1 // SPDX-License-Identifier: GPL-2.0-or-later 2 /* 3 * Copyright (C) 2016 Namjae Jeon <linkinjeon@kernel.org> 4 * Copyright (C) 2018 Samsung Electronics Co., Ltd. 5 */ 6 7 #include <crypto/utils.h> 8 #include <linux/inetdevice.h> 9 #include <net/addrconf.h> 10 #include <linux/syscalls.h> 11 #include <linux/namei.h> 12 #include <linux/statfs.h> 13 #include <linux/ethtool.h> 14 #include <linux/falloc.h> 15 #include <linux/mount.h> 16 #include <linux/filelock.h> 17 #include <linux/fileattr.h> 18 19 #include "glob.h" 20 #include "../common/smbfsctl.h" 21 #include "oplock.h" 22 #include "smbacl.h" 23 24 #include "auth.h" 25 #include "asn1.h" 26 #include "connection.h" 27 #include "transport_ipc.h" 28 #include "transport_rdma.h" 29 #include "vfs.h" 30 #include "vfs_cache.h" 31 #include "misc.h" 32 33 #include "server.h" 34 #include "smb_common.h" 35 #include "../common/smb2status.h" 36 #include "ksmbd_work.h" 37 #include "mgmt/user_config.h" 38 #include "mgmt/share_config.h" 39 #include "mgmt/tree_connect.h" 40 #include "mgmt/user_session.h" 41 #include "mgmt/ksmbd_ida.h" 42 #include "ndr.h" 43 #include "stats.h" 44 #include "transport_tcp.h" 45 #include "compress.h" 46 47 static void __wbuf(struct ksmbd_work *work, void **req, void **rsp) 48 { 49 if (work->next_smb2_rcv_hdr_off) { 50 *req = ksmbd_req_buf_next(work); 51 *rsp = ksmbd_resp_buf_next(work); 52 } else { 53 *req = smb_get_msg(work->request_buf); 54 *rsp = smb_get_msg(work->response_buf); 55 } 56 } 57 58 #define WORK_BUFFERS(w, rq, rs) __wbuf((w), (void **)&(rq), (void **)&(rs)) 59 60 #define SMB2_CREATE_FILE_ATTRIBUTE_MASK \ 61 (FILE_ATTRIBUTE_MASK & ~(FILE_ATTRIBUTE_INTEGRITY_STREAM | \ 62 FILE_ATTRIBUTE_NO_SCRUB_DATA)) 63 64 /** 65 * check_session_id() - check for valid session id in smb header 66 * @conn: connection instance 67 * @id: session id from smb header 68 * 69 * Return: 1 if valid session id, otherwise 0 70 */ 71 static inline bool check_session_id(struct ksmbd_conn *conn, u64 id) 72 { 73 struct ksmbd_session *sess; 74 75 if (id == 0 || id == -1) 76 return false; 77 78 sess = ksmbd_session_lookup_all(conn, id); 79 if (sess) { 80 ksmbd_user_session_put(sess); 81 return true; 82 } 83 pr_err("Invalid user session id: %llu\n", id); 84 return false; 85 } 86 87 struct channel *lookup_chann_list(struct ksmbd_session *sess, struct ksmbd_conn *conn) 88 { 89 struct channel *chann; 90 91 down_read(&sess->chann_lock); 92 chann = xa_load(&sess->ksmbd_chann_list, (long)conn); 93 up_read(&sess->chann_lock); 94 95 return chann; 96 } 97 98 /** 99 * smb2_get_ksmbd_tcon() - get tree connection information using a tree id. 100 * @work: smb work 101 * 102 * Return: 0 if there is a tree connection matched or these are 103 * skipable commands, otherwise error 104 */ 105 int smb2_get_ksmbd_tcon(struct ksmbd_work *work) 106 { 107 struct smb2_hdr *req_hdr = ksmbd_req_buf_next(work); 108 unsigned int cmd = le16_to_cpu(req_hdr->Command); 109 unsigned int tree_id; 110 111 if (cmd == SMB2_TREE_CONNECT_HE || 112 cmd == SMB2_CANCEL_HE || 113 cmd == SMB2_LOGOFF_HE) { 114 ksmbd_debug(SMB, "skip to check tree connect request\n"); 115 return 0; 116 } 117 118 if (xa_empty(&work->sess->tree_conns)) { 119 ksmbd_debug(SMB, "NO tree connected\n"); 120 return -ENOENT; 121 } 122 123 tree_id = le32_to_cpu(req_hdr->Id.SyncId.TreeId); 124 125 /* 126 * If request is not the first in Compound request, 127 * Just validate tree id in header with work->tcon->id. 128 */ 129 if (work->next_smb2_rcv_hdr_off) { 130 if (!work->tcon) { 131 pr_err("The first operation in the compound does not have tcon\n"); 132 return -EINVAL; 133 } 134 if (work->tcon->t_state != TREE_CONNECTED) 135 return -ENOENT; 136 if (tree_id != UINT_MAX && work->tcon->id != tree_id) { 137 pr_err("tree id(%u) is different with id(%u) in first operation\n", 138 tree_id, work->tcon->id); 139 return -EINVAL; 140 } 141 return 1; 142 } 143 144 work->tcon = ksmbd_tree_conn_lookup(work->sess, tree_id); 145 if (!work->tcon) { 146 pr_err("Invalid tid %d\n", tree_id); 147 return -ENOENT; 148 } 149 150 return 1; 151 } 152 153 /** 154 * smb2_set_err_rsp() - set error response code on smb response 155 * @work: smb work containing response buffer 156 */ 157 void smb2_set_err_rsp(struct ksmbd_work *work) 158 { 159 struct smb2_err_rsp *err_rsp; 160 161 if (work->next_smb2_rcv_hdr_off) 162 err_rsp = ksmbd_resp_buf_next(work); 163 else 164 err_rsp = smb_get_msg(work->response_buf); 165 166 if (err_rsp->hdr.Status != STATUS_STOPPED_ON_SYMLINK) { 167 int err; 168 169 err_rsp->StructureSize = SMB2_ERROR_STRUCTURE_SIZE2_LE; 170 err_rsp->ErrorContextCount = 0; 171 err_rsp->Reserved = 0; 172 err_rsp->ByteCount = 0; 173 err_rsp->ErrorData[0] = 0; 174 err = ksmbd_iov_pin_rsp(work, (void *)err_rsp, 175 __SMB2_HEADER_STRUCTURE_SIZE + 176 SMB2_ERROR_STRUCTURE_SIZE2); 177 if (err) 178 work->send_no_response = 1; 179 } 180 } 181 182 /** 183 * is_smb2_neg_cmd() - is it smb2 negotiation command 184 * @work: smb work containing smb header 185 * 186 * Return: true if smb2 negotiation command, otherwise false 187 */ 188 bool is_smb2_neg_cmd(struct ksmbd_work *work) 189 { 190 struct smb2_hdr *hdr = smb_get_msg(work->request_buf); 191 192 /* is it SMB2 header ? */ 193 if (hdr->ProtocolId != SMB2_PROTO_NUMBER) 194 return false; 195 196 /* make sure it is request not response message */ 197 if (hdr->Flags & SMB2_FLAGS_SERVER_TO_REDIR) 198 return false; 199 200 if (hdr->Command != SMB2_NEGOTIATE) 201 return false; 202 203 return true; 204 } 205 206 /** 207 * is_smb2_rsp() - is it smb2 response 208 * @work: smb work containing smb response buffer 209 * 210 * Return: true if smb2 response, otherwise false 211 */ 212 bool is_smb2_rsp(struct ksmbd_work *work) 213 { 214 struct smb2_hdr *hdr = smb_get_msg(work->response_buf); 215 216 /* is it SMB2 header ? */ 217 if (hdr->ProtocolId != SMB2_PROTO_NUMBER) 218 return false; 219 220 /* make sure it is response not request message */ 221 if (!(hdr->Flags & SMB2_FLAGS_SERVER_TO_REDIR)) 222 return false; 223 224 return true; 225 } 226 227 /** 228 * get_smb2_cmd_val() - get smb command code from smb header 229 * @work: smb work containing smb request buffer 230 * 231 * Return: smb2 request command value 232 */ 233 u16 get_smb2_cmd_val(struct ksmbd_work *work) 234 { 235 struct smb2_hdr *rcv_hdr; 236 237 if (work->next_smb2_rcv_hdr_off) 238 rcv_hdr = ksmbd_req_buf_next(work); 239 else 240 rcv_hdr = smb_get_msg(work->request_buf); 241 return le16_to_cpu(rcv_hdr->Command); 242 } 243 244 /** 245 * set_smb2_rsp_status() - set error response code on smb2 header 246 * @work: smb work containing response buffer 247 * @err: error response code 248 */ 249 void set_smb2_rsp_status(struct ksmbd_work *work, __le32 err) 250 { 251 struct smb2_hdr *rsp_hdr; 252 253 if (work->next_smb2_rcv_hdr_off) { 254 rsp_hdr = ksmbd_resp_buf_next(work); 255 rsp_hdr->Status = err; 256 smb2_set_err_rsp(work); 257 return; 258 } 259 260 rsp_hdr = smb_get_msg(work->response_buf); 261 rsp_hdr->Status = err; 262 263 work->iov_idx = 0; 264 work->iov_cnt = 0; 265 work->next_smb2_rcv_hdr_off = 0; 266 smb2_set_err_rsp(work); 267 } 268 269 /** 270 * init_smb2_neg_rsp() - initialize smb2 response for negotiate command 271 * @work: smb work containing smb request buffer 272 * 273 * smb2 negotiate response is sent in reply of smb1 negotiate command for 274 * dialect auto-negotiation. 275 */ 276 int init_smb2_neg_rsp(struct ksmbd_work *work) 277 { 278 struct smb2_hdr *rsp_hdr; 279 struct smb2_negotiate_rsp *rsp; 280 struct ksmbd_conn *conn = work->conn; 281 int err; 282 283 rsp_hdr = smb_get_msg(work->response_buf); 284 memset(rsp_hdr, 0, sizeof(struct smb2_hdr) + 2); 285 rsp_hdr->ProtocolId = SMB2_PROTO_NUMBER; 286 rsp_hdr->StructureSize = SMB2_HEADER_STRUCTURE_SIZE; 287 rsp_hdr->CreditRequest = cpu_to_le16(2); 288 rsp_hdr->Command = SMB2_NEGOTIATE; 289 rsp_hdr->Flags = (SMB2_FLAGS_SERVER_TO_REDIR); 290 rsp_hdr->NextCommand = 0; 291 rsp_hdr->MessageId = 0; 292 rsp_hdr->Id.SyncId.ProcessId = 0; 293 rsp_hdr->Id.SyncId.TreeId = 0; 294 rsp_hdr->SessionId = 0; 295 memset(rsp_hdr->Signature, 0, 16); 296 297 rsp = smb_get_msg(work->response_buf); 298 299 WARN_ON(ksmbd_conn_good(conn)); 300 301 rsp->StructureSize = cpu_to_le16(65); 302 ksmbd_debug(SMB, "conn->dialect 0x%x\n", conn->dialect); 303 rsp->DialectRevision = cpu_to_le16(conn->dialect); 304 /* Not setting conn guid rsp->ServerGUID, as it 305 * not used by client for identifying connection 306 */ 307 rsp->Capabilities = cpu_to_le32(conn->vals->req_capabilities); 308 /* Default Max Message Size till SMB2.0, 64K*/ 309 rsp->MaxTransactSize = cpu_to_le32(conn->vals->max_trans_size); 310 rsp->MaxReadSize = cpu_to_le32(conn->vals->max_read_size); 311 rsp->MaxWriteSize = cpu_to_le32(conn->vals->max_write_size); 312 313 rsp->SystemTime = cpu_to_le64(ksmbd_systime()); 314 rsp->ServerStartTime = 0; 315 316 rsp->SecurityBufferOffset = cpu_to_le16(128); 317 rsp->SecurityBufferLength = cpu_to_le16(AUTH_GSS_LENGTH); 318 ksmbd_copy_gss_neg_header((char *)(&rsp->hdr) + 319 le16_to_cpu(rsp->SecurityBufferOffset)); 320 rsp->SecurityMode = SMB2_NEGOTIATE_SIGNING_ENABLED_LE; 321 if (server_conf.signing == KSMBD_CONFIG_OPT_MANDATORY) 322 rsp->SecurityMode |= SMB2_NEGOTIATE_SIGNING_REQUIRED_LE; 323 err = ksmbd_iov_pin_rsp(work, rsp, 324 sizeof(struct smb2_negotiate_rsp) + AUTH_GSS_LENGTH); 325 if (err) 326 return err; 327 conn->use_spnego = true; 328 329 ksmbd_conn_set_need_negotiate(conn); 330 return 0; 331 } 332 333 /** 334 * smb2_set_rsp_credits() - set number of credits in response buffer 335 * @work: smb work containing smb response buffer 336 */ 337 int smb2_set_rsp_credits(struct ksmbd_work *work) 338 { 339 struct smb2_hdr *req_hdr = ksmbd_req_buf_next(work); 340 struct smb2_hdr *hdr = ksmbd_resp_buf_next(work); 341 struct ksmbd_conn *conn = work->conn; 342 unsigned short credits_requested, aux_max; 343 unsigned short credit_charge, credits_granted = 0; 344 345 if (work->send_no_response) 346 return 0; 347 348 hdr->CreditCharge = req_hdr->CreditCharge; 349 350 if (conn->total_credits > conn->vals->max_credits) { 351 hdr->CreditRequest = 0; 352 pr_err("Total credits overflow: %d\n", conn->total_credits); 353 return -EINVAL; 354 } 355 356 credit_charge = max_t(unsigned short, 357 le16_to_cpu(req_hdr->CreditCharge), 1); 358 if (credit_charge > conn->total_credits) { 359 ksmbd_debug(SMB, "Insufficient credits granted, given: %u, granted: %u\n", 360 credit_charge, conn->total_credits); 361 return -EINVAL; 362 } 363 364 conn->total_credits -= credit_charge; 365 conn->outstanding_credits -= credit_charge; 366 work->credit_charge = 0; 367 credits_requested = max_t(unsigned short, 368 le16_to_cpu(req_hdr->CreditRequest), 1); 369 370 /* according to smb2.credits smbtorture, Windows server 371 * 2016 or later grant up to 8192 credits at once. 372 * 373 * TODO: Need to adjuct CreditRequest value according to 374 * current cpu load 375 */ 376 if (hdr->Command == SMB2_NEGOTIATE) 377 aux_max = 1; 378 else 379 aux_max = conn->vals->max_credits - conn->total_credits; 380 credits_granted = min_t(unsigned short, credits_requested, aux_max); 381 382 conn->total_credits += credits_granted; 383 work->credits_granted += credits_granted; 384 385 if (!req_hdr->NextCommand) { 386 /* Update CreditRequest in last request */ 387 hdr->CreditRequest = cpu_to_le16(work->credits_granted); 388 } 389 ksmbd_debug(SMB, 390 "credits: requested[%d] granted[%d] total_granted[%d]\n", 391 credits_requested, credits_granted, 392 conn->total_credits); 393 return 0; 394 } 395 396 /** 397 * init_chained_smb2_rsp() - initialize smb2 chained response 398 * @work: smb work containing smb response buffer 399 */ 400 static void init_chained_smb2_rsp(struct ksmbd_work *work) 401 { 402 struct smb2_hdr *req = ksmbd_req_buf_next(work); 403 struct smb2_hdr *rsp = ksmbd_resp_buf_next(work); 404 struct smb2_hdr *rsp_hdr; 405 struct smb2_hdr *rcv_hdr; 406 int next_hdr_offset = 0; 407 int len, new_len; 408 409 /* Len of this response = updated RFC len - offset of previous cmd 410 * in the compound rsp 411 */ 412 413 /* Storing the current local FID which may be needed by subsequent 414 * command in the compound request 415 */ 416 if (req->Command == SMB2_CREATE && rsp->Status == STATUS_SUCCESS) { 417 work->compound_fid = ((struct smb2_create_rsp *)rsp)->VolatileFileId; 418 work->compound_pfid = ((struct smb2_create_rsp *)rsp)->PersistentFileId; 419 work->compound_sid = le64_to_cpu(rsp->SessionId); 420 work->compound_status = STATUS_SUCCESS; 421 } else if ((req->Command == SMB2_FLUSH || 422 req->Command == SMB2_READ || 423 req->Command == SMB2_WRITE) && 424 rsp->Status == STATUS_SUCCESS) { 425 u64 volatile_id = KSMBD_NO_FID; 426 u64 persistent_id = KSMBD_NO_FID; 427 428 if (req->Command == SMB2_FLUSH) { 429 struct smb2_flush_req *flush_req = 430 (struct smb2_flush_req *)req; 431 432 volatile_id = flush_req->VolatileFileId; 433 persistent_id = flush_req->PersistentFileId; 434 } else if (req->Command == SMB2_READ) { 435 struct smb2_read_req *read_req = 436 (struct smb2_read_req *)req; 437 438 volatile_id = read_req->VolatileFileId; 439 persistent_id = read_req->PersistentFileId; 440 } else { 441 struct smb2_write_req *write_req = 442 (struct smb2_write_req *)req; 443 444 volatile_id = write_req->VolatileFileId; 445 persistent_id = write_req->PersistentFileId; 446 } 447 448 if (has_file_id(volatile_id)) { 449 work->compound_fid = volatile_id; 450 work->compound_pfid = persistent_id; 451 work->compound_sid = le64_to_cpu(rsp->SessionId); 452 work->compound_status = STATUS_SUCCESS; 453 } 454 } else if (req->Command == SMB2_CREATE) { 455 work->compound_fid = KSMBD_NO_FID; 456 work->compound_pfid = KSMBD_NO_FID; 457 work->compound_sid = le64_to_cpu(rsp->SessionId); 458 work->compound_status = rsp->Status; 459 } else if (rsp->Status != STATUS_SUCCESS) { 460 work->compound_sid = le64_to_cpu(rsp->SessionId); 461 /* 462 * Only carry the failed status forward when the failing command 463 * was itself part of the related chain. An unrelated command 464 * that fails (e.g. a standalone request with a bad session id) 465 * must not seed the status for a following related command, 466 * which has to be evaluated on its own (and may legitimately 467 * fail with a different status such as INVALID_PARAMETER). The 468 * compound session id is still tracked so a following related 469 * command can validate it. 470 */ 471 if (req->Flags & SMB2_FLAGS_RELATED_OPERATIONS) 472 work->compound_status = rsp->Status; 473 } 474 475 len = get_rfc1002_len(work->response_buf) - work->next_smb2_rsp_hdr_off; 476 next_hdr_offset = le32_to_cpu(req->NextCommand); 477 478 new_len = ALIGN(len, 8); 479 work->iov[work->iov_idx].iov_len += (new_len - len); 480 inc_rfc1001_len(work->response_buf, new_len - len); 481 rsp->NextCommand = cpu_to_le32(new_len); 482 483 work->next_smb2_rcv_hdr_off += next_hdr_offset; 484 work->curr_smb2_rsp_hdr_off = work->next_smb2_rsp_hdr_off; 485 work->next_smb2_rsp_hdr_off += new_len; 486 ksmbd_debug(SMB, 487 "Compound req new_len = %d rcv off = %d rsp off = %d\n", 488 new_len, work->next_smb2_rcv_hdr_off, 489 work->next_smb2_rsp_hdr_off); 490 491 rsp_hdr = ksmbd_resp_buf_next(work); 492 rcv_hdr = ksmbd_req_buf_next(work); 493 494 if (!(rcv_hdr->Flags & SMB2_FLAGS_RELATED_OPERATIONS)) { 495 ksmbd_debug(SMB, "related flag should be set\n"); 496 work->compound_fid = KSMBD_NO_FID; 497 work->compound_pfid = KSMBD_NO_FID; 498 work->compound_status = STATUS_SUCCESS; 499 } 500 memset((char *)rsp_hdr, 0, sizeof(struct smb2_hdr) + 2); 501 rsp_hdr->ProtocolId = SMB2_PROTO_NUMBER; 502 rsp_hdr->StructureSize = SMB2_HEADER_STRUCTURE_SIZE; 503 rsp_hdr->Command = rcv_hdr->Command; 504 505 /* 506 * Message is response. We don't grant oplock yet. 507 */ 508 rsp_hdr->Flags = (SMB2_FLAGS_SERVER_TO_REDIR | 509 SMB2_FLAGS_RELATED_OPERATIONS); 510 rsp_hdr->NextCommand = 0; 511 rsp_hdr->MessageId = rcv_hdr->MessageId; 512 rsp_hdr->Id.SyncId.ProcessId = rcv_hdr->Id.SyncId.ProcessId; 513 rsp_hdr->Id.SyncId.TreeId = rcv_hdr->Id.SyncId.TreeId; 514 rsp_hdr->SessionId = rcv_hdr->SessionId; 515 memcpy(rsp_hdr->Signature, rcv_hdr->Signature, 16); 516 } 517 518 static bool smb2_compound_has_failed(struct ksmbd_work *work, 519 struct smb2_hdr *rsp) 520 { 521 if (!work->next_smb2_rcv_hdr_off || 522 has_file_id(work->compound_fid) || 523 work->compound_status == STATUS_SUCCESS) 524 return false; 525 526 rsp->Status = work->compound_status; 527 smb2_set_err_rsp(work); 528 return true; 529 } 530 531 /** 532 * is_chained_smb2_message() - check for chained command 533 * @work: smb work containing smb request buffer 534 * 535 * Return: true if chained request, otherwise false 536 */ 537 bool is_chained_smb2_message(struct ksmbd_work *work) 538 { 539 struct smb2_hdr *hdr = smb_get_msg(work->request_buf); 540 unsigned int len, next_cmd; 541 542 if (hdr->ProtocolId != SMB2_PROTO_NUMBER) 543 return false; 544 545 hdr = ksmbd_req_buf_next(work); 546 next_cmd = le32_to_cpu(hdr->NextCommand); 547 if (next_cmd > 0) { 548 if ((u64)work->next_smb2_rcv_hdr_off + next_cmd + 549 __SMB2_HEADER_STRUCTURE_SIZE > 550 get_rfc1002_len(work->request_buf)) { 551 pr_err("next command(%u) offset exceeds smb msg size\n", 552 next_cmd); 553 return false; 554 } 555 556 if ((u64)get_rfc1002_len(work->response_buf) + MAX_CIFS_SMALL_BUFFER_SIZE > 557 work->response_sz) { 558 pr_err("next response offset exceeds response buffer size\n"); 559 return false; 560 } 561 562 ksmbd_debug(SMB, "got SMB2 chained command\n"); 563 init_chained_smb2_rsp(work); 564 return true; 565 } else if (work->next_smb2_rcv_hdr_off) { 566 /* 567 * This is last request in chained command, 568 * align response to 8 byte 569 */ 570 len = ALIGN(get_rfc1002_len(work->response_buf), 8); 571 len = len - get_rfc1002_len(work->response_buf); 572 if (len) { 573 ksmbd_debug(SMB, "padding len %u\n", len); 574 work->iov[work->iov_idx].iov_len += len; 575 inc_rfc1001_len(work->response_buf, len); 576 } 577 work->curr_smb2_rsp_hdr_off = work->next_smb2_rsp_hdr_off; 578 } 579 return false; 580 } 581 582 /** 583 * init_smb2_rsp_hdr() - initialize smb2 response 584 * @work: smb work containing smb request buffer 585 * 586 * Return: 0 587 */ 588 int init_smb2_rsp_hdr(struct ksmbd_work *work) 589 { 590 struct smb2_hdr *rsp_hdr = smb_get_msg(work->response_buf); 591 struct smb2_hdr *rcv_hdr = smb_get_msg(work->request_buf); 592 593 memset(rsp_hdr, 0, sizeof(struct smb2_hdr) + 2); 594 rsp_hdr->ProtocolId = rcv_hdr->ProtocolId; 595 rsp_hdr->StructureSize = SMB2_HEADER_STRUCTURE_SIZE; 596 rsp_hdr->Command = rcv_hdr->Command; 597 598 /* 599 * Message is response. We don't grant oplock yet. 600 */ 601 rsp_hdr->Flags = (SMB2_FLAGS_SERVER_TO_REDIR); 602 rsp_hdr->NextCommand = 0; 603 rsp_hdr->MessageId = rcv_hdr->MessageId; 604 rsp_hdr->Id.SyncId.ProcessId = rcv_hdr->Id.SyncId.ProcessId; 605 rsp_hdr->Id.SyncId.TreeId = rcv_hdr->Id.SyncId.TreeId; 606 rsp_hdr->SessionId = rcv_hdr->SessionId; 607 memcpy(rsp_hdr->Signature, rcv_hdr->Signature, 16); 608 609 return 0; 610 } 611 612 /** 613 * smb2_allocate_rsp_buf() - allocate smb2 response buffer 614 * @work: smb work containing smb request buffer 615 * 616 * Return: 0 on success, otherwise error 617 */ 618 int smb2_allocate_rsp_buf(struct ksmbd_work *work) 619 { 620 struct smb2_hdr *hdr = smb_get_msg(work->request_buf); 621 size_t small_sz = MAX_CIFS_SMALL_BUFFER_SIZE; 622 size_t large_sz = small_sz + work->conn->vals->max_trans_size; 623 size_t sz = small_sz; 624 int cmd = le16_to_cpu(hdr->Command); 625 626 if (cmd == SMB2_IOCTL_HE || cmd == SMB2_QUERY_DIRECTORY_HE) 627 sz = large_sz; 628 629 if (cmd == SMB2_QUERY_INFO_HE) { 630 struct smb2_query_info_req *req; 631 632 if (get_rfc1002_len(work->request_buf) < 633 offsetof(struct smb2_query_info_req, OutputBufferLength)) 634 return -EINVAL; 635 636 req = smb_get_msg(work->request_buf); 637 if ((req->InfoType == SMB2_O_INFO_FILE && 638 (req->FileInfoClass == FILE_FULL_EA_INFORMATION || 639 req->FileInfoClass == FILE_ALL_INFORMATION)) || 640 req->InfoType == SMB2_O_INFO_SECURITY) 641 sz = large_sz; 642 } 643 644 /* allocate large response buf for chained commands */ 645 if (le32_to_cpu(hdr->NextCommand) > 0) 646 sz = large_sz; 647 648 work->response_buf = kvzalloc(sz, KSMBD_DEFAULT_GFP); 649 if (!work->response_buf) 650 return -ENOMEM; 651 652 work->response_sz = sz; 653 return 0; 654 } 655 656 /** 657 * smb2_check_user_session() - check for valid session for a user 658 * @work: smb work containing smb request buffer 659 * 660 * Return: 0 on success, otherwise error 661 */ 662 int smb2_check_user_session(struct ksmbd_work *work) 663 { 664 struct smb2_hdr *req_hdr = ksmbd_req_buf_next(work); 665 struct ksmbd_conn *conn = work->conn; 666 unsigned int cmd = le16_to_cpu(req_hdr->Command); 667 unsigned long long sess_id; 668 669 /* 670 * SMB2_ECHO, SMB2_NEGOTIATE, SMB2_SESSION_SETUP command do not 671 * require a session id, so no need to validate user session's for 672 * these commands. 673 */ 674 if (cmd == SMB2_ECHO_HE || cmd == SMB2_NEGOTIATE_HE || 675 cmd == SMB2_SESSION_SETUP_HE) 676 return 0; 677 678 if (!ksmbd_conn_good(conn)) 679 return -EIO; 680 681 sess_id = le64_to_cpu(req_hdr->SessionId); 682 683 /* 684 * If request is not the first in Compound request, 685 * Just validate session id in header with work->sess->id. 686 */ 687 if (work->next_smb2_rcv_hdr_off) { 688 if (!work->sess) { 689 pr_err("The first operation in the compound does not have sess\n"); 690 return -EINVAL; 691 } 692 if (sess_id != ULLONG_MAX && work->sess->id != sess_id) { 693 pr_err("session id(%llu) is different with the first operation(%lld)\n", 694 sess_id, work->sess->id); 695 return -EINVAL; 696 } 697 if (work->sess->state != SMB2_SESSION_VALID) { 698 pr_err("compound request on a non-valid session (state %d)\n", 699 work->sess->state); 700 return -EINVAL; 701 } 702 return 1; 703 } 704 705 /* Check for validity of user session */ 706 work->sess = ksmbd_session_lookup_all(conn, sess_id); 707 if (work->sess) 708 return 1; 709 ksmbd_debug(SMB, "Invalid user session, Uid %llu\n", sess_id); 710 return -ENOENT; 711 } 712 713 /** 714 * smb2_get_name() - get filename string from on the wire smb format 715 * @src: source buffer 716 * @maxlen: maxlen of source string 717 * @local_nls: nls_table pointer 718 * 719 * Return: matching converted filename on success, otherwise error ptr 720 */ 721 static char * 722 smb2_get_name(const char *src, const int maxlen, struct nls_table *local_nls) 723 { 724 char *name; 725 726 name = smb_strndup_from_utf16(src, maxlen, 1, local_nls); 727 if (IS_ERR(name)) { 728 pr_err("failed to get name %ld\n", PTR_ERR(name)); 729 return name; 730 } 731 732 if (*name == '\0') { 733 kfree(name); 734 return ERR_PTR(-EINVAL); 735 } 736 737 if (*name == '\\') { 738 pr_err("not allow directory name included leading slash\n"); 739 kfree(name); 740 return ERR_PTR(-EINVAL); 741 } 742 743 ksmbd_conv_path_to_unix(name); 744 ksmbd_strip_last_slash(name); 745 return name; 746 } 747 748 int setup_async_work(struct ksmbd_work *work, void (*fn)(void **), void **arg) 749 { 750 struct ksmbd_conn *conn = work->conn; 751 int id; 752 753 id = ksmbd_acquire_async_msg_id(&conn->async_ida); 754 if (id < 0) { 755 pr_err("Failed to alloc async message id\n"); 756 return id; 757 } 758 work->asynchronous = true; 759 work->async_id = id; 760 761 ksmbd_debug(SMB, 762 "Send interim Response to inform async request id : %d\n", 763 work->async_id); 764 765 work->cancel_fn = fn; 766 work->cancel_argv = arg; 767 768 if (list_empty(&work->async_request_entry)) { 769 spin_lock(&conn->request_lock); 770 list_add_tail(&work->async_request_entry, &conn->async_requests); 771 spin_unlock(&conn->request_lock); 772 } 773 774 return 0; 775 } 776 777 void release_async_work(struct ksmbd_work *work) 778 { 779 struct ksmbd_conn *conn = work->conn; 780 781 spin_lock(&conn->request_lock); 782 list_del_init(&work->async_request_entry); 783 spin_unlock(&conn->request_lock); 784 785 work->asynchronous = 0; 786 work->cancel_fn = NULL; 787 kfree(work->cancel_argv); 788 work->cancel_argv = NULL; 789 if (work->async_id) { 790 ksmbd_release_id(&conn->async_ida, work->async_id); 791 work->async_id = 0; 792 } 793 } 794 795 void smb2_send_interim_resp(struct ksmbd_work *work, __le32 status) 796 { 797 struct smb2_hdr *rsp_hdr; 798 struct ksmbd_work *in_work = ksmbd_alloc_work_struct(); 799 800 if (!in_work) 801 return; 802 803 if (allocate_interim_rsp_buf(in_work)) { 804 pr_err("smb_allocate_rsp_buf failed!\n"); 805 ksmbd_free_work_struct(in_work); 806 return; 807 } 808 809 in_work->conn = work->conn; 810 memcpy(smb_get_msg(in_work->response_buf), ksmbd_resp_buf_next(work), 811 __SMB2_HEADER_STRUCTURE_SIZE); 812 813 rsp_hdr = smb_get_msg(in_work->response_buf); 814 rsp_hdr->Flags |= SMB2_FLAGS_ASYNC_COMMAND; 815 rsp_hdr->Id.AsyncId = cpu_to_le64(work->async_id); 816 smb2_set_err_rsp(in_work); 817 rsp_hdr->Status = status; 818 819 ksmbd_conn_write(in_work); 820 ksmbd_free_work_struct(in_work); 821 } 822 823 static __le32 smb2_get_reparse_tag_special_file(umode_t mode) 824 { 825 if (S_ISDIR(mode) || S_ISREG(mode)) 826 return 0; 827 828 if (S_ISLNK(mode)) 829 return IO_REPARSE_TAG_LX_SYMLINK_LE; 830 else if (S_ISFIFO(mode)) 831 return IO_REPARSE_TAG_LX_FIFO_LE; 832 else if (S_ISSOCK(mode)) 833 return IO_REPARSE_TAG_AF_UNIX_LE; 834 else if (S_ISCHR(mode)) 835 return IO_REPARSE_TAG_LX_CHR_LE; 836 else if (S_ISBLK(mode)) 837 return IO_REPARSE_TAG_LX_BLK_LE; 838 839 return 0; 840 } 841 842 /** 843 * smb2_get_dos_mode() - get file mode in dos format from unix mode 844 * @stat: kstat containing file mode 845 * @attribute: attribute flags 846 * 847 * Return: converted dos mode 848 */ 849 static int smb2_get_dos_mode(struct kstat *stat, int attribute) 850 { 851 int attr = 0; 852 853 if (S_ISDIR(stat->mode)) { 854 attr = FILE_ATTRIBUTE_DIRECTORY | 855 (attribute & (FILE_ATTRIBUTE_HIDDEN | FILE_ATTRIBUTE_SYSTEM)); 856 } else { 857 attr = (attribute & 0x00005137) | FILE_ATTRIBUTE_ARCHIVE; 858 attr &= ~(FILE_ATTRIBUTE_DIRECTORY); 859 if (S_ISREG(stat->mode) && (server_conf.share_fake_fscaps & 860 FILE_SUPPORTS_SPARSE_FILES)) 861 attr |= FILE_ATTRIBUTE_SPARSE_FILE; 862 863 if (smb2_get_reparse_tag_special_file(stat->mode)) 864 attr |= FILE_ATTRIBUTE_REPARSE_POINT; 865 } 866 867 return attr; 868 } 869 870 static void build_preauth_ctxt(struct smb2_preauth_neg_context *pneg_ctxt, 871 __le16 hash_id) 872 { 873 pneg_ctxt->ContextType = SMB2_PREAUTH_INTEGRITY_CAPABILITIES; 874 pneg_ctxt->DataLength = cpu_to_le16(38); 875 pneg_ctxt->HashAlgorithmCount = cpu_to_le16(1); 876 pneg_ctxt->Reserved = cpu_to_le32(0); 877 pneg_ctxt->SaltLength = cpu_to_le16(SMB311_SALT_SIZE); 878 get_random_bytes(pneg_ctxt->Salt, SMB311_SALT_SIZE); 879 pneg_ctxt->HashAlgorithms = hash_id; 880 } 881 882 static void build_encrypt_ctxt(struct smb2_encryption_neg_context *pneg_ctxt, 883 __le16 cipher_type) 884 { 885 pneg_ctxt->ContextType = SMB2_ENCRYPTION_CAPABILITIES; 886 pneg_ctxt->DataLength = cpu_to_le16(4); 887 pneg_ctxt->Reserved = cpu_to_le32(0); 888 pneg_ctxt->CipherCount = cpu_to_le16(1); 889 pneg_ctxt->Ciphers[0] = cipher_type; 890 } 891 892 static void build_compress_ctxt(struct smb2_compression_capabilities_context *pneg_ctxt, 893 __le16 compress_algorithm, bool compress_chained, 894 bool compress_pattern) 895 { 896 /* 897 * Return only algorithms implemented by ksmbd. Pattern_V1 is advertised 898 * as a second ID when the client also enabled chained transforms. 899 */ 900 pneg_ctxt->ContextType = SMB2_COMPRESSION_CAPABILITIES; 901 pneg_ctxt->DataLength = cpu_to_le16(compress_pattern ? 12 : 10); 902 pneg_ctxt->Reserved = cpu_to_le32(0); 903 pneg_ctxt->CompressionAlgorithmCount = 904 cpu_to_le16(compress_pattern ? 2 : 1); 905 pneg_ctxt->Padding = cpu_to_le16(0); 906 pneg_ctxt->Flags = compress_chained ? 907 SMB2_COMPRESSION_CAPABILITIES_FLAG_CHAINED : 908 SMB2_COMPRESSION_CAPABILITIES_FLAG_NONE; 909 pneg_ctxt->CompressionAlgorithms[0] = compress_algorithm; 910 pneg_ctxt->CompressionAlgorithms[1] = compress_pattern ? 911 SMB3_COMPRESS_PATTERN : 0; 912 pneg_ctxt->CompressionAlgorithms[2] = 0; 913 pneg_ctxt->CompressionAlgorithms[3] = 0; 914 } 915 916 static void build_sign_cap_ctxt(struct smb2_signing_capabilities *pneg_ctxt, 917 __le16 sign_algo) 918 { 919 pneg_ctxt->ContextType = SMB2_SIGNING_CAPABILITIES; 920 pneg_ctxt->DataLength = 921 cpu_to_le16((sizeof(struct smb2_signing_capabilities) + 2) 922 - sizeof(struct smb2_neg_context)); 923 pneg_ctxt->Reserved = cpu_to_le32(0); 924 pneg_ctxt->SigningAlgorithmCount = cpu_to_le16(1); 925 pneg_ctxt->SigningAlgorithms[0] = sign_algo; 926 } 927 928 static void build_posix_ctxt(struct smb2_posix_neg_context *pneg_ctxt) 929 { 930 pneg_ctxt->ContextType = SMB2_POSIX_EXTENSIONS_AVAILABLE; 931 pneg_ctxt->DataLength = cpu_to_le16(POSIX_CTXT_DATA_LEN); 932 /* SMB2_CREATE_TAG_POSIX is "0x93AD25509CB411E7B42383DE968BCD7C" */ 933 pneg_ctxt->Name[0] = 0x93; 934 pneg_ctxt->Name[1] = 0xAD; 935 pneg_ctxt->Name[2] = 0x25; 936 pneg_ctxt->Name[3] = 0x50; 937 pneg_ctxt->Name[4] = 0x9C; 938 pneg_ctxt->Name[5] = 0xB4; 939 pneg_ctxt->Name[6] = 0x11; 940 pneg_ctxt->Name[7] = 0xE7; 941 pneg_ctxt->Name[8] = 0xB4; 942 pneg_ctxt->Name[9] = 0x23; 943 pneg_ctxt->Name[10] = 0x83; 944 pneg_ctxt->Name[11] = 0xDE; 945 pneg_ctxt->Name[12] = 0x96; 946 pneg_ctxt->Name[13] = 0x8B; 947 pneg_ctxt->Name[14] = 0xCD; 948 pneg_ctxt->Name[15] = 0x7C; 949 } 950 951 static unsigned int assemble_neg_contexts(struct ksmbd_conn *conn, 952 struct smb2_negotiate_rsp *rsp) 953 { 954 char * const pneg_ctxt = (char *)rsp + 955 le32_to_cpu(rsp->NegotiateContextOffset); 956 int neg_ctxt_cnt = 1; 957 int ctxt_size; 958 959 ksmbd_debug(SMB, 960 "assemble SMB2_PREAUTH_INTEGRITY_CAPABILITIES context\n"); 961 build_preauth_ctxt((struct smb2_preauth_neg_context *)pneg_ctxt, 962 conn->preauth_info->Preauth_HashId); 963 ctxt_size = sizeof(struct smb2_preauth_neg_context); 964 965 if (conn->cipher_type) { 966 /* Round to 8 byte boundary */ 967 ctxt_size = round_up(ctxt_size, 8); 968 ksmbd_debug(SMB, 969 "assemble SMB2_ENCRYPTION_CAPABILITIES context\n"); 970 build_encrypt_ctxt((struct smb2_encryption_neg_context *) 971 (pneg_ctxt + ctxt_size), 972 conn->cipher_type); 973 neg_ctxt_cnt++; 974 ctxt_size += sizeof(struct smb2_encryption_neg_context) + 2; 975 } 976 977 if (conn->compress_algorithm != SMB3_COMPRESS_NONE) { 978 ctxt_size = round_up(ctxt_size, 8); 979 ksmbd_debug(SMB, 980 "assemble SMB2_COMPRESSION_CAPABILITIES context\n"); 981 build_compress_ctxt((struct smb2_compression_capabilities_context *) 982 (pneg_ctxt + ctxt_size), 983 conn->compress_algorithm, 984 conn->compress_chained, 985 conn->compress_pattern); 986 neg_ctxt_cnt++; 987 ctxt_size += sizeof(struct smb2_neg_context) + 988 (conn->compress_pattern ? 12 : 10); 989 } 990 991 if (conn->posix_ext_supported) { 992 ctxt_size = round_up(ctxt_size, 8); 993 ksmbd_debug(SMB, 994 "assemble SMB2_POSIX_EXTENSIONS_AVAILABLE context\n"); 995 build_posix_ctxt((struct smb2_posix_neg_context *) 996 (pneg_ctxt + ctxt_size)); 997 neg_ctxt_cnt++; 998 ctxt_size += sizeof(struct smb2_posix_neg_context); 999 } 1000 1001 if (conn->signing_negotiated) { 1002 ctxt_size = round_up(ctxt_size, 8); 1003 ksmbd_debug(SMB, 1004 "assemble SMB2_SIGNING_CAPABILITIES context\n"); 1005 build_sign_cap_ctxt((struct smb2_signing_capabilities *) 1006 (pneg_ctxt + ctxt_size), 1007 conn->signing_algorithm); 1008 neg_ctxt_cnt++; 1009 ctxt_size += sizeof(struct smb2_signing_capabilities) + 2; 1010 } 1011 1012 rsp->NegotiateContextCount = cpu_to_le16(neg_ctxt_cnt); 1013 return ctxt_size + AUTH_GSS_PADDING; 1014 } 1015 1016 static __le32 decode_preauth_ctxt(struct ksmbd_conn *conn, 1017 struct smb2_preauth_neg_context *pneg_ctxt, 1018 int ctxt_len) 1019 { 1020 /* 1021 * sizeof(smb2_preauth_neg_context) assumes SMB311_SALT_SIZE Salt, 1022 * which may not be present. Only check for used HashAlgorithms[1]. 1023 */ 1024 if (ctxt_len < 1025 sizeof(struct smb2_neg_context) + MIN_PREAUTH_CTXT_DATA_LEN) 1026 return STATUS_INVALID_PARAMETER; 1027 1028 if (pneg_ctxt->HashAlgorithms != SMB2_PREAUTH_INTEGRITY_SHA512) 1029 return STATUS_SMB_NO_PREAUTH_INTEGRITY_HASH_OVERLAP; 1030 1031 conn->preauth_info->Preauth_HashId = SMB2_PREAUTH_INTEGRITY_SHA512; 1032 return STATUS_SUCCESS; 1033 } 1034 1035 static void decode_encrypt_ctxt(struct ksmbd_conn *conn, 1036 struct smb2_encryption_neg_context *pneg_ctxt, 1037 int ctxt_len) 1038 { 1039 int cph_cnt; 1040 int i, cphs_size; 1041 1042 if (sizeof(struct smb2_encryption_neg_context) > ctxt_len) { 1043 pr_err("Invalid SMB2_ENCRYPTION_CAPABILITIES context size\n"); 1044 return; 1045 } 1046 1047 conn->cipher_type = 0; 1048 1049 cph_cnt = le16_to_cpu(pneg_ctxt->CipherCount); 1050 cphs_size = cph_cnt * sizeof(__le16); 1051 1052 if (sizeof(struct smb2_encryption_neg_context) + cphs_size > 1053 ctxt_len) { 1054 pr_err("Invalid cipher count(%d)\n", cph_cnt); 1055 return; 1056 } 1057 1058 if (server_conf.flags & KSMBD_GLOBAL_FLAG_SMB2_ENCRYPTION_OFF) 1059 return; 1060 1061 for (i = 0; i < cph_cnt; i++) { 1062 if (pneg_ctxt->Ciphers[i] == SMB2_ENCRYPTION_AES128_GCM || 1063 pneg_ctxt->Ciphers[i] == SMB2_ENCRYPTION_AES128_CCM || 1064 pneg_ctxt->Ciphers[i] == SMB2_ENCRYPTION_AES256_CCM || 1065 pneg_ctxt->Ciphers[i] == SMB2_ENCRYPTION_AES256_GCM) { 1066 ksmbd_debug(SMB, "Cipher ID = 0x%x\n", 1067 pneg_ctxt->Ciphers[i]); 1068 conn->cipher_type = pneg_ctxt->Ciphers[i]; 1069 break; 1070 } 1071 } 1072 } 1073 1074 /** 1075 * smb3_encryption_negotiated() - checks if server and client agreed on enabling encryption 1076 * @conn: smb connection 1077 * 1078 * Return: true if connection should be encrypted, else false 1079 */ 1080 bool smb3_encryption_negotiated(struct ksmbd_conn *conn) 1081 { 1082 if (!conn->ops->generate_encryptionkey) 1083 return false; 1084 1085 /* 1086 * SMB 3.0 and 3.0.2 dialects use the SMB2_GLOBAL_CAP_ENCRYPTION flag. 1087 * SMB 3.1.1 uses the cipher_type field. 