089  * *****************************************************************************
1090  * **************** Functions called from the internal layers ******************
1091  * *****************************************************************************
1092  *
1093  * These functions are provided the relevant smb server by the caller.
1094  */
1095 
1096 void
1097 smb_server_get_cfg(smb_server_t *sv, smb_kmod_cfg_t *cfg)
1098 {
1099 	rw_enter(&sv->sv_cfg_lock, RW_READER);
1100 	bcopy(&sv->sv_cfg, cfg, sizeof (*cfg));
1101 	rw_exit(&sv->sv_cfg_lock);
1102 }
1103 
1104 /*
1105  *
1106  */
1107 void
1108 smb_server_inc_nbt_sess(smb_server_t *sv)
1109 {
1110 	SMB_SERVER_VALID(sv);
1111 	atomic_inc_32(&sv->sv_nbt_sess);
1112 }
1113 
1114 void
1115 smb_server_dec_nbt_sess(smb_server_t *sv)
1116 {
1117 	SMB_SERVER_VALID(sv);
1118 	atomic_dec_32(&sv->sv_nbt_sess);
1119 }
1120 
1121 void
1122 smb_server_inc_tcp_sess(smb_server_t *sv)
1123 {
1124 	SMB_SERVER_VALID(sv);
1125 	atomic_inc_32(&sv->sv_tcp_sess);
1126 }
1127 
1128 void
1129 smb_server_dec_tcp_sess(smb_server_t *sv)
1130 {
1131 	SMB_SERVER_VALID(sv);
1132 	atomic_dec_32(&sv->sv_tcp_sess);
1133 }
1134 
1135 void
1136 smb_server_inc_users(smb_server_t *sv)
1137 {
1138 	SMB_SERVER_VALID(sv);
1139 	atomic_inc_32(&sv->sv_users);
1140 }
1141 
1142 void
1143 smb_server_dec_users(smb_server_t *sv)
1144 {
1145 	SMB_SERVER_VALID(sv);
1146 	atomic_dec_32(&sv->sv_users);
1147 }
1148 
1149 void
1150 smb_server_inc_trees(smb_server_t *sv)
1151 {
1152 	SMB_SERVER_VALID(sv);
1153 	atomic_inc_32(&sv->sv_trees);
1154 }
1155 
1156 void
1157 smb_server_dec_trees(smb_server_t *sv)
1158 {
1159 	SMB_SERVER_VALID(sv);
1160 	atomic_dec_32(&sv->sv_trees);
1161 }
1162 
1163 void
1164 smb_server_inc_files(smb_server_t *sv)
1165 {
1166 	SMB_SERVER_VALID(sv);
1167 	atomic_inc_32(&sv->sv_files);
1168 }
1169 
1170 void
1171 smb_server_dec_files(smb_server_t *sv)
1172 {
1173 	SMB_SERVER_VALID(sv);
1174 	atomic_dec_32(&sv->sv_files);
1175 }
1176 
1177 void
1178 smb_server_inc_pipes(smb_server_t *sv)
1179 {
1180 	SMB_SERVER_VALID(sv);
1181 	atomic_inc_32(&sv->sv_pipes);
1182 }
1183 
1184 void
1185 smb_server_dec_pipes(smb_server_t *sv)
1186 {
1187 	SMB_SERVER_VALID(sv);
1188 	atomic_dec_32(&sv->sv_pipes);
1189 }
1190 
1191 void
1192 smb_server_add_rxb(smb_server_t *sv, int64_t value)
1193 {
1194 	SMB_SERVER_VALID(sv);
1195 	atomic_add_64(&sv->sv_rxb, value);
1196 }
1197 
1198 void
1199 smb_server_add_txb(smb_server_t *sv, int64_t value)
1200 {
1201 	SMB_SERVER_VALID(sv);
1202 	atomic_add_64(&sv->sv_txb, value);
1203 }
1204 
1205 void
1206 smb_server_inc_req(smb_server_t *sv)
1207 {
1208 	SMB_SERVER_VALID(sv);
1209 	atomic_inc_64(&sv->sv_nreq);
1210 }
1211 
1212 /*
1213  * *****************************************************************************
1214  * *************************** Static Functions ********************************
1215  * *****************************************************************************
1216  */
1217 
1218 static void
1219 smb_server_timers(smb_thread_t *thread, void *arg)
1220 {
1221 	smb_server_t	*sv = (smb_server_t *)arg;
1222 
1223 	ASSERT(sv != NULL);
1224 
1225 	while (smb_thread_continue_timedwait(thread, 1 /* Seconds */)) {
1226 		smb_session_timers(&sv->sv_nbt_daemon.ld_session_list);
1227 		smb_session_timers(&sv->sv_tcp_daemon.ld_session_list);
1228 	}
1229 }
1230 
1231 /*
1232  * smb_server_kstat_init
1233  */
1234 static void
1235 smb_server_kstat_init(smb_server_t *sv)
1236 {
1237 
1238 	sv->sv_ksp = kstat_create_zone(SMBSRV_KSTAT_MODULE, 0,
1239 	    SMBSRV_KSTAT_STATISTICS, SMBSRV_KSTAT_CLASS, KSTAT_TYPE_RAW,
1240 	    sizeof (smbsrv_kstats_t), 0, sv->sv_zid);
1241 
1242 	if (sv->sv_ksp != NULL) {
1243 		sv->sv_ksp->ks_update = smb_server_kstat_update;
1244 		sv->sv_ksp->ks_private = sv;
1245 		((smbsrv_kstats_t *)sv->sv_ksp->ks_data)->ks_start_time =
1246 		    sv->sv_start_time;
1247 		smb_dispatch_stats_init(sv);
1248 		kstat_install(sv->sv_ksp);
1249 	} else {
1250 		cmn_err(CE_WARN, "SMB Server: Statistics unavailable");
1251 	}
1252 
1253 	sv->sv_legacy_ksp = kstat_create_zone(SMBSRV_KSTAT_MODULE, 0,
1254 	    SMBSRV_KSTAT_NAME, SMBSRV_KSTAT_CLASS, KSTAT_TYPE_NAMED,
1255 	    sizeof (smb_server_legacy_kstat_t) / sizeof (kstat_named_t),
1256 	    0, sv->sv_zid);
1257 
1258 	if (sv->sv_legacy_ksp != NULL) {
1259 		smb_server_legacy_kstat_t *ksd;
1260 
1261 		ksd = sv->sv_legacy_ksp->ks_data;
1262 
1263 		(void) strlcpy(ksd->ls_files.name, "open_files",
1264 		    sizeof (ksd->ls_files.name));
1265 		ksd->ls_files.data_type = KSTAT_DATA_UINT32;
1266 
1267 		(void) strlcpy(ksd->ls_trees.name, "connections",
1268 		    sizeof (ksd->ls_trees.name));
1269 		ksd->ls_trees.data_type = KSTAT_DATA_UINT32;
1270 
1271 		(void) strlcpy(ksd->ls_users.name, "connections",
1272 		    sizeof (ksd->ls_users.name));
1273 		ksd->ls_users.data_type = KSTAT_DATA_UINT32;
1274 
1275 		mutex_init(&sv->sv_legacy_ksmtx, NULL, MUTEX_DEFAULT, NULL);
1276 		sv->sv_legacy_ksp->ks_lock = &sv->sv_legacy_ksmtx;
1277 		sv->sv_legacy_ksp->ks_update = smb_server_legacy_kstat_update;
1278 		kstat_install(sv->sv_legacy_ksp);
1279 	}
1280 }
1281 
1282 /*
1283  * smb_server_kstat_fini
1284  */
1285 static void
1286 smb_server_kstat_fini(smb_server_t *sv)
1287 {
1288 	if (sv->sv_legacy_ksp != NULL) {
1289 		kstat_delete(sv->sv_legacy_ksp);
1290 		mutex_destroy(&sv->sv_legacy_ksmtx);
1291 		sv->sv_legacy_ksp = NULL;
1292 	}
1293 
1294 	if (sv->sv_ksp != NULL) {
1295 		kstat_delete(sv->sv_ksp);
1296 		sv->sv_ksp = NULL;
1297 		smb_dispatch_stats_fini(sv);
1298 	}
1299 }
1300 
1301 /*
1302  * smb_server_kstat_update
1303  */
1304 static int
1305 smb_server_kstat_update(kstat_t *ksp, int rw)
1306 {
1307 	smb_server_t	*sv;
1308 	smbsrv_kstats_t	*ksd;
1309 
1310 	if (rw == KSTAT_READ) {
1311 		sv = ksp->ks_private;
1312 		SMB_SERVER_VALID(sv);
1313 		ksd = (smbsrv_kstats_t *)ksp->ks_data;
1314 		/*
1315 		 * Counters
1316 		 */
1317 		ksd->ks_nbt_sess = sv->sv_nbt_sess;
1318 		ksd->ks_tcp_sess = sv->sv_tcp_sess;
1319 		ksd->ks_users = sv->sv_users;
1320 		ksd->ks_trees = sv->sv_trees;
1321 		ksd->ks_files = sv->sv_files;
1322 		ksd->ks_pipes = sv->sv_pipes;
1323 		/*
1324 		 * Throughput
1325 		 */
1326 		ksd->ks_txb = sv->sv_txb;
1327 		ksd->ks_rxb = sv->sv_rxb;
1328 		ksd->ks_nreq = sv->sv_nreq;
1329 		/*
1330 		 * Busyness
1331 		 */
1332 		ksd->ks_maxreqs = sv->sv_cfg.skc_maxworkers;
1333 		smb_srqueue_update(&sv->sv_srqueue,
1334 		    &ksd->ks_utilization);
1335 		/*
1336 		 * Latency & Throughput of the requests
1337 		 */
1338 		smb_dispatch_stats_update(sv, ksd->ks_reqs, 0, SMB_COM_NUM);
1339 		return (0);
1340 	}
1341 	if (rw == KSTAT_WRITE)
1342 		return (EACCES);
1343 
1344 	return (EIO);
1345 }
1346 
1347 static int
1348 smb_server_legacy_kstat_update(kstat_t *ksp, int rw)
1349 {
1350 	smb_server_t			*sv;
1351 	smb_server_legacy_kstat_t	*ksd;
1352 	int				rc;
1353 
1354 	switch (rw) {
1355 	case KSTAT_WRITE:
1356 		rc = EACCES;
1357 		break;
1358 	case KSTAT_READ:
1359 		if (!smb_server_lookup(&sv)) {
1360 			ASSERT(MUTEX_HELD(ksp->ks_lock));
1361 			ASSERT(sv->sv_legacy_ksp == ksp);
1362 			ksd = (smb_server_legacy_kstat_t *)ksp->ks_data;
1363 			ksd->ls_files.value.ui32 = sv->sv_files + sv->sv_pipes;
1364 			ksd->ls_trees.value.ui32 = sv->sv_trees;
1365 			ksd->ls_users.value.ui32 = sv->sv_users;
1366 			smb_server_release(sv);
1367 			rc = 0;
1368 			break;
1369 		}
1370 		_NOTE(FALLTHRU)
1371 	default:
1372 		rc = EIO;
1373 		break;
1374 	}
1375 	return (rc);
1376 
1377 }
1378 
1379 /*
1380  * smb_server_shutdown
1381  */
1382 static void
1383 smb_server_shutdown(smb_server_t *sv)
1384 {
1385 	SMB_SERVER_VALID(sv);
1386 
1387 	/*
1388 	 * Stop the listeners first, so we don't get any more
1389 	 * new work while we're trying to shut down.
1390 	 */
1391 	smb_server_listener_stop(&sv->sv_nbt_daemon);
1392 	smb_server_listener_stop(&sv->sv_tcp_daemon);
1393 	smb_thread_stop(&sv->si_thread_timers);
1394 
1395 	/*
1396 	 * Wake up any threads we might have blocked.