1088 */ 1089 return (conn->vals->req_capabilities & SMB2_GLOBAL_CAP_ENCRYPTION) || 1090 conn->cipher_type; 1091 } 1092 1093 static __le32 decode_compress_ctxt(struct ksmbd_conn *conn, 1094 struct smb2_compression_capabilities_context *pneg_ctxt, 1095 int ctxt_len) 1096 { 1097 int alg_cnt, algs_size, i; 1098 __le16 *algs; 1099 1100 if (sizeof(struct smb2_neg_context) + 10 > ctxt_len) { 1101 pr_err("Invalid SMB2_COMPRESSION_CAPABILITIES context length\n"); 1102 return STATUS_INVALID_PARAMETER; 1103 } 1104 1105 conn->compress_algorithm = SMB3_COMPRESS_NONE; 1106 conn->compress_chained = false; 1107 conn->compress_pattern = false; 1108 1109 alg_cnt = le16_to_cpu(pneg_ctxt->CompressionAlgorithmCount); 1110 if (!alg_cnt) 1111 return STATUS_INVALID_PARAMETER; 1112 1113 if (pneg_ctxt->Flags != SMB2_COMPRESSION_CAPABILITIES_FLAG_NONE && 1114 pneg_ctxt->Flags != SMB2_COMPRESSION_CAPABILITIES_FLAG_CHAINED) 1115 return STATUS_INVALID_PARAMETER; 1116 1117 algs_size = alg_cnt * sizeof(__le16); 1118 if (sizeof(struct smb2_neg_context) + 8 + algs_size > ctxt_len) { 1119 pr_err("Invalid compression algorithm count(%d)\n", alg_cnt); 1120 return STATUS_INVALID_PARAMETER; 1121 } 1122 1123 /* 1124 * CompressionAlgorithms[] is declared as a fixed 4-element array, but 1125 * the actual element count is variable (clients such as Windows may 1126 * advertise more). The on-wire length was validated above, so walk the 1127 * algorithms through a pointer to avoid a fixed-array bounds check. 1128 */ 1129 algs = pneg_ctxt->CompressionAlgorithms; 1130 for (i = 0; i < alg_cnt; i++) { 1131 __le16 alg = algs[i]; 1132 1133 /* 1134 * LZ77 is the required general-purpose codec. Pattern_V1 is an 1135 * optional chained payload type and cannot stand alone. 1136 */ 1137 if (alg == SMB3_COMPRESS_LZ77) { 1138 conn->compress_algorithm = alg; 1139 conn->compress_chained = 1140 pneg_ctxt->Flags == 1141 SMB2_COMPRESSION_CAPABILITIES_FLAG_CHAINED; 1142 ksmbd_debug(SMB, "Compression Algorithm ID = 0x%x\n", 1143 le16_to_cpu(alg)); 1144 } else if (alg == SMB3_COMPRESS_PATTERN) { 1145 conn->compress_pattern = true; 1146 } 1147 } 1148 1149 if (conn->compress_algorithm == SMB3_COMPRESS_NONE || 1150 !conn->compress_chained) 1151 conn->compress_pattern = false; 1152 1153 return STATUS_SUCCESS; 1154 } 1155 1156 static void decode_sign_cap_ctxt(struct ksmbd_conn *conn, 1157 struct smb2_signing_capabilities *pneg_ctxt, 1158 int ctxt_len) 1159 { 1160 int sign_algo_cnt; 1161 int i, sign_alos_size; 1162 1163 if (sizeof(struct smb2_signing_capabilities) > ctxt_len) { 1164 pr_err("Invalid SMB2_SIGNING_CAPABILITIES context length\n"); 1165 return; 1166 } 1167 1168 conn->signing_negotiated = false; 1169 sign_algo_cnt = le16_to_cpu(pneg_ctxt->SigningAlgorithmCount); 1170 sign_alos_size = sign_algo_cnt * sizeof(__le16); 1171 1172 if (sizeof(struct smb2_signing_capabilities) + sign_alos_size > 1173 ctxt_len) { 1174 pr_err("Invalid signing algorithm count(%d)\n", sign_algo_cnt); 1175 return; 1176 } 1177 1178 for (i = 0; i < sign_algo_cnt; i++) { 1179 if (pneg_ctxt->SigningAlgorithms[i] == SIGNING_ALG_HMAC_SHA256_LE || 1180 pneg_ctxt->SigningAlgorithms[i] == SIGNING_ALG_AES_CMAC_LE) { 1181 ksmbd_debug(SMB, "Signing Algorithm ID = 0x%x\n", 1182 pneg_ctxt->SigningAlgorithms[i]); 1183 conn->signing_negotiated = true; 1184 conn->signing_algorithm = 1185 pneg_ctxt->SigningAlgorithms[i]; 1186 break; 1187 } 1188 } 1189 } 1190 1191 static __le32 deassemble_neg_contexts(struct ksmbd_conn *conn, 1192 struct smb2_negotiate_req *req, 1193 unsigned int len_of_smb) 1194 { 1195 /* +4 is to account for the RFC1001 len field */ 1196 struct smb2_neg_context *pctx = (struct smb2_neg_context *)req; 1197 int i = 0, len_of_ctxts; 1198 unsigned int offset = le32_to_cpu(req->NegotiateContextOffset); 1199 unsigned int neg_ctxt_cnt = le16_to_cpu(req->NegotiateContextCount); 1200 __le32 status = STATUS_INVALID_PARAMETER; 1201 int compress_ctxt_cnt = 0; 1202 1203 ksmbd_debug(SMB, "decoding %d negotiate contexts\n", neg_ctxt_cnt); 1204 if (len_of_smb <= offset) { 1205 ksmbd_debug(SMB, "Invalid response: negotiate context offset\n"); 1206 return status; 1207 } 1208 1209 len_of_ctxts = len_of_smb - offset; 1210 1211 while (i++ < neg_ctxt_cnt) { 1212 int clen, ctxt_len; 1213 1214 if (len_of_ctxts < (int)sizeof(struct smb2_neg_context)) 1215 break; 1216 1217 pctx = (struct smb2_neg_context *)((char *)pctx + offset); 1218 clen = le16_to_cpu(pctx->DataLength); 1219 ctxt_len = clen + sizeof(struct smb2_neg_context); 1220 1221 if (ctxt_len > len_of_ctxts) 1222 break; 1223 1224 if (pctx->ContextType == SMB2_PREAUTH_INTEGRITY_CAPABILITIES) { 1225 ksmbd_debug(SMB, 1226 "deassemble SMB2_PREAUTH_INTEGRITY_CAPABILITIES context\n"); 1227 if (conn->preauth_info->Preauth_HashId) 1228 break; 1229 1230 status = decode_preauth_ctxt(conn, 1231 (struct smb2_preauth_neg_context *)pctx, 1232 ctxt_len); 1233 if (status != STATUS_SUCCESS) 1234 break; 1235 } else if (pctx->ContextType == SMB2_ENCRYPTION_CAPABILITIES) { 1236 ksmbd_debug(SMB, 1237 "deassemble SMB2_ENCRYPTION_CAPABILITIES context\n"); 1238 if (conn->cipher_type) 1239 break; 1240 1241 decode_encrypt_ctxt(conn, 1242 (struct smb2_encryption_neg_context *)pctx, 1243 ctxt_len); 1244 } else if (pctx->ContextType == SMB2_COMPRESSION_CAPABILITIES) { 1245 ksmbd_debug(SMB, 1246 "deassemble SMB2_COMPRESSION_CAPABILITIES context\n"); 1247 if (compress_ctxt_cnt++) { 1248 status = STATUS_INVALID_PARAMETER; 1249 break; 1250 } 1251 1252 status = decode_compress_ctxt(conn, 1253 (struct smb2_compression_capabilities_context *) 1254 pctx, ctxt_len); 1255 if (status != STATUS_SUCCESS) 1256 break; 1257 } else if (pctx->ContextType == SMB2_NETNAME_NEGOTIATE_CONTEXT_ID) { 1258 ksmbd_debug(SMB, 1259 "deassemble SMB2_NETNAME_NEGOTIATE_CONTEXT_ID context\n"); 1260 } else if (pctx->ContextType == SMB2_POSIX_EXTENSIONS_AVAILABLE) { 1261 ksmbd_debug(SMB, 1262 "deassemble SMB2_POSIX_EXTENSIONS_AVAILABLE context\n"); 1263 conn->posix_ext_supported = true; 1264 } else if (pctx->ContextType == SMB2_SIGNING_CAPABILITIES) { 1265 ksmbd_debug(SMB, 1266 "deassemble SMB2_SIGNING_CAPABILITIES context\n"); 1267 1268 decode_sign_cap_ctxt(conn, 1269 (struct smb2_signing_capabilities *)pctx, 1270 ctxt_len); 1271 } 1272 1273 /* offsets must be 8 byte aligned */ 1274 offset = (ctxt_len + 7) & ~0x7; 1275 len_of_ctxts -= offset; 1276 } 1277 return status; 1278 } 1279 1280 /** 1281 * smb2_handle_negotiate() - handler for smb2 negotiate command 1282 * @work: smb work containing smb request buffer 1283 * 1284 * Return: 0 1285 */ 1286 int smb2_handle_negotiate(struct ksmbd_work *work) 1287 { 1288 struct ksmbd_conn *conn = work->conn; 1289 struct smb2_negotiate_req *req = smb_get_msg(work->request_buf); 1290 struct smb2_negotiate_rsp *rsp = smb_get_msg(work->response_buf); 1291 int rc = 0; 1292 unsigned int smb2_buf_len, smb2_neg_size, neg_ctxt_len = 0; 1293 __le32 status; 1294 1295 ksmbd_debug(SMB, "Received negotiate request\n"); 1296 conn->need_neg = false; 1297 if (ksmbd_conn_good(conn)) { 1298 pr_err("conn->tcp_status is already in CifsGood State\n"); 1299 work->send_no_response = 1; 1300 return rc; 1301 } 1302 1303 ksmbd_conn_lock(conn); 1304 smb2_buf_len = get_rfc1002_len(work->request_buf); 1305 smb2_neg_size = offsetof(struct smb2_negotiate_req, Dialects); 1306 if (smb2_neg_size > smb2_buf_len) { 1307 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 1308 rc = -EINVAL; 1309 goto err_out; 1310 } 1311 1312 if (req->DialectCount == 0) { 1313 pr_err("malformed packet\n"); 1314 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 1315 rc = -EINVAL; 1316 goto err_out; 1317 } 1318 1319 if (conn->dialect == SMB311_PROT_ID) { 1320 unsigned int nego_ctxt_off = le32_to_cpu(req->NegotiateContextOffset); 1321 1322 if (smb2_buf_len < nego_ctxt_off) { 1323 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 1324 rc = -EINVAL; 1325 goto err_out; 1326 } 1327 1328 if (smb2_neg_size > nego_ctxt_off) { 1329 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 1330 rc = -EINVAL; 1331 goto err_out; 1332 } 1333 1334 if (smb2_neg_size + le16_to_cpu(req->DialectCount) * sizeof(__le16) > 1335 nego_ctxt_off) { 1336 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 1337 rc = -EINVAL; 1338 goto err_out; 1339 } 1340 } else { 1341 if (smb2_neg_size + le16_to_cpu(req->DialectCount) * sizeof(__le16) > 1342 smb2_buf_len) { 1343 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 1344 rc = -EINVAL; 1345 goto err_out; 1346 } 1347 } 1348 1349 conn->cli_cap = le32_to_cpu(req->Capabilities); 1350 switch (conn->dialect) { 1351 case SMB311_PROT_ID: 1352 conn->preauth_info = 1353 kzalloc_obj(struct preauth_integrity_info, 1354 KSMBD_DEFAULT_GFP); 1355 if (!conn->preauth_info) { 1356 rc = -ENOMEM; 1357 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 1358 goto err_out; 1359 } 1360 1361 status = deassemble_neg_contexts(conn, req, 1362 get_rfc1002_len(work->request_buf)); 1363 if (status != STATUS_SUCCESS) { 1364 pr_err("deassemble_neg_contexts error(0x%x)\n", 1365 status); 1366 rsp->hdr.Status = status; 1367 rc = -EINVAL; 1368 kfree(conn->preauth_info); 1369 conn->preauth_info = NULL; 1370 goto err_out; 1371 } 1372 1373 rc = init_smb3_11_server(conn); 1374 if (rc < 0) { 1375 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 1376 kfree(conn->preauth_info); 1377 conn->preauth_info = NULL; 1378 goto err_out; 1379 } 1380 1381 ksmbd_gen_preauth_integrity_hash(conn, 1382 work->request_buf, 1383 conn->preauth_info->Preauth_HashValue); 1384 rsp->NegotiateContextOffset = 1385 cpu_to_le32(OFFSET_OF_NEG_CONTEXT); 1386 neg_ctxt_len = assemble_neg_contexts(conn, rsp); 1387 break; 1388 case SMB302_PROT_ID: 1389 init_smb3_02_server(conn); 1390 break; 1391 case SMB30_PROT_ID: 1392 init_smb3_0_server(conn); 1393 break; 1394 case SMB21_PROT_ID: 1395 init_smb2_1_server(conn); 1396 break; 1397 case SMB2X_PROT_ID: 1398 case BAD_PROT_ID: 1399 default: 1400 ksmbd_debug(SMB, "Server dialect :0x%x not supported\n", 1401 conn->dialect); 1402 rsp->hdr.Status = STATUS_NOT_SUPPORTED; 1403 rc = -EINVAL; 1404 goto err_out; 1405 } 1406 rsp->Capabilities = cpu_to_le32(conn->vals->req_capabilities); 1407 1408 /* For stats */ 1409 conn->connection_type = conn->dialect; 1410 1411 rsp->MaxTransactSize = cpu_to_le32(conn->vals->max_trans_size); 1412 rsp->MaxReadSize = cpu_to_le32(conn->vals->max_read_size); 1413 rsp->MaxWriteSize = cpu_to_le32(conn->vals->max_write_size); 1414 1415 memcpy(conn->ClientGUID, req->ClientGUID, 1416 SMB2_CLIENT_GUID_SIZE); 1417 conn->cli_sec_mode = le16_to_cpu(req->SecurityMode); 1418 1419 rsp->StructureSize = cpu_to_le16(65); 1420 rsp->DialectRevision = cpu_to_le16(conn->dialect); 1421 /* Not setting conn guid rsp->ServerGUID, as it 1422 * not used by client for identifying server 1423 */ 1424 memset(rsp->ServerGUID, 0, SMB2_CLIENT_GUID_SIZE); 1425 1426 rsp->SystemTime = cpu_to_le64(ksmbd_systime()); 1427 rsp->ServerStartTime = 0; 1428 ksmbd_debug(SMB, "negotiate context offset %d, count %d\n", 1429 le32_to_cpu(rsp->NegotiateContextOffset), 1430 le16_to_cpu(rsp->NegotiateContextCount)); 1431 1432 rsp->SecurityBufferOffset = cpu_to_le16(128); 1433 rsp->SecurityBufferLength = cpu_to_le16(AUTH_GSS_LENGTH); 1434 ksmbd_copy_gss_neg_header((char *)(&rsp->hdr) + 1435 le16_to_cpu(rsp->SecurityBufferOffset)); 1436 1437 rsp->SecurityMode = SMB2_NEGOTIATE_SIGNING_ENABLED_LE; 1438 conn->use_spnego = true; 1439 1440 if ((server_conf.signing == KSMBD_CONFIG_OPT_AUTO || 1441 server_conf.signing == KSMBD_CONFIG_OPT_DISABLED) && 1442 req->SecurityMode & SMB2_NEGOTIATE_SIGNING_REQUIRED_LE) 1443 conn->sign = true; 1444 else if (server_conf.signing == KSMBD_CONFIG_OPT_MANDATORY) { 1445 server_conf.enforced_signing = true; 1446 rsp->SecurityMode |= SMB2_NEGOTIATE_SIGNING_REQUIRED_LE; 1447 conn->sign = true; 1448 } 1449 1450 conn->srv_sec_mode = le16_to_cpu(rsp->SecurityMode); 1451 ksmbd_conn_set_need_setup(conn); 1452 1453 err_out: 1454 ksmbd_conn_unlock(conn); 1455 if (rc) 1456 rsp->hdr.Status = STATUS_INSUFFICIENT_RESOURCES; 1457 1458 if (!rc) 1459 rc = ksmbd_iov_pin_rsp(work, rsp, 1460 sizeof(struct smb2_negotiate_rsp) + 1461 AUTH_GSS_LENGTH + neg_ctxt_len); 1462 if (rc < 0) 1463 smb2_set_err_rsp(work); 1464 return rc; 1465 } 1466 1467 static int alloc_preauth_hash(struct ksmbd_session *sess, 1468 struct ksmbd_conn *conn) 1469 { 1470 if (sess->Preauth_HashValue) 1471 return 0; 1472 1473 if (!conn->preauth_info) 1474 return -ENOMEM; 1475 1476 sess->Preauth_HashValue = kmemdup(conn->preauth_info->Preauth_HashValue, 1477 PREAUTH_HASHVALUE_SIZE, KSMBD_DEFAULT_GFP); 1478 if (!sess->Preauth_HashValue) 1479 return -ENOMEM; 1480 1481 return 0; 1482 } 1483 1484 static int generate_preauth_hash(struct ksmbd_work *work) 1485 { 1486 struct ksmbd_conn *conn = work->conn; 1487 struct ksmbd_session *sess = work->sess; 1488 u8 *preauth_hash; 1489 1490 if (conn->dialect != SMB311_PROT_ID) 1491 return 0; 1492 1493 if (conn->binding) { 1494 struct preauth_session *preauth_sess; 1495 1496 preauth_sess = ksmbd_preauth_session_lookup(conn, sess->id); 1497 if (!preauth_sess) { 1498 preauth_sess = ksmbd_preauth_session_alloc(conn, sess->id); 1499 if (!preauth_sess) 1500 return -ENOMEM; 1501 } 1502 1503 preauth_hash = preauth_sess->Preauth_HashValue; 1504 } else { 1505 if (!sess->Preauth_HashValue) 1506 if (alloc_preauth_hash(sess, conn)) 1507 return -ENOMEM; 1508 preauth_hash = sess->Preauth_HashValue; 1509 } 1510 1511 ksmbd_gen_preauth_integrity_hash(conn, work->request_buf, preauth_hash); 1512 return 0; 1513 } 1514 1515 static int decode_negotiation_token(struct ksmbd_conn *conn, 1516 struct negotiate_message *negblob, 1517 size_t sz) 1518 { 1519 if (!conn->use_spnego) 1520 return -EINVAL; 1521 1522 if (ksmbd_decode_negTokenInit((char *)negblob, sz, conn)) { 1523 if (ksmbd_decode_negTokenTarg((char *)negblob, sz, conn)) { 1524 conn->auth_mechs |= KSMBD_AUTH_NTLMSSP; 1525 conn->preferred_auth_mech = KSMBD_AUTH_NTLMSSP; 1526 conn->use_spnego = false; 1527 } 1528 } 1529 return 0; 1530 } 1531 1532 static int ntlm_negotiate(struct ksmbd_work *work, 1533 struct negotiate_message *negblob, 1534 size_t negblob_len, struct smb2_sess_setup_rsp *rsp) 1535 { 1536 struct challenge_message *chgblob; 1537 unsigned char *spnego_blob = NULL; 1538 u16 spnego_blob_len; 1539 char *neg_blob; 1540 int sz, rc; 1541 1542 ksmbd_debug(SMB, "negotiate phase\n"); 1543 rc = ksmbd_decode_ntlmssp_neg_blob(negblob, negblob_len, work->conn); 1544 if (rc) 1545 return rc; 1546 1547 sz = le16_to_cpu(rsp->SecurityBufferOffset); 1548 chgblob = (struct challenge_message *)rsp->Buffer; 1549 memset(chgblob, 0, sizeof(struct challenge_message)); 1550 1551 if (!work->conn->use_spnego) { 1552 sz = ksmbd_build_ntlmssp_challenge_blob(chgblob, work->conn); 1553 if (sz < 0) 1554 return -ENOMEM; 1555 1556 rsp->SecurityBufferLength = cpu_to_le16(sz); 1557 return 0; 1558 } 1559 1560 sz = sizeof(struct challenge_message); 1561 sz += (strlen(ksmbd_netbios_name()) * 2 + 1 + 4) * 6; 1562 1563 neg_blob = kzalloc(sz, KSMBD_DEFAULT_GFP); 1564 if (!neg_blob) 1565 return -ENOMEM; 1566 1567 chgblob = (struct challenge_message *)neg_blob; 1568 sz = ksmbd_build_ntlmssp_challenge_blob(chgblob, work->conn); 1569 if (sz < 0) { 1570 rc = -ENOMEM; 1571 goto out; 1572 } 1573 1574 rc = build_spnego_ntlmssp_neg_blob(&spnego_blob, &spnego_blob_len, 1575 neg_blob, sz); 1576 if (rc) { 1577 rc = -ENOMEM; 1578 goto out; 1579 } 1580 1581 memcpy(rsp->Buffer, spnego_blob, spnego_blob_len); 1582 rsp->SecurityBufferLength = cpu_to_le16(spnego_blob_len); 1583 1584 out: 1585 kfree(spnego_blob); 1586 kfree(neg_blob); 1587 return rc; 1588 } 1589 1590 static struct authenticate_message *user_authblob(struct ksmbd_conn *conn, 1591 struct smb2_sess_setup_req *req) 1592 { 1593 int sz; 1594 1595 if (conn->use_spnego && conn->mechToken) 1596 return (struct authenticate_message *)conn->mechToken; 1597 1598 sz = le16_to_cpu(req->SecurityBufferOffset); 1599 return (struct authenticate_message *)((char *)&req->hdr.ProtocolId 1600 + sz); 1601 } 1602 1603 static struct ksmbd_user *session_user(struct ksmbd_conn *conn, 1604 struct smb2_sess_setup_req *req) 1605 { 1606 struct authenticate_message *authblob; 1607 struct ksmbd_user *user; 1608 char *name; 1609 unsigned int name_off, name_len, secbuf_len; 1610 1611 if (conn->use_spnego && conn->mechToken) 1612 secbuf_len = conn->mechTokenLen; 1613 else 1614 secbuf_len = le16_to_cpu(req->SecurityBufferLength); 1615 if (secbuf_len < sizeof(struct authenticate_message)) { 1616 ksmbd_debug(SMB, "blob len %d too small\n", secbuf_len); 1617 return NULL; 1618 } 1619 authblob = user_authblob(conn, req); 1620 name_off = le32_to_cpu(authblob->UserName.BufferOffset); 1621 name_len = le16_to_cpu(authblob->UserName.Length); 1622 1623 if (secbuf_len < (u64)name_off + name_len) 1624 return NULL; 1625 1626 name = smb_strndup_from_utf16((const char *)authblob + name_off, 1627 name_len, 1628 true, 1629 conn->local_nls); 1630 if (IS_ERR(name)) { 1631 pr_err("cannot allocate memory\n"); 1632 return NULL; 1633 } 1634 1635 ksmbd_debug(SMB, "session setup request for user %s\n", name); 1636 user = ksmbd_login_user(name); 1637 kfree(name); 1638 return user; 1639 } 1640 1641 static int ntlm_authenticate(struct ksmbd_work *work, 1642 struct smb2_sess_setup_req *req, 1643 struct smb2_sess_setup_rsp *rsp) 1644 { 1645 struct ksmbd_conn *conn = work->conn; 1646 struct ksmbd_session *sess = work->sess; 1647 struct channel *chann = NULL, *old; 1648 struct ksmbd_user *user; 1649 u64 prev_id; 1650 int sz, rc; 1651 1652 ksmbd_debug(SMB, "authenticate phase\n"); 1653 if (conn->use_spnego) { 1654 unsigned char *spnego_blob; 1655 u16 spnego_blob_len; 1656 1657 rc = build_spnego_ntlmssp_auth_blob(&spnego_blob, 1658 &spnego_blob_len, 1659 0); 1660 if (rc) 1661 return -ENOMEM; 1662 1663 memcpy(rsp->Buffer, spnego_blob, spnego_blob_len); 1664 rsp->SecurityBufferLength = cpu_to_le16(spnego_blob_len); 1665 kfree(spnego_blob); 1666 } 1667 1668 user = session_user(conn, req); 1669 if (!user) { 1670 ksmbd_debug(SMB, "Unknown user name or an error\n"); 1671 return -EPERM; 1672 } 1673 1674 /* Check for previous session */ 1675 prev_id = le64_to_cpu(req->PreviousSessionId); 1676 if (prev_id && prev_id != sess->id) 1677 destroy_previous_session(conn, user, prev_id); 1678 1679 if (sess->state == SMB2_SESSION_VALID) { 1680 /* 1681 * Reuse session if anonymous try to connect 1682 * on reauthetication. 1683 */ 1684 if (conn->binding == false && ksmbd_anonymous_user(user)) { 1685 ksmbd_free_user(user); 1686 return 0; 1687 } 1688 1689 if (!ksmbd_compare_user(sess->user, user)) { 1690 ksmbd_free_user(user); 1691 return -EPERM; 1692 } 1693 ksmbd_free_user(user); 1694 } else { 1695 sess->user = user; 1696 } 1697 1698 if (conn->binding == false && user_guest(sess->user)) { 1699 rsp->SessionFlags = SMB2_SESSION_FLAG_IS_GUEST_LE; 1700 } else { 1701 struct authenticate_message *authblob; 1702 1703 authblob = user_authblob(conn, req); 1704 if (conn->use_spnego && conn->mechToken) 1705 sz = conn->mechTokenLen; 1706 else 1707 sz = le16_to_cpu(req->SecurityBufferLength); 1708 rc = ksmbd_decode_ntlmssp_auth_blob(authblob, sz, conn, sess); 1709 if (rc) { 1710 set_user_flag(sess->user, KSMBD_USER_FLAG_BAD_PASSWORD); 1711 ksmbd_debug(SMB, "authentication failed\n"); 1712 return -EPERM; 1713 } 1714 } 1715 1716 /* 1717 * If session state is SMB2_SESSION_VALID, We can assume 1718 * that it is reauthentication. And the user/password 1719 * has been verified, so return it here. 1720 */ 1721 if (sess->state == SMB2_SESSION_VALID) { 1722 if (conn->binding) 1723 goto binding_session; 1724 return 0; 1725 } 1726 1727 if ((rsp->SessionFlags != SMB2_SESSION_FLAG_IS_GUEST_LE && 1728 (conn->sign || server_conf.enforced_signing)) || 1729 (req->SecurityMode & SMB2_NEGOTIATE_SIGNING_REQUIRED)) 1730 sess->sign = true; 1731 1732 if (smb3_encryption_negotiated(conn) && 1733 !(req->Flags & SMB2_SESSION_REQ_FLAG_BINDING)) { 1734 conn->ops->generate_encryptionkey(conn, sess); 1735 sess->enc = true; 1736 if (server_conf.flags & KSMBD_GLOBAL_FLAG_SMB2_ENCRYPTION) 1737 rsp->SessionFlags = SMB2_SESSION_FLAG_ENCRYPT_DATA_LE; 1738 /* 1739 * signing is disable if encryption is enable 1740 * on this session 1741 */ 1742 sess->sign = false; 1743 } 1744 1745 binding_session: 1746 if (conn->dialect >= SMB30_PROT_ID) { 1747 chann = lookup_chann_list(sess, conn); 1748 if (!chann) { 1749 chann = kmalloc_obj(struct channel, KSMBD_DEFAULT_GFP); 1750 if (!chann) 1751 return -ENOMEM; 1752 1753 chann->conn = conn; 1754 down_write(&sess->chann_lock); 1755 old = xa_store(&sess->ksmbd_chann_list, (long)conn, chann, 1756 KSMBD_DEFAULT_GFP); 1757 up_write(&sess->chann_lock); 1758 if (xa_is_err(old)) { 1759 kfree(chann); 1760 return xa_err(old); 1761 } 1762 } 1763 } 1764 1765 if (conn->ops->generate_signingkey) { 1766 rc = conn->ops->generate_signingkey(sess, conn); 1767 if (rc) { 1768 ksmbd_debug(SMB, "SMB3 signing key generation failed\n"); 1769 return -EINVAL; 1770 } 1771 } 1772 1773 if (!ksmbd_conn_lookup_dialect(conn)) { 1774 pr_err("fail to verify the dialect\n"); 1775 return -ENOENT; 1776 } 1777 return 0; 1778 } 1779 1780 #ifdef CONFIG_SMB_SERVER_KERBEROS5 1781 static int krb5_authenticate(struct ksmbd_work *work, 1782 struct smb2_sess_setup_req *req, 1783 struct smb2_sess_setup_rsp *rsp) 1784 { 1785 struct ksmbd_conn *conn = work->conn; 1786 struct ksmbd_session *sess = work->sess; 1787 char *in_blob, *out_blob; 1788 struct channel *chann = NULL, *old; 1789 u64 prev_sess_id; 1790 int in_len, out_len; 1791 int retval; 1792 1793 in_blob = (char *)&req->hdr.ProtocolId + 1794 le16_to_cpu(req->SecurityBufferOffset); 1795 in_len = le16_to_cpu(req->SecurityBufferLength); 1796 out_blob = (char *)&rsp->hdr.ProtocolId + 1797 le16_to_cpu(rsp->SecurityBufferOffset); 1798 out_len = work->response_sz - 1799 (le16_to_cpu(rsp->SecurityBufferOffset) + 4); 1800 1801 retval = ksmbd_krb5_authenticate(sess, in_blob, in_len, 1802 out_blob, &out_len); 1803 if (retval) { 1804 ksmbd_debug(SMB, "krb5 authentication failed\n"); 1805 return -EINVAL; 1806 } 1807 1808 /* Check previous session */ 1809 prev_sess_id = le64_to_cpu(req->PreviousSessionId); 1810 if (prev_sess_id && prev_sess_id != sess->id) 1811 destroy_previous_session(conn, sess->user, prev_sess_id); 1812 1813 rsp->SecurityBufferLength = cpu_to_le16(out_len); 1814 1815 /* 1816 * If session state is SMB2_SESSION_VALID, We can assume 1817 * that it is reauthentication. And the user/password 1818 * has been verified, so return it here. 1819 */ 1820 if (sess->state == SMB2_SESSION_VALID) { 1821 if (conn->binding) 1822 goto binding_session; 1823 return 0; 1824 } 1825 1826 if ((rsp->SessionFlags != SMB2_SESSION_FLAG_IS_GUEST_LE && 1827 (conn->sign || server_conf.enforced_signing)) || 1828 (req->SecurityMode & SMB2_NEGOTIATE_SIGNING_REQUIRED)) 1829 sess->sign = true; 1830 1831 if (smb3_encryption_negotiated(conn) && 1832 !(req->Flags & SMB2_SESSION_REQ_FLAG_BINDING)) { 1833 conn->ops->generate_encryptionkey(conn, sess); 1834 sess->enc = true; 1835 if (server_conf.flags & KSMBD_GLOBAL_FLAG_SMB2_ENCRYPTION) 1836 rsp->SessionFlags = SMB2_SESSION_FLAG_ENCRYPT_DATA_LE; 1837 sess->sign = false; 1838 } 1839 1840 binding_session: 1841 if (conn->dialect >= SMB30_PROT_ID) { 1842 chann = lookup_chann_list(sess, conn); 1843 if (!chann) { 1844 chann = kmalloc_obj(struct channel, KSMBD_DEFAULT_GFP); 1845 if (!chann) 1846 return -ENOMEM; 1847 1848 chann->conn = conn; 1849 down_write(&sess->chann_lock); 1850 old = xa_store(&sess->ksmbd_chann_list, (long)conn, 1851 chann, KSMBD_DEFAULT_GFP); 1852 up_write(&sess->chann_lock); 1853 if (xa_is_err(old)) { 1854 kfree(chann); 1855 return xa_err(old); 1856 } 1857 } 1858 } 1859 1860 if (conn->ops->generate_signingkey) { 1861 retval = conn->ops->generate_signingkey(sess, conn); 1862 if (retval) { 1863 ksmbd_debug(SMB, "SMB3 signing key generation failed\n"); 1864 return -EINVAL; 1865 } 1866 } 1867 1868 if (!ksmbd_conn_lookup_dialect(conn)) { 1869 pr_err("fail to verify the dialect\n"); 1870 return -ENOENT; 1871 } 1872 return 0; 1873 } 1874 #else 1875 static int krb5_authenticate(struct ksmbd_work *work, 1876 struct smb2_sess_setup_req *req, 1877 struct smb2_sess_setup_rsp *rsp) 1878 { 1879 return -EOPNOTSUPP; 1880 } 1881 #endif 1882 1883 int smb2_sess_setup(struct ksmbd_work *work) 1884 { 1885 struct ksmbd_conn *conn = work->conn; 1886 struct smb2_sess_setup_req *req; 1887 struct smb2_sess_setup_rsp *rsp; 1888 struct ksmbd_session *sess; 1889 struct negotiate_message *negblob; 1890 unsigned int negblob_len, negblob_off; 1891 int rc = 0; 1892 1893 ksmbd_debug(SMB, "Received smb2 session setup request\n"); 1894 1895 if (!ksmbd_conn_need_setup(conn) && !ksmbd_conn_good(conn)) { 1896 work->send_no_response = 1; 1897 return rc; 1898 } 1899 1900 WORK_BUFFERS(work, req, rsp); 1901 1902 rsp->StructureSize = cpu_to_le16(9); 1903 rsp->SessionFlags = 0; 1904 rsp->SecurityBufferOffset = cpu_to_le16(72); 1905 rsp->SecurityBufferLength = 0; 1906 1907 ksmbd_conn_lock(conn); 1908 if (!req->hdr.SessionId) { 1909 sess = ksmbd_smb2_session_create(); 1910 if (!sess) { 1911 rc = -ENOMEM; 1912 goto out_err; 1913 } 1914 rsp->hdr.SessionId = cpu_to_le64(sess->id); 1915 rc = ksmbd_session_register(conn, sess); 1916 if (rc) 1917 goto out_err; 1918 1919 conn->binding = false; 1920 } else if (conn->dialect >= SMB30_PROT_ID && 1921 (server_conf.flags & KSMBD_GLOBAL_FLAG_SMB3_MULTICHANNEL) && 1922 req->Flags & SMB2_SESSION_REQ_FLAG_BINDING) { 1923 u64 sess_id = le64_to_cpu(req->hdr.SessionId); 1924 1925 sess = ksmbd_session_lookup_slowpath(sess_id); 1926 if (!sess) { 1927 rc = -ENOENT; 1928 goto out_err; 1929 } 1930 1931 if (conn->dialect != sess->dialect) { 1932 rc = -EINVAL; 1933 goto out_err; 1934 } 1935 1936 if (!(req->hdr.Flags & SMB2_FLAGS_SIGNED)) { 1937 rc = -EINVAL; 1938 goto out_err; 1939 } 1940 1941 if (strncmp(conn->ClientGUID, sess->ClientGUID, 1942 SMB2_CLIENT_GUID_SIZE)) { 1943 rc = -ENOENT; 1944 goto out_err; 1945 } 1946 1947 if (sess->state == SMB2_SESSION_IN_PROGRESS) { 1948 rc = -EACCES; 1949 goto out_err; 1950 } 1951 1952 if (sess->state == SMB2_SESSION_EXPIRED) { 1953 rc = -EFAULT; 1954 goto out_err; 1955 } 1956 1957 if (ksmbd_conn_need_reconnect(conn)) { 1958 rc = -EFAULT; 1959 ksmbd_user_session_put(sess); 1960 sess = NULL; 1961 goto out_err; 1962 } 1963 1964 if (is_ksmbd_session_in_connection(conn, sess_id)) { 1965 rc = -EACCES; 1966 goto out_err; 1967 } 1968 1969 if (user_guest(sess->user)) { 1970 rc = -EOPNOTSUPP; 1971 goto out_err; 1972 } 1973 1974 conn->binding = true; 1975 } else if ((conn->dialect < SMB30_PROT_ID || 1976 server_conf.flags & KSMBD_GLOBAL_FLAG_SMB3_MULTICHANNEL) && 1977 (req->Flags & SMB2_SESSION_REQ_FLAG_BINDING)) { 1978 sess = NULL; 1979 rc = -EACCES; 1980 goto out_err; 1981 } else { 1982 sess = ksmbd_session_lookup(conn, 1983 le64_to_cpu(req->hdr.SessionId)); 1984 if (!sess) { 1985 rc = -ENOENT; 1986 goto out_err; 1987 } 1988 1989 if (sess->state == SMB2_SESSION_EXPIRED) { 1990 rc = -EFAULT; 1991 goto out_err; 1992 } 1993 1994 if (ksmbd_conn_need_reconnect(conn)) { 1995 rc = -EFAULT; 1996 ksmbd_user_session_put(sess); 1997 sess = NULL; 1998 goto out_err; 1999 } 2000 2001 conn->binding = false; 2002 } 2003 work->sess = sess; 2004 2005 negblob_off = le16_to_cpu(req->SecurityBufferOffset); 2006 negblob_len = le16_to_cpu(req->SecurityBufferLength); 2007 if (negblob_off < offsetof(struct smb2_sess_setup_req, Buffer)) { 2008 rc = -EINVAL; 2009 goto out_err; 2010 } 2011 2012 negblob = (struct negotiate_message *)((char *)&req->hdr.ProtocolId + 2013 negblob_off); 2014 2015 if (decode_negotiation_token(conn, negblob, negblob_len) == 0) { 2016 if (conn->mechToken) { 2017 negblob = (struct negotiate_message *)conn->mechToken; 2018 negblob_len = conn->mechTokenLen; 2019 } 2020 } 2021 2022 if (negblob_len < offsetof(struct negotiate_message, NegotiateFlags)) { 2023 rc = -EINVAL; 2024 goto out_err; 2025 } 2026 2027 if (server_conf.auth_mechs & conn->auth_mechs) { 2028 rc = generate_preauth_hash(work); 2029 if (rc) 2030 goto out_err; 2031 2032 if (conn->preferred_auth_mech & 2033 (KSMBD_AUTH_KRB5 | KSMBD_AUTH_MSKRB5)) { 2034 rc = krb5_authenticate(work, req, rsp); 2035 if (rc) { 2036 rc = -EINVAL; 2037 goto out_err; 2038 } 2039 2040 if (!ksmbd_conn_need_reconnect(conn)) { 2041 ksmbd_conn_set_good(conn); 2042 sess->state = SMB2_SESSION_VALID; 2043 } 2044 } else if (conn->preferred_auth_mech == KSMBD_AUTH_NTLMSSP) { 2045 if (negblob->MessageType == NtLmNegotiate) { 2046 rc = ntlm_negotiate(work, negblob, negblob_len, rsp); 2047 if (rc) 2048 goto out_err; 2049 rsp->hdr.Status = 2050 STATUS_MORE_PROCESSING_REQUIRED; 2051 } else if (negblob->MessageType == NtLmAuthenticate) { 2052 rc = ntlm_authenticate(work, req, rsp); 2053 if (rc) 2054 goto out_err; 2055 2056 if (!ksmbd_conn_need_reconnect(conn)) { 2057 ksmbd_conn_set_good(conn); 2058 sess->state = SMB2_SESSION_VALID; 2059 } 2060 if (conn->binding) { 2061 struct preauth_session *preauth_sess; 2062 2063 preauth_sess = 2064 ksmbd_preauth_session_lookup(conn, sess->id); 2065 if (preauth_sess) { 2066 list_del(&preauth_sess->preauth_entry); 2067 kfree(preauth_sess); 2068 } 2069 } 2070 } else { 2071 pr_info_ratelimited("Unknown NTLMSSP message type : 0x%x\n", 2072 le32_to_cpu(negblob->MessageType)); 2073 rc = -EINVAL; 2074 } 2075 } else { 2076 /* TODO: need one more negotiation */ 2077 pr_err("Not support the preferred authentication\n"); 2078 rc = -EINVAL; 2079 } 2080 } else { 2081 pr_err("Not support authentication\n"); 2082 rc = -EINVAL; 2083 } 2084 2085 out_err: 2086 if (rc == -EINVAL) 2087 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 2088 else if (rc == -ENOENT) 2089 rsp->hdr.Status = STATUS_USER_SESSION_DELETED; 2090 else if (rc == -EACCES) 2091 rsp->hdr.Status = STATUS_REQUEST_NOT_ACCEPTED; 2092 else if (rc == -EFAULT) 2093 rsp->hdr.Status = STATUS_NETWORK_SESSION_EXPIRED; 2094 else if (rc == -ENOMEM) 2095 rsp->hdr.Status = STATUS_INSUFFICIENT_RESOURCES; 2096 else if (rc == -EOPNOTSUPP) 2097 rsp->hdr.Status = STATUS_NOT_SUPPORTED; 2098 else if (rc) 2099 rsp->hdr.Status = STATUS_LOGON_FAILURE; 2100 2101 if (conn->mechToken) { 2102 kfree(conn->mechToken); 2103 conn->mechToken = NULL; 2104 } 2105 2106 if (rc < 0) { 2107 /* 2108 * SecurityBufferOffset should be set to zero 2109 * in session setup error response. 2110 */ 2111 rsp->SecurityBufferOffset = 0; 2112 2113 if (sess) { 2114 bool try_delay = false; 2115 2116 /* 2117 * To avoid dictionary attacks (repeated session setups rapidly sent) to 2118 * connect to server, ksmbd make a delay of a 5 seconds on session setup 2119 * failure to make it harder to send enough random connection requests 2120 * to break into a server. 2121 */ 2122 if (sess->user && sess->user->flags & KSMBD_USER_FLAG_DELAY_SESSION) 2123 try_delay = true; 2124 2125 /* 2126 * For binding requests, session belongs to another 2127 * connection. Do not expire it. 2128 */ 2129 if (!