1397 	 * Must precede kdoor_close etc. because those will
1398 	 * wait for such threads to get out.
1399 	 */
1400 	smb_event_cancel(sv, 0);
1401 	smb_threshold_wake_all(&sv->sv_ssetup_ct);
1402 	smb_threshold_wake_all(&sv->sv_tcon_ct);
1403 	smb_threshold_wake_all(&sv->sv_opipe_ct);
1404 
1405 	smb_opipe_door_close(sv);
1406 	smb_kdoor_close(sv);
1407 	smb_kshare_door_fini(sv->sv_lmshrd);
1408 	sv->sv_lmshrd = NULL;
1409 	smb_export_stop(sv);
1410 
1411 	if (sv->sv_session != NULL) {
1412 		/*
1413 		 * smb_kshare_export may have a request on here.
1414 		 * Normal sessions do this in smb_session_cancel()
1415 		 * but this is a "fake" session used only for the
1416 		 * requests used by the kshare thread(s).
1417 		 */
1418 		smb_slist_wait_for_empty(&sv->sv_session->s_req_list);
1419 
1420 		smb_session_delete(sv->sv_session);
1421 		sv->sv_session = NULL;
1422 	}
1423 
1424 	if (sv->sv_receiver_pool != NULL) {
1425 		taskq_destroy(sv->sv_receiver_pool);
1426 		sv->sv_receiver_pool = NULL;
1427 	}
1428 
1429 	if (sv->sv_worker_pool != NULL) {
1430 		taskq_destroy(sv->sv_worker_pool);
1431 		sv->sv_worker_pool = NULL;
1432 	}
1433 
1434 	smb_kshare_stop(sv);
1435 	smb_server_fsop_stop(sv);
1436 }
1437 
1438 /*
1439  * smb_server_listener_init
1440  *
1441  * Initializes listener contexts.
1442  */
1443 static void
1444 smb_server_listener_init(
1445     smb_server_t		*sv,
1446     smb_listener_daemon_t	*ld,
1447     char			*name,
1448     in_port_t			port,
1449     int				family)
1450 {
1451 	ASSERT(ld->ld_magic != SMB_LISTENER_MAGIC);
1452 
1453 	bzero(ld, sizeof (*ld));
1454 
1455 	ld->ld_sv = sv;
1456 	ld->ld_family = family;
1457 	ld->ld_port = port;
1458 
1459 	if (family == AF_INET) {
1460 		ld->ld_sin.sin_family = (uint32_t)family;
1461 		ld->ld_sin.sin_port = htons(port);
1462 		ld->ld_sin.sin_addr.s_addr = htonl(INADDR_ANY);
1463 	} else {
1464 		ld->ld_sin6.sin6_family = (uint32_t)family;
1465 		ld->ld_sin6.sin6_port = htons(port);
1466 		(void) memset(&ld->ld_sin6.sin6_addr.s6_addr, 0,
1467 		    sizeof (ld->ld_sin6.sin6_addr.s6_addr));
1468 	}
1469 
1470 	smb_llist_constructor(&ld->ld_session_list, sizeof (smb_session_t),
1471 	    offsetof(smb_session_t, s_lnd));
1472 	smb_thread_init(&ld->ld_thread, name, smb_server_listener, ld,
1473 	    smbsrv_listen_pri);
1474 	ld->ld_magic = SMB_LISTENER_MAGIC;
1475 }
1476 
1477 /*
1478  * smb_server_listener_destroy
1479  *
1480  * Destroyes listener contexts.
1481  */
1482 static void
1483 smb_server_listener_destroy(smb_listener_daemon_t *ld)
1484 {
1485 	SMB_LISTENER_VALID(ld);
1486 	ASSERT(ld->ld_so == NULL);
1487 	smb_thread_destroy(&ld->ld_thread);
1488 	smb_llist_destructor(&ld->ld_session_list);
1489 	ld->ld_magic = 0;
1490 }
1491 
1492 /*
1493  * smb_server_listener_start
1494  *
1495  * Starts the listener associated with the context passed in.
1496  *
1497  * Return:	0	Success
1498  *		not 0	Failure
1499  */
1500 static int
1501 smb_server_listener_start(smb_listener_daemon_t *ld)
1502 {
1503 	int		rc;
1504 	uint32_t	on;
1505 	uint32_t	off;
1506 
1507 	SMB_LISTENER_VALID(ld);
1508 
1509 	if (ld->ld_so != NULL)
1510 		return (EINVAL);
1511 
1512 	ld->ld_so = smb_socreate(ld->ld_family, SOCK_STREAM, 0);
1513 	if (ld->ld_so == NULL) {
1514 		cmn_err(CE_WARN, "port %d: socket create failed", ld->ld_port);
1515 		return (ENOMEM);
1516 	}
1517 
1518 	off = 0;
1519 	(void) ksocket_setsockopt(ld->ld_so, SOL_SOCKET,
1520 	    SO_MAC_EXEMPT, &off, sizeof (off), CRED());
1521 
1522 	on = 1;
1523 	(void) ksocket_setsockopt(ld->ld_so, SOL_SOCKET,
1524 	    SO_REUSEADDR, &on, sizeof (on), CRED());
1525 
1526 	if (ld->ld_family == AF_INET) {
1527 		rc = ksocket_bind(ld->ld_so,
1528 		    (struct sockaddr *)&ld->ld_sin,
1529 		    sizeof (ld->ld_sin), CRED());
1530 	} else {
1531 		rc = ksocket_bind(ld->ld_so,
1532 		    (struct sockaddr *)&ld->ld_sin6,
1533 		    sizeof (ld->ld_sin6), CRED());
1534 	}
1535 
1536 	if (rc != 0) {
1537 		cmn_err(CE_WARN, "port %d: bind failed", ld->ld_port);
1538 		return (rc);
1539 	}
1540 
1541 	rc =  ksocket_listen(ld->ld_so, 20, CRED());
1542 	if (rc < 0) {
1543 		cmn_err(CE_WARN, "port %d: listen failed", ld->ld_port);
1544 		return (rc);
1545 	}
1546 
1547 	ksocket_hold(ld->ld_so);
1548 	rc = smb_thread_start(&ld->ld_thread);
1549 	if (rc != 0) {
1550 		ksocket_rele(ld->ld_so);
1551 		cmn_err(CE_WARN, "port %d: listener failed to start",
1552 		    ld->ld_port);
1553 		return (rc);
1554 	}
1555 	return (0);
1556 }
1557 
1558 /*
1559  * smb_server_listener_stop
1560  *
1561  * Stops the listener associated with the context passed in.
1562  */
1563 static void
1564 smb_server_listener_stop(smb_listener_daemon_t *ld)
1565 {
1566 	SMB_LISTENER_VALID(ld);
1567 
1568 	if (ld->ld_so != NULL) {
1569 		smb_soshutdown(ld->ld_so);
1570 		smb_sodestroy(ld->ld_so);
1571 		smb_thread_stop(&ld->ld_thread);
1572 		ld->ld_so = NULL;
1573 	}
1574 }
1575 
1576 /*
1577  * smb_server_listener
1578  *
1579  * Entry point of the listeners.
1580  */
1581 static void
1582 smb_server_listener(smb_thread_t *thread, void *arg)
1583 {
1584 	_NOTE(ARGUNUSED(thread))
1585 	smb_listener_daemon_t	*ld;
1586 	smb_session_t		*session;
1587 	ksocket_t		s_so;
1588 	int			on;
1589 	int			txbuf_size;
1590 
1591 	ld = (smb_listener_daemon_t *)arg;
1592 
1593 	SMB_LISTENER_VALID(ld);
1594 
1595 	DTRACE_PROBE1(so__wait__accept, struct sonode *, ld->ld_so);
1596 
1597 	while (ksocket_accept(ld->ld_so, NULL, NULL, &s_so, CRED())
1598 	    == 0) {
1599 		DTRACE_PROBE1(so__accept, struct sonode *, s_so);
1600 
1601 		on = 1;
1602 		(void) ksocket_setsockopt(s_so, IPPROTO_TCP, TCP_NODELAY,
1603 		    &on, sizeof (on), CRED());
1604 
1605 		on = 1;
1606 		(void) ksocket_setsockopt(s_so, SOL_SOCKET, SO_KEEPALIVE,
1607 		    &on, sizeof (on), CRED());
1608 
1609 		txbuf_size = 128*1024;
1610 		(void) ksocket_setsockopt(s_so, SOL_SOCKET, SO_SNDBUF,
1611 		    (const void *)&txbuf_size, sizeof (txbuf_size), CRED());
1612 
1613 		/*
1614 		 * Create a session for this connection.
1615 		 */
1616 		smb_server_create_session(ld, s_so);
1617 	}
1618 	/* Disconnect all the sessions this listener created. */
1619 	smb_llist_enter(&ld->ld_session_list, RW_READER);
1620 	session = smb_llist_head(&ld->ld_session_list);
1621 	while (session != NULL) {
1622 		smb_session_disconnect(session);
1623 		session = smb_llist_next(&ld->ld_session_list, session);
1624 	}
1625 	smb_llist_exit(&ld->ld_session_list);
1626 	ksocket_rele(ld->ld_so);
1627 }
1628 
1629 /*
1630  * smb_server_receiver
1631  *
1632  * Entry point of the receiver threads.
1633  */
1634 static void
1635 smb_server_receiver(void *arg)
1636 {
1637 	smb_listener_daemon_t	*ld;
1638 	smb_session_t		*session;
1639 
1640 	ld = ((smb_receiver_arg_t *)arg)->ra_listener;
1641 	session = ((smb_receiver_arg_t *)arg)->ra_session;
1642 	smb_mem_free(arg);
1643 	smb_session_receiver(session);
1644 	smb_server_destroy_session(ld, session);
1645 }
1646 
1647 /*
1648  * smb_server_lookup
1649  *
1650  * This function finds the server associated with the zone of the
1651  * caller.  Note: requires a fix in the dynamic taskq code:
1652  * 1501 taskq_create_proc ... TQ_DYNAMIC puts tasks in p0
1653  */
1654 int
1655 smb_server_lookup(smb_server_t **psv)
1656 {
1657 	zoneid_t	zid;
1658 	smb_server_t	*sv;
1659 
1660 	zid = getzoneid();
1661 
1662 	smb_llist_enter(&smb_servers, RW_READER);
1663 	sv = smb_llist_head(&smb_servers);
1664 	while (sv) {
1665 		SMB_SERVER_VALID(sv);
1666 		if (sv->sv_zid == zid) {
1667 			mutex_enter(&sv->sv_mutex);
1668 			if (sv->sv_state != SMB_SERVER_STATE_DELETING) {
1669 				sv->sv_refcnt++;
1670 				mutex_exit(&sv->sv_mutex);
1671 				smb_llist_exit(&smb_servers);
1672 				*psv = sv;
1673 				return (0);
1674 			}
1675 			mutex_exit(&sv->sv_mutex);
1676 			break;
1677 		}
1678 		sv = smb_llist_next(&smb_servers, sv);
1679 	}
1680 	smb_llist_exit(&smb_servers);
1681 	return (EPERM);
1682 }
1683 
1684 /*
1685  * smb_server_release
1686  *
1687  * This function decrements the reference count of the server and signals its
1688  * condition variable if the state of the server is SMB_SERVER_STATE_DELETING.