(req->Flags & SMB2_SESSION_REQ_FLAG_BINDING)) { 2130 sess->last_active = jiffies; 2131 sess->state = SMB2_SESSION_EXPIRED; 2132 } 2133 ksmbd_user_session_put(sess); 2134 work->sess = NULL; 2135 if (try_delay) { 2136 ksmbd_conn_set_need_reconnect(conn); 2137 ssleep(5); 2138 ksmbd_conn_set_need_setup(conn); 2139 } 2140 } 2141 smb2_set_err_rsp(work); 2142 conn->binding = false; 2143 } else { 2144 unsigned int iov_len; 2145 2146 if (rsp->SecurityBufferLength) 2147 iov_len = offsetof(struct smb2_sess_setup_rsp, Buffer) + 2148 le16_to_cpu(rsp->SecurityBufferLength); 2149 else 2150 iov_len = sizeof(struct smb2_sess_setup_rsp); 2151 rc = ksmbd_iov_pin_rsp(work, rsp, iov_len); 2152 if (rc) 2153 rsp->hdr.Status = STATUS_INSUFFICIENT_RESOURCES; 2154 } 2155 2156 ksmbd_conn_unlock(conn); 2157 return rc; 2158 } 2159 2160 /** 2161 * smb2_tree_connect() - handler for smb2 tree connect command 2162 * @work: smb work containing smb request buffer 2163 * 2164 * Return: 0 on success, otherwise error 2165 */ 2166 int smb2_tree_connect(struct ksmbd_work *work) 2167 { 2168 struct ksmbd_conn *conn = work->conn; 2169 struct smb2_tree_connect_req *req; 2170 struct smb2_tree_connect_rsp *rsp; 2171 struct ksmbd_session *sess = work->sess; 2172 char *treename = NULL, *name = NULL; 2173 struct ksmbd_tree_conn_status status; 2174 struct ksmbd_share_config *share = NULL; 2175 int rc = -EINVAL; 2176 2177 ksmbd_debug(SMB, "Received smb2 tree connect request\n"); 2178 2179 WORK_BUFFERS(work, req, rsp); 2180 2181 treename = smb_strndup_from_utf16((char *)req + le16_to_cpu(req->PathOffset), 2182 le16_to_cpu(req->PathLength), true, 2183 conn->local_nls); 2184 if (IS_ERR(treename)) { 2185 pr_err("treename is NULL\n"); 2186 status.ret = KSMBD_TREE_CONN_STATUS_ERROR; 2187 goto out_err1; 2188 } 2189 2190 name = ksmbd_extract_sharename(conn->um, treename); 2191 if (IS_ERR(name)) { 2192 status.ret = KSMBD_TREE_CONN_STATUS_ERROR; 2193 goto out_err1; 2194 } 2195 2196 ksmbd_debug(SMB, "tree connect request for tree %s treename %s\n", 2197 name, treename); 2198 2199 status = ksmbd_tree_conn_connect(work, name); 2200 if (status.ret == KSMBD_TREE_CONN_STATUS_OK) 2201 rsp->hdr.Id.SyncId.TreeId = cpu_to_le32(status.tree_conn->id); 2202 else 2203 goto out_err1; 2204 2205 share = status.tree_conn->share_conf; 2206 if (test_share_config_flag(share, KSMBD_SHARE_FLAG_PIPE)) { 2207 ksmbd_debug(SMB, "IPC share path request\n"); 2208 rsp->ShareType = SMB2_SHARE_TYPE_PIPE; 2209 rsp->MaximalAccess = FILE_READ_DATA_LE | FILE_READ_EA_LE | 2210 FILE_EXECUTE_LE | FILE_READ_ATTRIBUTES_LE | 2211 FILE_DELETE_LE | FILE_READ_CONTROL_LE | 2212 FILE_WRITE_DAC_LE | FILE_WRITE_OWNER_LE | 2213 FILE_SYNCHRONIZE_LE; 2214 } else { 2215 rsp->ShareType = SMB2_SHARE_TYPE_DISK; 2216 rsp->MaximalAccess = FILE_READ_DATA_LE | FILE_READ_EA_LE | 2217 FILE_EXECUTE_LE | FILE_READ_ATTRIBUTES_LE; 2218 if (test_tree_conn_flag(status.tree_conn, 2219 KSMBD_TREE_CONN_FLAG_WRITABLE)) { 2220 rsp->MaximalAccess |= FILE_WRITE_DATA_LE | 2221 FILE_APPEND_DATA_LE | FILE_WRITE_EA_LE | 2222 FILE_DELETE_LE | FILE_WRITE_ATTRIBUTES_LE | 2223 FILE_DELETE_CHILD_LE | FILE_READ_CONTROL_LE | 2224 FILE_WRITE_DAC_LE | FILE_WRITE_OWNER_LE | 2225 FILE_SYNCHRONIZE_LE; 2226 } 2227 } 2228 2229 status.tree_conn->maximal_access = le32_to_cpu(rsp->MaximalAccess); 2230 if (conn->posix_ext_supported) 2231 status.tree_conn->posix_extensions = true; 2232 2233 down_write(&sess->tree_conns_lock); 2234 status.tree_conn->t_state = TREE_CONNECTED; 2235 up_write(&sess->tree_conns_lock); 2236 rsp->StructureSize = cpu_to_le16(16); 2237 out_err1: 2238 if (server_conf.flags & KSMBD_GLOBAL_FLAG_DURABLE_HANDLE && share && 2239 test_share_config_flag(share, 2240 KSMBD_SHARE_FLAG_CONTINUOUS_AVAILABILITY)) 2241 rsp->Capabilities = SMB2_SHARE_CAP_CONTINUOUS_AVAILABILITY; 2242 else 2243 rsp->Capabilities = 0; 2244 rsp->Reserved = 0; 2245 /* default manual caching */ 2246 rsp->ShareFlags = SMB2_SHAREFLAG_MANUAL_CACHING; 2247 /* Tell the client that READ requests may request compressed responses. */ 2248 if (conn->dialect == SMB311_PROT_ID && 2249 conn->compress_algorithm != SMB3_COMPRESS_NONE) 2250 rsp->ShareFlags |= cpu_to_le32(SMB2_SHAREFLAG_COMPRESS_DATA); 2251 2252 rc = ksmbd_iov_pin_rsp(work, rsp, sizeof(struct smb2_tree_connect_rsp)); 2253 if (rc) 2254 status.ret = KSMBD_TREE_CONN_STATUS_NOMEM; 2255 2256 if (!IS_ERR(treename)) 2257 kfree(treename); 2258 if (!IS_ERR(name)) 2259 kfree(name); 2260 2261 switch (status.ret) { 2262 case KSMBD_TREE_CONN_STATUS_OK: 2263 rsp->hdr.Status = STATUS_SUCCESS; 2264 rc = 0; 2265 break; 2266 case -ESTALE: 2267 case -ENOENT: 2268 case KSMBD_TREE_CONN_STATUS_NO_SHARE: 2269 rsp->hdr.Status = STATUS_BAD_NETWORK_NAME; 2270 break; 2271 case -ENOMEM: 2272 case KSMBD_TREE_CONN_STATUS_NOMEM: 2273 rsp->hdr.Status = STATUS_NO_MEMORY; 2274 break; 2275 case KSMBD_TREE_CONN_STATUS_ERROR: 2276 case KSMBD_TREE_CONN_STATUS_TOO_MANY_CONNS: 2277 case KSMBD_TREE_CONN_STATUS_TOO_MANY_SESSIONS: 2278 rsp->hdr.Status = STATUS_ACCESS_DENIED; 2279 break; 2280 case -EINVAL: 2281 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 2282 break; 2283 default: 2284 rsp->hdr.Status = STATUS_ACCESS_DENIED; 2285 } 2286 2287 if (status.ret != KSMBD_TREE_CONN_STATUS_OK) 2288 smb2_set_err_rsp(work); 2289 2290 return rc; 2291 } 2292 2293 /** 2294 * smb2_create_open_flags() - convert smb open flags to unix open flags 2295 * @file_present: is file already present 2296 * @access: file access flags 2297 * @disposition: file disposition flags 2298 * @may_flags: set with MAY_ flags 2299 * @coptions: file creation options 2300 * @mode: file mode 2301 * 2302 * Return: file open flags 2303 */ 2304 static int smb2_create_open_flags(bool file_present, __le32 access, 2305 __le32 disposition, 2306 int *may_flags, 2307 __le32 coptions, 2308 umode_t mode) 2309 { 2310 int oflags = O_NONBLOCK | O_LARGEFILE; 2311 2312 if (coptions & FILE_DIRECTORY_FILE_LE || S_ISDIR(mode)) { 2313 access &= ~FILE_WRITE_DESIRE_ACCESS_LE; 2314 ksmbd_debug(SMB, "Discard write access to a directory\n"); 2315 } 2316 2317 if (access & FILE_READ_DESIRED_ACCESS_LE && 2318 access & FILE_WRITE_DESIRE_ACCESS_LE) { 2319 oflags |= O_RDWR; 2320 *may_flags = MAY_OPEN | MAY_READ | MAY_WRITE; 2321 } else if (access & FILE_WRITE_DESIRE_ACCESS_LE) { 2322 oflags |= O_WRONLY; 2323 *may_flags = MAY_OPEN | MAY_WRITE; 2324 } else { 2325 oflags |= O_RDONLY; 2326 *may_flags = MAY_OPEN | MAY_READ; 2327 } 2328 2329 if (access == FILE_READ_ATTRIBUTES_LE || S_ISBLK(mode) || S_ISCHR(mode)) 2330 oflags |= O_PATH; 2331 2332 if (file_present) { 2333 switch (disposition & FILE_CREATE_MASK_LE) { 2334 case FILE_OPEN_LE: 2335 case FILE_CREATE_LE: 2336 break; 2337 case FILE_SUPERSEDE_LE: 2338 case FILE_OVERWRITE_LE: 2339 case FILE_OVERWRITE_IF_LE: 2340 oflags |= O_TRUNC; 2341 break; 2342 default: 2343 break; 2344 } 2345 } else { 2346 switch (disposition & FILE_CREATE_MASK_LE) { 2347 case FILE_SUPERSEDE_LE: 2348 case FILE_CREATE_LE: 2349 case FILE_OPEN_IF_LE: 2350 case FILE_OVERWRITE_IF_LE: 2351 oflags |= O_CREAT; 2352 break; 2353 case FILE_OPEN_LE: 2354 case FILE_OVERWRITE_LE: 2355 oflags &= ~O_CREAT; 2356 break; 2357 default: 2358 break; 2359 } 2360 } 2361 2362 return oflags; 2363 } 2364 2365 /** 2366 * smb2_tree_disconnect() - handler for smb tree connect request 2367 * @work: smb work containing request buffer 2368 * 2369 * Return: 0 on success, otherwise error 2370 */ 2371 int smb2_tree_disconnect(struct ksmbd_work *work) 2372 { 2373 struct smb2_tree_disconnect_rsp *rsp; 2374 struct smb2_tree_disconnect_req *req; 2375 struct ksmbd_session *sess = work->sess; 2376 struct ksmbd_tree_connect *tcon = work->tcon; 2377 int err; 2378 2379 ksmbd_debug(SMB, "Received smb2 tree disconnect request\n"); 2380 2381 WORK_BUFFERS(work, req, rsp); 2382 2383 if (!tcon) { 2384 ksmbd_debug(SMB, "Invalid tid %d\n", req->hdr.Id.SyncId.TreeId); 2385 2386 rsp->hdr.Status = STATUS_NETWORK_NAME_DELETED; 2387 err = -ENOENT; 2388 goto err_out; 2389 } 2390 2391 ksmbd_close_tree_conn_fds(work); 2392 2393 down_write(&sess->tree_conns_lock); 2394 if (tcon->t_state == TREE_DISCONNECTED) { 2395 up_write(&sess->tree_conns_lock); 2396 rsp->hdr.Status = STATUS_NETWORK_NAME_DELETED; 2397 err = -ENOENT; 2398 goto err_out; 2399 } 2400 2401 tcon->t_state = TREE_DISCONNECTED; 2402 up_write(&sess->tree_conns_lock); 2403 2404 err = ksmbd_tree_conn_disconnect(sess, tcon); 2405 if (err) { 2406 rsp->hdr.Status = STATUS_NETWORK_NAME_DELETED; 2407 goto err_out; 2408 } 2409 2410 rsp->StructureSize = cpu_to_le16(4); 2411 err = ksmbd_iov_pin_rsp(work, rsp, 2412 sizeof(struct smb2_tree_disconnect_rsp)); 2413 if (err) { 2414 rsp->hdr.Status = STATUS_INSUFFICIENT_RESOURCES; 2415 goto err_out; 2416 } 2417 2418 return 0; 2419 2420 err_out: 2421 smb2_set_err_rsp(work); 2422 return err; 2423 2424 } 2425 2426 /** 2427 * smb2_session_logoff() - handler for session log off request 2428 * @work: smb work containing request buffer 2429 * 2430 * Return: 0 on success, otherwise error 2431 */ 2432 int smb2_session_logoff(struct ksmbd_work *work) 2433 { 2434 struct ksmbd_conn *conn = work->conn; 2435 struct ksmbd_session *sess = work->sess; 2436 struct smb2_logoff_req *req; 2437 struct smb2_logoff_rsp *rsp; 2438 u64 sess_id; 2439 int err; 2440 2441 WORK_BUFFERS(work, req, rsp); 2442 2443 ksmbd_debug(SMB, "Received smb2 session logoff request\n"); 2444 2445 ksmbd_conn_lock(conn); 2446 if (!ksmbd_conn_good(conn)) { 2447 ksmbd_conn_unlock(conn); 2448 rsp->hdr.Status = STATUS_NETWORK_NAME_DELETED; 2449 smb2_set_err_rsp(work); 2450 return -ENOENT; 2451 } 2452 sess_id = le64_to_cpu(req->hdr.SessionId); 2453 ksmbd_all_conn_set_status(sess_id, KSMBD_SESS_NEED_RECONNECT); 2454 ksmbd_conn_unlock(conn); 2455 2456 ksmbd_close_session_fds(work); 2457 ksmbd_conn_wait_idle(conn); 2458 2459 if (ksmbd_tree_conn_session_logoff(sess)) { 2460 ksmbd_debug(SMB, "Invalid tid %d\n", req->hdr.Id.SyncId.TreeId); 2461 rsp->hdr.Status = STATUS_NETWORK_NAME_DELETED; 2462 smb2_set_err_rsp(work); 2463 return -ENOENT; 2464 } 2465 2466 down_write(&conn->session_lock); 2467 sess->state = SMB2_SESSION_EXPIRED; 2468 up_write(&conn->session_lock); 2469 2470 ksmbd_all_conn_set_status(sess_id, KSMBD_SESS_NEED_SETUP); 2471 2472 rsp->StructureSize = cpu_to_le16(4); 2473 err = ksmbd_iov_pin_rsp(work, rsp, sizeof(struct smb2_logoff_rsp)); 2474 if (err) { 2475 rsp->hdr.Status = STATUS_INSUFFICIENT_RESOURCES; 2476 smb2_set_err_rsp(work); 2477 return err; 2478 } 2479 return 0; 2480 } 2481 2482 /** 2483 * create_smb2_pipe() - create IPC pipe 2484 * @work: smb work containing request buffer 2485 * 2486 * Return: 0 on success, otherwise error 2487 */ 2488 static noinline int create_smb2_pipe(struct ksmbd_work *work) 2489 { 2490 struct smb2_create_rsp *rsp; 2491 struct smb2_create_req *req; 2492 int id = -1; 2493 int err; 2494 char *name; 2495 2496 WORK_BUFFERS(work, req, rsp); 2497 2498 name = smb_strndup_from_utf16(req->Buffer, le16_to_cpu(req->NameLength), 2499 1, work->conn->local_nls); 2500 if (IS_ERR(name)) { 2501 rsp->hdr.Status = STATUS_NO_MEMORY; 2502 err = PTR_ERR(name); 2503 goto out; 2504 } 2505 2506 id = ksmbd_session_rpc_open(work->sess, name); 2507 if (id < 0) { 2508 pr_err("Unable to open RPC pipe: %d\n", id); 2509 err = id; 2510 goto out; 2511 } 2512 2513 rsp->hdr.Status = STATUS_SUCCESS; 2514 rsp->StructureSize = cpu_to_le16(89); 2515 rsp->OplockLevel = SMB2_OPLOCK_LEVEL_NONE; 2516 rsp->Flags = 0; 2517 rsp->CreateAction = cpu_to_le32(FILE_OPENED); 2518 2519 rsp->CreationTime = cpu_to_le64(0); 2520 rsp->LastAccessTime = cpu_to_le64(0); 2521 rsp->ChangeTime = cpu_to_le64(0); 2522 rsp->AllocationSize = cpu_to_le64(0); 2523 rsp->EndofFile = cpu_to_le64(0); 2524 rsp->FileAttributes = FILE_ATTRIBUTE_NORMAL_LE; 2525 rsp->Reserved2 = 0; 2526 rsp->VolatileFileId = id; 2527 rsp->PersistentFileId = 0; 2528 rsp->CreateContextsOffset = 0; 2529 rsp->CreateContextsLength = 0; 2530 2531 err = ksmbd_iov_pin_rsp(work, rsp, offsetof(struct smb2_create_rsp, Buffer)); 2532 if (err) 2533 goto out; 2534 2535 kfree(name); 2536 return 0; 2537 2538 out: 2539 switch (err) { 2540 case -EINVAL: 2541 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 2542 break; 2543 case -ENOSPC: 2544 case -ENOMEM: 2545 rsp->hdr.Status = STATUS_NO_MEMORY; 2546 break; 2547 } 2548 2549 if (id >= 0) 2550 ksmbd_session_rpc_close(work->sess, id); 2551 2552 if (!IS_ERR(name)) 2553 kfree(name); 2554 2555 smb2_set_err_rsp(work); 2556 return err; 2557 } 2558 2559 /** 2560 * smb2_set_ea() - handler for setting extended attributes using set 2561 * info command 2562 * @eabuf: set info command buffer 2563 * @buf_len: set info command buffer length 2564 * @path: dentry path for get ea 2565 * @get_write: get write access to a mount 2566 * 2567 * Return: 0 on success, otherwise error 2568 */ 2569 static int smb2_set_ea(struct smb2_ea_info *eabuf, unsigned int buf_len, 2570 const struct path *path, bool get_write) 2571 { 2572 struct mnt_idmap *idmap = mnt_idmap(path->mnt); 2573 char *attr_name = NULL, *value; 2574 int rc = 0; 2575 unsigned int next = 0; 2576 2577 if (buf_len < sizeof(struct smb2_ea_info) + eabuf->EaNameLength + 1 + 2578 le16_to_cpu(eabuf->EaValueLength)) 2579 return -EINVAL; 2580 2581 attr_name = kmalloc(XATTR_NAME_MAX + 1, KSMBD_DEFAULT_GFP); 2582 if (!attr_name) 2583 return -ENOMEM; 2584 2585 do { 2586 if (!eabuf->EaNameLength) 2587 goto next; 2588 2589 ksmbd_debug(SMB, 2590 "name : <%s>, name_len : %u, value_len : %u, next : %u\n", 2591 eabuf->name, eabuf->EaNameLength, 2592 le16_to_cpu(eabuf->EaValueLength), 2593 le32_to_cpu(eabuf->NextEntryOffset)); 2594 2595 if (eabuf->EaNameLength > 2596 (XATTR_NAME_MAX - XATTR_USER_PREFIX_LEN)) { 2597 rc = -EINVAL; 2598 break; 2599 } 2600 2601 memcpy(attr_name, XATTR_USER_PREFIX, XATTR_USER_PREFIX_LEN); 2602 memcpy(&attr_name[XATTR_USER_PREFIX_LEN], eabuf->name, 2603 eabuf->EaNameLength); 2604 attr_name[XATTR_USER_PREFIX_LEN + eabuf->EaNameLength] = '\0'; 2605 value = (char *)&eabuf->name + eabuf->EaNameLength + 1; 2606 2607 if (!eabuf->EaValueLength) { 2608 rc = ksmbd_vfs_casexattr_len(idmap, 2609 path->dentry, 2610 attr_name, 2611 XATTR_USER_PREFIX_LEN + 2612 eabuf->EaNameLength); 2613 2614 /* delete the EA only when it exits */ 2615 if (rc > 0) { 2616 rc = ksmbd_vfs_remove_xattr(idmap, 2617 path, 2618 attr_name, 2619 get_write); 2620 2621 if (rc < 0) { 2622 ksmbd_debug(SMB, 2623 "remove xattr failed(%d)\n", 2624 rc); 2625 break; 2626 } 2627 } 2628 2629 /* if the EA doesn't exist, just do nothing. */ 2630 rc = 0; 2631 } else { 2632 rc = ksmbd_vfs_setxattr(idmap, path, attr_name, value, 2633 le16_to_cpu(eabuf->EaValueLength), 2634 0, get_write); 2635 if (rc < 0) { 2636 ksmbd_debug(SMB, 2637 "ksmbd_vfs_setxattr is failed(%d)\n", 2638 rc); 2639 break; 2640 } 2641 } 2642 2643 next: 2644 next = le32_to_cpu(eabuf->NextEntryOffset); 2645 if (next == 0 || buf_len < next) 2646 break; 2647 buf_len -= next; 2648 eabuf = (struct smb2_ea_info *)((char *)eabuf + next); 2649 if (buf_len < sizeof(struct smb2_ea_info)) { 2650 rc = -EINVAL; 2651 break; 2652 } 2653 2654 if (buf_len < sizeof(struct smb2_ea_info) + eabuf->EaNameLength + 1 + 2655 le16_to_cpu(eabuf->EaValueLength)) { 2656 rc = -EINVAL; 2657 break; 2658 } 2659 } while (next != 0); 2660 2661 kfree(attr_name); 2662 return rc; 2663 } 2664 2665 static noinline int smb2_set_stream_name_xattr(const struct path *path, 2666 struct ksmbd_file *fp, 2667 char *stream_name, int s_type) 2668 { 2669 struct mnt_idmap *idmap = mnt_idmap(path->mnt); 2670 size_t xattr_stream_size; 2671 char *xattr_stream_name; 2672 int rc; 2673 2674 rc = ksmbd_vfs_xattr_stream_name(stream_name, 2675 &xattr_stream_name, 2676 &xattr_stream_size, 2677 s_type); 2678 if (rc) 2679 return rc; 2680 2681 fp->stream.name = xattr_stream_name; 2682 fp->stream.size = xattr_stream_size; 2683 2684 /* Check if there is stream prefix in xattr space */ 2685 rc = ksmbd_vfs_casexattr_len(idmap, 2686 path->dentry, 2687 xattr_stream_name, 2688 xattr_stream_size); 2689 if (rc >= 0) 2690 return 0; 2691 2692 if (fp->cdoption == FILE_OPEN_LE) { 2693 ksmbd_debug(SMB, "XATTR stream name lookup failed: %d\n", rc); 2694 return -EBADF; 2695 } 2696 2697 rc = ksmbd_vfs_setxattr(idmap, path, xattr_stream_name, NULL, 0, 0, false); 2698 if (rc < 0) 2699 pr_err("Failed to store XATTR stream name :%d\n", rc); 2700 return 0; 2701 } 2702 2703 static int smb2_remove_smb_xattrs(const struct path *path) 2704 { 2705 struct mnt_idmap *idmap = mnt_idmap(path->mnt); 2706 char *name, *xattr_list = NULL; 2707 ssize_t xattr_list_len; 2708 int err = 0; 2709 2710 xattr_list_len = ksmbd_vfs_listxattr(path->dentry, &xattr_list); 2711 if (xattr_list_len < 0) { 2712 goto out; 2713 } else if (!xattr_list_len) { 2714 ksmbd_debug(SMB, "empty xattr in the file\n"); 2715 goto out; 2716 } 2717 2718 for (name = xattr_list; name - xattr_list < xattr_list_len; 2719 name += strlen(name) + 1) { 2720 ksmbd_debug(SMB, "%s, len %zd\n", name, strlen(name)); 2721 2722 if (!strncmp(name, XATTR_USER_PREFIX, XATTR_USER_PREFIX_LEN) && 2723 !strncmp(&name[XATTR_USER_PREFIX_LEN], STREAM_PREFIX, 2724 STREAM_PREFIX_LEN)) { 2725 err = ksmbd_vfs_remove_xattr(idmap, path, 2726 name, true); 2727 if (err) 2728 ksmbd_debug(SMB, "remove xattr failed : %s\n", 2729 name); 2730 } 2731 } 2732 out: 2733 kvfree(xattr_list); 2734 return err; 2735 } 2736 2737 static int smb2_create_truncate(const struct path *path) 2738 { 2739 int rc = vfs_truncate(path, 0); 2740 2741 if (rc) { 2742 pr_err("vfs_truncate failed, rc %d\n", rc); 2743 return rc; 2744 } 2745 2746 rc = smb2_remove_smb_xattrs(path); 2747 if (rc == -EOPNOTSUPP) 2748 rc = 0; 2749 if (rc) 2750 ksmbd_debug(SMB, 2751 "ksmbd_truncate_stream_name_xattr failed, rc %d\n", 2752 rc); 2753 return rc; 2754 } 2755 2756 static void smb2_new_xattrs(struct ksmbd_tree_connect *tcon, const struct path *path, 2757 struct ksmbd_file *fp) 2758 { 2759 struct xattr_dos_attrib da = {0}; 2760 int rc; 2761 2762 if (!test_share_config_flag(tcon->share_conf, 2763 KSMBD_SHARE_FLAG_STORE_DOS_ATTRS)) 2764 return; 2765 2766 da.version = 4; 2767 da.attr = le32_to_cpu(fp->f_ci->m_fattr); 2768 da.itime = da.create_time = fp->create_time; 2769 da.flags = XATTR_DOSINFO_ATTRIB | XATTR_DOSINFO_CREATE_TIME | 2770 XATTR_DOSINFO_ITIME; 2771 2772 rc = ksmbd_vfs_set_dos_attrib_xattr(mnt_idmap(path->mnt), path, &da, true); 2773 if (rc) 2774 ksmbd_debug(SMB, "failed to store file attribute into xattr\n"); 2775 } 2776 2777 static void smb2_update_xattrs(struct ksmbd_tree_connect *tcon, 2778 const struct path *path, struct ksmbd_file *fp) 2779 { 2780 struct xattr_dos_attrib da; 2781 int rc; 2782 2783 fp->f_ci->m_fattr &= ~(FILE_ATTRIBUTE_HIDDEN_LE | FILE_ATTRIBUTE_SYSTEM_LE); 2784 2785 /* get FileAttributes from XATTR_NAME_DOS_ATTRIBUTE */ 2786 if (!test_share_config_flag(tcon->share_conf, 2787 KSMBD_SHARE_FLAG_STORE_DOS_ATTRS)) 2788 return; 2789 2790 rc = ksmbd_vfs_get_dos_attrib_xattr(mnt_idmap(path->mnt), 2791 path->dentry, &da); 2792 if (rc > 0) { 2793 fp->f_ci->m_fattr = cpu_to_le32(da.attr); 2794 fp->create_time = da.create_time; 2795 fp->itime = da.itime; 2796 } 2797 } 2798 2799 static int smb2_creat(struct ksmbd_work *work, 2800 struct path *path, char *name, int open_flags, 2801 umode_t posix_mode, bool is_dir) 2802 { 2803 struct ksmbd_tree_connect *tcon = work->tcon; 2804 struct ksmbd_share_config *share = tcon->share_conf; 2805 umode_t mode; 2806 int rc; 2807 2808 if (!(open_flags & O_CREAT)) 2809 return -EBADF; 2810 2811 ksmbd_debug(SMB, "file does not exist, so creating\n"); 2812 if (is_dir == true) { 2813 ksmbd_debug(SMB, "creating directory\n"); 2814 2815 mode = share_config_directory_mode(share, posix_mode); 2816 rc = ksmbd_vfs_mkdir(work, name, mode); 2817 if (rc) 2818 return rc; 2819 } else { 2820 ksmbd_debug(SMB, "creating regular file\n"); 2821 2822 mode = share_config_create_mode(share, posix_mode); 2823 rc = ksmbd_vfs_create(work, name, mode); 2824 if (rc) 2825 return rc; 2826 } 2827 2828 rc = ksmbd_vfs_kern_path(work, name, 0, path, 0); 2829 if (rc) { 2830 pr_err("cannot get linux path (%s), err = %d\n", 2831 name, rc); 2832 return rc; 2833 } 2834 return 0; 2835 } 2836 2837 static int smb2_create_sd_buffer(struct ksmbd_work *work, 2838 struct smb2_create_req *req, 2839 const struct path *path) 2840 { 2841 struct create_context *context; 2842 struct create_sd_buf_req *sd_buf; 2843 2844 if (!req->CreateContextsOffset) 2845 return -ENOENT; 2846 2847 /* Parse SD BUFFER create contexts */ 2848 context = smb2_find_context_vals(req, SMB2_CREATE_SD_BUFFER, 4); 2849 if (!context) 2850 return -ENOENT; 2851 else if (IS_ERR(context)) 2852 return PTR_ERR(context); 2853 2854 ksmbd_debug(SMB, 2855 "Set ACLs using SMB2_CREATE_SD_BUFFER context\n"); 2856 sd_buf = (struct create_sd_buf_req *)context; 2857 if (le16_to_cpu(context->DataOffset) + 2858 le32_to_cpu(context->DataLength) < 2859 sizeof(struct create_sd_buf_req)) 2860 return -EINVAL; 2861 return set_info_sec(work->conn, work->tcon, path, &sd_buf->ntsd, 2862 le32_to_cpu(sd_buf->ccontext.DataLength), true, false); 2863 } 2864 2865 static void ksmbd_acls_fattr(struct smb_fattr *fattr, 2866 struct mnt_idmap *idmap, 2867 struct inode *inode) 2868 { 2869 vfsuid_t vfsuid = i_uid_into_vfsuid(idmap, inode); 2870 vfsgid_t vfsgid = i_gid_into_vfsgid(idmap, inode); 2871 2872 fattr->cf_uid = vfsuid_into_kuid(vfsuid); 2873 fattr->cf_gid = vfsgid_into_kgid(vfsgid); 2874 fattr->cf_mode = inode->i_mode; 2875 fattr->cf_acls = NULL; 2876 fattr->cf_dacls = NULL; 2877 2878 if (IS_ENABLED(CONFIG_FS_POSIX_ACL)) { 2879 fattr->cf_acls = get_inode_acl(inode, ACL_TYPE_ACCESS); 2880 if (S_ISDIR(inode->i_mode)) 2881 fattr->cf_dacls = get_inode_acl(inode, ACL_TYPE_DEFAULT); 2882 } 2883 } 2884 2885 enum { 2886 DURABLE_RECONN_V2 = 1, 2887 DURABLE_RECONN, 2888 DURABLE_REQ_V2, 2889 DURABLE_REQ, 2890 }; 2891 2892 struct durable_info { 2893 struct ksmbd_file *fp; 2894 unsigned short int type; 2895 bool persistent; 2896 bool reconnected; 2897 bool app_instance_id; 2898 unsigned int timeout; 2899 char *CreateGuid; 2900 char AppInstanceId[SMB2_CREATE_GUID_SIZE]; 2901 }; 2902 2903 static int parse_durable_handle_context(struct ksmbd_work *work, 2904 struct smb2_create_req *req, 2905 struct lease_ctx_info *lc, 2906 struct durable_info *dh_info) 2907 { 2908 struct ksmbd_conn *conn = work->conn; 2909 struct create_context *context; 2910 int dh_idx, err = 0; 2911 u64 persistent_id = 0; 2912 int req_op_level; 2913 static const char * const durable_arr[] = {"DH2C", "DHnC", "DH2Q", "DHnQ"}; 2914 2915 req_op_level = req->RequestedOplockLevel; 2916 for (dh_idx = DURABLE_RECONN_V2; dh_idx <= ARRAY_SIZE(durable_arr); 2917 dh_idx++) { 2918 context = smb2_find_context_vals(req, durable_arr[dh_idx - 1], 4); 2919 if (IS_ERR(context)) { 2920 err = PTR_ERR(context); 2921 goto out; 2922 } 2923 if (!context) 2924 continue; 2925 2926 switch (dh_idx) { 2927 case DURABLE_RECONN_V2: 2928 { 2929 struct create_durable_handle_reconnect_v2 *recon_v2; 2930 2931 if (dh_info->type == DURABLE_RECONN || 2932 dh_info->type == DURABLE_REQ_V2) { 2933 err = -EINVAL; 2934 goto out; 2935 } 2936 2937 if (le32_to_cpu(context->DataLength) < 2938 sizeof(recon_v2->dcontext)) { 2939 err = -EINVAL; 2940 goto out; 2941 } 2942 2943 recon_v2 = (struct create_durable_handle_reconnect_v2 *)context; 2944 persistent_id = recon_v2->dcontext.Fid.PersistentFileId; 2945 dh_info->fp = ksmbd_lookup_durable_fd(persistent_id); 2946 if (!dh_info->fp) { 2947 ksmbd_debug(SMB, "Failed to get durable handle state\n"); 2948 err = -EBADF; 2949 goto out; 2950 } 2951 2952 if (dh_info->fp->durable_volatile_id != 2953 recon_v2->dcontext.Fid.VolatileFileId) { 2954 err = -EBADF; 2955 ksmbd_put_durable_fd(dh_info->fp); 2956 goto out; 2957 } 2958 2959 if (memcmp(dh_info->fp->create_guid, recon_v2->dcontext.CreateGuid, 2960 SMB2_CREATE_GUID_SIZE)) { 2961 err = -EBADF; 2962 ksmbd_put_durable_fd(dh_info->fp); 2963 goto out; 2964 } 2965 2966 dh_info->type = dh_idx; 2967 dh_info->reconnected = true; 2968 ksmbd_debug(SMB, 2969 "reconnect v2 Persistent-id from reconnect = %llu\n", 2970 persistent_id); 2971 break; 2972 } 2973 case DURABLE_RECONN: 2974 { 2975 create_durable_reconn_t *recon; 2976 2977 if (dh_info->type == DURABLE_RECONN_V2 || 2978 dh_info->type == DURABLE_REQ_V2) { 2979 err = -EINVAL; 2980 goto out; 2981 } 2982 2983 if (le32_to_cpu(context->DataLength) < 2984 sizeof(recon->Data)) { 2985 err = -EINVAL; 2986 goto out; 2987 } 2988 2989 recon = (create_durable_reconn_t *)context; 2990 persistent_id = recon->Data.Fid.PersistentFileId; 2991 dh_info->fp = ksmbd_lookup_durable_fd(persistent_id); 2992 if (!dh_info->fp) { 2993 ksmbd_debug(SMB, "Failed to get durable handle state\n"); 2994 err = -EBADF; 2995 goto out; 2996 } 2997 2998 if (dh_info->fp->durable_volatile_id != 2999 recon->Data.Fid.VolatileFileId) { 3000 err = -EBADF; 3001 ksmbd_put_durable_fd(dh_info->fp); 3002 goto out; 3003 } 3004 3005 dh_info->type = dh_idx; 3006 dh_info->reconnected = true; 3007 ksmbd_debug(SMB, "reconnect Persistent-id from reconnect = %llu\n", 3008 persistent_id); 3009 break; 3010 } 3011 case DURABLE_REQ_V2: 3012 { 3013 struct create_durable_req_v2 *durable_v2_blob; 3014 3015 if (dh_info->type == DURABLE_RECONN || 3016 dh_info->type == DURABLE_RECONN_V2) { 3017 err = -EINVAL; 3018 goto out; 3019 } 3020 3021 if (le32_to_cpu(context->DataLength) < 3022 sizeof(durable_v2_blob->dcontext)) { 3023 err = -EINVAL; 3024 goto out; 3025 } 3026 3027 durable_v2_blob = 3028 (struct create_durable_req_v2 *)context; 3029 ksmbd_debug(SMB, "Request for durable v2 open\n"); 3030 dh_info->fp = ksmbd_lookup_fd_cguid(durable_v2_blob->dcontext.CreateGuid); 3031 if (dh_info->fp) { 3032 if (!memcmp(conn->ClientGUID, dh_info->fp->client_guid, 3033 SMB2_CLIENT_GUID_SIZE)) { 3034 if (!(req->hdr.Flags & SMB2_FLAGS_REPLAY_OPERATION)) { 3035 err = -ENOEXEC; 3036 ksmbd_put_durable_fd(dh_info->fp); 3037 goto out; 3038 } 3039 3040 if (dh_info->fp->conn) { 3041 ksmbd_put_durable_fd(dh_info->fp); 3042 err = -EBADF; 3043 goto out; 3044 } 3045 dh_info->reconnected = true; 3046 goto out; 3047 } 3048 ksmbd_put_durable_fd(dh_info->fp); 3049 dh_info->fp = NULL; 3050 } 3051 3052 if ((lc && (lc->req_state & SMB2_LEASE_HANDLE_CACHING_LE)) || 3053 req_op_level == SMB2_OPLOCK_LEVEL_BATCH) { 3054 dh_info->CreateGuid = 3055 durable_v2_blob->dcontext.CreateGuid; 3056 dh_info->persistent = 3057 le32_to_cpu(durable_v2_blob->dcontext.Flags); 3058 dh_info->timeout = 3059 le32_to_cpu(durable_v2_blob->dcontext.Timeout); 3060 dh_info->type = dh_idx; 3061 } 3062 break; 3063 } 3064 case DURABLE_REQ: 3065 if (dh_info->type == DURABLE_RECONN) 3066 goto out; 3067 if (dh_info->type == DURABLE_RECONN_V2 || 3068 dh_info->type == DURABLE_REQ_V2) { 3069 err = -EINVAL; 3070 goto out; 3071 } 3072 3073 if ((lc && (lc->req_state & SMB2_LEASE_HANDLE_CACHING_LE)) || 3074 req_op_level == SMB2_OPLOCK_LEVEL_BATCH) { 3075 ksmbd_debug(SMB, "Request for durable open\n"); 3076 dh_info->type = dh_idx; 3077 } 3078 } 3079 } 3080 3081 out: 3082 return err; 3083 } 3084 3085 static int parse_app_instance_id(struct smb2_create_req *req, 3086 struct durable_info *dh_info) 3087 { 3088 struct create_context *context; 3089 char *data; 3090 3091 context = smb2_find_context_vals(req, SMB2_CREATE_APP_INSTANCE_ID, 3092 SMB2_CREATE_GUID_SIZE); 3093 if (IS_ERR(context)) 3094 return PTR_ERR(context); 3095 if (!context) 3096 return 0; 3097 3098 if (le32_to_cpu(context->DataLength) < 20) 3099 return -EINVAL; 3100 3101 data = (char *)context + le16_to_cpu(context->DataOffset); 3102 if (data[0] != 20 || data[1]) 3103 return -EINVAL; 3104 3105 memcpy(dh_info->AppInstanceId, data + 4, SMB2_CREATE_GUID_SIZE); 3106 dh_info->app_instance_id = true; 3107 return 0; 3108 } 3109 3110 /** 3111 * smb2_open() - handler for smb file open request 3112 * @work: smb work containing request buffer 3113 * 3114 * Return: 0 on success, otherwise error 3115 */ 3116 int smb2_open(struct ksmbd_work *work) 3117 { 3118 struct ksmbd_conn *conn = work->conn; 3119 struct ksmbd_session *sess = work->sess; 3120 struct ksmbd_tree_connect *tcon = work->tcon; 3121 struct smb2_create_req *req; 3122 struct smb2_create_rsp *rsp; 3123 struct path path; 3124 struct ksmbd_share_config *share = tcon->share_conf; 3125 struct ksmbd_file *fp = NULL; 3126 struct file *filp = NULL; 3127 struct mnt_idmap *idmap = NULL; 3128 struct kstat stat; 3129 struct create_context *context; 3130 struct lease_ctx_info *lc = NULL; 3131 struct create_ea_buf_req *ea_buf = NULL; 3132 struct oplock_info *opinfo; 3133 struct durable_info dh_info = {0}; 3134 __le32 *next_ptr = NULL; 3135 int req_op_level = 0, open_flags = 0, may_flags = 0, file_info = 0; 3136 int rc = 0; 3137 int contxt_cnt = 0, query_disk_id = 0; 3138 bool maximal_access_ctxt = false, posix_ctxt = false; 3139 int s_type = 0; 3140 int next_off = 0; 3141 char *name = NULL; 3142 char *stream_name = NULL; 3143 bool file_present = false, created = false, already_permitted = false; 3144 int share_ret, need_truncate = 0; 3145 u64 time, alloc_size = 0; 3146 umode_t posix_mode = 0; 3147 __le32 daccess, maximal_access = 0; 3148 int iov_len = 0; 3149 3150 ksmbd_debug(SMB, "Received smb2 create request\n"); 3151 3152 WORK_BUFFERS(work, req, rsp); 3153 3154 if (req->hdr.NextCommand && !work->next_smb2_rcv_hdr_off && 3155 (req->hdr.Flags & SMB2_FLAGS_RELATED_OPERATIONS)) { 3156 ksmbd_debug(SMB, "invalid flag in chained command\n"); 3157 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 3158 smb2_set_err_rsp(work); 3159 return -EINVAL; 3160 } 3161 3162 if (test_share_config_flag(share, KSMBD_SHARE_FLAG_PIPE)) { 3163 ksmbd_debug(SMB, "IPC pipe create request\n"); 3164 return create_smb2_pipe(work); 3165 } 3166 3167 if (req->CreateContextsOffset && tcon->posix_extensions) { 3168 context = smb2_find_context_vals(req, SMB2_CREATE_TAG_POSIX, 16); 3169 if (IS_ERR(context)) { 3170 rc = PTR_ERR(context); 3171 goto err_out2; 3172 } else if (context) { 3173 struct create_posix *posix = (struct create_posix *)context; 3174 3175 if (le16_to_cpu(context->DataOffset) + 3176 le32_to_cpu(context->DataLength) < 3177 sizeof(struct create_posix) - 4) { 3178 rc = -EINVAL; 3179 goto err_out2; 3180 } 3181 ksmbd_debug(SMB, "get posix context\n"); 3182 3183 posix_mode = le32_to_cpu(posix->Mode); 3184 posix_ctxt = true; 3185 } 3186 } 3187 3188 if (req->NameLength) { 3189 name = smb2_get_name((char *)req + le16_to_cpu(req->NameOffset), 3190 le16_to_cpu(req->NameLength), 3191 work->conn->local_nls); 3192 if (IS_ERR(name)) { 3193 rc = PTR_ERR(name); 3194 name = NULL; 3195 goto err_out2; 3196 } 3197 3198 ksmbd_debug(SMB, "converted name = %s\n", name); 3199 3200 if (posix_ctxt == false) { 3201 if (strchr(name, ':')) { 3202 if (!test_share_config_flag(work->tcon->share_conf, 3203 KSMBD_SHARE_FLAG_STREAMS)) { 3204 rc = -EBADF; 3205 goto err_out2; 3206 } 3207 rc = parse_stream_name(name, &stream_name, &s_type); 3208 if (rc < 0) 3209 goto err_out2; 3210 } 3211 3212 rc = ksmbd_validate_filename(name); 3213 if (rc < 0) 3214 goto err_out2; 3215 } 3216 3217 if (ksmbd_share_veto_filename(share, name)) { 3218 rc = -ENOENT; 3219 ksmbd_debug(SMB, "Reject open(), vetoed file: %s\n", 3220 name); 3221 goto err_out2; 3222 } 3223 } else { 3224 name = kstrdup("", KSMBD_DEFAULT_GFP); 3225 if (!name) { 3226 rc = -ENOMEM; 3227 goto err_out2; 3228 } 3229 } 3230 3231 req_op_level = req->RequestedOplockLevel; 3232 3233 if (server_conf.flags & KSMBD_GLOBAL_FLAG_DURABLE_HANDLE && 3234 req->CreateContextsOffset) { 3235 lc = parse_lease_state(req); 3236 if (IS_ERR(lc)) { 3237 rc = PTR_ERR(lc); 3238 lc = NULL; 3239 goto err_out2; 3240 } 3241 if (lc && lc->version == 2 && conn->dialect < SMB30_PROT_ID) { 3242 kfree(lc); 3243 lc = NULL; 3244 if (req_op_level == SMB2_OPLOCK_LEVEL_LEASE) 3245 req_op_level = SMB2_OPLOCK_LEVEL_NONE; 3246 } 3247 rc = parse_durable_handle_context(work, req, lc, &dh_info); 3248 if (rc) { 3249 ksmbd_debug(SMB, "error parsing durable handle context\n"); 3250 goto err_out2; 3251 } 3252 rc = parse_app_instance_id(req, &dh_info); 3253 if (rc) 3254 goto err_out2; 3255 3256 if (dh_info.reconnected == true) { 3257 rc = smb2_check_durable_oplock(conn, share, dh_info.fp, 3258 lc, sess->user, name); 3259 if (rc) 3260 goto err_out2; 3261 3262 rc = ksmbd_reopen_durable_fd(work, dh_info.fp); 3263 if (rc) 3264 goto err_out2; 3265 3266 fp = dh_info.fp; 3267 3268 if (ksmbd_override_fsids(work)) { 3269 rc = -ENOMEM; 3270 goto err_out2; 3271 } 3272 3273 file_info = FILE_OPENED; 3274 3275 rc = ksmbd_vfs_getattr(&fp->filp->f_path, &stat); 3276 if (rc) 3277 goto err_out2; 3278 3279 goto reconnected_fp; 3280 } 3281 3282 if (dh_info.type == DURABLE_REQ_V2 && dh_info.app_instance_id) 3283 ksmbd_close_fd_app_instance_id(dh_info.AppInstanceId); 3284 } else if (req_op_level == SMB2_OPLOCK_LEVEL_LEASE) { 3285 lc = parse_lease_state(req); 3286 if (IS_ERR(lc)) { 3287 rc = PTR_ERR(lc); 3288 lc = NULL; 3289 goto err_out2; 3290 } 3291 if (lc && lc->version == 2 && conn->dialect < SMB30_PROT_ID) { 3292 kfree(lc); 3293 lc = NULL; 3294 req_op_level = SMB2_OPLOCK_LEVEL_NONE; 3295 } 3296 } 3297 3298 if (le32_to_cpu(req->ImpersonationLevel) > le32_to_cpu(IL_DELEGATE)) { 3299 pr_err("Invalid impersonationlevel : 0x%x\n", 3300 le32_to_cpu(req->ImpersonationLevel)); 3301 rc = -EIO; 3302 rsp->hdr.Status = STATUS_BAD_IMPERSONATION_LEVEL; 3303 goto err_out2; 3304 } 3305 3306 if (req->CreateOptions && !(req->CreateOptions & CREATE_OPTIONS_MASK_LE)) { 3307 pr_err("Invalid create options : 0x%x\n", 3308 le32_to_cpu(req->CreateOptions)); 3309 rc = -EINVAL; 3310 goto err_out2; 3311 } else { 3312 if (req->CreateOptions & FILE_SEQUENTIAL_ONLY_LE && 3313 req->CreateOptions & FILE_RANDOM_ACCESS_LE) 3314 req->CreateOptions &= ~FILE_SEQUENTIAL_ONLY_LE; 3315 3316 if (req->CreateOptions & 3317 (FILE_OPEN_BY_FILE_ID_LE | CREATE_TREE_CONNECTION | 3318 FILE_RESERVE_OPFILTER_LE)) { 3319 rc = -EOPNOTSUPP; 3320 goto err_out2; 3321 } 3322 3323 if (req->CreateOptions & FILE_DIRECTORY_FILE_LE) { 3324 if (req->CreateOptions & FILE_NON_DIRECTORY_FILE_LE) { 3325 rc = -EINVAL; 3326 goto err_out2; 3327 } else if (req->CreateOptions & FILE_NO_COMPRESSION_LE) { 3328 req->CreateOptions &= ~FILE_NO_COMPRESSION_LE; 3329 } 3330 } 3331 } 3332 3333 if (le32_to_cpu(req->CreateDisposition) > 3334 le32_to_cpu(FILE_OVERWRITE_IF_LE)) { 3335 pr_err("Invalid create disposition : 0x%x\n", 3336 le32_to_cpu(req->CreateDisposition)); 3337 rc = -EINVAL; 3338 goto err_out2; 3339 } 3340 3341 if (!