1689  */
1690 void
1691 smb_server_release(smb_server_t *sv)
1692 {
1693 	SMB_SERVER_VALID(sv);
1694 
1695 	mutex_enter(&sv->sv_mutex);
1696 	ASSERT(sv->sv_refcnt);
1697 	sv->sv_refcnt--;
1698 	if ((sv->sv_refcnt == 0) && (sv->sv_state == SMB_SERVER_STATE_DELETING))
1699 		cv_signal(&sv->sv_cv);
1700 	mutex_exit(&sv->sv_mutex);
1701 }
1702 
1703 /*
1704  * Enumerate the users associated with a session list.
1705  */
1706 static void
1707 smb_server_enum_users(smb_llist_t *ll, smb_svcenum_t *svcenum)
1708 {
1709 	smb_session_t	*sn;
1710 	smb_llist_t	*ulist;
1711 	smb_user_t	*user;
1712 	int		rc = 0;
1713 
1714 	smb_llist_enter(ll, RW_READER);
1715 	sn = smb_llist_head(ll);
1716 
1717 	while (sn != NULL) {
1718 		SMB_SESSION_VALID(sn);
1719 		ulist = &sn->s_user_list;
1720 		smb_llist_enter(ulist, RW_READER);
1721 		user = smb_llist_head(ulist);
1722 
1723 		while (user != NULL) {
1724 			if (smb_user_hold(user)) {
1725 				rc = smb_user_enum(user, svcenum);
1726 				smb_user_release(user);
1727 				if (rc != 0)
1728 					break;
1729 			}
1730 
1731 			user = smb_llist_next(ulist, user);
1732 		}
1733 
1734 		smb_llist_exit(ulist);
1735 
1736 		if (rc != 0)
1737 			break;
1738 
1739 		sn = smb_llist_next(ll, sn);
1740 	}
1741 
1742 	smb_llist_exit(ll);
1743 }
1744 
1745 /*
1746  * Enumerate the trees/files associated with a session list.
1747  */
1748 static void
1749 smb_server_enum_trees(smb_llist_t *ll, smb_svcenum_t *svcenum)
1750 {
1751 	smb_session_t	*sn;
1752 	smb_llist_t	*tlist;
1753 	smb_tree_t	*tree;
1754 	int		rc = 0;
1755 
1756 	smb_llist_enter(ll, RW_READER);
1757 	sn = smb_llist_head(ll);
1758 
1759 	while (sn != NULL) {
1760 		SMB_SESSION_VALID(sn);
1761 		tlist = &sn->s_tree_list;
1762 		smb_llist_enter(tlist, RW_READER);
1763 		tree = smb_llist_head(tlist);
1764 
1765 		while (tree != NULL) {
1766 			if (smb_tree_hold(tree)) {
1767 				rc = smb_tree_enum(tree, svcenum);
1768 				smb_tree_release(tree);
1769 				if (rc != 0)
1770 					break;
1771 			}
1772 
1773 			tree = smb_llist_next(tlist, tree);
1774 		}
1775 
1776 		smb_llist_exit(tlist);
1777 
1778 		if (rc != 0)
1779 			break;
1780 
1781 		sn = smb_llist_next(ll, sn);
1782 	}
1783 
1784 	smb_llist_exit(ll);
1785 }
1786 
1787 /*
1788  * Disconnect sessions associated with the specified client and username.
1789  * Empty strings are treated as wildcards.
1790  */
1791 static int
1792 smb_server_session_disconnect(smb_llist_t *ll,
1793     const char *client, const char *name)
1794 {
1795 	smb_session_t	*sn;
1796 	smb_llist_t	*ulist;
1797 	smb_user_t	*user;
1798 	boolean_t	match;
1799 	int		count = 0;
1800 
1801 	smb_llist_enter(ll, RW_READER);
1802 	sn = smb_llist_head(ll);
1803 
1804 	while (sn != NULL) {
1805 		SMB_SESSION_VALID(sn);
1806 
1807 		if ((*client != '\0') && (!smb_session_isclient(sn, client))) {
1808 			sn = smb_llist_next(ll, sn);
1809 			continue;
1810 		}
1811 
1812 		ulist = &sn->s_user_list;
1813 		smb_llist_enter(ulist, RW_READER);
1814 		user = smb_llist_head(ulist);
1815 
1816 		while (user != NULL) {
1817 			if (smb_user_hold(user)) {
1818 				match = (*name == '\0');
1819 				if (!match)
1820 					match = smb_user_namecmp(user, name);
1821 
1822 				if (match) {
1823 					smb_llist_exit(ulist);
1824 					smb_user_logoff(user);
1825 					++count;
1826 					smb_user_release(user);
1827 					smb_llist_enter(ulist, RW_READER);
1828 					user = smb_llist_head(ulist);
1829 					continue;
1830 				}
1831 
1832 				smb_user_release(user);
1833 			}
1834 
1835 			user = smb_llist_next(ulist, user);
1836 		}
1837 
1838 		smb_llist_exit(ulist);
1839 		sn = smb_llist_next(ll, sn);
1840 	}
1841 
1842 	smb_llist_exit(ll);
1843 	return (count);
1844 }
1845 
1846 /*
1847  * Close a file by its unique id.
1848  */
1849 static int
1850 smb_server_fclose(smb_llist_t *ll, uint32_t uniqid)
1851 {
1852 	smb_session_t	*sn;
1853 	smb_llist_t	*tlist;
1854 	smb_tree_t	*tree;
1855 	int		rc = ENOENT;
1856 
1857 	smb_llist_enter(ll, RW_READER);
1858 	sn = smb_llist_head(ll);
1859 
1860 	while ((sn != NULL) && (rc == ENOENT)) {
1861 		SMB_SESSION_VALID(sn);
1862 		tlist = &sn->s_tree_list;
1863 		smb_llist_enter(tlist, RW_READER);
1864 		tree = smb_llist_head(tlist);
1865 
1866 		while ((tree != NULL) && (rc == ENOENT)) {
1867 			if (smb_tree_hold(tree)) {
1868 				rc = smb_tree_fclose(tree, uniqid);
1869 				smb_tree_release(tree);
1870 			}
1871 
1872 			tree = smb_llist_next(tlist, tree);
1873 		}
1874 
1875 		smb_llist_exit(tlist);
1876 		sn = smb_llist_next(ll, sn);
1877 	}
1878 
1879 	smb_llist_exit(ll);
1880 	return (rc);
1881 }
1882 
1883 static void
1884 smb_server_store_cfg(smb_server_t *sv, smb_ioc_cfg_t *ioc)
1885 {
1886 	if (ioc->maxconnections == 0)
1887 		ioc->maxconnections = 0xFFFFFFFF;
1888 
1889 	smb_session_correct_keep_alive_values(
1890 	    &sv->sv_nbt_daemon.ld_session_list, ioc->keepalive);
1891 	smb_session_correct_keep_alive_values(
1892 	    &sv->sv_tcp_daemon.ld_session_list, ioc->keepalive);
1893 
1894 	sv->sv_cfg.skc_maxworkers = ioc->maxworkers;
1895 	sv->sv_cfg.skc_maxconnections = ioc->maxconnections;
1896 	sv->sv_cfg.skc_keepalive = ioc->keepalive;
1897 	sv->sv_cfg.skc_restrict_anon = ioc->restrict_anon;
1898 	sv->sv_cfg.skc_signing_enable = ioc->signing_enable;
1899 	sv->sv_cfg.skc_signing_required = ioc->signing_required;
1900 	sv->sv_cfg.skc_oplock_enable = ioc->oplock_enable;
1901 	sv->sv_cfg.skc_sync_enable = ioc->sync_enable;
1902 	sv->sv_cfg.skc_secmode = ioc->secmode;
1903 	sv->sv_cfg.skc_ipv6_enable = ioc->ipv6_enable;
1904 	sv->sv_cfg.skc_print_enable = ioc->print_enable;
1905 	sv->sv_cfg.skc_traverse_mounts = ioc->traverse_mounts;
1906 	sv->sv_cfg.skc_execflags = ioc->exec_flags;
1907 	sv->sv_cfg.skc_version = ioc->version;
1908 	(void) strlcpy(sv->sv_cfg.skc_nbdomain, ioc->nbdomain,
1909 	    sizeof (sv->sv_cfg.skc_nbdomain));
1910 	(void) strlcpy(sv->sv_cfg.skc_fqdn, ioc->fqdn,
1911 	    sizeof (sv->sv_cfg.skc_fqdn));
1912 	(void) strlcpy(sv->sv_cfg.skc_hostname, ioc->hostname,
1913 	    sizeof (sv->sv_cfg.skc_hostname));
1914 	(void) strlcpy(sv->sv_cfg.skc_system_comment, ioc->system_comment,
1915 	    sizeof (sv->sv_cfg.skc_system_comment));
1916 
1917 	if (sv->sv_cfg.skc_oplock_enable && smb_raw_mode) {
1918 		/*
1919 		 * Note that these two optional protocol features
1920 		 * (oplocks, raw_mode) have unfortunate interactions.
1921 		 * Since raw_mode is only wanted by ancient clients,
1922 		 * we just turn it off (that's what MS recommends).
1923 		 * Leave some evidence in the log if someone has
1924 		 * patched smb_raw_mode to enable it.
1925 		 */
1926 		cmn_err(CE_NOTE,
1927 		    "Raw mode enabled: Disabling opportunistic locks");
1928 		sv->sv_cfg.skc_oplock_enable = 0;
1929 	}
1930 }
1931 
1932 static int
1933 smb_server_fsop_start(smb_server_t *sv)
1934 {
1935 	int	error;
1936 
1937 	error = smb_node_root_init(sv, &sv->si_root_smb_node);
1938 	if (error != 0)
1939 		sv->si_root_smb_node = NULL;
1940 
1941 	return (error);
1942 }
1943 
1944 static void
1945 smb_server_fsop_stop(smb_server_t *sv)
1946 {
1947 	if (sv->si_root_smb_node != NULL) {
1948 		smb_node_release(sv->si_root_smb_node);
1949 		sv->si_root_smb_node = NULL;
1950 	}
1951 }
1952 
1953 smb_event_t *
1954 smb_event_create(smb_server_t *sv, int timeout)
1955 {
1956 	smb_event_t	*event;
1957 
1958 	if (smb_server_is_stopping(sv))
1959 		return (NULL);
1960 
1961 	event = kmem_cache_alloc(smb_cache_event, KM_SLEEP);
1962 
1963 	bzero(event, sizeof (smb_event_t));
1964 	mutex_init(&event->se_mutex, NULL, MUTEX_DEFAULT, NULL);
1965 	cv_init(&event->se_cv, NULL, CV_DEFAULT, NULL);
1966 	event->se_magic = SMB_EVENT_MAGIC;
1967 	event->se_txid = smb_event_alloc_txid();
1968 	event->se_server = sv;
1969 	event->se_timeout = timeout;
1970 
1971 	smb_llist_enter(&sv->sv_event_list, RW_WRITER);
1972 	smb_llist_insert_tail(&sv->sv_event_list, event);
1973 	smb_llist_exit(&sv->sv_event_list);
1974 
1975 	return (event);
1976 }
1977 
1978 void
1979 smb_event_destroy(smb_event_t *event)
1980 {
1981 	smb_server_t	*sv;
1982 
1983 	if (event == NULL)
1984 		return;
1985 
1986 	SMB_EVENT_VALID(event);
1987 	ASSERT(event->se_waittime == 0);
1988 	sv = event->se_server;
1989 	SMB_SERVER_VALID(sv);
1990 
1991 	smb_llist_enter(&sv->sv_event_list, RW_WRITER);
1992 	smb_llist_remove(&sv->sv_event_list, event);
1993 	smb_llist_exit(&sv->sv_event_list);
1994 
1995 	event->se_magic = (uint32_t)~SMB_EVENT_MAGIC;
1996 	cv_destroy(&event->se_cv);
1997 	mutex_destroy(&event->se_mutex);
1998 
1999 	kmem_cache_free(smb_cache_event, event);
2000 }
2001 
2002 /*
2003  * Get the txid for the specified event.