(req->DesiredAccess & DESIRED_ACCESS_MASK)) { 3342 pr_err("Invalid desired access : 0x%x\n", 3343 le32_to_cpu(req->DesiredAccess)); 3344 rc = -EACCES; 3345 goto err_out2; 3346 } 3347 3348 if (req->DesiredAccess == FILE_SYNCHRONIZE_LE && 3349 req->CreateDisposition == FILE_OPEN_IF_LE && 3350 !req->FileAttributes) { 3351 rc = -EACCES; 3352 goto err_out2; 3353 } 3354 3355 if (req->FileAttributes && 3356 (req->FileAttributes & ~cpu_to_le32(SMB2_CREATE_FILE_ATTRIBUTE_MASK))) { 3357 pr_err("Invalid file attribute : 0x%x\n", 3358 le32_to_cpu(req->FileAttributes)); 3359 rc = -EINVAL; 3360 goto err_out2; 3361 } 3362 3363 if (req->CreateContextsOffset) { 3364 /* Parse non-durable handle create contexts */ 3365 context = smb2_find_context_vals(req, SMB2_CREATE_EA_BUFFER, 4); 3366 if (IS_ERR(context)) { 3367 rc = PTR_ERR(context); 3368 goto err_out2; 3369 } else if (context) { 3370 ea_buf = (struct create_ea_buf_req *)context; 3371 if (le16_to_cpu(context->DataOffset) + 3372 le32_to_cpu(context->DataLength) < 3373 sizeof(struct create_ea_buf_req)) { 3374 rc = -EINVAL; 3375 goto err_out2; 3376 } 3377 if (req->CreateOptions & FILE_NO_EA_KNOWLEDGE_LE) { 3378 rsp->hdr.Status = STATUS_ACCESS_DENIED; 3379 rc = -EACCES; 3380 goto err_out2; 3381 } 3382 } 3383 3384 context = smb2_find_context_vals(req, 3385 SMB2_CREATE_QUERY_MAXIMAL_ACCESS_REQUEST, 4); 3386 if (IS_ERR(context)) { 3387 rc = PTR_ERR(context); 3388 goto err_out2; 3389 } else if (context) { 3390 ksmbd_debug(SMB, 3391 "get query maximal access context\n"); 3392 maximal_access_ctxt = 1; 3393 } 3394 3395 context = smb2_find_context_vals(req, 3396 SMB2_CREATE_TIMEWARP_REQUEST, 4); 3397 if (IS_ERR(context)) { 3398 rc = PTR_ERR(context); 3399 goto err_out2; 3400 } else if (context) { 3401 ksmbd_debug(SMB, "get timewarp context\n"); 3402 rc = -EBADF; 3403 goto err_out2; 3404 } 3405 } 3406 3407 if (ksmbd_override_fsids(work)) { 3408 rc = -ENOMEM; 3409 goto err_out2; 3410 } 3411 3412 rc = ksmbd_vfs_kern_path(work, name, LOOKUP_NO_SYMLINKS, 3413 &path, 1); 3414 3415 /* 3416 * A durable handle opened with delete-on-close is preserved across a 3417 * disconnect so it can be reclaimed by a durable reconnect. When a new 3418 * delete-on-close open for the same name arrives instead, the 3419 * disconnected handle must give way: close it so its delete-on-close 3420 * removes the file, then re-resolve so this open can create a fresh one. 3421 */ 3422 if (!rc && (req->CreateOptions & FILE_DELETE_ON_CLOSE_LE) && 3423 (req->CreateDisposition == FILE_OVERWRITE_IF_LE || 3424 req->CreateDisposition == FILE_OPEN_IF_LE) && 3425 ksmbd_close_disconnected_durable_delete_on_close(path.dentry)) { 3426 path_put(&path); 3427 rc = ksmbd_vfs_kern_path(work, name, LOOKUP_NO_SYMLINKS, 3428 &path, 1); 3429 } 3430 3431 if (!rc) { 3432 file_present = true; 3433 3434 if (req->CreateOptions & FILE_DELETE_ON_CLOSE_LE) { 3435 /* 3436 * If file exists with under flags, return access 3437 * denied error. 3438 */ 3439 if (req->CreateDisposition == FILE_OVERWRITE_IF_LE || 3440 req->CreateDisposition == FILE_OPEN_IF_LE) { 3441 rc = -EACCES; 3442 goto err_out; 3443 } 3444 3445 if (!test_tree_conn_flag(tcon, KSMBD_TREE_CONN_FLAG_WRITABLE)) { 3446 ksmbd_debug(SMB, 3447 "User does not have write permission\n"); 3448 rc = -EACCES; 3449 goto err_out; 3450 } 3451 } else if (d_is_symlink(path.dentry)) { 3452 rc = -EACCES; 3453 goto err_out; 3454 } 3455 3456 idmap = mnt_idmap(path.mnt); 3457 } else { 3458 if (rc != -ENOENT) 3459 goto err_out; 3460 ksmbd_debug(SMB, "can not get linux path for %s, rc = %d\n", 3461 name, rc); 3462 rc = 0; 3463 } 3464 3465 /* 3466 * An explicit ::$DATA suffix names the unnamed data stream and is 3467 * canonicalized to a NULL stream name (base file), but the request 3468 * still has to be validated against the data-stream type, e.g. opening 3469 * <dir>::$DATA with FILE_DIRECTORY_FILE must fail with 3470 * STATUS_NOT_A_DIRECTORY. 3471 */ 3472 if (stream_name || s_type == DATA_STREAM) { 3473 if (req->CreateOptions & FILE_DIRECTORY_FILE_LE) { 3474 if (s_type == DATA_STREAM) { 3475 rc = -EIO; 3476 rsp->hdr.Status = STATUS_NOT_A_DIRECTORY; 3477 } 3478 } else { 3479 if (file_present && S_ISDIR(d_inode(path.dentry)->i_mode) && 3480 s_type == DATA_STREAM) { 3481 rc = -EIO; 3482 rsp->hdr.Status = STATUS_FILE_IS_A_DIRECTORY; 3483 } 3484 } 3485 3486 if (req->CreateOptions & FILE_DIRECTORY_FILE_LE && 3487 req->FileAttributes & FILE_ATTRIBUTE_NORMAL_LE) { 3488 rsp->hdr.Status = STATUS_NOT_A_DIRECTORY; 3489 rc = -EIO; 3490 } 3491 3492 if (rc < 0) 3493 goto err_out; 3494 } 3495 3496 if (file_present && req->CreateOptions & FILE_NON_DIRECTORY_FILE_LE && 3497 S_ISDIR(d_inode(path.dentry)->i_mode) && 3498 !(req->CreateOptions & FILE_DELETE_ON_CLOSE_LE)) { 3499 ksmbd_debug(SMB, "open() argument is a directory: %s, %x\n", 3500 name, req->CreateOptions); 3501 rsp->hdr.Status = STATUS_FILE_IS_A_DIRECTORY; 3502 rc = -EIO; 3503 goto err_out; 3504 } 3505 3506 if (file_present && (req->CreateOptions & FILE_DIRECTORY_FILE_LE) && 3507 !(req->CreateDisposition == FILE_CREATE_LE) && 3508 !S_ISDIR(d_inode(path.dentry)->i_mode)) { 3509 rsp->hdr.Status = STATUS_NOT_A_DIRECTORY; 3510 rc = -EIO; 3511 goto err_out; 3512 } 3513 3514 if (!stream_name && file_present && 3515 req->CreateDisposition == FILE_CREATE_LE) { 3516 rc = -EEXIST; 3517 goto err_out; 3518 } 3519 3520 daccess = smb_map_generic_desired_access(req->DesiredAccess); 3521 3522 if (file_present && !(req->CreateOptions & FILE_DELETE_ON_CLOSE_LE)) { 3523 rc = smb_check_perm_dacl(conn, &path, &daccess, 3524 sess->user->uid); 3525 if (rc) 3526 goto err_out; 3527 } 3528 3529 if (daccess & FILE_MAXIMAL_ACCESS_LE) { 3530 if (!file_present) { 3531 daccess = cpu_to_le32(GENERIC_ALL_FLAGS); 3532 } else { 3533 ksmbd_vfs_query_maximal_access(idmap, 3534 path.dentry, 3535 &daccess); 3536 already_permitted = true; 3537 } 3538 maximal_access = daccess; 3539 } 3540 3541 open_flags = smb2_create_open_flags(file_present, daccess, 3542 req->CreateDisposition, 3543 &may_flags, 3544 req->CreateOptions, 3545 file_present ? d_inode(path.dentry)->i_mode : 0); 3546 3547 if (!test_tree_conn_flag(tcon, KSMBD_TREE_CONN_FLAG_WRITABLE)) { 3548 if (open_flags & (O_CREAT | O_TRUNC)) { 3549 ksmbd_debug(SMB, 3550 "User does not have write permission\n"); 3551 rc = -EACCES; 3552 goto err_out; 3553 } 3554 } 3555 3556 /*create file if not present */ 3557 if (!file_present) { 3558 rc = smb2_creat(work, &path, name, open_flags, 3559 posix_mode, 3560 req->CreateOptions & FILE_DIRECTORY_FILE_LE); 3561 if (rc) { 3562 if (rc == -ENOENT) { 3563 rc = -EIO; 3564 rsp->hdr.Status = STATUS_OBJECT_PATH_NOT_FOUND; 3565 } 3566 goto err_out; 3567 } 3568 3569 created = true; 3570 idmap = mnt_idmap(path.mnt); 3571 if (ea_buf) { 3572 if (le32_to_cpu(ea_buf->ccontext.DataLength) < 3573 sizeof(struct smb2_ea_info)) { 3574 rc = -EINVAL; 3575 goto err_out; 3576 } 3577 3578 rc = smb2_set_ea(&ea_buf->ea, 3579 le32_to_cpu(ea_buf->ccontext.DataLength), 3580 &path, false); 3581 if (rc == -EOPNOTSUPP) 3582 rc = 0; 3583 else if (rc) 3584 goto err_out; 3585 } 3586 } else if (!already_permitted) { 3587 /* FILE_READ_ATTRIBUTE is allowed without inode_permission, 3588 * because execute(search) permission on a parent directory, 3589 * is already granted. 3590 */ 3591 if (daccess & ~(FILE_READ_ATTRIBUTES_LE | FILE_READ_CONTROL_LE)) { 3592 rc = inode_permission(idmap, 3593 d_inode(path.dentry), 3594 may_flags); 3595 if (rc) 3596 goto err_out; 3597 3598 if ((daccess & FILE_DELETE_LE) || 3599 (req->CreateOptions & FILE_DELETE_ON_CLOSE_LE)) { 3600 rc = inode_permission(idmap, 3601 d_inode(path.dentry->d_parent), 3602 MAY_EXEC | MAY_WRITE); 3603 if (rc) 3604 goto err_out; 3605 } 3606 } 3607 } 3608 3609 rc = ksmbd_query_inode_status(path.dentry->d_parent); 3610 if (rc == KSMBD_INODE_STATUS_PENDING_DELETE) { 3611 rc = -EBUSY; 3612 goto err_out; 3613 } 3614 3615 rc = 0; 3616 filp = dentry_open(&path, open_flags, current_cred()); 3617 if (IS_ERR(filp)) { 3618 rc = PTR_ERR(filp); 3619 pr_err("dentry open for dir failed, rc %d\n", rc); 3620 goto err_out; 3621 } 3622 3623 if (file_present) { 3624 if (!(open_flags & O_TRUNC)) 3625 file_info = FILE_OPENED; 3626 else 3627 file_info = FILE_OVERWRITTEN; 3628 3629 if ((req->CreateDisposition & FILE_CREATE_MASK_LE) == 3630 FILE_SUPERSEDE_LE) 3631 file_info = FILE_SUPERSEDED; 3632 } else if (open_flags & O_CREAT) { 3633 file_info = FILE_CREATED; 3634 } 3635 3636 ksmbd_vfs_set_fadvise(filp, req->CreateOptions); 3637 3638 /* Obtain Volatile-ID */ 3639 fp = ksmbd_open_fd(work, filp); 3640 if (IS_ERR(fp)) { 3641 fput(filp); 3642 rc = PTR_ERR(fp); 3643 fp = NULL; 3644 goto err_out; 3645 } 3646 3647 /* Get Persistent-ID */ 3648 ksmbd_open_durable_fd(fp); 3649 if (!has_file_id(fp->persistent_id)) { 3650 rc = -ENOMEM; 3651 goto err_out; 3652 } 3653 3654 fp->cdoption = req->CreateDisposition; 3655 fp->daccess = daccess; 3656 fp->saccess = req->ShareAccess; 3657 fp->coption = req->CreateOptions; 3658 3659 /* Set default windows and posix acls if creating new file */ 3660 if (created) { 3661 int posix_acl_rc; 3662 struct inode *inode = d_inode(path.dentry); 3663 3664 posix_acl_rc = ksmbd_vfs_inherit_posix_acl(idmap, 3665 &path, 3666 d_inode(path.dentry->d_parent)); 3667 if (posix_acl_rc) 3668 ksmbd_debug(SMB, "inherit posix acl failed : %d\n", posix_acl_rc); 3669 3670 rc = smb2_create_sd_buffer(work, req, &path); 3671 if (rc && rc != -ENOENT) 3672 goto err_out; 3673 3674 if (rc == -ENOENT) { 3675 if (test_share_config_flag(work->tcon->share_conf, 3676 KSMBD_SHARE_FLAG_ACL_XATTR)) { 3677 rc = smb_inherit_dacl(conn, &path, sess->user->uid, 3678 sess->user->gid); 3679 } 3680 if (rc) { 3681 if (posix_acl_rc) 3682 ksmbd_vfs_set_init_posix_acl(idmap, 3683 &path); 3684 3685 if (test_share_config_flag(work->tcon->share_conf, 3686 KSMBD_SHARE_FLAG_ACL_XATTR)) { 3687 struct smb_fattr fattr; 3688 struct smb_ntsd *pntsd; 3689 int pntsd_size; 3690 size_t scratch_len; 3691 3692 ksmbd_acls_fattr(&fattr, idmap, inode); 3693 scratch_len = smb_acl_sec_desc_scratch_len(&fattr, 3694 NULL, 0, 3695 OWNER_SECINFO | GROUP_SECINFO | 3696 DACL_SECINFO); 3697 if (!scratch_len || scratch_len == SIZE_MAX) { 3698 rc = -EFBIG; 3699 posix_acl_release(fattr.cf_acls); 3700 posix_acl_release(fattr.cf_dacls); 3701 goto err_out; 3702 } 3703 3704 pntsd = kvzalloc(scratch_len, KSMBD_DEFAULT_GFP); 3705 if (!pntsd) { 3706 rc = -ENOMEM; 3707 posix_acl_release(fattr.cf_acls); 3708 posix_acl_release(fattr.cf_dacls); 3709 goto err_out; 3710 } 3711 3712 rc = build_sec_desc(idmap, 3713 pntsd, NULL, 0, 3714 OWNER_SECINFO | 3715 GROUP_SECINFO | 3716 DACL_SECINFO, 3717 &pntsd_size, &fattr); 3718 posix_acl_release(fattr.cf_acls); 3719 posix_acl_release(fattr.cf_dacls); 3720 if (rc) { 3721 kvfree(pntsd); 3722 goto err_out; 3723 } 3724 3725 rc = ksmbd_vfs_set_sd_xattr(conn, 3726 idmap, 3727 &path, 3728 pntsd, 3729 pntsd_size, 3730 false); 3731 kvfree(pntsd); 3732 if (rc) 3733 pr_err("failed to store ntacl in xattr : %d\n", 3734 rc); 3735 } 3736 } 3737 } 3738 rc = 0; 3739 } 3740 3741 if (stream_name) { 3742 rc = smb2_set_stream_name_xattr(&path, 3743 fp, 3744 stream_name, 3745 s_type); 3746 if (rc) 3747 goto err_out; 3748 file_info = FILE_CREATED; 3749 } 3750 3751 fp->attrib_only = !(req->DesiredAccess & ~(FILE_READ_ATTRIBUTES_LE | 3752 FILE_WRITE_ATTRIBUTES_LE | FILE_SYNCHRONIZE_LE)); 3753 3754 fp->is_posix_ctxt = posix_ctxt; 3755 3756 /* fp should be searchable through ksmbd_inode.m_fp_list 3757 * after daccess, saccess, attrib_only, and stream are 3758 * initialized. 3759 */ 3760 down_write(&fp->f_ci->m_lock); 3761 list_add(&fp->node, &fp->f_ci->m_fp_list); 3762 up_write(&fp->f_ci->m_lock); 3763 3764 /* Check delete pending among previous fp before oplock break */ 3765 if (ksmbd_inode_pending_delete(fp)) { 3766 rc = -EBUSY; 3767 goto err_out; 3768 } 3769 3770 if (!stream_name && daccess & FILE_DELETE_LE && 3771 ksmbd_has_stream_without_delete_share(fp)) { 3772 rc = -EPERM; 3773 goto err_out; 3774 } 3775 3776 if (file_present || created) 3777 path_put(&path); 3778 3779 if (!S_ISDIR(file_inode(filp)->i_mode) && open_flags & O_TRUNC && 3780 !fp->attrib_only && !stream_name) { 3781 smb_break_all_oplock(work, fp); 3782 need_truncate = 1; 3783 } 3784 3785 share_ret = ksmbd_smb_check_shared_mode(fp->filp, fp); 3786 if (!test_share_config_flag(work->tcon->share_conf, KSMBD_SHARE_FLAG_OPLOCKS) || 3787 (req_op_level == SMB2_OPLOCK_LEVEL_LEASE && 3788 !(conn->vals->req_capabilities & SMB2_GLOBAL_CAP_LEASING))) { 3789 if (share_ret < 0 && !S_ISDIR(file_inode(fp->filp)->i_mode)) { 3790 rc = share_ret; 3791 goto err_out1; 3792 } 3793 } else { 3794 if (req_op_level == SMB2_OPLOCK_LEVEL_LEASE && lc) { 3795 if (S_ISDIR(file_inode(filp)->i_mode)) { 3796 lc->req_state &= ~SMB2_LEASE_WRITE_CACHING_LE; 3797 lc->is_dir = true; 3798 } 3799 3800 /* 3801 * Compare parent lease using parent key. If there is no 3802 * a lease that has same parent key, Send lease break 3803 * notification. 3804 */ 3805 smb_send_parent_lease_break_noti(fp, lc); 3806 3807 req_op_level = smb2_map_lease_to_oplock(lc->req_state); 3808 ksmbd_debug(SMB, 3809 "lease req for(%s) req oplock state 0x%x, lease state 0x%x\n", 3810 name, req_op_level, lc->req_state); 3811 rc = find_same_lease_key(conn, fp->f_ci, lc); 3812 if (rc) 3813 goto err_out1; 3814 } else if (open_flags == O_RDONLY && 3815 (req_op_level == SMB2_OPLOCK_LEVEL_BATCH || 3816 req_op_level == SMB2_OPLOCK_LEVEL_EXCLUSIVE)) 3817 req_op_level = SMB2_OPLOCK_LEVEL_II; 3818 3819 rc = smb_grant_oplock(work, req_op_level, 3820 fp->persistent_id, fp, 3821 le32_to_cpu(req->hdr.Id.SyncId.TreeId), 3822 lc, share_ret); 3823 if (rc < 0) 3824 goto err_out1; 3825 } 3826 3827 if (req->CreateOptions & FILE_DELETE_ON_CLOSE_LE) { 3828 smb_break_all_levII_oplock_for_delete(work, fp); 3829 ksmbd_fd_set_delete_on_close(fp, file_info); 3830 } 3831 3832 if (need_truncate) { 3833 rc = smb2_create_truncate(&fp->filp->f_path); 3834 if (rc) 3835 goto err_out1; 3836 } 3837 3838 if (req->CreateContextsOffset) { 3839 struct create_alloc_size_req *az_req; 3840 3841 az_req = (struct create_alloc_size_req *)smb2_find_context_vals(req, 3842 SMB2_CREATE_ALLOCATION_SIZE, 4); 3843 if (IS_ERR(az_req)) { 3844 rc = PTR_ERR(az_req); 3845 goto err_out1; 3846 } else if (az_req) { 3847 int err; 3848 3849 if (le16_to_cpu(az_req->ccontext.DataOffset) + 3850 le32_to_cpu(az_req->ccontext.DataLength) < 3851 sizeof(struct create_alloc_size_req)) { 3852 rc = -EINVAL; 3853 goto err_out1; 3854 } 3855 alloc_size = le64_to_cpu(az_req->AllocationSize); 3856 ksmbd_debug(SMB, 3857 "request smb2 create allocate size : %llu\n", 3858 alloc_size); 3859 smb_break_all_levII_oplock(work, fp, 1); 3860 err = vfs_fallocate(fp->filp, FALLOC_FL_KEEP_SIZE, 0, 3861 alloc_size); 3862 if (err < 0) 3863 ksmbd_debug(SMB, 3864 "vfs_fallocate is failed : %d\n", 3865 err); 3866 } 3867 3868 context = smb2_find_context_vals(req, SMB2_CREATE_QUERY_ON_DISK_ID, 4); 3869 if (IS_ERR(context)) { 3870 rc = PTR_ERR(context); 3871 goto err_out1; 3872 } else if (context) { 3873 ksmbd_debug(SMB, "get query on disk id context\n"); 3874 query_disk_id = 1; 3875 } 3876 3877 if (conn->is_aapl == false) { 3878 context = smb2_find_context_vals(req, SMB2_CREATE_AAPL, 4); 3879 if (IS_ERR(context)) { 3880 rc = PTR_ERR(context); 3881 goto err_out1; 3882 } else if (context) 3883 conn->is_aapl = true; 3884 } 3885 } 3886 3887 rc = ksmbd_vfs_getattr(&path, &stat); 3888 if (rc) 3889 goto err_out1; 3890 3891 if (stat.result_mask & STATX_BTIME) 3892 fp->create_time = ksmbd_UnixTimeToNT(stat.btime); 3893 else 3894 fp->create_time = ksmbd_UnixTimeToNT(stat.ctime); 3895 fp->change_time = ksmbd_UnixTimeToNT(stat.ctime); 3896 fp->allocation_size = S_ISDIR(stat.mode) ? 0 : 3897 (alloc_size ?: stat.blocks << 9); 3898 if (req->FileAttributes || fp->f_ci->m_fattr == 0) 3899 fp->f_ci->m_fattr = 3900 cpu_to_le32(smb2_get_dos_mode(&stat, le32_to_cpu(req->FileAttributes))); 3901 3902 if (!created) 3903 smb2_update_xattrs(tcon, &path, fp); 3904 3905 ksmbd_vfs_update_compressed_fattr(path.dentry, &fp->f_ci->m_fattr); 3906 3907 if (created) 3908 smb2_new_xattrs(tcon, &path, fp); 3909 3910 memcpy(fp->client_guid, conn->ClientGUID, SMB2_CLIENT_GUID_SIZE); 3911 3912 if (dh_info.type == DURABLE_REQ_V2 || dh_info.type == DURABLE_REQ) { 3913 if (dh_info.type == DURABLE_REQ_V2 && dh_info.persistent && 3914 test_share_config_flag(work->tcon->share_conf, 3915 KSMBD_SHARE_FLAG_CONTINUOUS_AVAILABILITY)) 3916 fp->is_persistent = true; 3917 else 3918 fp->is_durable = true; 3919 3920 if (dh_info.type == DURABLE_REQ_V2) { 3921 memcpy(fp->create_guid, dh_info.CreateGuid, 3922 SMB2_CREATE_GUID_SIZE); 3923 if (dh_info.app_instance_id) 3924 memcpy(fp->app_instance_id, 3925 dh_info.AppInstanceId, 3926 SMB2_CREATE_GUID_SIZE); 3927 if (dh_info.timeout) 3928 fp->durable_timeout = 3929 min_t(unsigned int, dh_info.timeout, 3930 DURABLE_HANDLE_MAX_TIMEOUT); 3931 else 3932 fp->durable_timeout = 60; 3933 } 3934 } 3935 3936 reconnected_fp: 3937 rsp->StructureSize = cpu_to_le16(89); 3938 opinfo = opinfo_get(fp); 3939 rsp->OplockLevel = opinfo != NULL ? opinfo->level : 0; 3940 rsp->Flags = 0; 3941 rsp->CreateAction = cpu_to_le32(file_info); 3942 rsp->CreationTime = cpu_to_le64(fp->create_time); 3943 time = ksmbd_UnixTimeToNT(stat.atime); 3944 rsp->LastAccessTime = cpu_to_le64(time); 3945 time = ksmbd_UnixTimeToNT(stat.mtime); 3946 rsp->LastWriteTime = cpu_to_le64(time); 3947 rsp->ChangeTime = cpu_to_le64(fp->change_time); 3948 /* 3949 * The cached allocation size hides filesystem rounding for the 3950 * requested allocation, but it can go stale when the file grows past 3951 * it via writes (e.g. across a durable reconnect). Refresh it once the 3952 * file exceeds the cached value, rounding the end of file up to the 3953 * volume allocation unit (the filesystem block size, matching the 3954 * SectorsPerAllocationUnit/BytesPerSector ksmbd advertises) rather than 3955 * using the raw on-disk block count, which can include filesystem 3956 * preallocation and metadata rounding. 3957 */ 3958 if (!S_ISDIR(stat.mode) && stat.size > fp->allocation_size) 3959 fp->allocation_size = round_up(stat.size, stat.blksize); 3960 rsp->AllocationSize = cpu_to_le64(fp->allocation_size); 3961 rsp->EndofFile = S_ISDIR(stat.mode) ? 0 : cpu_to_le64(stat.size); 3962 rsp->FileAttributes = fp->f_ci->m_fattr; 3963 3964 rsp->Reserved2 = 0; 3965 3966 rsp->PersistentFileId = fp->persistent_id; 3967 rsp->VolatileFileId = fp->volatile_id; 3968 3969 rsp->CreateContextsOffset = 0; 3970 rsp->CreateContextsLength = 0; 3971 iov_len = offsetof(struct smb2_create_rsp, Buffer); 3972 3973 /* If lease is request send lease context response */ 3974 if (opinfo && opinfo->is_lease) { 3975 struct create_context *lease_ccontext; 3976 3977 ksmbd_debug(SMB, "lease granted on(%s) lease state 0x%x\n", 3978 name, opinfo->o_lease->state); 3979 rsp->OplockLevel = SMB2_OPLOCK_LEVEL_LEASE; 3980 3981 lease_ccontext = (struct create_context *)rsp->Buffer; 3982 contxt_cnt++; 3983 create_lease_buf(rsp->Buffer, opinfo->o_lease); 3984 le32_add_cpu(&rsp->CreateContextsLength, 3985 conn->vals->create_lease_size); 3986 iov_len += conn->vals->create_lease_size; 3987 next_ptr = &lease_ccontext->Next; 3988 next_off = conn->vals->create_lease_size; 3989 } 3990 opinfo_put(opinfo); 3991 3992 if (maximal_access_ctxt) { 3993 struct create_context *mxac_ccontext; 3994 3995 if (maximal_access == 0) 3996 ksmbd_vfs_query_maximal_access(idmap, 3997 path.dentry, 3998 &maximal_access); 3999 mxac_ccontext = (struct create_context *)(rsp->Buffer + 4000 le32_to_cpu(rsp->CreateContextsLength)); 4001 contxt_cnt++; 4002 create_mxac_rsp_buf(rsp->Buffer + 4003 le32_to_cpu(rsp->CreateContextsLength), 4004 le32_to_cpu(maximal_access)); 4005 le32_add_cpu(&rsp->CreateContextsLength, 4006 conn->vals->create_mxac_size); 4007 iov_len += conn->vals->create_mxac_size; 4008 if (next_ptr) 4009 *next_ptr = cpu_to_le32(next_off); 4010 next_ptr = &mxac_ccontext->Next; 4011 next_off = conn->vals->create_mxac_size; 4012 } 4013 4014 if (query_disk_id) { 4015 struct create_context *disk_id_ccontext; 4016 4017 disk_id_ccontext = (struct create_context *)(rsp->Buffer + 4018 le32_to_cpu(rsp->CreateContextsLength)); 4019 contxt_cnt++; 4020 create_disk_id_rsp_buf(rsp->Buffer + 4021 le32_to_cpu(rsp->CreateContextsLength), 4022 stat.ino, tcon->id); 4023 le32_add_cpu(&rsp->CreateContextsLength, 4024 conn->vals->create_disk_id_size); 4025 iov_len += conn->vals->create_disk_id_size; 4026 if (next_ptr) 4027 *next_ptr = cpu_to_le32(next_off); 4028 next_ptr = &disk_id_ccontext->Next; 4029 next_off = conn->vals->create_disk_id_size; 4030 } 4031 4032 if (dh_info.type == DURABLE_REQ || dh_info.type == DURABLE_REQ_V2) { 4033 struct create_context *durable_ccontext; 4034 4035 durable_ccontext = (struct create_context *)(rsp->Buffer + 4036 le32_to_cpu(rsp->CreateContextsLength)); 4037 contxt_cnt++; 4038 if (dh_info.type == DURABLE_REQ) { 4039 create_durable_rsp_buf(rsp->Buffer + 4040 le32_to_cpu(rsp->CreateContextsLength)); 4041 le32_add_cpu(&rsp->CreateContextsLength, 4042 conn->vals->create_durable_size); 4043 iov_len += conn->vals->create_durable_size; 4044 } else { 4045 create_durable_v2_rsp_buf(rsp->Buffer + 4046 le32_to_cpu(rsp->CreateContextsLength), 4047 fp); 4048 le32_add_cpu(&rsp->CreateContextsLength, 4049 conn->vals->create_durable_v2_size); 4050 iov_len += conn->vals->create_durable_v2_size; 4051 } 4052 4053 if (next_ptr) 4054 *next_ptr = cpu_to_le32(next_off); 4055 next_ptr = &durable_ccontext->Next; 4056 next_off = conn->vals->create_durable_size; 4057 } 4058 4059 if (posix_ctxt) { 4060 contxt_cnt++; 4061 create_posix_rsp_buf(rsp->Buffer + 4062 le32_to_cpu(rsp->CreateContextsLength), 4063 fp); 4064 le32_add_cpu(&rsp->CreateContextsLength, 4065 conn->vals->create_posix_size); 4066 iov_len += conn->vals->create_posix_size; 4067 if (next_ptr) 4068 *next_ptr = cpu_to_le32(next_off); 4069 } 4070 4071 if (contxt_cnt > 0) { 4072 rsp->CreateContextsOffset = 4073 cpu_to_le32(offsetof(struct smb2_create_rsp, Buffer)); 4074 } 4075 4076 err_out: 4077 if (rc && (file_present || created)) 4078 path_put(&path); 4079 4080 err_out1: 4081 ksmbd_revert_fsids(work); 4082 4083 err_out2: 4084 if (!rc) { 4085 rc = ksmbd_update_fstate(&work->sess->file_table, fp, 4086 FP_INITED); 4087 if (!rc) 4088 rc = ksmbd_iov_pin_rsp(work, (void *)rsp, iov_len); 4089 } 4090 if (rc) { 4091 if (rc == -EINVAL) 4092 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 4093 else if (rc == -EOPNOTSUPP) 4094 rsp->hdr.Status = STATUS_NOT_SUPPORTED; 4095 else if (rc == -EACCES || rc == -ESTALE || rc == -EXDEV) 4096 rsp->hdr.Status = STATUS_ACCESS_DENIED; 4097 else if (rc == -ENOENT) 4098 rsp->hdr.Status = STATUS_OBJECT_NAME_INVALID; 4099 else if (rc == -EPERM) 4100 rsp->hdr.Status = STATUS_SHARING_VIOLATION; 4101 else if (rc == -EBUSY) 4102 rsp->hdr.Status = STATUS_DELETE_PENDING; 4103 else if (rc == -EBADF) 4104 rsp->hdr.Status = STATUS_OBJECT_NAME_NOT_FOUND; 4105 else if (rc == -ENOEXEC) 4106 rsp->hdr.Status = STATUS_DUPLICATE_OBJECTID; 4107 else if (rc == -ENXIO) 4108 rsp->hdr.Status = STATUS_NO_SUCH_DEVICE; 4109 else if (rc == -EEXIST) 4110 rsp->hdr.Status = STATUS_OBJECT_NAME_COLLISION; 4111 else if (rc == -EMFILE) 4112 rsp->hdr.Status = STATUS_INSUFFICIENT_RESOURCES; 4113 if (!rsp->hdr.Status) 4114 rsp->hdr.Status = STATUS_UNEXPECTED_IO_ERROR; 4115 4116 if (fp) 4117 ksmbd_fd_put(work, fp); 4118 smb2_set_err_rsp(work); 4119 ksmbd_debug(SMB, "Error response: %x\n", rsp->hdr.Status); 4120 } 4121 4122 if (dh_info.reconnected) { 4123 /* 4124 * If reconnect succeeded, fp was republished in the 4125 * session file table. On a later error, ksmbd_fd_put() 4126 * above drops the session reference; drop the durable 4127 * lookup reference through the same session-aware path so 4128 * final close removes the volatile id before freeing fp. 4129 */ 4130 if (rc && fp == dh_info.fp) 4131 ksmbd_fd_put(work, dh_info.fp); 4132 else 4133 ksmbd_put_durable_fd(dh_info.fp); 4134 } 4135 4136 kfree(name); 4137 kfree(lc); 4138 4139 return rc; 4140 } 4141 4142 static int readdir_info_level_struct_sz(int info_level) 4143 { 4144 switch (info_level) { 4145 case FILE_FULL_DIRECTORY_INFORMATION: 4146 return sizeof(FILE_FULL_DIRECTORY_INFO); 4147 case FILE_BOTH_DIRECTORY_INFORMATION: 4148 return sizeof(FILE_BOTH_DIRECTORY_INFO); 4149 case FILE_DIRECTORY_INFORMATION: 4150 return sizeof(FILE_DIRECTORY_INFO); 4151 case FILE_NAMES_INFORMATION: 4152 return sizeof(struct file_names_info); 4153 case FILEID_FULL_DIRECTORY_INFORMATION: 4154 return sizeof(FILE_ID_FULL_DIR_INFO); 4155 case FILEID_BOTH_DIRECTORY_INFORMATION: 4156 return sizeof(struct file_id_both_directory_info); 4157 case SMB_FIND_FILE_POSIX_INFO: 4158 return sizeof(struct smb2_posix_info); 4159 default: 4160 return -EOPNOTSUPP; 4161 } 4162 } 4163 4164 static int dentry_name(struct ksmbd_dir_info *d_info, int info_level) 4165 { 4166 switch (info_level) { 4167 case FILE_FULL_DIRECTORY_INFORMATION: 4168 { 4169 FILE_FULL_DIRECTORY_INFO *ffdinfo; 4170 4171 ffdinfo = (FILE_FULL_DIRECTORY_INFO *)d_info->rptr; 4172 d_info->rptr += le32_to_cpu(ffdinfo->NextEntryOffset); 4173 d_info->name = ffdinfo->FileName; 4174 d_info->name_len = le32_to_cpu(ffdinfo->FileNameLength); 4175 return 0; 4176 } 4177 case FILE_BOTH_DIRECTORY_INFORMATION: 4178 { 4179 FILE_BOTH_DIRECTORY_INFO *fbdinfo; 4180 4181 fbdinfo = (FILE_BOTH_DIRECTORY_INFO *)d_info->rptr; 4182 d_info->rptr += le32_to_cpu(fbdinfo->NextEntryOffset); 4183 d_info->name = fbdinfo->FileName; 4184 d_info->name_len = le32_to_cpu(fbdinfo->FileNameLength); 4185 return 0; 4186 } 4187 case FILE_DIRECTORY_INFORMATION: 4188 { 4189 FILE_DIRECTORY_INFO *fdinfo; 4190 4191 fdinfo = (FILE_DIRECTORY_INFO *)d_info->rptr; 4192 d_info->rptr += le32_to_cpu(fdinfo->NextEntryOffset); 4193 d_info->name = fdinfo->FileName; 4194 d_info->name_len = le32_to_cpu(fdinfo->FileNameLength); 4195 return 0; 4196 } 4197 case FILE_NAMES_INFORMATION: 4198 { 4199 struct file_names_info *fninfo; 4200 4201 fninfo = (struct file_names_info *)d_info->rptr; 4202 d_info->rptr += le32_to_cpu(fninfo->NextEntryOffset); 4203 d_info->name = fninfo->FileName; 4204 d_info->name_len = le32_to_cpu(fninfo->FileNameLength); 4205 return 0; 4206 } 4207 case FILEID_FULL_DIRECTORY_INFORMATION: 4208 { 4209 FILE_ID_FULL_DIR_INFO *dinfo; 4210 4211 dinfo = (FILE_ID_FULL_DIR_INFO *)d_info->rptr; 4212 d_info->rptr += le32_to_cpu(dinfo->NextEntryOffset); 4213 d_info->name = dinfo->FileName; 4214 d_info->name_len = le32_to_cpu(dinfo->FileNameLength); 4215 return 0; 4216 } 4217 case FILEID_BOTH_DIRECTORY_INFORMATION: 4218 { 4219 struct file_id_both_directory_info *fibdinfo; 4220 4221 fibdinfo = (struct file_id_both_directory_info *)d_info->rptr; 4222 d_info->rptr += le32_to_cpu(fibdinfo->NextEntryOffset); 4223 d_info->name = fibdinfo->FileName; 4224 d_info->name_len = le32_to_cpu(fibdinfo->FileNameLength); 4225 return 0; 4226 } 4227 case SMB_FIND_FILE_POSIX_INFO: 4228 { 4229 struct smb2_posix_info *posix_info; 4230 4231 posix_info = (struct smb2_posix_info *)d_info->rptr; 4232 d_info->rptr += le32_to_cpu(posix_info->NextEntryOffset); 4233 d_info->name = posix_info->name; 4234 d_info->name_len = le32_to_cpu(posix_info->name_len); 4235 return 0; 4236 } 4237 default: 4238 return -EINVAL; 4239 } 4240 } 4241 4242 /** 4243 * smb2_populate_readdir_entry() - encode directory entry in smb2 response 4244 * buffer 4245 * @conn: connection instance 4246 * @info_level: smb information level 4247 * @d_info: structure included variables for query dir 4248 * @ksmbd_kstat: ksmbd wrapper of dirent stat information 4249 * 4250 * if directory has many entries, find first can't read it fully. 4251 * find next might be called multiple times to read remaining dir entries 4252 * 4253 * Return: 0 on success, otherwise error 4254 */ 4255 static int smb2_populate_readdir_entry(struct ksmbd_conn *conn, int info_level, 4256 struct ksmbd_dir_info *d_info, 4257 struct ksmbd_kstat *ksmbd_kstat) 4258 { 4259 int next_entry_offset = 0; 4260 char *conv_name; 4261 int conv_len; 4262 void *kstat; 4263 int struct_sz, rc = 0; 4264 4265 conv_name = ksmbd_convert_dir_info_name(d_info, 4266 conn->local_nls, 4267 &conv_len); 4268 if (!conv_name) 4269 return -ENOMEM; 4270 4271 /* Somehow the name has only terminating NULL bytes */ 4272 if (conv_len < 0) { 4273 rc = -EINVAL; 4274 goto free_conv_name; 4275 } 4276 4277 struct_sz = readdir_info_level_struct_sz(info_level); 4278 if (struct_sz == -EOPNOTSUPP) { 4279 rc = -EINVAL; 4280 goto free_conv_name; 4281 } 4282 4283 struct_sz += conv_len; 4284 next_entry_offset = ALIGN(struct_sz, KSMBD_DIR_INFO_ALIGNMENT); 4285 d_info->last_entry_off_align = next_entry_offset - struct_sz; 4286 4287 if (next_entry_offset > d_info->out_buf_len) { 4288 d_info->out_buf_len = 0; 4289 rc = -ENOSPC; 4290 goto free_conv_name; 4291 } 4292 4293 kstat = d_info->wptr; 4294 if (info_level != FILE_NAMES_INFORMATION) 4295 kstat = ksmbd_vfs_init_kstat(&d_info->wptr, ksmbd_kstat); 4296 4297 switch (info_level) { 4298 case FILE_FULL_DIRECTORY_INFORMATION: 4299 { 4300 FILE_FULL_DIRECTORY_INFO *ffdinfo; 4301 4302 ffdinfo = (FILE_FULL_DIRECTORY_INFO *)kstat; 4303 ffdinfo->FileNameLength = cpu_to_le32(conv_len); 4304 ffdinfo->EaSize = 4305 smb2_get_reparse_tag_special_file(ksmbd_kstat->kstat->mode); 4306 if (ffdinfo->EaSize) 4307 ffdinfo->ExtFileAttributes = FILE_ATTRIBUTE_REPARSE_POINT_LE; 4308 if (d_info->hide_dot_file && d_info->name[0] == '.') 4309 ffdinfo->ExtFileAttributes |= FILE_ATTRIBUTE_HIDDEN_LE; 4310 memcpy(ffdinfo->FileName, conv_name, conv_len); 4311 ffdinfo->NextEntryOffset = cpu_to_le32(next_entry_offset); 4312 break; 4313 } 4314 case FILE_BOTH_DIRECTORY_INFORMATION: 4315 { 4316 FILE_BOTH_DIRECTORY_INFO *fbdinfo; 4317 4318 fbdinfo = (FILE_BOTH_DIRECTORY_INFO *)kstat; 4319 fbdinfo->FileNameLength = cpu_to_le32(conv_len); 4320 fbdinfo->EaSize = 4321 smb2_get_reparse_tag_special_file(ksmbd_kstat->kstat->mode); 4322 if (fbdinfo->EaSize) 4323 fbdinfo->ExtFileAttributes = FILE_ATTRIBUTE_REPARSE_POINT_LE; 4324 fbdinfo->ShortNameLength = 0; 4325 fbdinfo->Reserved = 0; 4326 if (d_info->hide_dot_file && d_info->name[0] == '.') 4327 fbdinfo->ExtFileAttributes |= FILE_ATTRIBUTE_HIDDEN_LE; 4328 memcpy(fbdinfo->FileName, conv_name, conv_len); 4329 fbdinfo->NextEntryOffset = cpu_to_le32(next_entry_offset); 4330 break; 4331 } 4332 case FILE_DIRECTORY_INFORMATION: 4333 { 4334 FILE_DIRECTORY_INFO *fdinfo; 4335 4336 fdinfo = (FILE_DIRECTORY_INFO *)kstat; 4337 fdinfo->FileNameLength = cpu_to_le32(conv_len); 4338 if (d_info->hide_dot_file && d_info->name[0] == '.') 4339 fdinfo->ExtFileAttributes |= FILE_ATTRIBUTE_HIDDEN_LE; 4340 memcpy(fdinfo->FileName, conv_name, conv_len); 4341 fdinfo->NextEntryOffset = cpu_to_le32(next_entry_offset); 4342 break; 4343 } 4344 case FILE_NAMES_INFORMATION: 4345 { 4346 struct file_names_info *fninfo; 4347 4348 fninfo = (struct file_names_info *)kstat; 4349 fninfo->FileNameLength = cpu_to_le32(conv_len); 4350 memcpy(fninfo->FileName, conv_name, conv_len); 4351 fninfo->NextEntryOffset = cpu_to_le32(next_entry_offset); 4352 break; 4353 } 4354 case FILEID_FULL_DIRECTORY_INFORMATION: 4355 { 4356 FILE_ID_FULL_DIR_INFO *dinfo; 4357 4358 dinfo = (FILE_ID_FULL_DIR_INFO *)kstat; 4359 dinfo->FileNameLength = cpu_to_le32(conv_len); 4360 dinfo->EaSize = 4361 smb2_get_reparse_tag_special_file(ksmbd_kstat->kstat->mode); 4362 if (dinfo->EaSize) 4363 dinfo->ExtFileAttributes = FILE_ATTRIBUTE_REPARSE_POINT_LE; 4364 dinfo->Reserved = 0; 4365 if (conn->is_aapl) 4366 dinfo->UniqueId = 0; 4367 else 4368 dinfo->UniqueId = cpu_to_le64(ksmbd_kstat->kstat->ino); 4369 if (d_info->hide_dot_file && d_info->name[0] == '.') 4370 dinfo->ExtFileAttributes |= FILE_ATTRIBUTE_HIDDEN_LE; 4371 memcpy(dinfo->FileName, conv_name, conv_len); 4372 dinfo->NextEntryOffset = cpu_to_le32(next_entry_offset); 4373 break; 4374 } 4375 case FILEID_BOTH_DIRECTORY_INFORMATION: 4376 { 4377 struct file_id_both_directory_info *fibdinfo; 4378 4379 fibdinfo = (struct file_id_both_directory_info *)kstat; 4380 fibdinfo->FileNameLength = cpu_to_le32(conv_len); 4381 fibdinfo->EaSize = 4382 smb2_get_reparse_tag_special_file(ksmbd_kstat->kstat->mode); 4383 if (fibdinfo->EaSize) 4384 fibdinfo->ExtFileAttributes = FILE_ATTRIBUTE_REPARSE_POINT_LE; 4385 if (conn->is_aapl) 4386 fibdinfo->UniqueId = 0; 4387 else 4388 fibdinfo->UniqueId = cpu_to_le64(ksmbd_kstat->kstat->ino); 4389 fibdinfo->ShortNameLength = 0; 4390 fibdinfo->Reserved = 0; 4391 fibdinfo->Reserved2 = cpu_to_le16(0); 4392 if (d_info->hide_dot_file && d_info->name[0] == '.') 4393 fibdinfo->ExtFileAttributes |= FILE_ATTRIBUTE_HIDDEN_LE; 4394 memcpy(fibdinfo->FileName, conv_name, conv_len); 4395 fibdinfo->NextEntryOffset = cpu_to_le32(next_entry_offset); 4396 break; 4397 } 4398 case SMB_FIND_FILE_POSIX_INFO: 4399 { 4400 struct smb2_posix_info *posix_info; 4401 u64 time; 4402 4403 posix_info = (struct smb2_posix_info *)kstat; 4404 posix_info->Ignored = 0; 4405 posix_info->CreationTime = cpu_to_le64(ksmbd_kstat->create_time); 4406 time = ksmbd_UnixTimeToNT(ksmbd_kstat->kstat->ctime); 4407 posix_info->ChangeTime = cpu_to_le64(time); 4408 time = ksmbd_UnixTimeToNT(ksmbd_kstat->kstat->atime); 4409 posix_info->LastAccessTime = cpu_to_le64(time); 4410 time = ksmbd_UnixTimeToNT(ksmbd_kstat->kstat->mtime); 4411 posix_info->LastWriteTime = cpu_to_le64(time); 4412 posix_info->EndOfFile = cpu_to_le64(ksmbd_kstat->kstat->size); 4413 posix_info->AllocationSize = cpu_to_le64(ksmbd_kstat->kstat->blocks << 9); 4414 posix_info->DeviceId = cpu_to_le32(ksmbd_kstat->kstat->rdev); 4415 posix_info->HardLinks = cpu_to_le32(ksmbd_kstat->kstat->nlink); 4416 posix_info->Mode = cpu_to_le32(ksmbd_kstat->kstat->mode & 0777); 4417 switch (ksmbd_kstat->kstat->mode & S_IFMT) { 4418 case S_IFDIR: 4419 posix_info->Mode |= cpu_to_le32(POSIX_TYPE_DIR << POSIX_FILETYPE_SHIFT); 4420 break; 4421 case S_IFLNK: 4422 posix_info->Mode |= cpu_to_le32(POSIX_TYPE_SYMLINK << POSIX_FILETYPE_SHIFT); 4423 break; 4424 case S_IFCHR: 4425 posix_info->Mode |= cpu_to_le32(POSIX_TYPE_CHARDEV << POSIX_FILETYPE_SHIFT); 4426 break; 4427 case S_IFBLK: 4428 posix_info->Mode |= cpu_to_le32(POSIX_TYPE_BLKDEV << POSIX_FILETYPE_SHIFT); 4429 break; 4430 case S_IFIFO: 4431 posix_info->Mode |= cpu_to_le32(POSIX_TYPE_FIFO << POSIX_FILETYPE_SHIFT); 4432 break; 4433 case S_IFSOCK: 4434 posix_info->Mode |= cpu_to_le32(POSIX_TYPE_SOCKET << POSIX_FILETYPE_SHIFT); 4435 } 4436 4437 posix_info->Inode = cpu_to_le64(ksmbd_kstat->kstat->ino); 4438 posix_info->DosAttributes = 4439 S_ISDIR(ksmbd_kstat->kstat->mode) ? 