2004  */
2005 uint32_t
2006 smb_event_txid(smb_event_t *event)
2007 {
2008 	if (event != NULL) {
2009 		SMB_EVENT_VALID(event);
2010 		return (event->se_txid);
2011 	}
2012 
2013 	cmn_err(CE_NOTE, "smb_event_txid failed");
2014 	return ((uint32_t)-1);
2015 }
2016 
2017 /*
2018  * Wait for event notification.
2019  */
2020 int
2021 smb_event_wait(smb_event_t *event)
2022 {
2023 	int	seconds = 1;
2024 	int	ticks;
2025 	int	err;
2026 
2027 	if (event == NULL)
2028 		return (EINVAL);
2029 
2030 	SMB_EVENT_VALID(event);
2031 
2032 	mutex_enter(&event->se_mutex);
2033 	event->se_waittime = 1;
2034 	event->se_errno = 0;
2035 
2036 	while (!(event->se_notified)) {
2037 		if (smb_event_debug && ((event->se_waittime % 30) == 0))
2038 			cmn_err(CE_NOTE, "smb_event_wait[%d] (%d sec)",
2039 			    event->se_txid, event->se_waittime);
2040 
2041 		if (event->se_errno != 0)
2042 			break;
2043 
2044 		if (event->se_waittime > event->se_timeout) {
2045 			event->se_errno = ETIME;
2046 			break;
2047 		}
2048 
2049 		ticks = SEC_TO_TICK(seconds);
2050 		(void) cv_reltimedwait(&event->se_cv,
2051 		    &event->se_mutex, (clock_t)ticks, TR_CLOCK_TICK);
2052 		++event->se_waittime;
2053 	}
2054 
2055 	err = event->se_errno;
2056 	event->se_waittime = 0;
2057 	event->se_notified = B_FALSE;
2058 	cv_signal(&event->se_cv);
2059 	mutex_exit(&event->se_mutex);
2060 	return (err);
2061 }
2062 
2063 /*
2064  * If txid is non-zero, cancel the specified event.
2065  * Otherwise, cancel all events.
2066  */
2067 static void
2068 smb_event_cancel(smb_server_t *sv, uint32_t txid)
2069 {
2070 	smb_event_t	*event;
2071 	smb_llist_t	*event_list;
2072 
2073 	SMB_SERVER_VALID(sv);
2074 
2075 	event_list = &sv->sv_event_list;
2076 	smb_llist_enter(event_list, RW_WRITER);
2077 
2078 	event = smb_llist_head(event_list);
2079 	while (event) {
2080 		SMB_EVENT_VALID(event);
2081 
2082 		if (txid == 0 || event->se_txid == txid) {
2083 			mutex_enter(&event->se_mutex);
2084 			event->se_errno = ECANCELED;
2085 			event->se_notified = B_TRUE;
2086 			cv_signal(&event->se_cv);
2087 			mutex_exit(&event->se_mutex);
2088 
2089 			if (txid != 0)
2090 				break;
2091 		}
2092 
2093 		event = smb_llist_next(event_list, event);
2094 	}
2095 
2096 	smb_llist_exit(event_list);
2097 }
2098 
2099 /*
2100  * If txid is non-zero, notify the specified event.
2101  * Otherwise, notify all events.
2102  */
2103 void
2104 smb_event_notify(smb_server_t *sv, uint32_t txid)
2105 {
2106 	smb_event_t	*event;
2107 	smb_llist_t	*event_list;
2108 
2109 	SMB_SERVER_VALID(sv);
2110 
2111 	event_list = &sv->sv_event_list;
2112 	smb_llist_enter(event_list, RW_READER);
2113 
2114 	event = smb_llist_head(event_list);
2115 	while (event) {
2116 		SMB_EVENT_VALID(event);
2117 
2118 		if (txid == 0 || event->se_txid == txid) {
2119 			mutex_enter(&event->se_mutex);
2120 			event->se_notified = B_TRUE;
2121 			cv_signal(&event->se_cv);
2122 			mutex_exit(&event->se_mutex);
2123 
2124 			if (txid != 0)
2125 				break;
2126 		}
2127 
2128 		event = smb_llist_next(event_list, event);
2129 	}
2130 
2131 	smb_llist_exit(event_list);
2132 }
2133 
2134 /*
2135  * Allocate a new transaction id (txid).
2136  *
2137  * 0 or -1 are not assigned because they are used to detect invalid
2138  * conditions or to indicate all open id's.