4440 FILE_ATTRIBUTE_DIRECTORY_LE : FILE_ATTRIBUTE_ARCHIVE_LE; 4441 if (d_info->hide_dot_file && d_info->name[0] == '.') 4442 posix_info->DosAttributes |= FILE_ATTRIBUTE_HIDDEN_LE; 4443 /* 4444 * SidBuffer(32) contain two sids(Domain sid(16), UNIX group sid(16)). 4445 * UNIX sid(16) = revision(1) + num_subauth(1) + authority(6) + 4446 * sub_auth(4 * 1(num_subauth)) + RID(4). 4447 */ 4448 id_to_sid(from_kuid_munged(&init_user_ns, ksmbd_kstat->kstat->uid), 4449 SIDUNIX_USER, (struct smb_sid *)&posix_info->SidBuffer[0]); 4450 id_to_sid(from_kgid_munged(&init_user_ns, ksmbd_kstat->kstat->gid), 4451 SIDUNIX_GROUP, (struct smb_sid *)&posix_info->SidBuffer[16]); 4452 memcpy(posix_info->name, conv_name, conv_len); 4453 posix_info->name_len = cpu_to_le32(conv_len); 4454 posix_info->NextEntryOffset = cpu_to_le32(next_entry_offset); 4455 break; 4456 } 4457 4458 } /* switch (info_level) */ 4459 4460 d_info->last_entry_offset = d_info->data_count; 4461 d_info->data_count += next_entry_offset; 4462 d_info->out_buf_len -= next_entry_offset; 4463 d_info->wptr += next_entry_offset; 4464 4465 ksmbd_debug(SMB, 4466 "info_level : %d, buf_len :%d, next_offset : %d, data_count : %d\n", 4467 info_level, d_info->out_buf_len, 4468 next_entry_offset, d_info->data_count); 4469 4470 free_conv_name: 4471 kfree(conv_name); 4472 return rc; 4473 } 4474 4475 struct smb2_query_dir_private { 4476 struct ksmbd_work *work; 4477 char *search_pattern; 4478 struct ksmbd_file *dir_fp; 4479 4480 struct ksmbd_dir_info *d_info; 4481 int info_level; 4482 }; 4483 4484 static int process_query_dir_entries(struct smb2_query_dir_private *priv) 4485 { 4486 struct mnt_idmap *idmap = file_mnt_idmap(priv->dir_fp->filp); 4487 struct kstat kstat; 4488 struct ksmbd_kstat ksmbd_kstat; 4489 int rc; 4490 int i; 4491 4492 for (i = 0; i < priv->d_info->num_entry; i++) { 4493 struct dentry *dent; 4494 4495 if (dentry_name(priv->d_info, priv->info_level)) 4496 return -EINVAL; 4497 4498 dent = lookup_one_unlocked(idmap, 4499 &QSTR_LEN(priv->d_info->name, 4500 priv->d_info->name_len), 4501 priv->dir_fp->filp->f_path.dentry); 4502 4503 if (IS_ERR(dent)) { 4504 ksmbd_debug(SMB, "Cannot lookup `%s' [%ld]\n", 4505 priv->d_info->name, 4506 PTR_ERR(dent)); 4507 continue; 4508 } 4509 if (unlikely(d_is_negative(dent))) { 4510 dput(dent); 4511 ksmbd_debug(SMB, "Negative dentry `%s'\n", 4512 priv->d_info->name); 4513 continue; 4514 } 4515 4516 ksmbd_kstat.kstat = &kstat; 4517 if (priv->info_level != FILE_NAMES_INFORMATION) { 4518 rc = ksmbd_vfs_fill_dentry_attrs(priv->work, 4519 idmap, 4520 dent, 4521 &ksmbd_kstat); 4522 if (rc) { 4523 dput(dent); 4524 continue; 4525 } 4526 } 4527 4528 rc = smb2_populate_readdir_entry(priv->work->conn, 4529 priv->info_level, 4530 priv->d_info, 4531 &ksmbd_kstat); 4532 dput(dent); 4533 if (rc) 4534 return rc; 4535 } 4536 return 0; 4537 } 4538 4539 static int reserve_populate_dentry(struct ksmbd_dir_info *d_info, 4540 int info_level) 4541 { 4542 int struct_sz; 4543 int conv_len; 4544 int next_entry_offset; 4545 4546 struct_sz = readdir_info_level_struct_sz(info_level); 4547 if (struct_sz == -EOPNOTSUPP) 4548 return -EOPNOTSUPP; 4549 4550 conv_len = (d_info->name_len + 1) * 2; 4551 next_entry_offset = ALIGN(struct_sz + conv_len, 4552 KSMBD_DIR_INFO_ALIGNMENT); 4553 4554 if (next_entry_offset > d_info->out_buf_len) { 4555 d_info->out_buf_len = 0; 4556 return -ENOSPC; 4557 } 4558 4559 switch (info_level) { 4560 case FILE_FULL_DIRECTORY_INFORMATION: 4561 { 4562 FILE_FULL_DIRECTORY_INFO *ffdinfo; 4563 4564 ffdinfo = (FILE_FULL_DIRECTORY_INFO *)d_info->wptr; 4565 memcpy(ffdinfo->FileName, d_info->name, d_info->name_len); 4566 ffdinfo->FileName[d_info->name_len] = 0x00; 4567 ffdinfo->FileNameLength = cpu_to_le32(d_info->name_len); 4568 ffdinfo->NextEntryOffset = cpu_to_le32(next_entry_offset); 4569 break; 4570 } 4571 case FILE_BOTH_DIRECTORY_INFORMATION: 4572 { 4573 FILE_BOTH_DIRECTORY_INFO *fbdinfo; 4574 4575 fbdinfo = (FILE_BOTH_DIRECTORY_INFO *)d_info->wptr; 4576 memcpy(fbdinfo->FileName, d_info->name, d_info->name_len); 4577 fbdinfo->FileName[d_info->name_len] = 0x00; 4578 fbdinfo->FileNameLength = cpu_to_le32(d_info->name_len); 4579 fbdinfo->NextEntryOffset = cpu_to_le32(next_entry_offset); 4580 break; 4581 } 4582 case FILE_DIRECTORY_INFORMATION: 4583 { 4584 FILE_DIRECTORY_INFO *fdinfo; 4585 4586 fdinfo = (FILE_DIRECTORY_INFO *)d_info->wptr; 4587 memcpy(fdinfo->FileName, d_info->name, d_info->name_len); 4588 fdinfo->FileName[d_info->name_len] = 0x00; 4589 fdinfo->FileNameLength = cpu_to_le32(d_info->name_len); 4590 fdinfo->NextEntryOffset = cpu_to_le32(next_entry_offset); 4591 break; 4592 } 4593 case FILE_NAMES_INFORMATION: 4594 { 4595 struct file_names_info *fninfo; 4596 4597 fninfo = (struct file_names_info *)d_info->wptr; 4598 memcpy(fninfo->FileName, d_info->name, d_info->name_len); 4599 fninfo->FileName[d_info->name_len] = 0x00; 4600 fninfo->FileNameLength = cpu_to_le32(d_info->name_len); 4601 fninfo->NextEntryOffset = cpu_to_le32(next_entry_offset); 4602 break; 4603 } 4604 case FILEID_FULL_DIRECTORY_INFORMATION: 4605 { 4606 FILE_ID_FULL_DIR_INFO *dinfo; 4607 4608 dinfo = (FILE_ID_FULL_DIR_INFO *)d_info->wptr; 4609 memcpy(dinfo->FileName, d_info->name, d_info->name_len); 4610 dinfo->FileName[d_info->name_len] = 0x00; 4611 dinfo->FileNameLength = cpu_to_le32(d_info->name_len); 4612 dinfo->NextEntryOffset = cpu_to_le32(next_entry_offset); 4613 break; 4614 } 4615 case FILEID_BOTH_DIRECTORY_INFORMATION: 4616 { 4617 struct file_id_both_directory_info *fibdinfo; 4618 4619 fibdinfo = (struct file_id_both_directory_info *)d_info->wptr; 4620 memcpy(fibdinfo->FileName, d_info->name, d_info->name_len); 4621 fibdinfo->FileName[d_info->name_len] = 0x00; 4622 fibdinfo->FileNameLength = cpu_to_le32(d_info->name_len); 4623 fibdinfo->NextEntryOffset = cpu_to_le32(next_entry_offset); 4624 break; 4625 } 4626 case SMB_FIND_FILE_POSIX_INFO: 4627 { 4628 struct smb2_posix_info *posix_info; 4629 4630 posix_info = (struct smb2_posix_info *)d_info->wptr; 4631 memcpy(posix_info->name, d_info->name, d_info->name_len); 4632 posix_info->name[d_info->name_len] = 0x00; 4633 posix_info->name_len = cpu_to_le32(d_info->name_len); 4634 posix_info->NextEntryOffset = 4635 cpu_to_le32(next_entry_offset); 4636 break; 4637 } 4638 } /* switch (info_level) */ 4639 4640 d_info->num_entry++; 4641 d_info->out_buf_len -= next_entry_offset; 4642 d_info->wptr += next_entry_offset; 4643 return 0; 4644 } 4645 4646 static bool __query_dir(struct dir_context *ctx, const char *name, int namlen, 4647 loff_t offset, u64 ino, unsigned int d_type) 4648 { 4649 struct ksmbd_readdir_data *buf; 4650 struct smb2_query_dir_private *priv; 4651 struct ksmbd_dir_info *d_info; 4652 int rc; 4653 4654 buf = container_of(ctx, struct ksmbd_readdir_data, ctx); 4655 priv = buf->private; 4656 d_info = priv->d_info; 4657 4658 /* dot and dotdot entries are already reserved */ 4659 if (!strcmp(".", name) || !strcmp("..", name)) 4660 return true; 4661 d_info->num_scan++; 4662 if (ksmbd_share_veto_filename(priv->work->tcon->share_conf, name)) 4663 return true; 4664 if (!match_pattern(name, namlen, priv->search_pattern)) 4665 return true; 4666 4667 d_info->name = name; 4668 d_info->name_len = namlen; 4669 rc = reserve_populate_dentry(d_info, priv->info_level); 4670 if (rc) 4671 return false; 4672 if (d_info->flags & SMB2_RETURN_SINGLE_ENTRY) 4673 d_info->out_buf_len = 0; 4674 return true; 4675 } 4676 4677 static int verify_info_level(int info_level) 4678 { 4679 switch (info_level) { 4680 case FILE_FULL_DIRECTORY_INFORMATION: 4681 case FILE_BOTH_DIRECTORY_INFORMATION: 4682 case FILE_DIRECTORY_INFORMATION: 4683 case FILE_NAMES_INFORMATION: 4684 case FILEID_FULL_DIRECTORY_INFORMATION: 4685 case FILEID_BOTH_DIRECTORY_INFORMATION: 4686 case SMB_FIND_FILE_POSIX_INFO: 4687 break; 4688 default: 4689 return -EOPNOTSUPP; 4690 } 4691 4692 return 0; 4693 } 4694 4695 static int smb2_resp_buf_len(struct ksmbd_work *work, unsigned short hdr2_len) 4696 { 4697 int free_len; 4698 4699 free_len = (int)(work->response_sz - 4700 (get_rfc1002_len(work->response_buf) + 4)) - hdr2_len; 4701 return free_len; 4702 } 4703 4704 static int smb2_calc_max_out_buf_len(struct ksmbd_work *work, 4705 unsigned short hdr2_len, 4706 unsigned int out_buf_len) 4707 { 4708 int free_len; 4709 4710 if (out_buf_len > work->conn->vals->max_trans_size) 4711 return -EINVAL; 4712 4713 free_len = smb2_resp_buf_len(work, hdr2_len); 4714 if (free_len < 0) 4715 return -EINVAL; 4716 4717 return min_t(int, out_buf_len, free_len); 4718 } 4719 4720 int smb2_query_dir(struct ksmbd_work *work) 4721 { 4722 struct ksmbd_conn *conn = work->conn; 4723 struct smb2_query_directory_req *req; 4724 struct smb2_query_directory_rsp *rsp; 4725 struct ksmbd_share_config *share = work->tcon->share_conf; 4726 struct ksmbd_file *dir_fp = NULL; 4727 struct ksmbd_dir_info d_info; 4728 int rc = 0; 4729 char *srch_ptr = NULL; 4730 unsigned char srch_flag; 4731 int buffer_sz; 4732 struct smb2_query_dir_private query_dir_private = {NULL, }; 4733 unsigned int id = KSMBD_NO_FID, pid = KSMBD_NO_FID; 4734 4735 ksmbd_debug(SMB, "Received smb2 query directory request\n"); 4736 4737 WORK_BUFFERS(work, req, rsp); 4738 4739 if (smb2_compound_has_failed(work, &rsp->hdr)) 4740 return -EACCES; 4741 4742 if (work->next_smb2_rcv_hdr_off && 4743 !has_file_id(req->VolatileFileId)) { 4744 ksmbd_debug(SMB, "Compound request set FID = %llu\n", 4745 work->compound_fid); 4746 id = work->compound_fid; 4747 pid = work->compound_pfid; 4748 } 4749 4750 if (!has_file_id(id)) { 4751 id = req->VolatileFileId; 4752 pid = req->PersistentFileId; 4753 } 4754 4755 if (ksmbd_override_fsids(work)) { 4756 rsp->hdr.Status = STATUS_NO_MEMORY; 4757 smb2_set_err_rsp(work); 4758 return -ENOMEM; 4759 } 4760 4761 rc = verify_info_level(req->FileInformationClass); 4762 if (rc) { 4763 rc = -EFAULT; 4764 goto err_out2; 4765 } 4766 4767 dir_fp = ksmbd_lookup_fd_slow(work, id, pid); 4768 if (!dir_fp) { 4769 rc = -EBADF; 4770 goto err_out2; 4771 } 4772 4773 if (!(dir_fp->daccess & FILE_LIST_DIRECTORY_LE) || 4774 inode_permission(file_mnt_idmap(dir_fp->filp), 4775 file_inode(dir_fp->filp), 4776 MAY_READ | MAY_EXEC)) { 4777 pr_err("no right to enumerate directory (%pD)\n", dir_fp->filp); 4778 rc = -EACCES; 4779 goto err_out2; 4780 } 4781 4782 if (!S_ISDIR(file_inode(dir_fp->filp)->i_mode)) { 4783 pr_err("can't do query dir for a file\n"); 4784 rc = -EINVAL; 4785 goto err_out2; 4786 } 4787 4788 srch_flag = req->Flags; 4789 srch_ptr = smb_strndup_from_utf16((char *)req + le16_to_cpu(req->FileNameOffset), 4790 le16_to_cpu(req->FileNameLength), 1, 4791 conn->local_nls); 4792 if (IS_ERR(srch_ptr)) { 4793 ksmbd_debug(SMB, "Search Pattern not found\n"); 4794 rc = -EINVAL; 4795 goto err_out2; 4796 } else { 4797 ksmbd_debug(SMB, "Search pattern is %s\n", srch_ptr); 4798 } 4799 4800 mutex_lock(&dir_fp->readdir_lock); 4801 4802 if (srch_flag & SMB2_REOPEN || srch_flag & SMB2_RESTART_SCANS) { 4803 ksmbd_debug(SMB, "Restart directory scan\n"); 4804 generic_file_llseek(dir_fp->filp, 0, SEEK_SET); 4805 } 4806 4807 memset(&d_info, 0, sizeof(struct ksmbd_dir_info)); 4808 d_info.wptr = (char *)rsp->Buffer; 4809 d_info.rptr = (char *)rsp->Buffer; 4810 d_info.out_buf_len = 4811 smb2_calc_max_out_buf_len(work, 4812 offsetof(struct smb2_query_directory_rsp, Buffer), 4813 le32_to_cpu(req->OutputBufferLength)); 4814 if (d_info.out_buf_len < 0) { 4815 rc = -EINVAL; 4816 goto err_out; 4817 } 4818 d_info.flags = srch_flag; 4819 4820 /* 4821 * reserve dot and dotdot entries in head of buffer 4822 * in first response 4823 */ 4824 rc = ksmbd_populate_dot_dotdot_entries(work, req->FileInformationClass, 4825 dir_fp, &d_info, srch_ptr, 4826 smb2_populate_readdir_entry); 4827 if (rc == -ENOSPC) 4828 rc = 0; 4829 else if (rc) 4830 goto err_out; 4831 4832 if (test_share_config_flag(share, KSMBD_SHARE_FLAG_HIDE_DOT_FILES)) 4833 d_info.hide_dot_file = true; 4834 4835 buffer_sz = d_info.out_buf_len; 4836 d_info.rptr = d_info.wptr; 4837 query_dir_private.work = work; 4838 query_dir_private.search_pattern = srch_ptr; 4839 query_dir_private.dir_fp = dir_fp; 4840 query_dir_private.d_info = &d_info; 4841 query_dir_private.info_level = req->FileInformationClass; 4842 dir_fp->readdir_data.private = &query_dir_private; 4843 set_ctx_actor(&dir_fp->readdir_data.ctx, __query_dir); 4844 again: 4845 d_info.num_scan = 0; 4846 rc = iterate_dir(dir_fp->filp, &dir_fp->readdir_data.ctx); 4847 /* 4848 * num_entry can be 0 if the directory iteration stops before reaching 4849 * the end of the directory and no file is matched with the search 4850 * pattern. 4851 */ 4852 if (rc >= 0 && !d_info.num_entry && d_info.num_scan && 4853 d_info.out_buf_len > 0) 4854 goto again; 4855 /* 4856 * req->OutputBufferLength is too small to contain even one entry. 4857 * In this case, it immediately returns OutputBufferLength 0 to client. 4858 */ 4859 if (!d_info.out_buf_len && !d_info.num_entry) 4860 goto no_buf_len; 4861 if (rc > 0 || rc == -ENOSPC) 4862 rc = 0; 4863 else if (rc) 4864 goto err_out; 4865 4866 d_info.wptr = d_info.rptr; 4867 d_info.out_buf_len = buffer_sz; 4868 rc = process_query_dir_entries(&query_dir_private); 4869 if (rc) 4870 goto err_out; 4871 4872 if (!d_info.data_count && d_info.out_buf_len >= 0) { 4873 if (srch_flag & SMB2_RETURN_SINGLE_ENTRY && !is_asterisk(srch_ptr)) { 4874 rsp->hdr.Status = STATUS_NO_SUCH_FILE; 4875 } else { 4876 dir_fp->dot_dotdot[0] = dir_fp->dot_dotdot[1] = 0; 4877 rsp->hdr.Status = STATUS_NO_MORE_FILES; 4878 } 4879 rsp->StructureSize = cpu_to_le16(9); 4880 rsp->OutputBufferOffset = cpu_to_le16(0); 4881 rsp->OutputBufferLength = cpu_to_le32(0); 4882 rsp->Buffer[0] = 0; 4883 rc = ksmbd_iov_pin_rsp(work, (void *)rsp, 4884 offsetof(struct smb2_query_directory_rsp, Buffer) 4885 + 1); 4886 if (rc) 4887 goto err_out; 4888 } else { 4889 no_buf_len: 4890 ((FILE_DIRECTORY_INFO *) 4891 ((char *)rsp->Buffer + d_info.last_entry_offset)) 4892 ->NextEntryOffset = 0; 4893 if (d_info.data_count >= d_info.last_entry_off_align) 4894 d_info.data_count -= d_info.last_entry_off_align; 4895 4896 rsp->StructureSize = cpu_to_le16(9); 4897 rsp->OutputBufferOffset = cpu_to_le16(72); 4898 rsp->OutputBufferLength = cpu_to_le32(d_info.data_count); 4899 rc = ksmbd_iov_pin_rsp(work, (void *)rsp, 4900 offsetof(struct smb2_query_directory_rsp, Buffer) + 4901 d_info.data_count); 4902 if (rc) 4903 goto err_out; 4904 } 4905 4906 mutex_unlock(&dir_fp->readdir_lock); 4907 kfree(srch_ptr); 4908 ksmbd_fd_put(work, dir_fp); 4909 ksmbd_revert_fsids(work); 4910 return 0; 4911 4912 err_out: 4913 pr_err("error while processing smb2 query dir rc = %d\n", rc); 4914 mutex_unlock(&dir_fp->readdir_lock); 4915 kfree(srch_ptr); 4916 4917 err_out2: 4918 if (rc == -EINVAL) 4919 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 4920 else if (rc == -EACCES) 4921 rsp->hdr.Status = STATUS_ACCESS_DENIED; 4922 else if (rc == -ENOENT) 4923 rsp->hdr.Status = STATUS_NO_SUCH_FILE; 4924 else if (rc == -EBADF) 4925 rsp->hdr.Status = STATUS_FILE_CLOSED; 4926 else if (rc == -ENOMEM) 4927 rsp->hdr.Status = STATUS_NO_MEMORY; 4928 else if (rc == -EFAULT) 4929 rsp->hdr.Status = STATUS_INVALID_INFO_CLASS; 4930 else if (rc == -EIO) 4931 rsp->hdr.Status = STATUS_FILE_CORRUPT_ERROR; 4932 if (!rsp->hdr.Status) 4933 rsp->hdr.Status = STATUS_UNEXPECTED_IO_ERROR; 4934 4935 smb2_set_err_rsp(work); 4936 ksmbd_fd_put(work, dir_fp); 4937 ksmbd_revert_fsids(work); 4938 return rc; 4939 } 4940 4941 /** 4942 * buffer_check_err() - helper function to check buffer errors 4943 * @reqOutputBufferLength: max buffer length expected in command response 4944 * @rsp: query info response buffer contains output buffer length 4945 * @rsp_org: base response buffer pointer in case of chained response 4946 * 4947 * Return: 0 on success, otherwise error 4948 */ 4949 static int buffer_check_err(int reqOutputBufferLength, 4950 struct smb2_query_info_rsp *rsp, 4951 void *rsp_org) 4952 { 4953 if (reqOutputBufferLength < le32_to_cpu(rsp->OutputBufferLength)) { 4954 pr_err("Invalid Buffer Size Requested\n"); 4955 rsp->hdr.Status = STATUS_INFO_LENGTH_MISMATCH; 4956 *(__be32 *)rsp_org = cpu_to_be32(sizeof(struct smb2_hdr)); 4957 return -EINVAL; 4958 } 4959 return 0; 4960 } 4961 4962 static void get_standard_info_pipe(struct smb2_query_info_rsp *rsp, 4963 void *rsp_org) 4964 { 4965 struct smb2_file_standard_info *sinfo; 4966 4967 sinfo = (struct smb2_file_standard_info *)rsp->Buffer; 4968 4969 sinfo->AllocationSize = cpu_to_le64(4096); 4970 sinfo->EndOfFile = cpu_to_le64(0); 4971 sinfo->NumberOfLinks = cpu_to_le32(1); 4972 sinfo->DeletePending = 1; 4973 sinfo->Directory = 0; 4974 rsp->OutputBufferLength = 4975 cpu_to_le32(sizeof(struct smb2_file_standard_info)); 4976 } 4977 4978 static void get_internal_info_pipe(struct smb2_query_info_rsp *rsp, u64 num, 4979 void *rsp_org) 4980 { 4981 struct smb2_file_internal_info *file_info; 4982 4983 file_info = (struct smb2_file_internal_info *)rsp->Buffer; 4984 4985 /* any unique number */ 4986 file_info->IndexNumber = cpu_to_le64(num | (1ULL << 63)); 4987 rsp->OutputBufferLength = 4988 cpu_to_le32(sizeof(struct smb2_file_internal_info)); 4989 } 4990 4991 static int smb2_get_info_file_pipe(struct ksmbd_session *sess, 4992 struct smb2_query_info_req *req, 4993 struct smb2_query_info_rsp *rsp, 4994 void *rsp_org) 4995 { 4996 u64 id; 4997 int rc; 4998 4999 /* 5000 * Windows can sometime send query file info request on 5001 * pipe without opening it, checking error condition here 5002 */ 5003 id = req->VolatileFileId; 5004 5005 lockdep_assert_not_held(&sess->rpc_lock); 5006 5007 down_read(&sess->rpc_lock); 5008 if (!ksmbd_session_rpc_method(sess, id)) { 5009 up_read(&sess->rpc_lock); 5010 return -ENOENT; 5011 } 5012 up_read(&sess->rpc_lock); 5013 5014 ksmbd_debug(SMB, "FileInfoClass %u, FileId 0x%llx\n", 5015 req->FileInfoClass, req->VolatileFileId); 5016 5017 switch (req->FileInfoClass) { 5018 case FILE_STANDARD_INFORMATION: 5019 get_standard_info_pipe(rsp, rsp_org); 5020 rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength), 5021 rsp, rsp_org); 5022 break; 5023 case FILE_INTERNAL_INFORMATION: 5024 get_internal_info_pipe(rsp, id, rsp_org); 5025 rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength), 5026 rsp, rsp_org); 5027 break; 5028 default: 5029 ksmbd_debug(SMB, "smb2_info_file_pipe for %u not supported\n", 5030 req->FileInfoClass); 5031 rc = -EOPNOTSUPP; 5032 } 5033 return rc; 5034 } 5035 5036 /** 5037 * smb2_get_ea() - handler for smb2 get extended attribute command 5038 * @work: smb work containing query info command buffer 5039 * @fp: ksmbd_file pointer 5040 * @req: get extended attribute request 5041 * @rsp: response buffer pointer 5042 * @rsp_org: base response buffer pointer in case of chained response 5043 * 5044 * Return: 0 on success, otherwise error 5045 */ 5046 static int smb2_get_ea(struct ksmbd_work *work, struct ksmbd_file *fp, 5047 struct smb2_query_info_req *req, 5048 struct smb2_query_info_rsp *rsp, void *rsp_org) 5049 { 5050 struct smb2_ea_info *eainfo, *prev_eainfo; 5051 char *name, *ptr, *xattr_list = NULL, *buf; 5052 int rc, name_len, value_len, xattr_list_len, idx; 5053 ssize_t buf_free_len, alignment_bytes, next_offset, rsp_data_cnt = 0; 5054 struct smb2_ea_info_req *ea_req = NULL; 5055 const struct path *path; 5056 struct mnt_idmap *idmap = file_mnt_idmap(fp->filp); 5057 5058 if (!(fp->daccess & FILE_READ_EA_LE)) { 5059 pr_err("Not permitted to read ext attr : 0x%x\n", 5060 fp->daccess); 5061 return -EACCES; 5062 } 5063 5064 path = &fp->filp->f_path; 5065 /* single EA entry is requested with given user.* name */ 5066 if (req->InputBufferLength) { 5067 if (le32_to_cpu(req->InputBufferLength) <= 5068 sizeof(struct smb2_ea_info_req)) 5069 return -EINVAL; 5070 5071 ea_req = (struct smb2_ea_info_req *)((char *)req + 5072 le16_to_cpu(req->InputBufferOffset)); 5073 5074 if (le32_to_cpu(req->InputBufferLength) < 5075 offsetof(struct smb2_ea_info_req, name) + 5076 ea_req->EaNameLength) 5077 return -EINVAL; 5078 } else { 5079 /* need to send all EAs, if no specific EA is requested*/ 5080 if (le32_to_cpu(req->Flags) & SL_RETURN_SINGLE_ENTRY) 5081 ksmbd_debug(SMB, 5082 "All EAs are requested but need to send single EA entry in rsp flags 0x%x\n", 5083 le32_to_cpu(req->Flags)); 5084 } 5085 5086 buf_free_len = 5087 smb2_calc_max_out_buf_len(work, 5088 offsetof(struct smb2_query_info_rsp, Buffer), 5089 le32_to_cpu(req->OutputBufferLength)); 5090 if (buf_free_len < 0) 5091 return -EINVAL; 5092 5093 rc = ksmbd_vfs_listxattr(path->dentry, &xattr_list); 5094 if (rc < 0) { 5095 rsp->hdr.Status = STATUS_INVALID_HANDLE; 5096 goto out; 5097 } else if (!rc) { /* there is no EA in the file */ 5098 ksmbd_debug(SMB, "no ea data in the file\n"); 5099 goto done; 5100 } 5101 xattr_list_len = rc; 5102 5103 ptr = (char *)rsp->Buffer; 5104 eainfo = (struct smb2_ea_info *)ptr; 5105 prev_eainfo = eainfo; 5106 idx = 0; 5107 5108 while (idx < xattr_list_len) { 5109 name = xattr_list + idx; 5110 name_len = strlen(name); 5111 5112 ksmbd_debug(SMB, "%s, len %d\n", name, name_len); 5113 idx += name_len + 1; 5114 5115 /* 5116 * CIFS does not support EA other than user.* namespace, 5117 * still keep the framework generic, to list other attrs 5118 * in future. 5119 */ 5120 if (strncmp(name, XATTR_USER_PREFIX, XATTR_USER_PREFIX_LEN)) 5121 continue; 5122 5123 if (!strncmp(&name[XATTR_USER_PREFIX_LEN], STREAM_PREFIX, 5124 STREAM_PREFIX_LEN)) 5125 continue; 5126 5127 if (req->InputBufferLength && 5128 strncmp(&name[XATTR_USER_PREFIX_LEN], ea_req->name, 5129 ea_req->EaNameLength)) 5130 continue; 5131 5132 if (!strncmp(&name[XATTR_USER_PREFIX_LEN], 5133 DOS_ATTRIBUTE_PREFIX, DOS_ATTRIBUTE_PREFIX_LEN)) 5134 continue; 5135 5136 if (!strncmp(name, XATTR_USER_PREFIX, XATTR_USER_PREFIX_LEN)) 5137 name_len -= XATTR_USER_PREFIX_LEN; 5138 5139 ptr = eainfo->name + name_len + 1; 5140 buf_free_len -= (offsetof(struct smb2_ea_info, name) + 5141 name_len + 1); 5142 /* bailout if xattr can't fit in buf_free_len */ 5143 value_len = ksmbd_vfs_getxattr(idmap, path->dentry, 5144 name, &buf); 5145 if (value_len <= 0) { 5146 rc = -ENOENT; 5147 rsp->hdr.Status = STATUS_INVALID_HANDLE; 5148 goto out; 5149 } 5150 5151 buf_free_len -= value_len; 5152 if (buf_free_len < 0) { 5153 kfree(buf); 5154 break; 5155 } 5156 5157 memcpy(ptr, buf, value_len); 5158 kfree(buf); 5159 5160 ptr += value_len; 5161 eainfo->Flags = 0; 5162 eainfo->EaNameLength = name_len; 5163 5164 if (!strncmp(name, XATTR_USER_PREFIX, XATTR_USER_PREFIX_LEN)) 5165 memcpy(eainfo->name, &name[XATTR_USER_PREFIX_LEN], 5166 name_len); 5167 else 5168 memcpy(eainfo->name, name, name_len); 5169 5170 eainfo->name[name_len] = '\0'; 5171 eainfo->EaValueLength = cpu_to_le16(value_len); 5172 next_offset = offsetof(struct smb2_ea_info, name) + 5173 name_len + 1 + value_len; 5174 5175 /* align next xattr entry at 4 byte bundary */ 5176 alignment_bytes = ((next_offset + 3) & ~3) - next_offset; 5177 if (alignment_bytes) { 5178 if (buf_free_len < alignment_bytes) 5179 break; 5180 memset(ptr, '\0', alignment_bytes); 5181 ptr += alignment_bytes; 5182 next_offset += alignment_bytes; 5183 buf_free_len -= alignment_bytes; 5184 } 5185 eainfo->NextEntryOffset = cpu_to_le32(next_offset); 5186 prev_eainfo = eainfo; 5187 eainfo = (struct smb2_ea_info *)ptr; 5188 rsp_data_cnt += next_offset; 5189 5190 if (req->InputBufferLength) { 5191 ksmbd_debug(SMB, "single entry requested\n"); 5192 break; 5193 } 5194 } 5195 5196 /* no more ea entries */ 5197 prev_eainfo->NextEntryOffset = 0; 5198 done: 5199 rc = 0; 5200 if (rsp_data_cnt == 0) 5201 rsp->hdr.Status = STATUS_NO_EAS_ON_FILE; 5202 rsp->OutputBufferLength = cpu_to_le32(rsp_data_cnt); 5203 out: 5204 kvfree(xattr_list); 5205 return rc; 5206 } 5207 5208 static void get_file_access_info(struct smb2_query_info_rsp *rsp, 5209 struct ksmbd_file *fp, void *rsp_org) 5210 { 5211 struct smb2_file_access_info *file_info; 5212 5213 file_info = (struct smb2_file_access_info *)rsp->Buffer; 5214 file_info->AccessFlags = fp->daccess; 5215 rsp->OutputBufferLength = 5216 cpu_to_le32(sizeof(struct smb2_file_access_info)); 5217 } 5218 5219 static int get_file_basic_info(struct smb2_query_info_rsp *rsp, 5220 struct ksmbd_file *fp, void *rsp_org) 5221 { 5222 struct file_basic_info *basic_info; 5223 struct kstat stat; 5224 u64 time; 5225 int ret; 5226 5227 if (!(fp->daccess & FILE_READ_ATTRIBUTES_LE)) { 5228 pr_err("no right to read the attributes : 0x%x\n", 5229 fp->daccess); 5230 return -EACCES; 5231 } 5232 5233 ret = vfs_getattr(&fp->filp->f_path, &stat, STATX_BASIC_STATS, 5234 AT_STATX_SYNC_AS_STAT); 5235 if (ret) 5236 return ret; 5237 5238 basic_info = (struct file_basic_info *)rsp->Buffer; 5239 basic_info->CreationTime = cpu_to_le64(fp->create_time); 5240 time = ksmbd_UnixTimeToNT(stat.atime); 5241 basic_info->LastAccessTime = cpu_to_le64(time); 5242 time = ksmbd_UnixTimeToNT(stat.mtime); 5243 basic_info->LastWriteTime = cpu_to_le64(time); 5244 basic_info->ChangeTime = cpu_to_le64(fp->change_time); 5245 basic_info->Attributes = fp->f_ci->m_fattr; 5246 basic_info->Pad = 0; 5247 rsp->OutputBufferLength = 5248 cpu_to_le32(sizeof(struct file_basic_info)); 5249 return 0; 5250 } 5251 5252 static int get_file_standard_info(struct smb2_query_info_rsp *rsp, 5253 struct ksmbd_file *fp, void *rsp_org) 5254 { 5255 struct smb2_file_standard_info *sinfo; 5256 unsigned int delete_pending; 5257 struct kstat stat; 5258 int ret; 5259 5260 ret = vfs_getattr(&fp->filp->f_path, &stat, STATX_BASIC_STATS, 5261 AT_STATX_SYNC_AS_STAT); 5262 if (ret) 5263 return ret; 5264 5265 sinfo = (struct smb2_file_standard_info *)rsp->Buffer; 5266 delete_pending = ksmbd_inode_pending_delete(fp); 5267 5268 if (ksmbd_stream_fd(fp) == false) { 5269 sinfo->AllocationSize = cpu_to_le64(fp->allocation_size); 5270 sinfo->EndOfFile = S_ISDIR(stat.mode) ? 0 : cpu_to_le64(stat.size); 5271 } else { 5272 sinfo->AllocationSize = cpu_to_le64(fp->stream.size); 5273 sinfo->EndOfFile = cpu_to_le64(fp->stream.size); 5274 } 5275 sinfo->NumberOfLinks = cpu_to_le32(get_nlink(&stat) - delete_pending); 5276 sinfo->DeletePending = delete_pending; 5277 sinfo->Directory = S_ISDIR(stat.mode) ? 1 : 0; 5278 rsp->OutputBufferLength = 5279 cpu_to_le32(sizeof(struct smb2_file_standard_info)); 5280 5281 return 0; 5282 } 5283 5284 static void get_file_alignment_info(struct smb2_query_info_rsp *rsp, 5285 void *rsp_org) 5286 { 5287 struct smb2_file_alignment_info *file_info; 5288 5289 file_info = (struct smb2_file_alignment_info *)rsp->Buffer; 5290 file_info->AlignmentRequirement = 0; 5291 rsp->OutputBufferLength = 5292 cpu_to_le32(sizeof(struct smb2_file_alignment_info)); 5293 } 5294 5295 static int get_file_all_info(struct ksmbd_work *work, 5296 struct smb2_query_info_rsp *rsp, 5297 struct ksmbd_file *fp, 5298 void *rsp_org) 5299 { 5300 struct ksmbd_conn *conn = work->conn; 5301 struct smb2_file_all_info *file_info; 5302 unsigned int delete_pending; 5303 struct kstat stat; 5304 int conv_len; 5305 char *filename; 5306 u64 time; 5307 int ret, buf_free_len, filename_len; 5308 struct smb2_query_info_req *req = ksmbd_req_buf_next(work); 5309 5310 if (!(fp->daccess & FILE_READ_ATTRIBUTES_LE)) { 5311 ksmbd_debug(SMB, "no right to read the attributes : 0x%x\n", 5312 fp->daccess); 5313 return -EACCES; 5314 } 5315 5316 filename = convert_to_nt_pathname(work->tcon->share_conf, &fp->filp->f_path); 5317 if (IS_ERR(filename)) 5318 return PTR_ERR(filename); 5319 5320 filename_len = strlen(filename); 5321 buf_free_len = smb2_calc_max_out_buf_len(work, 5322 offsetof(struct smb2_query_info_rsp, Buffer) + 5323 offsetof(struct smb2_file_all_info, FileName), 5324 le32_to_cpu(req->OutputBufferLength)); 5325 if (buf_free_len < (filename_len + 1) * 2) { 5326 kfree(filename); 5327 return -EINVAL; 5328 } 5329 5330 ret = vfs_getattr(&fp->filp->f_path, &stat, STATX_BASIC_STATS, 5331 AT_STATX_SYNC_AS_STAT); 5332 if (ret) { 5333 kfree(filename); 5334 return ret; 5335 } 5336 5337 ksmbd_debug(SMB, "filename = %s\n", filename); 5338 delete_pending = ksmbd_inode_pending_delete(fp); 5339 file_info = (struct smb2_file_all_info *)rsp->Buffer; 5340 5341 file_info->CreationTime = cpu_to_le64(fp->create_time); 5342 time = ksmbd_UnixTimeToNT(stat.atime); 5343 file_info->LastAccessTime = cpu_to_le64(time); 5344 time = ksmbd_UnixTimeToNT(stat.mtime); 5345 file_info->LastWriteTime = cpu_to_le64(time); 5346 file_info->ChangeTime = cpu_to_le64(fp->change_time); 5347 file_info->Attributes = fp->f_ci->m_fattr; 5348 file_info->Pad1 = 0; 5349 if (ksmbd_stream_fd(fp) == false) { 5350 file_info->AllocationSize = cpu_to_le64(fp->allocation_size); 5351 file_info->EndOfFile = S_ISDIR(stat.mode) ? 0 : cpu_to_le64(stat.size); 5352 } else { 5353 file_info->AllocationSize = cpu_to_le64(fp->stream.size); 5354 file_info->EndOfFile = cpu_to_le64(fp->stream.size); 5355 } 5356 file_info->NumberOfLinks = 5357 cpu_to_le32(get_nlink(&stat) - delete_pending); 5358 file_info->DeletePending = delete_pending; 5359 file_info->Directory = S_ISDIR(stat.mode) ? 1 : 0; 5360 file_info->Pad2 = 0; 5361 file_info->IndexNumber = cpu_to_le64(stat.ino); 5362 file_info->EASize = 0; 5363 file_info->AccessFlags = fp->daccess; 5364 if (ksmbd_stream_fd(fp) == false) 5365 file_info->CurrentByteOffset = cpu_to_le64(fp->filp->f_pos); 5366 else 5367 file_info->CurrentByteOffset = cpu_to_le64(fp->stream.pos); 5368 file_info->Mode = fp->coption; 5369 file_info->AlignmentRequirement = 0; 5370 conv_len = smbConvertToUTF16((__le16 *)file_info->FileName, filename, 5371 min(filename_len, PATH_MAX), 5372 conn->local_nls, 0); 5373 conv_len *= 2; 5374 file_info->FileNameLength = cpu_to_le32(conv_len); 5375 rsp->OutputBufferLength = 5376 cpu_to_le32(sizeof(struct smb2_file_all_info) + conv_len - 1); 5377 kfree(filename); 5378 return 0; 5379 } 5380 5381 static void get_file_alternate_info(struct ksmbd_work *work, 5382 struct smb2_query_info_rsp *rsp, 5383 struct ksmbd_file *fp, 5384 void *rsp_org) 5385 { 5386 struct ksmbd_conn *conn = work->conn; 5387 struct smb2_file_alt_name_info *file_info; 5388 struct dentry *dentry = fp->filp->f_path.dentry; 5389 int conv_len; 5390 5391 spin_lock(&dentry->d_lock); 5392 file_info = (struct smb2_file_alt_name_info *)rsp->Buffer; 5393 conv_len = ksmbd_extract_shortname(conn, 5394 dentry->d_name.name, 5395 file_info->FileName); 5396 spin_unlock(&dentry->d_lock); 5397 file_info->FileNameLength = cpu_to_le32(conv_len); 5398 rsp->OutputBufferLength = 5399 cpu_to_le32(struct_size(file_info, FileName, conv_len)); 5400 } 5401 5402 static int get_file_stream_info(struct ksmbd_work *work, 5403 struct smb2_query_info_rsp *rsp, 5404 struct ksmbd_file *fp, 5405 void *rsp_org) 5406 { 5407 struct ksmbd_conn *conn = work->conn; 5408 struct smb2_file_stream_info *file_info; 5409 char *stream_name, *xattr_list = NULL, *stream_buf; 5410 struct kstat stat; 5411 const struct path *path = &fp->filp->f_path; 5412 ssize_t xattr_list_len; 5413 int nbytes = 0, streamlen, stream_name_len, next, idx = 0; 5414 int buf_free_len; 5415 struct smb2_query_info_req *req = ksmbd_req_buf_next(work); 5416 int ret; 5417 5418 ret = vfs_getattr(&fp->filp->f_path, &stat, STATX_BASIC_STATS, 5419 AT_STATX_SYNC_AS_STAT); 5420 if (ret) 5421 return ret; 5422 5423 file_info = (struct smb2_file_stream_info *)rsp->Buffer; 5424 5425 buf_free_len = 5426 smb2_calc_max_out_buf_len(work, 5427 offsetof(struct smb2_query_info_rsp, Buffer), 5428 le32_to_cpu(req->OutputBufferLength)); 5429 if (buf_free_len < 0) 5430 goto out; 5431 5432 xattr_list_len = ksmbd_vfs_listxattr(path->dentry, &xattr_list); 5433 if (xattr_list_len < 0) { 5434 goto out; 5435 } else if (!xattr_list_len) { 5436 ksmbd_debug(SMB, "empty xattr in the file\n"); 5437 goto out; 5438 } 5439 5440 while (idx < xattr_list_len) { 5441 stream_name = xattr_list + idx; 5442 streamlen = strlen(stream_name); 5443 idx += streamlen + 1; 5444 5445 ksmbd_debug(SMB, "%s, len %d\n", stream_name, streamlen); 5446 5447 if (strncmp(&stream_name[XATTR_USER_PREFIX_LEN], 5448 STREAM_PREFIX, STREAM_PREFIX_LEN)) 5449 continue; 5450 5451 stream_name_len = streamlen - (XATTR_USER_PREFIX_LEN + 5452 STREAM_PREFIX_LEN); 5453 streamlen = stream_name_len; 5454 5455 /* plus : size */ 5456 streamlen += 1; 5457 stream_buf = kmalloc(streamlen + 1, KSMBD_DEFAULT_GFP); 5458 if (!stream_buf) 5459 break; 5460 5461 streamlen = snprintf(stream_buf, streamlen + 1, 5462 ":%s", &stream_name[XATTR_NAME_STREAM_LEN]); 5463 5464 next = sizeof(struct smb2_file_stream_info) + streamlen * 2; 5465 if (next > buf_free_len) { 5466 kfree(stream_buf); 5467 break; 5468 } 5469 5470 file_info = (struct smb2_file_stream_info *)&rsp->Buffer[nbytes]; 5471 streamlen = smbConvertToUTF16((__le16 *)file_info->StreamName, 5472 stream_buf, streamlen, 5473 conn->local_nls, 0); 5474 streamlen *= 2; 5475 kfree(stream_buf); 5476 file_info->StreamNameLength = cpu_to_le32(streamlen); 5477 file_info->StreamSize = cpu_to_le64(stream_name_len); 5478 file_info->StreamAllocationSize = cpu_to_le64(stream_name_len); 5479 5480 nbytes += next; 5481 buf_free_len -= next; 5482 file_info->NextEntryOffset = cpu_to_le32(next); 5483 } 5484 5485 out: 5486 if (!S_ISDIR(stat.mode) && 5487 buf_free_len >= sizeof(struct smb2_file_stream_info) + 7 * 2) { 5488 file_info = (struct smb2_file_stream_info *) 5489 &rsp->Buffer[nbytes]; 5490 streamlen = smbConvertToUTF16((__le16 *)file_info->StreamName, 5491 "::$DATA", 7, conn->local_nls, 0); 5492 streamlen *= 2; 5493 file_info->StreamNameLength = cpu_to_le32(streamlen); 5494 file_info->StreamSize = cpu_to_le64(stat.size); 5495 file_info->StreamAllocationSize = cpu_to_le64(stat.blocks << 9); 5496 nbytes += sizeof(struct smb2_file_stream_info) + streamlen; 5497 } 5498 5499 /* last entry offset should be 0 */ 5500 file_info->NextEntryOffset = 0; 5501 kvfree(xattr_list); 5502 5503 rsp->OutputBufferLength = cpu_to_le32(nbytes); 5504 5505 return 0; 5506 } 5507 5508 static int get_file_internal_info(struct smb2_query_info_rsp *rsp, 5509 struct ksmbd_file *fp, void *rsp_org) 5510 { 5511 struct smb2_file_internal_info *file_info; 5512 struct kstat stat; 5513 int ret; 5514 5515 ret = vfs_getattr(&fp->filp->f_path, &stat, STATX_BASIC_STATS, 5516 AT_STATX_SYNC_AS_STAT); 5517 if (ret) 5518 return ret; 5519 5520 file_info = (struct smb2_file_internal_info *)rsp->Buffer; 5521 file_info->IndexNumber = cpu_to_le64(stat.ino); 5522 rsp->OutputBufferLength = 5523 cpu_to_le32(sizeof(struct smb2_file_internal_info)); 5524 5525 return 0; 5526 } 5527 5528 static int get_file_network_open_info(struct smb2_query_info_rsp *rsp, 5529 struct ksmbd_file *fp, void *rsp_org) 5530 { 5531 struct smb2_file_network_open_info *file_info; 5532 struct kstat stat; 5533 u64 time; 5534 int ret; 5535 5536 if (!(fp->daccess & FILE_READ_ATTRIBUTES_LE)) { 5537 pr_err("no right to read the attributes : 0x%x\n", 5538 fp->daccess); 5539 return -EACCES; 5540 } 5541 5542 ret = vfs_getattr(&fp->filp->f_path, &stat, STATX_BASIC_STATS, 5543 AT_STATX_SYNC_AS_STAT); 5544 if (ret) 5545 return ret; 5546 5547 file_info = (struct smb2_file_network_open_info *)rsp->Buffer; 5548 5549 file_info->CreationTime = cpu_to_le64(fp->create_time); 5550 time = ksmbd_UnixTimeToNT(stat.atime); 5551 file_info->LastAccessTime = cpu_to_le64(time); 5552 time = ksmbd_UnixTimeToNT(stat.mtime); 5553 file_info->LastWriteTime = cpu_to_le64(time); 5554 file_info->ChangeTime = cpu_to_le64(fp->change_time); 5555 file_info->Attributes = fp->f_ci->m_fattr; 5556 if (ksmbd_stream_fd(fp) == false) { 5557 file_info->AllocationSize = cpu_to_le64(fp->allocation_size); 5558 file_info->EndOfFile = S_ISDIR(stat.mode) ? 0 : cpu_to_le64(stat.size); 5559 } else { 5560 file_info->AllocationSize = cpu_to_le64(fp->stream.size); 5561 file_info->EndOfFile = cpu_to_le64(fp->stream.size); 5562 } 5563 file_info->Reserved = cpu_to_le32(0); 5564 rsp->OutputBufferLength = 5565 cpu_to_le32(sizeof(struct smb2_file_network_open_info)); 5566 return 0; 5567 } 5568 5569 static void get_file_ea_info(struct smb2_query_info_rsp *rsp, void *rsp_org) 5570 { 5571 struct smb2_file_ea_info *file_info; 5572 5573 file_info = (struct smb2_file_ea_info *)rsp->Buffer; 5574 file_info->EASize = 0; 5575 rsp->OutputBufferLength = 5576 cpu_to_le32(sizeof(struct smb2_file_ea_info)); 5577 } 5578 5579 static void get_file_position_info(struct smb2_query_info_rsp *rsp, 5580 struct ksmbd_file *fp, void *rsp_org) 5581 { 5582 struct smb2_file_pos_info *file_info; 5583 5584 file_info = (struct smb2_file_pos_info *)rsp->Buffer; 5585 if (ksmbd_stream_fd(fp) == false) 5586 file_info->CurrentByteOffset = cpu_to_le64(fp->filp->f_pos); 5587 else 5588 file_info->CurrentByteOffset = cpu_to_le64(fp->stream.pos); 5589 5590 rsp->OutputBufferLength = 5591 cpu_to_le32(sizeof(struct smb2_file_pos_info)); 5592 } 5593 5594 static void get_file_mode_info(struct smb2_query_info_rsp *rsp, 5595 struct ksmbd_file *fp, void *rsp_org) 5596 { 5597 struct smb2_file_mode_info *file_info; 5598 5599 file_info = (struct smb2_file_mode_info *)rsp->Buffer; 5600 file_info->Mode = fp->coption & FILE_MODE_INFO_MASK; 5601 rsp->OutputBufferLength = 5602 cpu_to_le32(sizeof(struct smb2_file_mode_info)); 5603 } 5604 5605 static int get_file_compression_info(struct smb2_query_info_rsp *rsp, 5606 struct ksmbd_file *fp, void *rsp_org) 5607 { 5608 struct smb2_file_comp_info *file_info; 5609 struct kstat stat; 5610 u16 fmt; 5611 int ret; 5612 5613 ret = vfs_getattr(&fp->filp->f_path, &stat, STATX_BASIC_STATS, 5614 AT_STATX_SYNC_AS_STAT); 5615 if (ret) 5616 return ret; 5617 5618 ret = ksmbd_vfs_get_compression(fp, &fmt); 5619 if (ret) 5620 return ret; 5621 5622 file_info = (struct smb2_file_comp_info *)rsp->Buffer; 5623 file_info->CompressedFileSize = cpu_to_le64(min_t(u64, stat.blocks << 9, stat.size)); 5624 file_info->CompressionFormat = cpu_to_le16(fmt); 5625 file_info->CompressionUnitShift = 0; 5626 file_info->ChunkShift = 0; 5627 file_info->ClusterShift = 0; 5628 memset(&file_info->Reserved[0], 0, 3); 5629 5630 rsp->OutputBufferLength = 5631 cpu_to_le32(sizeof(struct smb2_file_comp_info)); 5632 5633 return 0; 5634 } 5635 5636 static int get_file_attribute_tag_info(struct smb2_query_info_rsp *rsp, 5637 struct ksmbd_file *fp, void *rsp_org) 5638 { 5639 struct smb2_file_attr_tag_info *file_info; 5640 5641 if (!(fp->daccess & FILE_READ_ATTRIBUTES_LE)) { 5642 pr_err("no right to read the attributes : 0x%x\n", 5643 fp->daccess); 5644 return -EACCES; 5645 } 5646 5647 file_info = (struct smb2_file_attr_tag_info *)rsp->Buffer; 5648 file_info->FileAttributes = fp->f_ci->m_fattr; 5649 file_info->ReparseTag = 0; 5650 rsp->OutputBufferLength = 5651 cpu_to_le32(sizeof(struct smb2_file_attr_tag_info)); 5652 return 0; 5653 } 5654 5655 static int find_file_posix_info(struct smb2_query_info_rsp *rsp, 5656 struct ksmbd_file *fp, void *rsp_org) 5657 { 5658 struct smb311_posix_qinfo *file_info; 5659 struct inode *inode = file_inode(fp->filp); 5660 struct mnt_idmap *idmap = file_mnt_idmap(fp->filp); 5661 vfsuid_t vfsuid = i_uid_into_vfsuid(idmap, inode); 5662 vfsgid_t vfsgid = i_gid_into_vfsgid(idmap, inode); 5663 struct kstat stat; 5664 u64 time; 5665 int out_buf_len = sizeof(struct smb311_posix_qinfo) + 32; 5666 int ret; 5667 5668 if (!(fp->daccess & FILE_READ_ATTRIBUTES_LE)) { 5669 pr_err("no right to read the attributes : 0x%x\n", 5670 fp->daccess); 5671 return -EACCES; 5672 } 5673 5674 ret = vfs_getattr(&fp->filp->f_path, &stat, STATX_BASIC_STATS, 5675 AT_STATX_SYNC_AS_STAT); 5676 if (ret) 5677 return ret; 5678 5679 file_info = (struct smb311_posix_qinfo *)rsp->Buffer; 5680 file_info->CreationTime = cpu_to_le64(fp->create_time); 5681 time = ksmbd_UnixTimeToNT(stat.atime); 5682 file_info->LastAccessTime = cpu_to_le64(time); 5683 time = ksmbd_UnixTimeToNT(stat.mtime); 5684 file_info->LastWriteTime = cpu_to_le64(time); 5685 file_info->ChangeTime = cpu_to_le64(fp->change_time); 5686 file_info->DosAttributes = fp->f_ci->m_fattr; 5687 file_info->Inode = cpu_to_le64(stat.ino); 5688 if (ksmbd_stream_fd(fp) == false) { 5689 file_info->EndOfFile = cpu_to_le64(stat.size); 5690 file_info->AllocationSize = cpu_to_le64(fp->allocation_size); 5691 } else { 5692 file_info->EndOfFile = cpu_to_le64(fp->stream.size); 5693 file_info->AllocationSize = cpu_to_le64(fp->stream.size); 5694 } 5695 file_info->HardLinks = cpu_to_le32(stat.nlink); 5696 file_info->Mode = cpu_to_le32(stat.mode & 0777); 5697 switch (stat.mode & S_IFMT) { 5698 case S_IFDIR: 5699 file_info->Mode |= cpu_to_le32(POSIX_TYPE_DIR << POSIX_FILETYPE_SHIFT); 5700 break; 5701 case S_IFLNK: 5702 file_info->Mode |= cpu_to_le32(POSIX_TYPE_SYMLINK << POSIX_FILETYPE_SHIFT); 5703 break; 5704 case S_IFCHR: 5705 file_info->Mode |= cpu_to_le32(POSIX_TYPE_CHARDEV << POSIX_FILETYPE_SHIFT); 5706 break; 5707 case S_IFBLK: 5708 file_info->Mode |= cpu_to_le32(POSIX_TYPE_BLKDEV << POSIX_FILETYPE_SHIFT); 5709 break; 5710 case S_IFIFO: 5711 file_info->Mode |= cpu_to_le32(POSIX_TYPE_FIFO << POSIX_FILETYPE_SHIFT); 5712 break; 5713 case S_IFSOCK: 5714 file_info->Mode |= cpu_to_le32(POSIX_TYPE_SOCKET << POSIX_FILETYPE_SHIFT); 5715 } 5716 5717 file_info->DeviceId = cpu_to_le32(stat.rdev); 5718 5719 /* 5720 * Sids(32) contain two sids(Domain sid(16), UNIX group sid(16)). 5721 * UNIX sid(16) = revision(1) + num_subauth(1) + authority(6) + 5722 * sub_auth(4 * 1(num_subauth)) + RID(4). 5723 */ 5724 id_to_sid(from_kuid_munged(&init_user_ns, vfsuid_into_kuid(vfsuid)), 5725 SIDUNIX_USER, (struct smb_sid *)&file_info->Sids[0]); 5726 id_to_sid(from_kgid_munged(&init_user_ns, vfsgid_into_kgid(vfsgid)), 5727 SIDUNIX_GROUP, (struct smb_sid *)&file_info->Sids[16]); 5728 5729 rsp->OutputBufferLength = cpu_to_le32(out_buf_len); 5730 5731 return 0; 5732 } 5733 5734 static int smb2_get_info_file(struct ksmbd_work *work, 5735 struct smb2_query_info_req *req, 5736 struct smb2_query_info_rsp *rsp) 5737 { 5738 struct ksmbd_file *fp; 5739 int fileinfoclass = 0; 5740 int rc = 0; 5741 unsigned int id = KSMBD_NO_FID, pid = KSMBD_NO_FID; 5742 5743 if (test_share_config_flag(work->tcon->share_conf, 5744 KSMBD_SHARE_FLAG_PIPE)) { 5745 /* smb2 info file called for pipe */ 5746 rc = smb2_get_info_file_pipe(work->sess, req, rsp, 5747 work->response_buf); 5748 goto iov_pin_out; 5749 } 5750 5751 if (work->next_smb2_rcv_hdr_off) { 5752 if (!has_file_id(req->VolatileFileId)) { 5753 ksmbd_debug(SMB, "Compound request set FID = %llu\n", 5754 work->compound_fid); 5755 id = work->compound_fid; 5756 pid = work->compound_pfid; 5757 } 5758 } 5759 5760 if (!has_file_id(id)) { 5761 id = req->VolatileFileId; 5762 pid = req->PersistentFileId; 5763 } 5764 5765 fp = ksmbd_lookup_fd_slow(work, id, pid); 5766 if (!fp) 5767 return -ENOENT; 5768 5769 fileinfoclass = req->FileInfoClass; 5770 5771 switch (fileinfoclass) { 5772 case FILE_ACCESS_INFORMATION: 5773 get_file_access_info(rsp, fp, work->response_buf); 5774 break; 5775 5776 case FILE_BASIC_INFORMATION: 5777 rc = get_file_basic_info(rsp, fp, work->response_buf); 5778 break; 5779 5780 case FILE_STANDARD_INFORMATION: 5781 rc = get_file_standard_info(rsp, fp, work->response_buf); 5782 break; 5783 5784 case FILE_ALIGNMENT_INFORMATION: 5785 get_file_alignment_info(rsp, work->response_buf); 5786 break; 5787 5788 case FILE_ALL_INFORMATION: 5789 rc = get_file_all_info(work, rsp, fp, work->response_buf); 5790 break; 5791 5792 case FILE_ALTERNATE_NAME_INFORMATION: 5793 get_file_alternate_info(work, rsp, fp, work->response_buf); 5794 break; 5795 5796 case FILE_STREAM_INFORMATION: 5797 rc = get_file_stream_info(work, rsp, fp, work->response_buf); 5798 break; 5799 5800 case FILE_INTERNAL_INFORMATION: 5801 rc = get_file_internal_info(rsp, fp, work->response_buf); 5802 break; 5803 5804 case FILE_NETWORK_OPEN_INFORMATION: 5805 rc = get_file_network_open_info(rsp, fp, work->response_buf); 5806 break; 5807 5808 case FILE_EA_INFORMATION: 5809 get_file_ea_info(rsp, work->response_buf); 5810 break; 5811 5812 case FILE_FULL_EA_INFORMATION: 5813 rc = smb2_get_ea(work, fp, req, rsp, work->response_buf); 5814 break; 5815 5816 case FILE_POSITION_INFORMATION: 5817 get_file_position_info(rsp, fp, work->response_buf); 5818 break; 5819 5820 case FILE_MODE_INFORMATION: 5821 get_file_mode_info(rsp, fp, work->response_buf); 5822 break; 5823 5824 case FILE_COMPRESSION_INFORMATION: 5825 rc = get_file_compression_info(rsp, fp, work->response_buf); 5826 break; 5827 5828 case FILE_ATTRIBUTE_TAG_INFORMATION: 5829 rc = get_file_attribute_tag_info(rsp, fp, work->response_buf); 5830 break; 5831 case SMB_FIND_FILE_POSIX_INFO: 5832 if (!work->tcon->posix_extensions) { 5833 pr_err("client doesn't negotiate with SMB3.1.1 POSIX Extensions\n"); 5834 rc = -EOPNOTSUPP; 5835 } else { 5836 rc = find_file_posix_info(rsp, fp, work->response_buf); 5837 } 5838 break; 5839 default: 5840 ksmbd_debug(SMB, "fileinfoclass %d not supported yet\n", 5841 fileinfoclass); 5842 rc = -EOPNOTSUPP; 5843 } 5844 if (!rc) 5845 rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength), 5846 rsp, work->response_buf); 5847 ksmbd_fd_put(work, fp); 5848 5849 iov_pin_out: 5850 if (!rc) 5851 rc = ksmbd_iov_pin_rsp(work, (void *)rsp, 5852 offsetof(struct smb2_query_info_rsp, Buffer) + 5853 le32_to_cpu(rsp->OutputBufferLength)); 5854 return rc; 5855 } 5856 5857 static int smb2_get_info_filesystem(struct ksmbd_work *work, 5858 struct smb2_query_info_req *req, 5859 struct smb2_query_info_rsp *rsp) 5860 { 5861 struct ksmbd_conn *conn = work->conn; 5862 struct ksmbd_share_config *share = work->tcon->share_conf; 5863 int fsinfoclass = 0; 5864 struct kstatfs stfs; 5865 struct path path; 5866 int rc = 0, len; 5867 5868 if (!share->path) 5869 return -EIO; 5870 5871 rc = kern_path(share->path, LOOKUP_NO_SYMLINKS, &path); 5872 if (rc) { 5873 pr_err("cannot create vfs path\n"); 5874 return -EIO; 5875 } 5876 5877 rc = vfs_statfs(&path, &stfs); 5878 if (rc) { 5879 pr_err("cannot do stat of path %s\n", share->path); 5880 path_put(&path); 5881 return -EIO; 5882 } 5883 5884 fsinfoclass = req->FileInfoClass; 5885 5886 switch (fsinfoclass) { 5887 case FS_DEVICE_INFORMATION: 5888 { 5889 FILE_SYSTEM_DEVICE_INFO *info; 5890 5891 info = (FILE_SYSTEM_DEVICE_INFO *)rsp->Buffer; 5892 5893 info->DeviceType = cpu_to_le32(FILE_DEVICE_DISK); 5894 info->DeviceCharacteristics = 5895 cpu_to_le32(FILE_DEVICE_IS_MOUNTED); 5896 if (!test_tree_conn_flag(work->tcon, 5897 KSMBD_TREE_CONN_FLAG_WRITABLE)) 5898 info->DeviceCharacteristics |= 5899 cpu_to_le32(FILE_READ_ONLY_DEVICE); 5900 rsp->OutputBufferLength = cpu_to_le32(8); 5901 break; 5902 } 5903 case FS_ATTRIBUTE_INFORMATION: 5904 { 5905 FILE_SYSTEM_ATTRIBUTE_INFO *info; 5906 struct file_kattr fa = {}; 5907 size_t sz; 5908 u32 attrs; 5909 int err; 5910 5911 info = (FILE_SYSTEM_ATTRIBUTE_INFO *)rsp->Buffer; 5912 attrs = FILE_SUPPORTS_OBJECT_IDS | 5913 FILE_PERSISTENT_ACLS | 5914 FILE_UNICODE_ON_DISK | 5915 FILE_SUPPORTS_BLOCK_REFCOUNTING; 5916 5917 err = vfs_fileattr_get(path.dentry, &fa); 5918 /* 5919 * -EINVAL, -EOPNOTSUPP: ntfs-3g and other FUSE 5920 * filesystems that lack FS_IOC_FSGETXATTR support. 5921 */ 5922 if (err && err != -ENOIOCTLCMD && err != -ENOTTY && 5923 err != -EINVAL && err != -EOPNOTSUPP) { 5924 path_put(&path); 5925 return err; 5926 } 5927 if (!(fa.fsx_xflags & FS_XFLAG_CASEFOLD)) 5928 attrs |= FILE_CASE_SENSITIVE_SEARCH; 5929 if (!(fa.fsx_xflags & FS_XFLAG_CASENONPRESERVING)) 5930 attrs |= FILE_CASE_PRESERVED_NAMES; 5931 5932 info->Attributes = cpu_to_le32(attrs); 5933 info->Attributes |= cpu_to_le32(server_conf.share_fake_fscaps); 5934 5935 if (test_share_config_flag(work->tcon->share_conf, 5936 KSMBD_SHARE_FLAG_STREAMS)) 5937 info->Attributes |= cpu_to_le32(FILE_NAMED_STREAMS); 5938 5939 info->MaxPathNameComponentLength = cpu_to_le32(stfs.f_namelen); 5940 /* 5941 * some application(potableapp) can not run on ksmbd share 5942 * because only NTFS handle security setting on windows. 5943 * So Although local fs(EXT4 or F2fs, etc) is not NTFS, 5944 * ksmbd should show share as NTFS. Later, If needed, we can add 5945 * fs type(s) parameter to change fs type user wanted. 5946 */ 5947 len = smbConvertToUTF16((__le16 *)info->FileSystemName, 5948 "NTFS", PATH_MAX, conn->local_nls, 0); 5949 len = len * 2; 5950 info->FileSystemNameLen = cpu_to_le32(len); 5951 sz = sizeof(FILE_SYSTEM_ATTRIBUTE_INFO) + len; 5952 rsp->OutputBufferLength = cpu_to_le32(sz); 5953 break; 5954 } 5955 case FS_VOLUME_INFORMATION: 5956 { 5957 struct filesystem_vol_info *info; 5958 size_t sz; 5959 unsigned int serial_crc = 0; 5960 5961 info = (struct filesystem_vol_info *)(rsp->Buffer); 5962 info->VolumeCreationTime = 0; 5963 serial_crc = crc32_le(serial_crc, share->name, 5964 strlen(share->name)); 5965 serial_crc = crc32_le(serial_crc, share->path, 5966 strlen(share->path)); 5967 serial_crc = crc32_le(serial_crc, ksmbd_netbios_name(), 5968 strlen(ksmbd_netbios_name())); 5969 /* Taking dummy value of serial number*/ 5970 info->VolumeSerialNumber = cpu_to_le32(serial_crc); 5971 len = smbConvertToUTF16((__le16 *)info->VolumeLabel, 5972 share->name, PATH_MAX, 5973 conn->local_nls, 0); 5974 len = len * 2; 5975 info->VolumeLabelLength = cpu_to_le32(len); 5976 info->Reserved = 0; 5977 info->SupportsObjects = 0; 5978 sz = sizeof(struct filesystem_vol_info) + len; 5979 rsp->OutputBufferLength = cpu_to_le32(sz); 5980 break; 5981 } 5982 case FS_SIZE_INFORMATION: 5983 { 5984 FILE_SYSTEM_SIZE_INFO *info; 5985 5986 info = (FILE_SYSTEM_SIZE_INFO *)(rsp->Buffer); 5987 info->TotalAllocationUnits = cpu_to_le64(stfs.f_blocks); 5988 info->AvailableAllocationUnits = cpu_to_le64(stfs.f_bfree); 5989 info->SectorsPerAllocationUnit = cpu_to_le32(1); 5990 info->BytesPerSector = cpu_to_le32(stfs.f_bsize); 5991 rsp->OutputBufferLength = cpu_to_le32(24); 5992 break; 5993 } 5994 case FS_FULL_SIZE_INFORMATION: 5995 { 5996 struct smb2_fs_full_size_info *info; 5997 5998 info = (struct smb2_fs_full_size_info *)(rsp->Buffer); 5999 info->TotalAllocationUnits = cpu_to_le64(stfs.f_blocks); 6000 info->CallerAvailableAllocationUnits = 6001 cpu_to_le64(stfs.f_bavail); 6002 info->ActualAvailableAllocationUnits = 6003 cpu_to_le64(stfs.f_bfree); 6004 info->SectorsPerAllocationUnit = cpu_to_le32(1); 6005 info->BytesPerSector = cpu_to_le32(stfs.f_bsize); 6006 rsp->OutputBufferLength = cpu_to_le32(32); 6007 break; 6008 } 6009 case FS_OBJECT_ID_INFORMATION: 6010 { 6011 struct object_id_info *info; 6012 6013 info = (struct object_id_info *)(rsp->Buffer); 6014 6015 if (path.mnt->mnt_sb->s_uuid_len == 16) 6016 memcpy(info->objid, path.mnt->mnt_sb->s_uuid.b, 6017 path.mnt->mnt_sb->s_uuid_len); 6018 else 6019 memcpy(info->objid, &stfs.f_fsid, sizeof(stfs.f_fsid)); 6020 6021 info->extended_info.magic = cpu_to_le32(EXTENDED_INFO_MAGIC); 6022 info->extended_info.version = cpu_to_le32(1); 6023 info->extended_info.release = cpu_to_le32(1); 6024 info->extended_info.rel_date = 0; 6025 memcpy(info->extended_info.version_string, "1.1.0", strlen("1.1.0")); 6026 rsp->OutputBufferLength = cpu_to_le32(64); 6027 break; 6028 } 6029 case FS_SECTOR_SIZE_INFORMATION: 6030 { 6031 struct smb3_fs_ss_info *info; 6032 unsigned int sector_size = 6033 min_t(unsigned int, path.mnt->mnt_sb->s_blocksize, 4096); 6034 6035 info = (struct smb3_fs_ss_info *)(rsp->Buffer); 6036 6037 info->LogicalBytesPerSector = cpu_to_le32(sector_size); 6038 info->PhysicalBytesPerSectorForAtomicity = 6039 cpu_to_le32(sector_size); 6040 info->PhysicalBytesPerSectorForPerf = cpu_to_le32(sector_size); 6041 info->FSEffPhysicalBytesPerSectorForAtomicity = 6042 cpu_to_le32(sector_size); 6043 info->Flags = cpu_to_le32(SSINFO_FLAGS_ALIGNED_DEVICE | 6044 SSINFO_FLAGS_PARTITION_ALIGNED_ON_DEVICE); 6045 info->ByteOffsetForSectorAlignment = 0; 6046 info->ByteOffsetForPartitionAlignment = 0; 6047 rsp->OutputBufferLength = cpu_to_le32(28); 6048 break; 6049 } 6050 case FS_CONTROL_INFORMATION: 6051 { 6052 /* 6053 * TODO : The current implementation is based on 6054 * test result with win7(NTFS) server. It's need to 6055 * modify this to get valid Quota values 6056 * from Linux kernel 6057 */ 6058 struct smb2_fs_control_info *info; 6059 6060 info = (struct smb2_fs_control_info *)(rsp->Buffer); 6061 info->FreeSpaceStartFiltering = 0; 6062 info->FreeSpaceThreshold = 0; 6063 info->FreeSpaceStopFiltering = 0; 6064 info->DefaultQuotaThreshold = cpu_to_le64(SMB2_NO_FID); 6065 info->DefaultQuotaLimit = cpu_to_le64(SMB2_NO_FID); 6066 info->Padding = 0; 6067 rsp->OutputBufferLength = cpu_to_le32(48); 6068 break; 6069 } 6070 case FS_POSIX_INFORMATION: 6071 { 6072 FILE_SYSTEM_POSIX_INFO *info; 6073 6074 if (!work->tcon->posix_extensions) { 6075 pr_err("client doesn't negotiate with SMB3.1.1 POSIX Extensions\n"); 6076 path_put(&path); 6077 return -EOPNOTSUPP; 6078 } else { 6079 info = (FILE_SYSTEM_POSIX_INFO *)(rsp->Buffer); 6080 info->OptimalTransferSize = cpu_to_le32(stfs.f_bsize); 6081 info->BlockSize = cpu_to_le32(stfs.f_bsize); 6082 info->TotalBlocks = cpu_to_le64(stfs.f_blocks); 6083 info->BlocksAvail = cpu_to_le64(stfs.f_bfree); 6084 info->UserBlocksAvail = cpu_to_le64(stfs.f_bavail); 6085 info->TotalFileNodes = cpu_to_le64(stfs.f_files); 6086 info->FreeFileNodes = cpu_to_le64(stfs.f_ffree); 6087 rsp->OutputBufferLength = cpu_to_le32(56); 6088 } 6089 break; 6090 } 6091 default: 6092 path_put(&path); 6093 return -EOPNOTSUPP; 6094 } 6095 rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength), 6096 rsp, work->response_buf); 6097 path_put(&path); 6098 6099 if (!rc) 6100 rc = ksmbd_iov_pin_rsp(work, (void *)rsp, 6101 offsetof(struct smb2_query_info_rsp, Buffer) + 6102 le32_to_cpu(rsp->OutputBufferLength)); 6103 return rc; 6104 } 6105 6106 static int smb2_get_info_sec(struct ksmbd_work *work, 6107 struct smb2_query_info_req *req, 6108 struct smb2_query_info_rsp *rsp) 6109 { 6110 struct ksmbd_file *fp; 6111 struct mnt_idmap *idmap; 6112 struct smb_ntsd *pntsd = NULL, *ppntsd = NULL; 6113 struct smb_fattr fattr = {{0}}; 6114 struct inode *inode; 6115 __u32 secdesclen = 0; 6116 unsigned int id = KSMBD_NO_FID, pid = KSMBD_NO_FID; 6117 int addition_info = le32_to_cpu(req->AdditionalInformation); 6118 int rc = 0, ppntsd_size = 0, max_len; 6119 size_t scratch_len = 0; 6120 6121 if (addition_info & ~(OWNER_SECINFO | GROUP_SECINFO | DACL_SECINFO | 6122 PROTECTED_DACL_SECINFO | 6123 UNPROTECTED_DACL_SECINFO)) { 6124 ksmbd_debug(SMB, "Unsupported addition info: 0x%x)\n", 6125 addition_info); 6126 6127 rsp->hdr.Status = STATUS_NOT_SUPPORTED; 6128 return -EINVAL; 6129 } 6130 6131 if (work->next_smb2_rcv_hdr_off) { 6132 if (!has_file_id(req->VolatileFileId)) { 6133 ksmbd_debug(SMB, "Compound request set FID = %llu\n", 6134 work->compound_fid); 6135 id = work->compound_fid; 6136 pid = work->compound_pfid; 6137 } 6138 } 6139 6140 if (!has_file_id(id)) { 6141 id = req->VolatileFileId; 6142 pid = req->PersistentFileId; 6143 } 6144 6145 fp = ksmbd_lookup_fd_slow(work, id, pid); 6146 if (!fp) 6147 return -ENOENT; 6148 6149 idmap = file_mnt_idmap(fp->filp); 6150 inode = file_inode(fp->filp); 6151 ksmbd_acls_fattr(&fattr, idmap, inode); 6152 6153 if (test_share_config_flag(work->tcon->share_conf, 6154 KSMBD_SHARE_FLAG_ACL_XATTR)) 6155 ppntsd_size = ksmbd_vfs_get_sd_xattr(work->conn, idmap, 6156 fp->filp->f_path.dentry, 6157 &ppntsd); 6158 6159 /* Check if sd buffer size exceeds response buffer size */ 6160 max_len = smb2_calc_max_out_buf_len(work, 6161 offsetof(struct smb2_query_info_rsp, Buffer), 6162 le32_to_cpu(req->OutputBufferLength)); 6163 if (max_len < 0) { 6164 rc = -EINVAL; 6165 goto release_acl; 6166 } 6167 6168 scratch_len = smb_acl_sec_desc_scratch_len(&fattr, ppntsd, 6169 ppntsd_size, addition_info); 6170 if (!scratch_len || scratch_len == SIZE_MAX) { 6171 rc = -EFBIG; 6172 goto release_acl; 6173 } 6174 6175 pntsd = kvzalloc(scratch_len, KSMBD_DEFAULT_GFP); 6176 if (!pntsd) { 6177 rc = -ENOMEM; 6178 goto release_acl; 6179 } 6180 6181 rc = build_sec_desc(idmap, pntsd, ppntsd, ppntsd_size, 6182 addition_info, &secdesclen, &fattr); 6183 6184 release_acl: 6185 posix_acl_release(fattr.cf_acls); 6186 posix_acl_release(fattr.cf_dacls); 6187 kfree(ppntsd); 6188 ksmbd_fd_put(work, fp); 6189 6190 if (!rc && ALIGN(secdesclen, 8) > scratch_len) 6191 rc = -EFBIG; 6192 if (rc) 6193 goto err_out; 6194 6195 rsp->OutputBufferLength = cpu_to_le32(secdesclen); 6196 rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength), 6197 rsp, work->response_buf); 6198 if (rc) 6199 goto err_out; 6200 6201 rc = ksmbd_iov_pin_rsp_read(work, (void *)rsp, 6202 offsetof(struct smb2_query_info_rsp, Buffer), 6203 pntsd, secdesclen); 6204 err_out: 6205 if (rc) { 6206 rsp->OutputBufferLength = 0; 6207 kvfree(pntsd); 6208 } 6209 6210 return rc; 6211 } 6212 6213 /** 6214 * smb2_query_info() - handler for smb2 query info command 6215 * @work: smb work containing query info request buffer 6216 * 6217 * Return: 0 on success, otherwise error 6218 */ 6219 int smb2_query_info(struct ksmbd_work *work) 6220 { 6221 struct smb2_query_info_req *req; 6222 struct smb2_query_info_rsp *rsp; 6223 int rc = 0; 6224 6225 ksmbd_debug(SMB, "Received request smb2 query info request\n"); 6226 6227 WORK_BUFFERS(work, req, rsp); 6228 6229 if (smb2_compound_has_failed(work, &rsp->hdr)) 6230 return -EACCES; 6231 6232 if (ksmbd_override_fsids(work)) { 6233 rc = -ENOMEM; 6234 goto err_out; 6235 } 6236 6237 rsp->StructureSize = cpu_to_le16(9); 6238 rsp->OutputBufferOffset = cpu_to_le16(72); 6239 6240 switch (req->InfoType) { 6241 case SMB2_O_INFO_FILE: 6242 ksmbd_debug(SMB, "GOT SMB2_O_INFO_FILE\n"); 6243 rc = smb2_get_info_file(work, req, rsp); 6244 break; 6245 case SMB2_O_INFO_FILESYSTEM: 6246 ksmbd_debug(SMB, "GOT SMB2_O_INFO_FILESYSTEM\n"); 6247 rc = smb2_get_info_filesystem(work, req, rsp); 6248 break; 6249 case SMB2_O_INFO_SECURITY: 6250 ksmbd_debug(SMB, "GOT SMB2_O_INFO_SECURITY\n"); 6251 rc = smb2_get_info_sec(work, req, rsp); 6252 break; 6253 default: 6254 ksmbd_debug(SMB, "InfoType %d not supported yet\n", 6255 req->InfoType); 6256 rc = -EOPNOTSUPP; 6257 } 6258 ksmbd_revert_fsids(work); 6259 6260 err_out: 6261 if (rc < 0) { 6262 if (rc == -EACCES) 6263 rsp->hdr.Status = STATUS_ACCESS_DENIED; 6264 else if (rc == -ENOENT) 6265 rsp->hdr.Status = STATUS_FILE_CLOSED; 6266 else if (rc == -EIO) 6267 rsp->hdr.Status = STATUS_UNEXPECTED_IO_ERROR; 6268 else if (rc == -ENOMEM) 6269 rsp->hdr.Status = STATUS_INSUFFICIENT_RESOURCES; 6270 else if (rc == -EINVAL && rsp->hdr.Status == 0) 6271 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 6272 else if (rc == -EOPNOTSUPP || rsp->hdr.Status == 0) 6273 rsp->hdr.Status = STATUS_INVALID_INFO_CLASS; 6274 smb2_set_err_rsp(work); 6275 6276 ksmbd_debug(SMB, "error while processing smb2 query rc = %d\n", 6277 rc); 6278 return rc; 6279 } 6280 return 0; 6281 } 6282 6283 /** 6284 * smb2_close_pipe() - handler for closing IPC pipe 6285 * @work: smb work containing close request buffer 6286 * 6287 * Return: 0 6288 */ 6289 static noinline int smb2_close_pipe(struct ksmbd_work *work) 6290 { 6291 u64 id; 6292 struct smb2_close_req *req; 6293 struct smb2_close_rsp *rsp; 6294 6295 WORK_BUFFERS(work, req, rsp); 6296 6297 id = req->VolatileFileId; 6298 ksmbd_session_rpc_close(work->sess, id); 6299 6300 rsp->StructureSize = cpu_to_le16(60); 6301 rsp->Flags = 0; 6302 rsp->Reserved = 0; 6303 rsp->CreationTime = 0; 6304 rsp->LastAccessTime = 0; 6305 rsp->LastWriteTime = 0; 6306 rsp->ChangeTime = 0; 6307 rsp->AllocationSize = 0; 6308 rsp->EndOfFile = 0; 6309 rsp->Attributes = 0; 6310 6311 return ksmbd_iov_pin_rsp(work, (void *)rsp, 6312 sizeof(struct smb2_close_rsp)); 6313 } 6314 6315 /** 6316 * smb2_close() - handler for smb2 close file command 6317 * @work: smb work containing close request buffer 6318 * 6319 * Return: 0 on success, otherwise error 6320 */ 6321 int smb2_close(struct ksmbd_work *work) 6322 { 6323 u64 volatile_id = KSMBD_NO_FID; 6324 u64 sess_id; 6325 struct smb2_close_req *req; 6326 struct smb2_close_rsp *rsp; 6327 struct ksmbd_conn *conn = work->conn; 6328 struct ksmbd_file *fp; 6329 u64 time; 6330 int err = 0; 6331 6332 ksmbd_debug(SMB, "Received smb2 close request\n"); 6333 6334 WORK_BUFFERS(work, req, rsp); 6335 6336 if (smb2_compound_has_failed(work, &rsp->hdr)) 6337 return -EACCES; 6338 6339 if (test_share_config_flag(work->tcon->share_conf, 6340 KSMBD_SHARE_FLAG_PIPE)) { 6341 ksmbd_debug(SMB, "IPC pipe close request\n"); 6342 return smb2_close_pipe(work); 6343 } 6344 6345 sess_id = le64_to_cpu(req->hdr.SessionId); 6346 if (req->hdr.Flags & SMB2_FLAGS_RELATED_OPERATIONS) 6347 sess_id = work->compound_sid; 6348 6349 work->compound_sid = 0; 6350 if (check_session_id(conn, sess_id)) { 6351 work->compound_sid = sess_id; 6352 } else { 6353 rsp->hdr.Status = STATUS_USER_SESSION_DELETED; 6354 if (req->hdr.Flags & SMB2_FLAGS_RELATED_OPERATIONS) 6355 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 6356 err = -EBADF; 6357 goto out; 6358 } 6359 6360 if (work->next_smb2_rcv_hdr_off && 6361 !has_file_id(req->VolatileFileId)) { 6362 if (!has_file_id(work->compound_fid)) { 6363 /* file already closed, return FILE_CLOSED */ 6364 ksmbd_debug(SMB, "file already closed\n"); 6365 rsp->hdr.Status = STATUS_FILE_CLOSED; 6366 err = -EBADF; 6367 goto out; 6368 } else { 6369 ksmbd_debug(SMB, 6370 "Compound request set FID = %llu:%llu\n", 6371 work->compound_fid, 6372 work->compound_pfid); 6373 volatile_id = work->compound_fid; 6374 6375 /* file closed, stored id is not valid anymore */ 6376 work->compound_fid = KSMBD_NO_FID; 6377 work->compound_pfid = KSMBD_NO_FID; 6378 } 6379 } else { 6380 volatile_id = req->VolatileFileId; 6381 } 6382 ksmbd_debug(SMB, "volatile_id = %llu\n", volatile_id); 6383 6384 rsp->StructureSize = cpu_to_le16(60); 6385 rsp->Reserved = 0; 6386 6387 if (req->Flags == SMB2_CLOSE_FLAG_POSTQUERY_ATTRIB) { 6388 struct kstat stat; 6389 int ret; 6390 6391 fp = ksmbd_lookup_fd_fast(work, volatile_id); 6392 if (!fp) { 6393 err = -ENOENT; 6394 goto out; 6395 } 6396 6397 ret = vfs_getattr(&fp->filp->f_path, &stat, STATX_BASIC_STATS, 6398 AT_STATX_SYNC_AS_STAT); 6399 if (ret) { 6400 ksmbd_fd_put(work, fp); 6401 goto out; 6402 } 6403 6404 rsp->Flags = SMB2_CLOSE_FLAG_POSTQUERY_ATTRIB; 6405 rsp->AllocationSize = cpu_to_le64(fp->allocation_size); 6406 rsp->EndOfFile = cpu_to_le64(stat.size); 6407 rsp->Attributes = fp->f_ci->m_fattr; 6408 rsp->CreationTime = cpu_to_le64(fp->create_time); 6409 time = ksmbd_UnixTimeToNT(stat.atime); 6410 rsp->LastAccessTime = cpu_to_le64(time); 6411 time = ksmbd_UnixTimeToNT(stat.mtime); 6412 rsp->LastWriteTime = cpu_to_le64(time); 6413 rsp->ChangeTime = cpu_to_le64(fp->change_time); 6414 ksmbd_fd_put(work, fp); 6415 } else { 6416 rsp->Flags = 0; 6417 rsp->AllocationSize = 0; 6418 rsp->EndOfFile = 0; 6419 rsp->Attributes = 0; 6420 rsp->CreationTime = 0; 6421 rsp->LastAccessTime = 0; 6422 rsp->LastWriteTime = 0; 6423 rsp->ChangeTime = 0; 6424 } 6425 6426 err = ksmbd_close_fd(work, volatile_id); 6427 out: 6428 if (!err) 6429 err = ksmbd_iov_pin_rsp(work, (void *)rsp, 6430 sizeof(struct smb2_close_rsp)); 6431 6432 if (err) { 6433 if (rsp->hdr.Status == 0) 6434 rsp->hdr.Status = STATUS_FILE_CLOSED; 6435 smb2_set_err_rsp(work); 6436 } 6437 6438 return err; 6439 } 6440 6441 /** 6442 * smb2_echo() - handler for smb2 echo(ping) command 6443 * @work: smb work containing echo request buffer 6444 * 6445 * Return: 0 on success, otherwise error 6446 */ 6447 int smb2_echo(struct ksmbd_work *work) 6448 { 6449 struct smb2_echo_rsp *rsp = smb_get_msg(work->response_buf); 6450 6451 ksmbd_debug(SMB, "Received smb2 echo request\n"); 6452 6453 if (work->next_smb2_rcv_hdr_off) 6454 rsp = ksmbd_resp_buf_next(work); 6455 6456 rsp->StructureSize = cpu_to_le16(4); 6457 rsp->Reserved = 0; 6458 return ksmbd_iov_pin_rsp(work, rsp, sizeof(struct smb2_echo_rsp)); 6459 } 6460 6461 static int smb2_rename(struct ksmbd_work *work, 6462 struct ksmbd_file *fp, 6463 struct smb2_file_rename_info *file_info, 6464 struct nls_table *local_nls) 6465 { 6466 struct ksmbd_share_config *share = fp->tcon->share_conf; 6467 char *new_name = NULL; 6468 int rc, flags = 0; 6469 6470 ksmbd_debug(SMB, "setting FILE_RENAME_INFO\n"); 6471 new_name = smb2_get_name(file_info->FileName, 6472 le32_to_cpu(file_info->FileNameLength), 6473 local_nls); 6474 if (IS_ERR(new_name)) 6475 return PTR_ERR(new_name); 6476 6477 if (fp->is_posix_ctxt == false && strchr(new_name, ':')) { 6478 int s_type; 6479 char *xattr_stream_name, *stream_name = NULL; 6480 size_t xattr_stream_size; 6481 int len; 6482 6483 rc = parse_stream_name(new_name, &stream_name, &s_type); 6484 if (rc < 0) 6485 goto out; 6486 6487 len = strlen(new_name); 6488 if (len > 0 && new_name[len - 1] != '/') { 6489 pr_err("not allow base filename in rename\n"); 6490 rc = -ESHARE; 6491 goto out; 6492 } 6493 6494 rc = ksmbd_vfs_xattr_stream_name(stream_name, 6495 &xattr_stream_name, 6496 &xattr_stream_size, 6497 s_type); 6498 if (rc) 6499 goto out; 6500 6501 rc = ksmbd_vfs_setxattr(file_mnt_idmap(fp->filp), 6502 &fp->filp->f_path, 6503 xattr_stream_name, 6504 NULL, 0, 0, true); 6505 if (rc < 0) { 6506 pr_err("failed to store stream name in xattr: %d\n", 6507 rc); 6508 rc = -EINVAL; 6509 goto out; 6510 } 6511 6512 goto out; 6513 } 6514 6515 ksmbd_debug(SMB, "new name %s\n", new_name); 6516 if (ksmbd_share_veto_filename(share, new_name)) { 6517 rc = -ENOENT; 6518 ksmbd_debug(SMB, "Can't rename vetoed file: %s\n", new_name); 6519 goto out; 6520 } 6521 6522 if (!file_info->ReplaceIfExists) 6523 flags = RENAME_NOREPLACE; 6524 6525 rc = ksmbd_vfs_rename(work, &fp->filp->f_path, new_name, flags); 6526 if (!rc) 6527 smb_break_all_levII_oplock(work, fp, 0); 6528 out: 6529 kfree(new_name); 6530 return rc; 6531 } 6532 6533 static int smb2_create_link(struct ksmbd_work *work, 6534 struct ksmbd_share_config *share, 6535 struct smb2_file_link_info *file_info, 6536 unsigned int buf_len, struct file *filp, 6537 struct nls_table *local_nls) 6538 { 6539 char *link_name = NULL, *target_name = NULL, *pathname = NULL; 6540 struct path path; 6541 int rc; 6542 6543 if (buf_len < (u64)sizeof(struct smb2_file_link_info) + 6544 le32_to_cpu(file_info->FileNameLength)) 6545 return -EINVAL; 6546 6547 ksmbd_debug(SMB, "setting FILE_LINK_INFORMATION\n"); 6548 pathname = kmalloc(PATH_MAX, KSMBD_DEFAULT_GFP); 6549 if (!pathname) 6550 return -ENOMEM; 6551 6552 link_name = smb2_get_name(file_info->FileName, 6553 le32_to_cpu(file_info->FileNameLength), 6554 local_nls); 6555 if (IS_ERR(link_name) || S_ISDIR(file_inode(filp)->i_mode)) { 6556 rc = -EINVAL; 6557 goto out; 6558 } 6559 6560 ksmbd_debug(SMB, "link name is %s\n", link_name); 6561 target_name = file_path(filp, pathname, PATH_MAX); 6562 if (IS_ERR(target_name)) { 6563 rc = -EINVAL; 6564 goto out; 6565 } 6566 6567 ksmbd_debug(SMB, "target name is %s\n", target_name); 6568 rc = ksmbd_vfs_kern_path_start_removing(work, link_name, LOOKUP_NO_SYMLINKS, 6569 &path, 0); 6570 if (rc) { 6571 if (rc != -ENOENT) 6572 goto out; 6573 } else { 6574 if (file_info->ReplaceIfExists) { 6575 rc = ksmbd_vfs_remove_file(work, &path); 6576 if (rc) { 6577 rc = -EINVAL; 6578 ksmbd_debug(SMB, "cannot delete %s\n", 6579 link_name); 6580 } 6581 } else { 6582 rc = -EEXIST; 6583 ksmbd_debug(SMB, "link already exists\n"); 6584 } 6585 ksmbd_vfs_kern_path_end_removing(&path); 6586 if (rc) 6587 goto out; 6588 } 6589 rc = ksmbd_vfs_link(work, target_name, link_name); 6590 if (rc) 6591 rc = -EINVAL; 6592 out: 6593 6594 if (!IS_ERR(link_name)) 6595 kfree(link_name); 6596 kfree(pathname); 6597 return rc; 6598 } 6599 6600 static int set_file_basic_info(struct ksmbd_file *fp, 6601 struct file_basic_info *file_info, 6602 struct ksmbd_share_config *share) 6603 { 6604 struct iattr attrs; 6605 struct file *filp; 6606 struct inode *inode; 6607 struct mnt_idmap *idmap; 6608 int rc = 0; 6609 6610 if (!