2139  */
2140 static uint32_t
2141 smb_event_alloc_txid(void)
2142 {
2143 	static kmutex_t	txmutex;
2144 	static uint32_t	txid;
2145 	uint32_t	txid_ret;
2146 
2147 	mutex_enter(&txmutex);
2148 
2149 	if (txid == 0)
2150 		txid = ddi_get_lbolt() << 11;
2151 
2152 	do {
2153 		++txid;
2154 	} while (txid == 0 || txid == (uint32_t)-1);
2155 
2156 	txid_ret = txid;
2157 	mutex_exit(&txmutex);
2158 
2159 	return (txid_ret);
2160 }
2161 
2162 /*
2163  * Called by the ioctl to find the corresponding
2164  * spooldoc node.  removes node on success
2165  *
2166  * Return values
2167  * rc
2168  * B_FALSE - not found
2169  * B_TRUE  - found
2170  *
2171  */
2172 
2173 static boolean_t
2174 smb_spool_lookup_doc_byfid(smb_server_t *sv, uint16_t fid,
2175     smb_kspooldoc_t *spdoc)
2176 {
2177 	smb_kspooldoc_t *sp;
2178 	smb_llist_t	*splist;
2179 
2180 	splist = &sv->sp_info.sp_list;
2181 	smb_llist_enter(splist, RW_WRITER);
2182 	sp = smb_llist_head(splist);
2183 	while (sp != NULL) {
2184 		/*
2185 		 * check for a matching fid
2186 		 */
2187 		if (sp->sd_fid == fid) {
2188 			*spdoc = *sp;
2189 			smb_llist_remove(splist, sp);
2190 			smb_llist_exit(splist);
2191 			kmem_free(sp, sizeof (smb_kspooldoc_t));
2192 			return (B_TRUE);
2193 		}
2194 		sp = smb_llist_next(splist, sp);
2195 	}
2196 	cmn_err(CE_WARN, "smb_spool_lookup_user_byfid: no fid:%d", fid);
2197 	smb_llist_exit(splist);
2198 	return (B_FALSE);
2199 }
2200 
2201 /*
2202  * Adds the spool fid to a linked list to be used
2203  * as a search key in the spooldoc queue
2204  *
2205  * Return values
2206  *      rc non-zero error
2207  *	rc zero success
2208  *
2209  */
2210 
2211 void
2212 smb_spool_add_fid(smb_server_t *sv, uint16_t fid)
2213 {
2214 	smb_llist_t	*fidlist;
2215 	smb_spoolfid_t  *sf;
2216 
2217 	if (sv->sv_cfg.skc_print_enable == 0)
2218 		return;
2219 
2220 	sf = kmem_zalloc(sizeof (smb_spoolfid_t), KM_SLEEP);
2221 	fidlist = &sv->sp_info.sp_fidlist;
2222 	smb_llist_enter(fidlist, RW_WRITER);
2223 	sf->sf_fid = fid;
2224 	smb_llist_insert_tail(fidlist, sf);
2225 	smb_llist_exit(fidlist);
2226 	cv_broadcast(&sv->sp_info.sp_cv);
2227 }
2228 
2229 /*
2230  * Called by the ioctl to get and remove the head of the fid list
2231  *
2232  * Return values
2233  * int fd
2234  * greater than 0 success
2235  * 0 - error
2236  *
2237  */
2238 
2239 static uint16_t
2240 smb_spool_get_fid(smb_server_t *sv)
2241 {
2242 	smb_spoolfid_t	*spfid;
2243 	smb_llist_t	*splist;
2244 	uint16_t	fid;
2245 
2246 	splist = &sv->sp_info.sp_fidlist;
2247 	smb_llist_enter(splist, RW_WRITER);
2248 	spfid = smb_llist_head(splist);
2249 	if (spfid != NULL) {
2250 		fid = spfid->sf_fid;
2251 		smb_llist_remove(&sv->sp_info.sp_fidlist, spfid);
2252 		kmem_free(spfid, sizeof (smb_spoolfid_t));
2253 	} else {
2254 		fid = 0;
2255 	}
2256 	smb_llist_exit(splist);
2257 	return (fid);
2258 }
2259 
2260 /*
2261  * Adds the spooldoc to the tail of the spooldoc list
2262  *
2263  * Return values
2264  *      rc non-zero error
2265  *	rc zero success
2266  */
2267 int
2268 smb_spool_add_doc(smb_tree_t *tree, smb_kspooldoc_t *sp)
2269 {
2270 	smb_llist_t	*splist;
2271 	smb_server_t	*sv = tree->t_server;
2272 	int rc = 0;
2273 
2274 	splist = &sv->sp_info.sp_list;
2275 	smb_llist_enter(splist, RW_WRITER);
2276 	sp->sd_spool_num = atomic_inc_32_nv(&sv->sp_info.sp_cnt);
2277 	smb_llist_insert_tail(splist, sp);
2278 	smb_llist_exit(splist);
2279 
2280 	return (rc);
2281 }
2282 
2283 /*
2284  * smb_server_create_session
2285  */
2286 static void
2287 smb_server_create_session(smb_listener_daemon_t *ld, ksocket_t s_so)
2288 {
2289 	smb_session_t		*session;
2290 	smb_receiver_arg_t	*rarg;
2291 	taskqid_t		tqid;
2292 
2293 	session = smb_session_create(s_so, ld->ld_port, ld->ld_sv,
2294 	    ld->ld_family);
2295 
2296 	if (session == NULL) {
2297 		smb_soshutdown(s_so);
2298 		smb_sodestroy(s_so);
2299 		cmn_err(CE_WARN, "SMB Session: alloc failed");
2300 		return;
2301 	}
2302 
2303 	smb_llist_enter(&ld->ld_session_list, RW_WRITER);
2304 	smb_llist_insert_tail(&ld->ld_session_list, session);
2305 	smb_llist_exit(&ld->ld_session_list);
2306 
2307 	rarg = (smb_receiver_arg_t *)smb_mem_alloc(
2308 	    sizeof (smb_receiver_arg_t));
2309 	rarg->ra_listener = ld;
2310 	rarg->ra_session = session;
2311 
2312 	/*
2313 	 * These taskq entries must run independently of one another,
2314 	 * so TQ_NOQUEUE.  TQ_SLEEP (==0) just for clarity.
2315 	 */
2316 	tqid = taskq_dispatch(ld->ld_sv->sv_receiver_pool,
2317 	    smb_server_receiver, rarg, TQ_NOQUEUE | TQ_SLEEP);
2318 	if (tqid == 0) {
2319 		smb_mem_free(rarg);
2320 		smb_session_disconnect(session);
2321 		smb_server_destroy_session(ld, session);
2322 		cmn_err(CE_WARN, "SMB Session: taskq_dispatch failed");
2323 		return;
2324 	}
2325 	/* handy for debugging */
2326 	session->s_receiver_tqid = tqid;
2327 }
2328 
2329 static void
2330 smb_server_destroy_session(smb_listener_daemon_t *ld, smb_session_t *session)
2331 {
2332 	smb_llist_enter(&ld->ld_session_list, RW_WRITER);
2333 	smb_llist_remove(&ld->ld_session_list, session);
2334 	smb_llist_exit(&ld->ld_session_list);
2335 	smb_session_delete(session);
2336 }
2337