(fp->daccess & FILE_WRITE_ATTRIBUTES_LE)) 6611 return -EACCES; 6612 6613 attrs.ia_valid = 0; 6614 filp = fp->filp; 6615 inode = file_inode(filp); 6616 idmap = file_mnt_idmap(filp); 6617 6618 if (file_info->CreationTime) 6619 fp->create_time = le64_to_cpu(file_info->CreationTime); 6620 6621 if (file_info->LastAccessTime) { 6622 attrs.ia_atime = ksmbd_NTtimeToUnix(file_info->LastAccessTime); 6623 attrs.ia_valid |= (ATTR_ATIME | ATTR_ATIME_SET); 6624 } 6625 6626 if (file_info->ChangeTime) { 6627 fp->change_time = le64_to_cpu(file_info->ChangeTime); 6628 inode_set_ctime_to_ts(inode, 6629 ksmbd_NTtimeToUnix(file_info->ChangeTime)); 6630 } 6631 6632 if (file_info->LastWriteTime) { 6633 attrs.ia_mtime = ksmbd_NTtimeToUnix(file_info->LastWriteTime); 6634 attrs.ia_valid |= (ATTR_MTIME | ATTR_MTIME_SET | ATTR_CTIME); 6635 } 6636 6637 if (file_info->Attributes) { 6638 if (!S_ISDIR(inode->i_mode) && 6639 file_info->Attributes & FILE_ATTRIBUTE_DIRECTORY_LE) { 6640 pr_err("can't change a file to a directory\n"); 6641 return -EINVAL; 6642 } 6643 6644 if (!(S_ISDIR(inode->i_mode) && file_info->Attributes == FILE_ATTRIBUTE_NORMAL_LE)) 6645 fp->f_ci->m_fattr = file_info->Attributes | 6646 (fp->f_ci->m_fattr & FILE_ATTRIBUTE_DIRECTORY_LE); 6647 } 6648 6649 if (test_share_config_flag(share, KSMBD_SHARE_FLAG_STORE_DOS_ATTRS) && 6650 (file_info->CreationTime || file_info->Attributes)) { 6651 struct xattr_dos_attrib da = {0}; 6652 6653 da.version = 4; 6654 da.itime = fp->itime; 6655 da.create_time = fp->create_time; 6656 da.attr = le32_to_cpu(fp->f_ci->m_fattr); 6657 da.flags = XATTR_DOSINFO_ATTRIB | XATTR_DOSINFO_CREATE_TIME | 6658 XATTR_DOSINFO_ITIME; 6659 6660 rc = ksmbd_vfs_set_dos_attrib_xattr(idmap, &filp->f_path, &da, 6661 true); 6662 if (rc) 6663 ksmbd_debug(SMB, 6664 "failed to restore file attribute in EA\n"); 6665 rc = 0; 6666 } 6667 6668 if (attrs.ia_valid) { 6669 struct dentry *dentry = filp->f_path.dentry; 6670 struct inode *inode = d_inode(dentry); 6671 6672 if (IS_IMMUTABLE(inode) || IS_APPEND(inode)) 6673 return -EACCES; 6674 6675 inode_lock(inode); 6676 rc = notify_change(idmap, dentry, &attrs, NULL); 6677 inode_unlock(inode); 6678 } 6679 return rc; 6680 } 6681 6682 static int set_file_allocation_info(struct ksmbd_work *work, 6683 struct ksmbd_file *fp, 6684 struct smb2_file_alloc_info *file_alloc_info) 6685 { 6686 /* 6687 * TODO : It's working fine only when store dos attributes 6688 * is not yes. need to implement a logic which works 6689 * properly with any smb.conf option 6690 */ 6691 6692 loff_t alloc_blks; 6693 struct inode *inode; 6694 struct kstat stat; 6695 int rc; 6696 6697 if (!(fp->daccess & FILE_WRITE_DATA_LE)) 6698 return -EACCES; 6699 6700 if (ksmbd_stream_fd(fp) == true) 6701 return 0; 6702 6703 rc = vfs_getattr(&fp->filp->f_path, &stat, STATX_BASIC_STATS, 6704 AT_STATX_SYNC_AS_STAT); 6705 if (rc) 6706 return rc; 6707 6708 alloc_blks = (le64_to_cpu(file_alloc_info->AllocationSize) + 511) >> 9; 6709 inode = file_inode(fp->filp); 6710 6711 if (alloc_blks > stat.blocks) { 6712 smb_break_all_levII_oplock(work, fp, 1); 6713 rc = vfs_fallocate(fp->filp, FALLOC_FL_KEEP_SIZE, 0, 6714 alloc_blks * 512); 6715 if (rc && rc != -EOPNOTSUPP) { 6716 pr_err("vfs_fallocate is failed : %d\n", rc); 6717 return rc; 6718 } 6719 } else if (alloc_blks < stat.blocks) { 6720 loff_t size; 6721 6722 /* 6723 * Allocation size could be smaller than original one 6724 * which means allocated blocks in file should be 6725 * deallocated. use truncate to cut out it, but inode 6726 * size is also updated with truncate offset. 6727 * inode size is retained by backup inode size. 6728 */ 6729 size = i_size_read(inode); 6730 rc = ksmbd_vfs_truncate(work, fp, alloc_blks * 512); 6731 if (rc) { 6732 pr_err("truncate failed!, err %d\n", rc); 6733 return rc; 6734 } 6735 if (size < alloc_blks * 512) 6736 i_size_write(inode, size); 6737 } 6738 6739 fp->allocation_size = le64_to_cpu(file_alloc_info->AllocationSize); 6740 return 0; 6741 } 6742 6743 static int set_end_of_file_info(struct ksmbd_work *work, struct ksmbd_file *fp, 6744 struct smb2_file_eof_info *file_eof_info) 6745 { 6746 loff_t newsize; 6747 struct inode *inode; 6748 int rc; 6749 6750 if (!(fp->daccess & FILE_WRITE_DATA_LE)) 6751 return -EACCES; 6752 6753 newsize = le64_to_cpu(file_eof_info->EndOfFile); 6754 inode = file_inode(fp->filp); 6755 6756 /* 6757 * If FILE_END_OF_FILE_INFORMATION of set_info_file is called 6758 * on FAT32 shared device, truncate execution time is too long 6759 * and network error could cause from windows client. because 6760 * truncate of some filesystem like FAT32 fill zero data in 6761 * truncated range. 6762 */ 6763 if (inode->i_sb->s_magic != MSDOS_SUPER_MAGIC && 6764 ksmbd_stream_fd(fp) == false) { 6765 ksmbd_debug(SMB, "truncated to newsize %lld\n", newsize); 6766 rc = ksmbd_vfs_truncate(work, fp, newsize); 6767 if (rc) { 6768 ksmbd_debug(SMB, "truncate failed!, err %d\n", rc); 6769 if (rc != -EAGAIN) 6770 rc = -EBADF; 6771 return rc; 6772 } 6773 } 6774 return 0; 6775 } 6776 6777 static int set_rename_info(struct ksmbd_work *work, struct ksmbd_file *fp, 6778 struct smb2_file_rename_info *rename_info, 6779 unsigned int buf_len) 6780 { 6781 if (!(fp->daccess & FILE_DELETE_LE)) { 6782 pr_err("no right to delete : 0x%x\n", fp->daccess); 6783 return -EACCES; 6784 } 6785 6786 if (buf_len < (u64)sizeof(struct smb2_file_rename_info) + 6787 le32_to_cpu(rename_info->FileNameLength)) 6788 return -EINVAL; 6789 6790 if (!le32_to_cpu(rename_info->FileNameLength)) 6791 return -EINVAL; 6792 6793 return smb2_rename(work, fp, rename_info, work->conn->local_nls); 6794 } 6795 6796 static int set_file_disposition_info(struct ksmbd_work *work, 6797 struct ksmbd_file *fp, 6798 struct smb2_file_disposition_info *file_info) 6799 { 6800 struct inode *inode; 6801 6802 if (!(fp->daccess & FILE_DELETE_LE)) { 6803 pr_err("no right to delete : 0x%x\n", fp->daccess); 6804 return -EACCES; 6805 } 6806 6807 inode = file_inode(fp->filp); 6808 if (file_info->DeletePending) { 6809 if (ksmbd_has_stream_without_delete_share(fp)) 6810 return -ESHARE; 6811 6812 if (S_ISDIR(inode->i_mode) && 6813 ksmbd_vfs_empty_dir(fp) == -ENOTEMPTY) 6814 return -EBUSY; 6815 smb_break_all_levII_oplock_for_delete(work, fp); 6816 ksmbd_set_inode_pending_delete(fp); 6817 } else { 6818 ksmbd_clear_inode_pending_delete(fp); 6819 } 6820 return 0; 6821 } 6822 6823 static int set_file_position_info(struct ksmbd_file *fp, 6824 struct smb2_file_pos_info *file_info) 6825 { 6826 loff_t current_byte_offset; 6827 unsigned long sector_size; 6828 struct inode *inode; 6829 6830 inode = file_inode(fp->filp); 6831 current_byte_offset = le64_to_cpu(file_info->CurrentByteOffset); 6832 sector_size = inode->i_sb->s_blocksize; 6833 6834 if (current_byte_offset < 0 || 6835 (fp->coption == FILE_NO_INTERMEDIATE_BUFFERING_LE && 6836 current_byte_offset & (sector_size - 1))) { 6837 pr_err("CurrentByteOffset is not valid : %llu\n", 6838 current_byte_offset); 6839 return -EINVAL; 6840 } 6841 6842 if (ksmbd_stream_fd(fp) == false) 6843 fp->filp->f_pos = current_byte_offset; 6844 else { 6845 if (current_byte_offset > XATTR_SIZE_MAX) 6846 current_byte_offset = XATTR_SIZE_MAX; 6847 fp->stream.pos = current_byte_offset; 6848 } 6849 return 0; 6850 } 6851 6852 static int set_file_mode_info(struct ksmbd_file *fp, 6853 struct smb2_file_mode_info *file_info) 6854 { 6855 __le32 mode; 6856 6857 mode = file_info->Mode; 6858 6859 if ((mode & ~FILE_MODE_INFO_MASK)) { 6860 pr_err("Mode is not valid : 0x%x\n", le32_to_cpu(mode)); 6861 return -EINVAL; 6862 } 6863 6864 /* 6865 * TODO : need to implement consideration for 6866 * FILE_SYNCHRONOUS_IO_ALERT and FILE_SYNCHRONOUS_IO_NONALERT 6867 */ 6868 ksmbd_vfs_set_fadvise(fp->filp, mode); 6869 fp->coption = mode; 6870 return 0; 6871 } 6872 6873 /** 6874 * smb2_set_info_file() - handler for smb2 set info command 6875 * @work: smb work containing set info command buffer 6876 * @fp: ksmbd_file pointer 6877 * @req: request buffer pointer 6878 * @share: ksmbd_share_config pointer 6879 * 6880 * Return: 0 on success, otherwise error 6881 */ 6882 static int smb2_set_info_file(struct ksmbd_work *work, struct ksmbd_file *fp, 6883 struct smb2_set_info_req *req, 6884 struct ksmbd_share_config *share) 6885 { 6886 unsigned int buf_len = le32_to_cpu(req->BufferLength); 6887 char *buffer = (char *)req + le16_to_cpu(req->BufferOffset); 6888 6889 switch (req->FileInfoClass) { 6890 case FILE_BASIC_INFORMATION: 6891 { 6892 if (buf_len < sizeof(struct file_basic_info)) 6893 return -EMSGSIZE; 6894 6895 return set_file_basic_info(fp, (struct file_basic_info *)buffer, share); 6896 } 6897 case FILE_ALLOCATION_INFORMATION: 6898 { 6899 if (buf_len < sizeof(struct smb2_file_alloc_info)) 6900 return -EMSGSIZE; 6901 6902 return set_file_allocation_info(work, fp, 6903 (struct smb2_file_alloc_info *)buffer); 6904 } 6905 case FILE_END_OF_FILE_INFORMATION: 6906 { 6907 if (buf_len < sizeof(struct smb2_file_eof_info)) 6908 return -EMSGSIZE; 6909 6910 return set_end_of_file_info(work, fp, 6911 (struct smb2_file_eof_info *)buffer); 6912 } 6913 case FILE_RENAME_INFORMATION: 6914 { 6915 if (buf_len < sizeof(struct smb2_file_rename_info)) 6916 return -EMSGSIZE; 6917 6918 return set_rename_info(work, fp, 6919 (struct smb2_file_rename_info *)buffer, 6920 buf_len); 6921 } 6922 case FILE_LINK_INFORMATION: 6923 { 6924 struct smb2_file_link_info *file_info; 6925 6926 if (buf_len < sizeof(struct smb2_file_link_info)) 6927 return -EMSGSIZE; 6928 6929 file_info = (struct smb2_file_link_info *)buffer; 6930 if (file_info->ReplaceIfExists && !(fp->daccess & FILE_DELETE_LE)) { 6931 pr_err("no right to delete : 0x%x\n", fp->daccess); 6932 return -EACCES; 6933 } 6934 6935 return smb2_create_link(work, work->tcon->share_conf, file_info, 6936 buf_len, fp->filp, 6937 work->conn->local_nls); 6938 } 6939 case FILE_DISPOSITION_INFORMATION: 6940 { 6941 if (buf_len < sizeof(struct smb2_file_disposition_info)) 6942 return -EMSGSIZE; 6943 6944 return set_file_disposition_info(work, fp, 6945 (struct smb2_file_disposition_info *)buffer); 6946 } 6947 case FILE_FULL_EA_INFORMATION: 6948 { 6949 if (!(fp->daccess & FILE_WRITE_EA_LE)) { 6950 pr_err("Not permitted to write ext attr: 0x%x\n", 6951 fp->daccess); 6952 return -EACCES; 6953 } 6954 6955 if (buf_len < sizeof(struct smb2_ea_info)) 6956 return -EMSGSIZE; 6957 6958 return smb2_set_ea((struct smb2_ea_info *)buffer, 6959 buf_len, &fp->filp->f_path, true); 6960 } 6961 case FILE_POSITION_INFORMATION: 6962 { 6963 if (buf_len < sizeof(struct smb2_file_pos_info)) 6964 return -EMSGSIZE; 6965 6966 return set_file_position_info(fp, (struct smb2_file_pos_info *)buffer); 6967 } 6968 case FILE_MODE_INFORMATION: 6969 { 6970 if (buf_len < sizeof(struct smb2_file_mode_info)) 6971 return -EMSGSIZE; 6972 6973 return set_file_mode_info(fp, (struct smb2_file_mode_info *)buffer); 6974 } 6975 } 6976 6977 pr_err("Unimplemented Fileinfoclass :%d\n", req->FileInfoClass); 6978 return -EOPNOTSUPP; 6979 } 6980 6981 static int smb2_set_info_sec(struct ksmbd_file *fp, int addition_info, 6982 char *buffer, int buf_len) 6983 { 6984 struct smb_ntsd *pntsd = (struct smb_ntsd *)buffer; 6985 6986 fp->saccess |= FILE_SHARE_DELETE_LE; 6987 6988 if (!(fp->daccess & (FILE_WRITE_DAC_LE | FILE_WRITE_OWNER_LE))) 6989 return -EACCES; 6990 6991 return set_info_sec(fp->conn, fp->tcon, &fp->filp->f_path, pntsd, 6992 buf_len, false, true); 6993 } 6994 6995 /** 6996 * smb2_set_info() - handler for smb2 set info command handler 6997 * @work: smb work containing set info request buffer 6998 * 6999 * Return: 0 on success, otherwise error 7000 */ 7001 int smb2_set_info(struct ksmbd_work *work) 7002 { 7003 const struct cred *saved_cred; 7004 struct smb2_set_info_req *req; 7005 struct smb2_set_info_rsp *rsp; 7006 struct ksmbd_file *fp = NULL; 7007 int rc = 0; 7008 unsigned int id = KSMBD_NO_FID, pid = KSMBD_NO_FID; 7009 7010 ksmbd_debug(SMB, "Received smb2 set info request\n"); 7011 7012 if (work->next_smb2_rcv_hdr_off) { 7013 req = ksmbd_req_buf_next(work); 7014 rsp = ksmbd_resp_buf_next(work); 7015 if (smb2_compound_has_failed(work, &rsp->hdr)) 7016 return -EACCES; 7017 if (!has_file_id(req->VolatileFileId)) { 7018 ksmbd_debug(SMB, "Compound request set FID = %llu\n", 7019 work->compound_fid); 7020 id = work->compound_fid; 7021 pid = work->compound_pfid; 7022 } 7023 } else { 7024 req = smb_get_msg(work->request_buf); 7025 rsp = smb_get_msg(work->response_buf); 7026 } 7027 7028 if (!test_tree_conn_flag(work->tcon, KSMBD_TREE_CONN_FLAG_WRITABLE)) { 7029 ksmbd_debug(SMB, "User does not have write permission\n"); 7030 pr_err("User does not have write permission\n"); 7031 rc = -EACCES; 7032 goto err_out; 7033 } 7034 7035 if (!has_file_id(id)) { 7036 id = req->VolatileFileId; 7037 pid = req->PersistentFileId; 7038 } 7039 7040 fp = ksmbd_lookup_fd_slow(work, id, pid); 7041 if (!fp) { 7042 ksmbd_debug(SMB, "Invalid id for close: %u\n", id); 7043 rc = -ENOENT; 7044 goto err_out; 7045 } 7046 7047 saved_cred = override_creds(fp->filp->f_cred); 7048 switch (req->InfoType) { 7049 case SMB2_O_INFO_FILE: 7050 ksmbd_debug(SMB, "GOT SMB2_O_INFO_FILE\n"); 7051 rc = smb2_set_info_file(work, fp, req, work->tcon->share_conf); 7052 break; 7053 case SMB2_O_INFO_SECURITY: 7054 ksmbd_debug(SMB, "GOT SMB2_O_INFO_SECURITY\n"); 7055 rc = smb2_set_info_sec(fp, 7056 le32_to_cpu(req->AdditionalInformation), 7057 (char *)req + le16_to_cpu(req->BufferOffset), 7058 le32_to_cpu(req->BufferLength)); 7059 break; 7060 default: 7061 rc = -EOPNOTSUPP; 7062 } 7063 revert_creds(saved_cred); 7064 7065 if (rc < 0) 7066 goto err_out; 7067 7068 rsp->StructureSize = cpu_to_le16(2); 7069 rc = ksmbd_iov_pin_rsp(work, (void *)rsp, 7070 sizeof(struct smb2_set_info_rsp)); 7071 if (rc) 7072 goto err_out; 7073 ksmbd_fd_put(work, fp); 7074 return 0; 7075 7076 err_out: 7077 if (rc == -EACCES || rc == -EPERM || rc == -EXDEV) 7078 rsp->hdr.Status = STATUS_ACCESS_DENIED; 7079 else if (rc == -EINVAL) 7080 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 7081 else if (rc == -EMSGSIZE) 7082 rsp->hdr.Status = STATUS_INFO_LENGTH_MISMATCH; 7083 else if (rc == -ESHARE) 7084 rsp->hdr.Status = STATUS_SHARING_VIOLATION; 7085 else if (rc == -ENOENT) 7086 rsp->hdr.Status = STATUS_OBJECT_NAME_INVALID; 7087 else if (rc == -EBUSY || rc == -ENOTEMPTY) 7088 rsp->hdr.Status = STATUS_DIRECTORY_NOT_EMPTY; 7089 else if (rc == -EAGAIN) 7090 rsp->hdr.Status = STATUS_FILE_LOCK_CONFLICT; 7091 else if (rc == -EBADF || rc == -ESTALE) 7092 rsp->hdr.Status = STATUS_INVALID_HANDLE; 7093 else if (rc == -EEXIST) 7094 rsp->hdr.Status = STATUS_OBJECT_NAME_COLLISION; 7095 else if (rsp->hdr.Status == 0 || rc == -EOPNOTSUPP) 7096 rsp->hdr.Status = STATUS_INVALID_INFO_CLASS; 7097 smb2_set_err_rsp(work); 7098 ksmbd_fd_put(work, fp); 7099 ksmbd_debug(SMB, "error while processing smb2 query rc = %d\n", rc); 7100 return rc; 7101 } 7102 7103 /** 7104 * smb2_read_pipe() - handler for smb2 read from IPC pipe 7105 * @work: smb work containing read IPC pipe command buffer 7106 * 7107 * Return: 0 on success, otherwise error 7108 */ 7109 static noinline int smb2_read_pipe(struct ksmbd_work *work) 7110 { 7111 int nbytes = 0, err; 7112 u64 id; 7113 struct ksmbd_rpc_command *rpc_resp; 7114 struct smb2_read_req *req; 7115 struct smb2_read_rsp *rsp; 7116 7117 WORK_BUFFERS(work, req, rsp); 7118 7119 id = req->VolatileFileId; 7120 7121 rpc_resp = ksmbd_rpc_read(work->sess, id); 7122 if (rpc_resp) { 7123 void *aux_payload_buf; 7124 7125 if (rpc_resp->flags != KSMBD_RPC_OK) { 7126 err = -EINVAL; 7127 goto out; 7128 } 7129 7130 aux_payload_buf = 7131 kvmalloc(rpc_resp->payload_sz, KSMBD_DEFAULT_GFP); 7132 if (!aux_payload_buf) { 7133 err = -ENOMEM; 7134 goto out; 7135 } 7136 7137 memcpy(aux_payload_buf, rpc_resp->payload, rpc_resp->payload_sz); 7138 7139 nbytes = rpc_resp->payload_sz; 7140 err = ksmbd_iov_pin_rsp_read(work, (void *)rsp, 7141 offsetof(struct smb2_read_rsp, Buffer), 7142 aux_payload_buf, nbytes); 7143 if (err) { 7144 kvfree(aux_payload_buf); 7145 goto out; 7146 } 7147 kvfree(rpc_resp); 7148 } else { 7149 err = ksmbd_iov_pin_rsp(work, (void *)rsp, 7150 offsetof(struct smb2_read_rsp, Buffer)); 7151 if (err) 7152 goto out; 7153 } 7154 7155 rsp->StructureSize = cpu_to_le16(17); 7156 rsp->DataOffset = 80; 7157 rsp->Reserved = 0; 7158 rsp->DataLength = cpu_to_le32(nbytes); 7159 rsp->DataRemaining = 0; 7160 rsp->Flags = 0; 7161 return 0; 7162 7163 out: 7164 rsp->hdr.Status = STATUS_UNEXPECTED_IO_ERROR; 7165 smb2_set_err_rsp(work); 7166 kvfree(rpc_resp); 7167 return err; 7168 } 7169 7170 static int smb2_set_remote_key_for_rdma(struct ksmbd_work *work, 7171 struct smbdirect_buffer_descriptor_v1 *desc, 7172 __le32 Channel, 7173 __le16 ChannelInfoLength) 7174 { 7175 unsigned int i, ch_count; 7176 7177 if (work->conn->dialect == SMB30_PROT_ID && 7178 Channel != SMB2_CHANNEL_RDMA_V1) 7179 return -EINVAL; 7180 7181 ch_count = le16_to_cpu(ChannelInfoLength) / sizeof(*desc); 7182 if (ksmbd_debug_types & KSMBD_DEBUG_RDMA) { 7183 for (i = 0; i < ch_count; i++) { 7184 pr_info("RDMA r/w request %#x: token %#x, length %#x\n", 7185 i, 7186 le32_to_cpu(desc[i].token), 7187 le32_to_cpu(desc[i].length)); 7188 } 7189 } 7190 if (!ch_count) 7191 return -EINVAL; 7192 7193 work->need_invalidate_rkey = 7194 (Channel == SMB2_CHANNEL_RDMA_V1_INVALIDATE); 7195 if (Channel == SMB2_CHANNEL_RDMA_V1_INVALIDATE) 7196 work->remote_key = le32_to_cpu(desc->token); 7197 return 0; 7198 } 7199 7200 static ssize_t smb2_read_rdma_channel(struct ksmbd_work *work, 7201 struct smb2_read_req *req, void *data_buf, 7202 size_t length) 7203 { 7204 int err; 7205 7206 err = ksmbd_conn_rdma_write(work->conn, data_buf, length, 7207 (struct smbdirect_buffer_descriptor_v1 *) 7208 ((char *)req + le16_to_cpu(req->ReadChannelInfoOffset)), 7209 le16_to_cpu(req->ReadChannelInfoLength)); 7210 if (err) 7211 return err; 7212 7213 return length; 7214 } 7215 7216 /** 7217 * smb2_read() - handler for smb2 read from file 7218 * @work: smb work containing read command buffer 7219 * 7220 * Return: 0 on success, otherwise error 7221 */ 7222 int smb2_read(struct ksmbd_work *work) 7223 { 7224 struct ksmbd_conn *conn = work->conn; 7225 struct smb2_read_req *req; 7226 struct smb2_read_rsp *rsp; 7227 struct ksmbd_file *fp = NULL; 7228 loff_t offset; 7229 size_t length, mincount; 7230 ssize_t nbytes = 0, remain_bytes = 0; 7231 int err = 0; 7232 bool is_rdma_channel = false, async_interim = false; 7233 unsigned int max_read_size = conn->vals->max_read_size; 7234 unsigned int id = KSMBD_NO_FID, pid = KSMBD_NO_FID; 7235 void *aux_payload_buf; 7236 7237 ksmbd_debug(SMB, "Received smb2 read request\n"); 7238 7239 if (test_share_config_flag(work->tcon->share_conf, 7240 KSMBD_SHARE_FLAG_PIPE)) { 7241 ksmbd_debug(SMB, "IPC pipe read request\n"); 7242 return smb2_read_pipe(work); 7243 } 7244 7245 if (work->next_smb2_rcv_hdr_off) { 7246 req = ksmbd_req_buf_next(work); 7247 rsp = ksmbd_resp_buf_next(work); 7248 if (smb2_compound_has_failed(work, &rsp->hdr)) 7249 return -EACCES; 7250 if (!has_file_id(req->VolatileFileId)) { 7251 ksmbd_debug(SMB, "Compound request set FID = %llu\n", 7252 work->compound_fid); 7253 id = work->compound_fid; 7254 pid = work->compound_pfid; 7255 } 7256 } else { 7257 req = smb_get_msg(work->request_buf); 7258 rsp = smb_get_msg(work->response_buf); 7259 } 7260 7261 if (!has_file_id(id)) { 7262 id = req->VolatileFileId; 7263 pid = req->PersistentFileId; 7264 } 7265 7266 if (req->Channel == SMB2_CHANNEL_RDMA_V1_INVALIDATE || 7267 req->Channel == SMB2_CHANNEL_RDMA_V1) { 7268 is_rdma_channel = true; 7269 max_read_size = get_smbd_max_read_write_size(work->conn->transport); 7270 if (max_read_size == 0) { 7271 err = -EINVAL; 7272 goto out; 7273 } 7274 } 7275 7276 if (is_rdma_channel == true) { 7277 unsigned int ch_offset = le16_to_cpu(req->ReadChannelInfoOffset); 7278 7279 if (ch_offset < offsetof(struct smb2_read_req, Buffer)) { 7280 err = -EINVAL; 7281 goto out; 7282 } 7283 err = smb2_set_remote_key_for_rdma(work, 7284 (struct smbdirect_buffer_descriptor_v1 *) 7285 ((char *)req + ch_offset), 7286 req->Channel, 7287 req->ReadChannelInfoLength); 7288 if (err) 7289 goto out; 7290 } 7291 7292 fp = ksmbd_lookup_fd_slow(work, id, pid); 7293 if (!fp) { 7294 err = -ENOENT; 7295 goto out; 7296 } 7297 7298 if (!(fp->daccess & (FILE_READ_DATA_LE | FILE_READ_ATTRIBUTES_LE))) { 7299 pr_err("Not permitted to read : 0x%x\n", fp->daccess); 7300 err = -EACCES; 7301 goto out; 7302 } 7303 7304 if (work->next_smb2_rcv_hdr_off && !req->hdr.NextCommand) { 7305 err = setup_async_work(work, NULL, NULL); 7306 if (err) 7307 goto out; 7308 smb2_send_interim_resp(work, STATUS_PENDING); 7309 async_interim = true; 7310 } 7311 7312 offset = le64_to_cpu(req->Offset); 7313 if (offset < 0) { 7314 err = -EINVAL; 7315 goto out; 7316 } 7317 length = le32_to_cpu(req->Length); 7318 mincount = le32_to_cpu(req->MinimumCount); 7319 7320 if (length > max_read_size) { 7321 ksmbd_debug(SMB, "limiting read size to max size(%u)\n", 7322 max_read_size); 7323 err = -EINVAL; 7324 goto out; 7325 } 7326 7327 ksmbd_debug(SMB, "filename %pD, offset %lld, len %zu\n", 7328 fp->filp, offset, length); 7329 7330 aux_payload_buf = kvmalloc(ALIGN(length, 8), KSMBD_DEFAULT_GFP); 7331 if (!aux_payload_buf) { 7332 err = -ENOMEM; 7333 goto out; 7334 } 7335 7336 nbytes = ksmbd_vfs_read(work, fp, length, &offset, aux_payload_buf); 7337 if (nbytes < 0) { 7338 kvfree(aux_payload_buf); 7339 err = nbytes; 7340 goto out; 7341 } 7342 7343 if ((nbytes == 0 && length != 0) || nbytes < mincount) { 7344 kvfree(aux_payload_buf); 7345 rsp->hdr.Status = STATUS_END_OF_FILE; 7346 smb2_set_err_rsp(work); 7347 if (async_interim) 7348 release_async_work(work); 7349 ksmbd_fd_put(work, fp); 7350 return -ENODATA; 7351 } 7352 7353 ksmbd_debug(SMB, "nbytes %zu, offset %lld mincount %zu\n", 7354 nbytes, offset, mincount); 7355 7356 if (is_rdma_channel == true) { 7357 /* write data to the client using rdma channel */ 7358 remain_bytes = smb2_read_rdma_channel(work, req, 7359 aux_payload_buf, 7360 nbytes); 7361 kvfree(aux_payload_buf); 7362 aux_payload_buf = NULL; 7363 nbytes = 0; 7364 if (remain_bytes < 0) { 7365 err = (int)remain_bytes; 7366 goto out; 7367 } 7368 } 7369 7370 rsp->StructureSize = cpu_to_le16(17); 7371 rsp->DataOffset = 80; 7372 rsp->Reserved = 0; 7373 rsp->DataLength = cpu_to_le32(nbytes); 7374 rsp->DataRemaining = cpu_to_le32(remain_bytes); 7375 rsp->Flags = 0; 7376 err = ksmbd_iov_pin_rsp_read(work, (void *)rsp, 7377 offsetof(struct smb2_read_rsp, Buffer), 7378 aux_payload_buf, nbytes); 7379 if (err) { 7380 kvfree(aux_payload_buf); 7381 goto out; 7382 } 7383 if (async_interim) 7384 release_async_work(work); 7385 /* 7386 * RDMA responses are transferred through channel buffers and encrypted 7387 * responses use the encryption transform, so only normal SMB transport 7388 * responses are candidates for compression. 7389 */ 7390 if (!is_rdma_channel && nbytes && 7391 (req->Flags & SMB2_READFLAG_REQUEST_COMPRESSED) && 7392 conn->compress_algorithm != SMB3_COMPRESS_NONE) 7393 work->compress_response = true; 7394 ksmbd_fd_put(work, fp); 7395 return 0; 7396 7397 out: 7398 if (async_interim) 7399 release_async_work(work); 7400 if (err) { 7401 if (err == -EISDIR) 7402 rsp->hdr.Status = STATUS_INVALID_DEVICE_REQUEST; 7403 else if (err == -EAGAIN) 7404 rsp->hdr.Status = STATUS_FILE_LOCK_CONFLICT; 7405 else if (err == -ENOENT) 7406 rsp->hdr.Status = STATUS_FILE_CLOSED; 7407 else if (err == -EACCES) 7408 rsp->hdr.Status = STATUS_ACCESS_DENIED; 7409 else if (err == -ESHARE) 7410 rsp->hdr.Status = STATUS_SHARING_VIOLATION; 7411 else if (err == -EINVAL) 7412 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 7413 else 7414 rsp->hdr.Status = STATUS_INVALID_HANDLE; 7415 7416 smb2_set_err_rsp(work); 7417 } 7418 ksmbd_fd_put(work, fp); 7419 return err; 7420 } 7421 7422 /** 7423 * smb2_write_pipe() - handler for smb2 write on IPC pipe 7424 * @work: smb work containing write IPC pipe command buffer 7425 * 7426 * Return: 0 on success, otherwise error 7427 */ 7428 static noinline int smb2_write_pipe(struct ksmbd_work *work) 7429 { 7430 struct smb2_write_req *req; 7431 struct smb2_write_rsp *rsp; 7432 struct ksmbd_rpc_command *rpc_resp; 7433 u64 id = 0; 7434 int err = 0, ret = 0; 7435 char *data_buf; 7436 size_t length; 7437 7438 WORK_BUFFERS(work, req, rsp); 7439 7440 length = le32_to_cpu(req->Length); 7441 id = req->VolatileFileId; 7442 7443 if ((u64)le16_to_cpu(req->DataOffset) + length > 7444 get_rfc1002_len(work->request_buf)) { 7445 pr_err("invalid write data offset %u, smb_len %u\n", 7446 le16_to_cpu(req->DataOffset), 7447 get_rfc1002_len(work->request_buf)); 7448 err = -EINVAL; 7449 goto out; 7450 } 7451 7452 data_buf = (char *)(((char *)&req->hdr.ProtocolId) + 7453 le16_to_cpu(req->DataOffset)); 7454 7455 rpc_resp = ksmbd_rpc_write(work->sess, id, data_buf, length); 7456 if (rpc_resp) { 7457 if (rpc_resp->flags == KSMBD_RPC_ENOTIMPLEMENTED) { 7458 rsp->hdr.Status = STATUS_NOT_SUPPORTED; 7459 kvfree(rpc_resp); 7460 smb2_set_err_rsp(work); 7461 return -EOPNOTSUPP; 7462 } 7463 if (rpc_resp->flags != KSMBD_RPC_OK) { 7464 rsp->hdr.Status = STATUS_INVALID_HANDLE; 7465 smb2_set_err_rsp(work); 7466 kvfree(rpc_resp); 7467 return ret; 7468 } 7469 kvfree(rpc_resp); 7470 } 7471 7472 rsp->StructureSize = cpu_to_le16(17); 7473 rsp->DataOffset = 0; 7474 rsp->Reserved = 0; 7475 rsp->DataLength = cpu_to_le32(length); 7476 rsp->DataRemaining = 0; 7477 rsp->Reserved2 = 0; 7478 err = ksmbd_iov_pin_rsp(work, (void *)rsp, 7479 offsetof(struct smb2_write_rsp, Buffer)); 7480 out: 7481 if (err) { 7482 rsp->hdr.Status = STATUS_INVALID_HANDLE; 7483 smb2_set_err_rsp(work); 7484 } 7485 7486 return err; 7487 } 7488 7489 static ssize_t smb2_write_rdma_channel(struct ksmbd_work *work, 7490 struct smb2_write_req *req, 7491 struct ksmbd_file *fp, 7492 loff_t offset, size_t length, bool sync) 7493 { 7494 char *data_buf; 7495 int ret; 7496 ssize_t nbytes; 7497 7498 data_buf = kvzalloc(length, KSMBD_DEFAULT_GFP); 7499 if (!data_buf) 7500 return -ENOMEM; 7501 7502 ret = ksmbd_conn_rdma_read(work->conn, data_buf, length, 7503 (struct smbdirect_buffer_descriptor_v1 *) 7504 ((char *)req + le16_to_cpu(req->WriteChannelInfoOffset)), 7505 le16_to_cpu(req->WriteChannelInfoLength)); 7506 if (ret < 0) { 7507 kvfree(data_buf); 7508 return ret; 7509 } 7510 7511 ret = ksmbd_vfs_write(work, fp, data_buf, length, &offset, sync, &nbytes); 7512 kvfree(data_buf); 7513 if (ret < 0) 7514 return ret; 7515 7516 return nbytes; 7517 } 7518 7519 /** 7520 * smb2_write() - handler for smb2 write from file 7521 * @work: smb work containing write command buffer 7522 * 7523 * Return: 0 on success, otherwise error 7524 */ 7525 int smb2_write(struct ksmbd_work *work) 7526 { 7527 struct smb2_write_req *req; 7528 struct smb2_write_rsp *rsp; 7529 struct ksmbd_file *fp = NULL; 7530 loff_t offset; 7531 size_t length; 7532 ssize_t nbytes; 7533 char *data_buf; 7534 bool writethrough = false, is_rdma_channel = false; 7535 bool async_interim = false; 7536 int err = 0; 7537 unsigned int max_write_size = work->conn->vals->max_write_size; 7538 unsigned int id = KSMBD_NO_FID, pid = KSMBD_NO_FID; 7539 7540 ksmbd_debug(SMB, "Received smb2 write request\n"); 7541 7542 WORK_BUFFERS(work, req, rsp); 7543 7544 if (smb2_compound_has_failed(work, &rsp->hdr)) 7545 return -EACCES; 7546 7547 if (work->next_smb2_rcv_hdr_off && 7548 !has_file_id(req->VolatileFileId)) { 7549 ksmbd_debug(SMB, "Compound request set FID = %llu\n", 7550 work->compound_fid); 7551 id = work->compound_fid; 7552 pid = work->compound_pfid; 7553 } 7554 7555 if (!has_file_id(id)) { 7556 id = req->VolatileFileId; 7557 pid = req->PersistentFileId; 7558 } 7559 7560 if (test_share_config_flag(work->tcon->share_conf, KSMBD_SHARE_FLAG_PIPE)) { 7561 ksmbd_debug(SMB, "IPC pipe write request\n"); 7562 return smb2_write_pipe(work); 7563 } 7564 7565 offset = le64_to_cpu(req->Offset); 7566 if (offset < 0) 7567 return -EINVAL; 7568 length = le32_to_cpu(req->Length); 7569 7570 if (req->Channel == SMB2_CHANNEL_RDMA_V1 || 7571 req->Channel == SMB2_CHANNEL_RDMA_V1_INVALIDATE) { 7572 is_rdma_channel = true; 7573 max_write_size = get_smbd_max_read_write_size(work->conn->transport); 7574 if (max_write_size == 0) { 7575 err = -EINVAL; 7576 goto out; 7577 } 7578 length = le32_to_cpu(req->RemainingBytes); 7579 } 7580 7581 if (is_rdma_channel == true) { 7582 unsigned int ch_offset = le16_to_cpu(req->WriteChannelInfoOffset); 7583 7584 if (req->Length != 0 || req->DataOffset != 0 || 7585 ch_offset < offsetof(struct smb2_write_req, Buffer)) { 7586 err = -EINVAL; 7587 goto out; 7588 } 7589 err = smb2_set_remote_key_for_rdma(work, 7590 (struct smbdirect_buffer_descriptor_v1 *) 7591 ((char *)req + ch_offset), 7592 req->Channel, 7593 req->WriteChannelInfoLength); 7594 if (err) 7595 goto out; 7596 } 7597 7598 if (!test_tree_conn_flag(work->tcon, KSMBD_TREE_CONN_FLAG_WRITABLE)) { 7599 ksmbd_debug(SMB, "User does not have write permission\n"); 7600 err = -EACCES; 7601 goto out; 7602 } 7603 7604 fp = ksmbd_lookup_fd_slow(work, id, pid); 7605 if (!fp) { 7606 err = -ENOENT; 7607 goto out; 7608 } 7609 7610 if (!(fp->daccess & (FILE_WRITE_DATA_LE | FILE_READ_ATTRIBUTES_LE))) { 7611 pr_err("Not permitted to write : 0x%x\n", fp->daccess); 7612 err = -EACCES; 7613 goto out; 7614 } 7615 7616 if (work->next_smb2_rcv_hdr_off && !req->hdr.NextCommand) { 7617 err = setup_async_work(work, NULL, NULL); 7618 if (err) 7619 goto out; 7620 smb2_send_interim_resp(work, STATUS_PENDING); 7621 async_interim = true; 7622 } 7623 7624 if (length > max_write_size) { 7625 ksmbd_debug(SMB, "limiting write size to max size(%u)\n", 7626 max_write_size); 7627 err = -EINVAL; 7628 goto out; 7629 } 7630 7631 ksmbd_debug(SMB, "flags %u\n", le32_to_cpu(req->Flags)); 7632 if (le32_to_cpu(req->Flags) & SMB2_WRITEFLAG_WRITE_THROUGH) 7633 writethrough = true; 7634 7635 if (is_rdma_channel == false) { 7636 if (le16_to_cpu(req->DataOffset) < 7637 offsetof(struct smb2_write_req, Buffer)) { 7638 err = -EINVAL; 7639 goto out; 7640 } 7641 7642 data_buf = (char *)(((char *)&req->hdr.ProtocolId) + 7643 le16_to_cpu(req->DataOffset)); 7644 7645 ksmbd_debug(SMB, "filename %pD, offset %lld, len %zu\n", 7646 fp->filp, offset, length); 7647 err = ksmbd_vfs_write(work, fp, data_buf, length, &offset, 7648 writethrough, &nbytes); 7649 if (err < 0) 7650 goto out; 7651 } else { 7652 /* read data from the client using rdma channel, and 7653 * write the data. 7654 */ 7655 nbytes = smb2_write_rdma_channel(work, req, fp, offset, length, 7656 writethrough); 7657 if (nbytes < 0) { 7658 err = (int)nbytes; 7659 goto out; 7660 } 7661 } 7662 7663 rsp->StructureSize = cpu_to_le16(17); 7664 rsp->DataOffset = 0; 7665 rsp->Reserved = 0; 7666 rsp->DataLength = cpu_to_le32(nbytes); 7667 rsp->DataRemaining = 0; 7668 rsp->Reserved2 = 0; 7669 err = ksmbd_iov_pin_rsp(work, rsp, offsetof(struct smb2_write_rsp, Buffer)); 7670 if (err) 7671 goto out; 7672 if (async_interim) 7673 release_async_work(work); 7674 ksmbd_fd_put(work, fp); 7675 return 0; 7676 7677 out: 7678 if (async_interim) 7679 release_async_work(work); 7680 7681 if (err == -EAGAIN) 7682 rsp->hdr.Status = STATUS_FILE_LOCK_CONFLICT; 7683 else if (err == -ENOSPC || err == -EFBIG) 7684 rsp->hdr.Status = STATUS_DISK_FULL; 7685 else if (err == -ENOENT) 7686 rsp->hdr.Status = STATUS_FILE_CLOSED; 7687 else if (err == -EACCES) 7688 rsp->hdr.Status = STATUS_ACCESS_DENIED; 7689 else if (err == -ESHARE) 7690 rsp->hdr.Status = STATUS_SHARING_VIOLATION; 7691 else if (err == -EINVAL) 7692 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 7693 else 7694 rsp->hdr.Status = STATUS_INVALID_HANDLE; 7695 7696 smb2_set_err_rsp(work); 7697 ksmbd_fd_put(work, fp); 7698 return err; 7699 } 7700 7701 /** 7702 * smb2_flush() - handler for smb2 flush file - fsync 7703 * @work: smb work containing flush command buffer 7704 * 7705 * Return: 0 on success, otherwise error 7706 */ 7707 int smb2_flush(struct ksmbd_work *work) 7708 { 7709 struct smb2_flush_req *req; 7710 struct smb2_flush_rsp *rsp; 7711 u64 id = KSMBD_NO_FID, pid = KSMBD_NO_FID; 7712 int err; 7713 7714 WORK_BUFFERS(work, req, rsp); 7715 7716 ksmbd_debug(SMB, "Received smb2 flush request(fid : %llu)\n", req->VolatileFileId); 7717 7718 if (smb2_compound_has_failed(work, &rsp->hdr)) 7719 return -EACCES; 7720 7721 if (work->next_smb2_rcv_hdr_off && 7722 !has_file_id(req->VolatileFileId)) { 7723 ksmbd_debug(SMB, "Compound request set FID = %llu\n", 7724 work->compound_fid); 7725 id = work->compound_fid; 7726 pid = work->compound_pfid; 7727 } 7728 7729 if (!has_file_id(id)) { 7730 id = req->VolatileFileId; 7731 pid = req->PersistentFileId; 7732 } 7733 7734 err = ksmbd_vfs_fsync(work, id, pid); 7735 if (err) 7736 goto out; 7737 7738 rsp->StructureSize = cpu_to_le16(4); 7739 rsp->Reserved = 0; 7740 return ksmbd_iov_pin_rsp(work, rsp, sizeof(struct smb2_flush_rsp)); 7741 7742 out: 7743 rsp->hdr.Status = STATUS_INVALID_HANDLE; 7744 smb2_set_err_rsp(work); 7745 return err; 7746 } 7747 7748 /** 7749 * smb2_cancel() - handler for smb2 cancel command 7750 * @work: smb work containing cancel command buffer 7751 * 7752 * Return: 0 on success, otherwise error 7753 */ 7754 int smb2_cancel(struct ksmbd_work *work) 7755 { 7756 struct ksmbd_conn *conn = work->conn; 7757 struct smb2_hdr *hdr = smb_get_msg(work->request_buf); 7758 struct smb2_hdr *chdr; 7759 struct ksmbd_work *iter; 7760 struct list_head *command_list; 7761 7762 if (work->next_smb2_rcv_hdr_off) 7763 hdr = ksmbd_resp_buf_next(work); 7764 7765 ksmbd_debug(SMB, "smb2 cancel called on mid %llu, async flags 0x%x\n", 7766 le64_to_cpu(hdr->MessageId), 7767 le32_to_cpu(hdr->Flags)); 7768 7769 if (hdr->Flags & SMB2_FLAGS_ASYNC_COMMAND) { 7770 command_list = &conn->async_requests; 7771 7772 spin_lock(&conn->request_lock); 7773 list_for_each_entry(iter, command_list, 7774 async_request_entry) { 7775 chdr = smb_get_msg(iter->request_buf); 7776 7777 if (iter->async_id != 7778 le64_to_cpu(hdr->Id.AsyncId)) 7779 continue; 7780 7781 /* 7782 * Only an ACTIVE deferred work may have its cancel_fn 7783 * fired. A CANCELLED or CLOSED work already took the 7784 * smb2_lock() non-ACTIVE early-exit that frees the 7785 * file_lock and skips release_async_work(), so it is 7786 * still on conn->async_requests with a live cancel_fn 7787 * pointing at the freed file_lock. 7788 */ 7789 if (iter->state != KSMBD_WORK_ACTIVE) 7790 break; 7791 7792 ksmbd_debug(SMB, 7793 "smb2 with AsyncId %llu cancelled command = 0x%x\n", 7794 le64_to_cpu(hdr->Id.AsyncId), 7795 le16_to_cpu(chdr->Command)); 7796 iter->state = KSMBD_WORK_CANCELLED; 7797 if (iter->cancel_fn) 7798 iter->cancel_fn(iter->cancel_argv); 7799 break; 7800 } 7801 spin_unlock(&conn->request_lock); 7802 } else { 7803 command_list = &conn->requests; 7804 7805 spin_lock(&conn->request_lock); 7806 list_for_each_entry(iter, command_list, request_entry) { 7807 chdr = smb_get_msg(iter->request_buf); 7808 7809 if (chdr->MessageId != hdr->MessageId || 7810 iter == work) 7811 continue; 7812 7813 ksmbd_debug(SMB, 7814 "smb2 with mid %llu cancelled command = 0x%x\n", 7815 le64_to_cpu(hdr->MessageId), 7816 le16_to_cpu(chdr->Command)); 7817 iter->state = KSMBD_WORK_CANCELLED; 7818 break; 7819 } 7820 spin_unlock(&conn->request_lock); 7821 } 7822 7823 /* For SMB2_CANCEL command itself send no response*/ 7824 work->send_no_response = 1; 7825 return 0; 7826 } 7827 7828 struct file_lock *smb_flock_init(struct file *f) 7829 { 7830 struct file_lock *fl; 7831 7832 fl = locks_alloc_lock(); 7833 if (!fl) 7834 goto out; 7835 7836 locks_init_lock(fl); 7837 7838 fl->c.flc_owner = f; 7839 fl->c.flc_pid = current->tgid; 7840 fl->c.flc_file = f; 7841 fl->c.flc_flags = FL_POSIX; 7842 fl->fl_ops = NULL; 7843 fl->fl_lmops = NULL; 7844 7845 out: 7846 return fl; 7847 } 7848 7849 static int smb2_set_flock_flags(struct file_lock *flock, int flags) 7850 { 7851 int cmd = -EINVAL; 7852 7853 /* Checking for wrong flag combination during lock request*/ 7854 switch (flags) { 7855 case SMB2_LOCKFLAG_SHARED: 7856 ksmbd_debug(SMB, "received shared request\n"); 7857 cmd = F_SETLKW; 7858 flock->c.flc_type = F_RDLCK; 7859 flock->c.flc_flags |= FL_SLEEP; 7860 break; 7861 case SMB2_LOCKFLAG_EXCLUSIVE: 7862 ksmbd_debug(SMB, "received exclusive request\n"); 7863 cmd = F_SETLKW; 7864 flock->c.flc_type = F_WRLCK; 7865 flock->c.flc_flags |= FL_SLEEP; 7866 break; 7867 case SMB2_LOCKFLAG_SHARED | SMB2_LOCKFLAG_FAIL_IMMEDIATELY: 7868 ksmbd_debug(SMB, 7869 "received shared & fail immediately request\n"); 7870 cmd = F_SETLK; 7871 flock->c.flc_type = F_RDLCK; 7872 break; 7873 case SMB2_LOCKFLAG_EXCLUSIVE | SMB2_LOCKFLAG_FAIL_IMMEDIATELY: 7874 ksmbd_debug(SMB, 7875 "received exclusive & fail immediately request\n"); 7876 cmd = F_SETLK; 7877 flock->c.flc_type = F_WRLCK; 7878 break; 7879 case SMB2_LOCKFLAG_UNLOCK: 7880 ksmbd_debug(SMB, "received unlock request\n"); 7881 flock->c.flc_type = F_UNLCK; 7882 cmd = F_SETLK; 7883 break; 7884 } 7885 7886 return cmd; 7887 } 7888 7889 static struct ksmbd_lock *smb2_lock_init(struct file_lock *flock, 7890 unsigned int cmd, int flags, 7891 struct list_head *lock_list) 7892 { 7893 struct ksmbd_lock *lock; 7894 7895 lock = kzalloc_obj(struct ksmbd_lock, KSMBD_DEFAULT_GFP); 7896 if (!lock) 7897 return NULL; 7898 7899 lock->cmd = cmd; 7900 lock->fl = flock; 7901 lock->start = flock->fl_start; 7902 lock->end = flock->fl_end; 7903 lock->flags = flags; 7904 if (lock->start == lock->end) 7905 lock->zero_len = 1; 7906 INIT_LIST_HEAD(&lock->clist); 7907 INIT_LIST_HEAD(&lock->flist); 7908 INIT_LIST_HEAD(&lock->llist); 7909 list_add_tail(&lock->llist, lock_list); 7910 7911 return lock; 7912 } 7913 7914 static void smb2_remove_blocked_lock(void **argv) 7915 { 7916 struct file_lock *flock = (struct file_lock *)argv[0]; 7917 7918 ksmbd_vfs_posix_lock_unblock(flock); 7919 locks_wake_up(flock); 7920 } 7921 7922 static inline bool lock_defer_pending(struct file_lock *fl) 7923 { 7924 /* check pending lock waiters */ 7925 return waitqueue_active(&fl->c.flc_wait); 7926 } 7927 7928 /** 7929 * smb2_lock() - handler for smb2 file lock command 7930 * @work: smb work containing lock command buffer 7931 * 7932 * Return: 0 on success, otherwise error 7933 */ 7934 int smb2_lock(struct ksmbd_work *work) 7935 { 7936 struct smb2_lock_req *req; 7937 struct smb2_lock_rsp *rsp; 7938 struct smb2_lock_element *lock_ele; 7939 struct ksmbd_file *fp = NULL; 7940 struct file_lock *flock = NULL; 7941 struct file *filp = NULL; 7942 int lock_count; 7943 int flags = 0; 7944 int cmd = 0; 7945 int err = -EIO, i, rc = 0; 7946 u64 lock_start, lock_length; 7947 struct ksmbd_lock *smb_lock = NULL, *cmp_lock, *tmp, *tmp2; 7948 struct ksmbd_conn *conn; 7949 int nolock = 0; 7950 LIST_HEAD(lock_list); 7951 LIST_HEAD(rollback_list); 7952 int prior_lock = 0, bkt; 7953 unsigned int id = KSMBD_NO_FID, pid = KSMBD_NO_FID; 7954 7955 WORK_BUFFERS(work, req, rsp); 7956 7957 ksmbd_debug(SMB, "Received smb2 lock request\n"); 7958 7959 if (smb2_compound_has_failed(work, &rsp->hdr)) 7960 return -EACCES; 7961 7962 if (work->next_smb2_rcv_hdr_off && 7963 !has_file_id(req->VolatileFileId)) { 7964 ksmbd_debug(SMB, "Compound request set FID = %llu\n", 7965 work->compound_fid); 7966 id = work->compound_fid; 7967 pid = work->compound_pfid; 7968 } 7969 7970 if (!has_file_id(id)) { 7971 id = req->VolatileFileId; 7972 pid = req->PersistentFileId; 7973 } 7974 7975 fp = ksmbd_lookup_fd_slow(work, id, pid); 7976 if (!fp) { 7977 ksmbd_debug(SMB, "Invalid file id for lock : %llu\n", req->VolatileFileId); 7978 err = -ENOENT; 7979 goto out2; 7980 } 7981 7982 filp = fp->filp; 7983 lock_count = le16_to_cpu(req->LockCount); 7984 lock_ele = req->locks; 7985 7986 ksmbd_debug(SMB, "lock count is %d\n", lock_count); 7987 /* 7988 * Cap lock_count at 64. The MS-SMB2 spec defines Open.LockSequenceArray 7989 * as exactly 64 entries so 64 is the intended ceiling. No real workload 7990 * comes close to this in a single request. 7991 */ 7992 if (!lock_count || lock_count > 64) { 7993 err = -EINVAL; 7994 goto out2; 7995 } 7996 7997 for (i = 0; i < lock_count; i++) { 7998 flags = le32_to_cpu(lock_ele[i].Flags); 7999 8000 flock = smb_flock_init(filp); 8001 if (!flock) 8002 goto out; 8003 8004 cmd = smb2_set_flock_flags(flock, flags); 8005 8006 lock_start = le64_to_cpu(lock_ele[i].Offset); 8007 lock_length = le64_to_cpu(lock_ele[i].Length); 8008 if (lock_start > U64_MAX - lock_length) { 8009 pr_err("Invalid lock range requested\n"); 8010 rsp->hdr.Status = STATUS_INVALID_LOCK_RANGE; 8011 locks_free_lock(flock); 8012 goto out; 8013 } 8014 8015 if (lock_start > OFFSET_MAX) 8016 flock->fl_start = OFFSET_MAX; 8017 else 8018 flock->fl_start = lock_start; 8019 8020 lock_length = le64_to_cpu(lock_ele[i].Length); 8021 if (lock_length > OFFSET_MAX - flock->fl_start) 8022 lock_length = OFFSET_MAX - flock->fl_start; 8023 8024 flock->fl_end = flock->fl_start + lock_length; 8025 8026 if (flock->fl_end < flock->fl_start) { 8027 ksmbd_debug(SMB, 8028 "the end offset(%llx) is smaller than the start offset(%llx)\n", 8029 flock->fl_end, flock->fl_start); 8030 rsp->hdr.Status = STATUS_INVALID_LOCK_RANGE; 8031 locks_free_lock(flock); 8032 goto out; 8033 } 8034 8035 /* Check conflict locks in one request */ 8036 list_for_each_entry(cmp_lock, &lock_list, llist) { 8037 if (cmp_lock->fl->fl_start <= flock->fl_start && 8038 cmp_lock->fl->fl_end >= flock->fl_end) { 8039 if (cmp_lock->fl->c.flc_type != F_UNLCK && 8040 flock->c.flc_type != F_UNLCK) { 8041 pr_err("conflict two locks in one request\n"); 8042 err = -EINVAL; 8043 locks_free_lock(flock); 8044 goto out; 8045 } 8046 } 8047 } 8048 8049 smb_lock = smb2_lock_init(flock, cmd, flags, &lock_list); 8050 if (!smb_lock) { 8051 err = -EINVAL; 8052 locks_free_lock(flock); 8053 goto out; 8054 } 8055 } 8056 8057 list_for_each_entry_safe(smb_lock, tmp, &lock_list, llist) { 8058 if (smb_lock->cmd < 0) { 8059 err = -EINVAL; 8060 goto out; 8061 } 8062 8063 if (!(smb_lock->flags & SMB2_LOCKFLAG_MASK)) { 8064 err = -EINVAL; 8065 goto out; 8066 } 8067 8068 if ((prior_lock & (SMB2_LOCKFLAG_EXCLUSIVE | SMB2_LOCKFLAG_SHARED) && 8069 smb_lock->flags & SMB2_LOCKFLAG_UNLOCK) || 8070 (prior_lock == SMB2_LOCKFLAG_UNLOCK && 8071 !(smb_lock->flags & SMB2_LOCKFLAG_UNLOCK))) { 8072 err = -EINVAL; 8073 goto out; 8074 } 8075 8076 prior_lock = smb_lock->flags; 8077 8078 if (!(smb_lock->flags & SMB2_LOCKFLAG_UNLOCK) && 8079 !(smb_lock->flags & SMB2_LOCKFLAG_FAIL_IMMEDIATELY)) 8080 goto no_check_cl; 8081 8082 nolock = 1; 8083 /* check locks in connection list */ 8084 down_read(&conn_list_lock); 8085 hash_for_each(conn_list, bkt, conn, hlist) { 8086 spin_lock(&conn->llist_lock); 8087 list_for_each_entry_safe(cmp_lock, tmp2, &conn->lock_list, clist) { 8088 if (file_inode(cmp_lock->fl->c.flc_file) != 8089 file_inode(smb_lock->fl->c.flc_file)) 8090 continue; 8091 8092 if (lock_is_unlock(smb_lock->fl)) { 8093 if (cmp_lock->fl->c.flc_file == smb_lock->fl->c.flc_file && 8094 cmp_lock->start == smb_lock->start && 8095 cmp_lock->end == smb_lock->end && 8096 !lock_defer_pending(cmp_lock->fl)) { 8097 nolock = 0; 8098 list_del(&cmp_lock->flist); 8099 list_del(&cmp_lock->clist); 8100 cmp_lock->conn = NULL; 8101 spin_unlock(&conn->llist_lock); 8102 up_read(&conn_list_lock); 8103 8104 ksmbd_conn_put(conn); 8105 locks_free_lock(cmp_lock->fl); 8106 kfree(cmp_lock); 8107 goto out_check_cl; 8108 } 8109 continue; 8110 } 8111 8112 if (cmp_lock->fl->c.flc_file == smb_lock->fl->c.flc_file) { 8113 if (smb_lock->flags & SMB2_LOCKFLAG_SHARED) 8114 continue; 8115 } else { 8116 if (cmp_lock->flags & SMB2_LOCKFLAG_SHARED) 8117 continue; 8118 } 8119 8120 /* check zero byte lock range */ 8121 if (cmp_lock->zero_len && !smb_lock->zero_len && 8122 cmp_lock->start > smb_lock->start && 8123 cmp_lock->start < smb_lock->end) { 8124 spin_unlock(&conn->llist_lock); 8125 up_read(&conn_list_lock); 8126 pr_err("previous lock conflict with zero byte lock range\n"); 8127 goto out; 8128 } 8129 8130 if (smb_lock->zero_len && !cmp_lock->zero_len && 8131 smb_lock->start > cmp_lock->start && 8132 smb_lock->start < cmp_lock->end) { 8133 spin_unlock(&conn->llist_lock); 8134 up_read(&conn_list_lock); 8135 pr_err("current lock conflict with zero byte lock range\n"); 8136 goto out; 8137 } 8138 8139 if (((cmp_lock->start <= smb_lock->start && 8140 cmp_lock->end > smb_lock->start) || 8141 (cmp_lock->start < smb_lock->end && 8142 cmp_lock->end >= smb_lock->end)) && 8143 !cmp_lock->zero_len && !smb_lock->zero_len) { 8144 spin_unlock(&conn->llist_lock); 8145 up_read(&conn_list_lock); 8146 pr_err("Not allow lock operation on exclusive lock range\n"); 8147 goto out; 8148 } 8149 } 8150 spin_unlock(&conn->llist_lock); 8151 } 8152 up_read(&conn_list_lock); 8153 out_check_cl: 8154 if (lock_is_unlock(smb_lock->fl) && nolock) { 8155 pr_err("Try to unlock nolocked range\n"); 8156 rsp->hdr.Status = STATUS_RANGE_NOT_LOCKED; 8157 goto out; 8158 } 8159 8160 no_check_cl: 8161 flock = smb_lock->fl; 8162 list_del(&smb_lock->llist); 8163 8164 if (smb_lock->zero_len) { 8165 err = 0; 8166 goto skip; 8167 } 8168 retry: 8169 rc = vfs_lock_file(filp, smb_lock->cmd, flock, NULL); 8170 skip: 8171 if (smb_lock->flags & SMB2_LOCKFLAG_UNLOCK) { 8172 locks_free_lock(flock); 8173 kfree(smb_lock); 8174 if (!rc) { 8175 ksmbd_debug(SMB, "File unlocked\n"); 8176 } else if (rc == -ENOENT) { 8177 rsp->hdr.Status = STATUS_NOT_LOCKED; 8178 err = rc; 8179 goto out; 8180 } 8181 } else { 8182 if (rc == FILE_LOCK_DEFERRED) { 8183 void **argv; 8184 8185 ksmbd_debug(SMB, 8186 "would have to wait for getting lock\n"); 8187 list_add(&smb_lock->llist, &rollback_list); 8188 8189 argv = kmalloc(sizeof(void *), KSMBD_DEFAULT_GFP); 8190 if (!argv) { 8191 err = -ENOMEM; 8192 goto out; 8193 } 8194 argv[0] = flock; 8195 8196 rc = setup_async_work(work, 8197 smb2_remove_blocked_lock, 8198 argv); 8199 if (rc) { 8200 kfree(argv); 8201 err = -ENOMEM; 8202 goto out; 8203 } 8204 spin_lock(&fp->f_lock); 8205 list_add(&work->fp_entry, &fp->blocked_works); 8206 spin_unlock(&fp->f_lock); 8207 8208 smb2_send_interim_resp(work, STATUS_PENDING); 8209 8210 ksmbd_vfs_posix_lock_wait(flock); 8211 8212 spin_lock(&fp->f_lock); 8213 list_del(&work->fp_entry); 8214 spin_unlock(&fp->f_lock); 8215 8216 list_del(&smb_lock->llist); 8217 release_async_work(work); 8218 8219 if (work->state == KSMBD_WORK_ACTIVE) 8220 goto retry; 8221 8222 locks_free_lock(flock); 8223 8224 if (work->state == KSMBD_WORK_CANCELLED) { 8225 rsp->hdr.Status = STATUS_CANCELLED; 8226 kfree(smb_lock); 8227 smb2_send_interim_resp(work, 8228 STATUS_CANCELLED); 8229 work->send_no_response = 1; 8230 goto out; 8231 } 8232 8233 rsp->hdr.Status = 8234 STATUS_RANGE_NOT_LOCKED; 8235 kfree(smb_lock); 8236 goto out2; 8237 } else if (!rc) { 8238 list_add(&smb_lock->llist, &rollback_list); 8239 smb_lock->conn = ksmbd_conn_get(work->conn); 8240 spin_lock(&work->conn->llist_lock); 8241 list_add_tail(&smb_lock->clist, 8242 &work->conn->lock_list); 8243 list_add_tail(&smb_lock->flist, 8244 &fp->lock_list); 8245 spin_unlock(&work->conn->llist_lock); 8246 ksmbd_debug(SMB, "successful in taking lock\n"); 8247 } else { 8248 locks_free_lock(flock); 8249 kfree(smb_lock); 8250 err = rc; 8251 goto out; 8252 } 8253 } 8254 } 8255 8256 if (atomic_read(&fp->f_ci->op_count) > 1) 8257 smb_break_all_oplock(work, fp); 8258 8259 rsp->StructureSize = cpu_to_le16(4); 8260 ksmbd_debug(SMB, "successful in taking lock\n"); 8261 rsp->hdr.Status = STATUS_SUCCESS; 8262 rsp->Reserved = 0; 8263 err = ksmbd_iov_pin_rsp(work, rsp, sizeof(struct smb2_lock_rsp)); 8264 if (err) 8265 goto out; 8266 8267 ksmbd_fd_put(work, fp); 8268 return 0; 8269 8270 out: 8271 list_for_each_entry_safe(smb_lock, tmp, &lock_list, llist) { 8272 locks_free_lock(smb_lock->fl); 8273 list_del(&smb_lock->llist); 8274 kfree(smb_lock); 8275 } 8276 8277 list_for_each_entry_safe(smb_lock, tmp, &rollback_list, llist) { 8278 struct file_lock *rlock = NULL; 8279 8280 rlock = smb_flock_init(filp); 8281 if (rlock) { 8282 rlock->c.flc_type = F_UNLCK; 8283 rlock->fl_start = smb_lock->start; 8284 rlock->fl_end = smb_lock->end; 8285 8286 rc = vfs_lock_file(filp, F_SETLK, rlock, NULL); 8287 if (rc) 8288 pr_err("rollback unlock fail : %d\n", rc); 8289 } else { 8290 pr_err("rollback unlock alloc failed\n"); 8291 } 8292 8293 list_del(&smb_lock->llist); 8294 conn = smb_lock->conn; 8295 spin_lock(&conn->llist_lock); 8296 if (!list_empty(&smb_lock->flist)) 8297 list_del(&smb_lock->flist); 8298 list_del(&smb_lock->clist); 8299 smb_lock->conn = NULL; 8300 spin_unlock(&conn->llist_lock); 8301 ksmbd_conn_put(conn); 8302 8303 locks_free_lock(smb_lock->fl); 8304 if (rlock) 8305 locks_free_lock(rlock); 8306 kfree(smb_lock); 8307 } 8308 out2: 8309 ksmbd_debug(SMB, "failed in taking lock(flags : %x), err : %d\n", flags, err); 8310 8311 if (!rsp->hdr.Status) { 8312 if (err == -EINVAL) 8313 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 8314 else if (err == -ENOMEM) 8315 rsp->hdr.Status = STATUS_INSUFFICIENT_RESOURCES; 8316 else if (err == -ENOENT) 8317 rsp->hdr.Status = STATUS_FILE_CLOSED; 8318 else 8319 rsp->hdr.Status = STATUS_LOCK_NOT_GRANTED; 8320 } 8321 8322 smb2_set_err_rsp(work); 8323 ksmbd_fd_put(work, fp); 8324 return err; 8325 } 8326 8327 static int fsctl_copychunk(struct ksmbd_work *work, 8328 struct copychunk_ioctl_req *ci_req, 8329 unsigned int cnt_code, 8330 unsigned int input_count, 8331 unsigned long long volatile_id, 8332 unsigned long long persistent_id, 8333 struct smb2_ioctl_rsp *rsp) 8334 { 8335 struct copychunk_ioctl_rsp *ci_rsp; 8336 struct ksmbd_file *src_fp = NULL, *dst_fp = NULL; 8337 struct srv_copychunk *chunks; 8338 unsigned int i, chunk_count, chunk_count_written = 0; 8339 unsigned int chunk_size_written = 0; 8340 loff_t total_size_written = 0; 8341 int ret = 0; 8342 8343 ci_rsp = (struct copychunk_ioctl_rsp *)&rsp->Buffer[0]; 8344 8345 rsp->VolatileFileId = volatile_id; 8346 rsp->PersistentFileId = persistent_id; 8347 ci_rsp->ChunksWritten = 8348 cpu_to_le32(ksmbd_server_side_copy_max_chunk_count()); 8349 ci_rsp->ChunkBytesWritten = 8350 cpu_to_le32(ksmbd_server_side_copy_max_chunk_size()); 8351 ci_rsp->TotalBytesWritten = 8352 cpu_to_le32(ksmbd_server_side_copy_max_total_size()); 8353 8354 chunk_count = le32_to_cpu(ci_req->ChunkCount); 8355 if (chunk_count == 0) 8356 goto out; 8357 total_size_written = 0; 8358 8359 /* verify the SRV_COPYCHUNK_COPY packet */ 8360 if (chunk_count > ksmbd_server_side_copy_max_chunk_count() || 8361 input_count < struct_size(ci_req, Chunks, chunk_count)) { 8362 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 8363 return -EINVAL; 8364 } 8365 8366 chunks = &ci_req->Chunks[0]; 8367 for (i = 0; i < chunk_count; i++) { 8368 if (le32_to_cpu(chunks[i].Length) == 0 || 8369 le32_to_cpu(chunks[i].Length) > ksmbd_server_side_copy_max_chunk_size()) 8370 break; 8371 total_size_written += le32_to_cpu(chunks[i].Length); 8372 } 8373 8374 if (i < chunk_count || 8375 total_size_written > ksmbd_server_side_copy_max_total_size()) { 8376 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 8377 return -EINVAL; 8378 } 8379 8380 src_fp = ksmbd_lookup_foreign_fd(work, 8381 le64_to_cpu(ci_req->SourceKeyU64[0])); 8382 dst_fp = ksmbd_lookup_fd_slow(work, volatile_id, persistent_id); 8383 ret = -EINVAL; 8384 if (!src_fp || 8385 src_fp->persistent_id != le64_to_cpu(ci_req->SourceKeyU64[1])) { 8386 rsp->hdr.Status = STATUS_OBJECT_NAME_NOT_FOUND; 8387 goto out; 8388 } 8389 8390 if (!dst_fp) { 8391 rsp->hdr.Status = STATUS_FILE_CLOSED; 8392 goto out; 8393 } 8394 8395 /* 8396 * FILE_READ_DATA should only be included in 8397 * the FSCTL_SRV_COPYCHUNK case 8398 */ 8399 if (cnt_code == FSCTL_SRV_COPYCHUNK && 8400 !(dst_fp->daccess & (FILE_READ_DATA_LE | FILE_GENERIC_READ_LE))) { 8401 rsp->hdr.Status = STATUS_ACCESS_DENIED; 8402 goto out; 8403 } 8404 8405 ret = ksmbd_vfs_copy_file_ranges(work, src_fp, dst_fp, 8406 chunks, chunk_count, 8407 &chunk_count_written, 8408 &chunk_size_written, 8409 &total_size_written); 8410 if (ret < 0) { 8411 if (ret == -EACCES) 8412 rsp->hdr.Status = STATUS_ACCESS_DENIED; 8413 if (ret == -EAGAIN) 8414 rsp->hdr.Status = STATUS_FILE_LOCK_CONFLICT; 8415 else if (ret == -EBADF) 8416 rsp->hdr.Status = STATUS_INVALID_HANDLE; 8417 else if (ret == -EFBIG || ret == -ENOSPC) 8418 rsp->hdr.Status = STATUS_DISK_FULL; 8419 else if (ret == -EINVAL) 8420 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 8421 else if (ret == -EISDIR) 8422 rsp->hdr.Status = STATUS_FILE_IS_A_DIRECTORY; 8423 else if (ret == -E2BIG) 8424 rsp->hdr.Status = STATUS_INVALID_VIEW_SIZE; 8425 else 8426 rsp->hdr.Status = STATUS_UNEXPECTED_IO_ERROR; 8427 } 8428 8429 ci_rsp->ChunksWritten = cpu_to_le32(chunk_count_written); 8430 ci_rsp->ChunkBytesWritten = cpu_to_le32(chunk_size_written); 8431 ci_rsp->TotalBytesWritten = cpu_to_le32(total_size_written); 8432 out: 8433 ksmbd_fd_put(work, src_fp); 8434 ksmbd_fd_put(work, dst_fp); 8435 return ret; 8436 } 8437 8438 static __be32 idev_ipv4_address(struct in_device *idev) 8439 { 8440 __be32 addr = 0; 8441 8442 struct in_ifaddr *ifa; 8443 8444 rcu_read_lock(); 8445 in_dev_for_each_ifa_rcu(ifa, idev) { 8446 if (ifa->ifa_flags & IFA_F_SECONDARY) 8447 continue; 8448 8449 addr = ifa->ifa_address; 8450 break; 8451 } 8452 rcu_read_unlock(); 8453 return addr; 8454 } 8455 8456 static int fsctl_query_iface_info_ioctl(struct ksmbd_conn *conn, 8457 struct smb2_ioctl_rsp *rsp, 8458 unsigned int out_buf_len) 8459 { 8460 struct network_interface_info_ioctl_rsp *nii_rsp = NULL; 8461 int nbytes = 0; 8462 struct net_device *netdev; 8463 struct sockaddr_storage_rsp *sockaddr_storage; 8464 unsigned int flags; 8465 unsigned long long speed; 8466 8467 rtnl_lock(); 8468 for_each_netdev(&init_net, netdev) { 8469 bool ipv4_set = false; 8470 8471 if (netdev->type == ARPHRD_LOOPBACK) 8472 continue; 8473 8474 if (!ksmbd_find_netdev_name_iface_list(netdev->name)) 8475 continue; 8476 8477 flags = netif_get_flags(netdev); 8478 if (!(flags & IFF_RUNNING)) 8479 continue; 8480 ipv6_retry: 8481 if (out_buf_len < 8482 nbytes + sizeof(struct network_interface_info_ioctl_rsp)) { 8483 rtnl_unlock(); 8484 return -ENOSPC; 8485 } 8486 8487 nii_rsp = (struct network_interface_info_ioctl_rsp *) 8488 &rsp->Buffer[nbytes]; 8489 nii_rsp->IfIndex = cpu_to_le32(netdev->ifindex); 8490 8491 nii_rsp->Capability = 0; 8492 if (netdev->real_num_tx_queues > 1) 8493 nii_rsp->Capability |= RSS_CAPABLE; 8494 if (ksmbd_rdma_capable_netdev(netdev)) 8495 nii_rsp->Capability |= RDMA_CAPABLE; 8496 8497 nii_rsp->Next = cpu_to_le32(152); 8498 nii_rsp->Reserved = 0; 8499 8500 if (netdev->ethtool_ops->get_link_ksettings) { 8501 struct ethtool_link_ksettings cmd; 8502 8503 netdev->ethtool_ops->get_link_ksettings(netdev, &cmd); 8504 speed = cmd.base.speed; 8505 } else { 8506 ksmbd_debug(SMB, "%s %s\n", netdev->name, 8507 "speed is unknown, defaulting to 1Gb/sec"); 8508 speed = SPEED_1000; 8509 } 8510 8511 speed *= 1000000; 8512 nii_rsp->LinkSpeed = cpu_to_le64(speed); 8513 8514 sockaddr_storage = (struct sockaddr_storage_rsp *) 8515 nii_rsp->SockAddr_Storage; 8516 memset(sockaddr_storage, 0, 128); 8517 8518 if (!ipv4_set) { 8519 struct in_device *idev; 8520 8521 sockaddr_storage->Family = INTERNETWORK; 8522 sockaddr_storage->addr4.Port = 0; 8523 8524 idev = __in_dev_get_rtnl(netdev); 8525 if (!idev) 8526 continue; 8527 sockaddr_storage->addr4.IPv4Address = 8528 idev_ipv4_address(idev); 8529 nbytes += sizeof(struct network_interface_info_ioctl_rsp); 8530 ipv4_set = true; 8531 goto ipv6_retry; 8532 } else { 8533 struct inet6_dev *idev6; 8534 struct inet6_ifaddr *ifa; 8535 __u8 *ipv6_addr = sockaddr_storage->addr6.IPv6Address; 8536 8537 sockaddr_storage->Family = INTERNETWORKV6; 8538 sockaddr_storage->addr6.Port = 0; 8539 sockaddr_storage->addr6.FlowInfo = 0; 8540 8541 idev6 = __in6_dev_get(netdev); 8542 if (!idev6) 8543 continue; 8544 8545 list_for_each_entry(ifa, &idev6->addr_list, if_list) { 8546 if (ifa->flags & (IFA_F_TENTATIVE | 8547 IFA_F_DEPRECATED)) 8548 continue; 8549 memcpy(ipv6_addr, ifa->addr.s6_addr, 16); 8550 break; 8551 } 8552 sockaddr_storage->addr6.ScopeId = 0; 8553 nbytes += sizeof(struct network_interface_info_ioctl_rsp); 8554 } 8555 } 8556 rtnl_unlock(); 8557 8558 /* zero if this is last one */ 8559 if (nii_rsp) 8560 nii_rsp->Next = 0; 8561 8562 rsp->PersistentFileId = SMB2_NO_FID; 8563 rsp->VolatileFileId = SMB2_NO_FID; 8564 return nbytes; 8565 } 8566 8567 static int fsctl_validate_negotiate_info(struct ksmbd_conn *conn, 8568 struct validate_negotiate_info_req *neg_req, 8569 struct validate_negotiate_info_rsp *neg_rsp, 8570 unsigned int in_buf_len) 8571 { 8572 int ret = 0; 8573 int dialect; 8574 8575 if (in_buf_len < offsetof(struct validate_negotiate_info_req, Dialects) + 8576 le16_to_cpu(neg_req->DialectCount) * sizeof(__le16)) 8577 return -EINVAL; 8578 8579 dialect = ksmbd_lookup_dialect_by_id(neg_req->Dialects, 8580 neg_req->DialectCount); 8581 if (dialect == BAD_PROT_ID || dialect != conn->dialect) { 8582 ret = -EINVAL; 8583 goto err_out; 8584 } 8585 8586 if (strncmp(neg_req->Guid, conn->ClientGUID, SMB2_CLIENT_GUID_SIZE)) { 8587 ret = -EINVAL; 8588 goto err_out; 8589 } 8590 8591 if (le16_to_cpu(neg_req->SecurityMode) != conn->cli_sec_mode) { 8592 ret = -EINVAL; 8593 goto err_out; 8594 } 8595 8596 if (le32_to_cpu(neg_req->Capabilities) != conn->cli_cap) { 8597 ret = -EINVAL; 8598 goto err_out; 8599 } 8600 8601 neg_rsp->Capabilities = cpu_to_le32(conn->vals->req_capabilities); 8602 memset(neg_rsp->Guid, 0, SMB2_CLIENT_GUID_SIZE); 8603 neg_rsp->SecurityMode = cpu_to_le16(conn->srv_sec_mode); 8604 neg_rsp->Dialect = cpu_to_le16(conn->dialect); 8605 err_out: 8606 return ret; 8607 } 8608 8609 static int fsctl_query_allocated_ranges(struct ksmbd_work *work, u64 id, 8610 struct file_allocated_range_buffer *qar_req, 8611 struct file_allocated_range_buffer *qar_rsp, 8612 unsigned int in_count, unsigned int *out_count) 8613 { 8614 struct ksmbd_file *fp; 8615 loff_t start, length; 8616 int ret = 0; 8617 8618 *out_count = 0; 8619 if (in_count == 0) 8620 return -EINVAL; 8621 8622 start = le64_to_cpu(qar_req->file_offset); 8623 length = le64_to_cpu(qar_req->length); 8624 8625 if (start < 0 || length < 0) 8626 return -EINVAL; 8627 8628 fp = ksmbd_lookup_fd_fast(work, id); 8629 if (!fp) 8630 return -ENOENT; 8631 8632 ret = ksmbd_vfs_fqar_lseek(fp, start, length, 8633 qar_rsp, in_count, out_count); 8634 if (ret && ret != -E2BIG) 8635 *out_count = 0; 8636 8637 ksmbd_fd_put(work, fp); 8638 return ret; 8639 } 8640 8641 static int fsctl_pipe_transceive(struct ksmbd_work *work, u64 id, 8642 unsigned int out_buf_len, 8643 struct smb2_ioctl_req *req, 8644 struct smb2_ioctl_rsp *rsp) 8645 { 8646 struct ksmbd_rpc_command *rpc_resp; 8647 char *data_buf = (char *)req + le32_to_cpu(req->InputOffset); 8648 int nbytes = 0; 8649 8650 rpc_resp = ksmbd_rpc_ioctl(work->sess, id, data_buf, 8651 le32_to_cpu(req->InputCount)); 8652 if (rpc_resp) { 8653 if (rpc_resp->flags == KSMBD_RPC_SOME_NOT_MAPPED) { 8654 /* 8655 * set STATUS_SOME_NOT_MAPPED response 8656 * for unknown domain sid. 8657 */ 8658 rsp->hdr.Status = STATUS_SOME_NOT_MAPPED; 8659 } else if (rpc_resp->flags == KSMBD_RPC_ENOTIMPLEMENTED) { 8660 rsp->hdr.Status = STATUS_NOT_SUPPORTED; 8661 goto out; 8662 } else if (rpc_resp->flags != KSMBD_RPC_OK) { 8663 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 8664 goto out; 8665 } 8666 8667 nbytes = rpc_resp->payload_sz; 8668 if (rpc_resp->payload_sz > out_buf_len) { 8669 rsp->hdr.Status = STATUS_BUFFER_OVERFLOW; 8670 nbytes = out_buf_len; 8671 } 8672 8673 if (!rpc_resp->payload_sz) { 8674 rsp->hdr.Status = 8675 STATUS_UNEXPECTED_IO_ERROR; 8676 goto out; 8677 } 8678 8679 memcpy((char *)rsp->Buffer, rpc_resp->payload, nbytes); 8680 } 8681 out: 8682 kvfree(rpc_resp); 8683 return nbytes; 8684 } 8685 8686 static inline int fsctl_set_sparse(struct ksmbd_work *work, u64 id, 8687 struct file_sparse *sparse) 8688 { 8689 struct ksmbd_file *fp; 8690 struct mnt_idmap *idmap; 8691 int ret = 0; 8692 __le32 old_fattr; 8693 8694 if (!test_tree_conn_flag(work->tcon, KSMBD_TREE_CONN_FLAG_WRITABLE)) { 8695 ksmbd_debug(SMB, "User does not have write permission\n"); 8696 return -EACCES; 8697 } 8698 8699 fp = ksmbd_lookup_fd_fast(work, id); 8700 if (!fp) 8701 return -ENOENT; 8702 8703 if (!(fp->daccess & (FILE_WRITE_DATA_LE | FILE_WRITE_ATTRIBUTES_LE))) { 8704 ret = -EACCES; 8705 goto out; 8706 } 8707 8708 idmap = file_mnt_idmap(fp->filp); 8709 8710 old_fattr = fp->f_ci->m_fattr; 8711 if (sparse->SetSparse) 8712 fp->f_ci->m_fattr |= FILE_ATTRIBUTE_SPARSE_FILE_LE; 8713 else 8714 fp->f_ci->m_fattr &= ~FILE_ATTRIBUTE_SPARSE_FILE_LE; 8715 8716 if (fp->f_ci->m_fattr != old_fattr && 8717 test_share_config_flag(work->tcon->share_conf, 8718 KSMBD_SHARE_FLAG_STORE_DOS_ATTRS)) { 8719 const struct cred *saved_cred; 8720 struct xattr_dos_attrib da; 8721 8722 ret = ksmbd_vfs_get_dos_attrib_xattr(idmap, 8723 fp->filp->f_path.dentry, &da); 8724 if (ret <= 0) 8725 goto out; 8726 8727 da.attr = le32_to_cpu(fp->f_ci->m_fattr); 8728 saved_cred = override_creds(fp->filp->f_cred); 8729 ret = ksmbd_vfs_set_dos_attrib_xattr(idmap, 8730 &fp->filp->f_path, 8731 &da, true); 8732 revert_creds(saved_cred); 8733 if (ret) 8734 fp->f_ci->m_fattr = old_fattr; 8735 } 8736 8737 out: 8738 ksmbd_fd_put(work, fp); 8739 return ret; 8740 } 8741 8742 static int fsctl_request_resume_key(struct ksmbd_work *work, 8743 struct smb2_ioctl_req *req, 8744 struct resume_key_ioctl_rsp *key_rsp) 8745 { 8746 struct ksmbd_file *fp; 8747 8748 fp = ksmbd_lookup_fd_slow(work, req->VolatileFileId, req->PersistentFileId); 8749 if (!fp) 8750 return -ENOENT; 8751 8752 memset(key_rsp, 0, sizeof(*key_rsp)); 8753 key_rsp->ResumeKeyU64[0] = req->VolatileFileId; 8754 key_rsp->ResumeKeyU64[1] = req->PersistentFileId; 8755 ksmbd_fd_put(work, fp); 8756 8757 return 0; 8758 } 8759 8760 /** 8761 * smb2_ioctl() - handler for smb2 ioctl command 8762 * @work: smb work containing ioctl command buffer 8763 * 8764 * Return: 0 on success, otherwise error 8765 */ 8766 int smb2_ioctl(struct ksmbd_work *work) 8767 { 8768 struct smb2_ioctl_req *req; 8769 struct smb2_ioctl_rsp *rsp; 8770 unsigned int cnt_code, nbytes = 0, out_buf_len, in_buf_len; 8771 u64 id = KSMBD_NO_FID; 8772 struct ksmbd_conn *conn = work->conn; 8773 int ret = 0; 8774 char *buffer; 8775 8776 ksmbd_debug(SMB, "Received smb2 ioctl request\n"); 8777 8778 if (work->next_smb2_rcv_hdr_off) { 8779 req = ksmbd_req_buf_next(work); 8780 rsp = ksmbd_resp_buf_next(work); 8781 if (smb2_compound_has_failed(work, &rsp->hdr)) 8782 return -EACCES; 8783 if (!has_file_id(req->VolatileFileId)) { 8784 ksmbd_debug(SMB, "Compound request set FID = %llu\n", 8785 work->compound_fid); 8786 id = work->compound_fid; 8787 } 8788 } else { 8789 req = smb_get_msg(work->request_buf); 8790 rsp = smb_get_msg(work->response_buf); 8791 } 8792 8793 if (!has_file_id(id)) 8794 id = req->VolatileFileId; 8795 8796 if (req->Flags != cpu_to_le32(SMB2_0_IOCTL_IS_FSCTL)) { 8797 ret = -EOPNOTSUPP; 8798 goto out; 8799 } 8800 8801 buffer = (char *)req + le32_to_cpu(req->InputOffset); 8802 8803 cnt_code = le32_to_cpu(req->CtlCode); 8804 ret = smb2_calc_max_out_buf_len(work, 8805 offsetof(struct smb2_ioctl_rsp, Buffer), 8806 le32_to_cpu(req->MaxOutputResponse)); 8807 if (ret < 0) { 8808 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 8809 goto out; 8810 } 8811 out_buf_len = (unsigned int)ret; 8812 in_buf_len = le32_to_cpu(req->InputCount); 8813 8814 switch (cnt_code) { 8815 case FSCTL_DFS_GET_REFERRALS: 8816 case FSCTL_DFS_GET_REFERRALS_EX: 8817 /* Not support DFS yet */ 8818 ret = -EOPNOTSUPP; 8819 rsp->hdr.Status = STATUS_FS_DRIVER_REQUIRED; 8820 goto out2; 8821 case FSCTL_GET_COMPRESSION: { 8822 struct compress_ioctl *cmpr_rsp; 8823 struct ksmbd_file *fp; 8824 u16 fmt; 8825 8826 if (out_buf_len < sizeof(struct compress_ioctl)) { 8827 ret = -EINVAL; 8828 goto out; 8829 } 8830 8831 fp = ksmbd_lookup_fd_fast(work, id); 8832 if (!fp) { 8833 ret = -ENOENT; 8834 goto out; 8835 } 8836 8837 ret = ksmbd_vfs_get_compression(fp, &fmt); 8838 ksmbd_fd_put(work, fp); 8839 if (ret < 0) 8840 goto out; 8841 8842 cmpr_rsp = (struct compress_ioctl *)&rsp->Buffer[0]; 8843 cmpr_rsp->CompressionState = cpu_to_le16(fmt); 8844 nbytes = sizeof(struct compress_ioctl); 8845 rsp->PersistentFileId = req->PersistentFileId; 8846 rsp->VolatileFileId = req->VolatileFileId; 8847 break; 8848 } 8849 case FSCTL_SET_COMPRESSION: { 8850 struct compress_ioctl *cmpr_req; 8851 struct ksmbd_file *fp; 8852 8853 if (in_buf_len < sizeof(struct compress_ioctl)) { 8854 ret = -EINVAL; 8855 goto out; 8856 } 8857 8858 if (!test_tree_conn_flag(work->tcon, KSMBD_TREE_CONN_FLAG_WRITABLE)) { 8859 ksmbd_debug(SMB, "User does not have write permission\n"); 8860 ret = -EACCES; 8861 goto out; 8862 } 8863 8864 cmpr_req = (struct compress_ioctl *)buffer; 8865 fp = ksmbd_lookup_fd_fast(work, id); 8866 if (!fp) { 8867 ret = -ENOENT; 8868 goto out; 8869 } 8870 8871 ret = ksmbd_vfs_set_compression(work, fp, le16_to_cpu(cmpr_req->CompressionState)); 8872 ksmbd_fd_put(work, fp); 8873 if (ret) 8874 goto out; 8875 break; 8876 } 8877 case FSCTL_CREATE_OR_GET_OBJECT_ID: 8878 { 8879 struct file_object_buf_type1_ioctl_rsp *obj_buf; 8880 struct ksmbd_file *fp; 8881 8882 fp = ksmbd_lookup_fd_fast(work, id); 8883 if (!fp) { 8884 ret = -EBADF; 8885 rsp->hdr.Status = STATUS_FILE_CLOSED; 8886 goto out2; 8887 } 8888 ksmbd_fd_put(work, fp); 8889 8890 nbytes = sizeof(struct file_object_buf_type1_ioctl_rsp); 8891 obj_buf = (struct file_object_buf_type1_ioctl_rsp *) 8892 &rsp->Buffer[0]; 8893 8894 /* 8895 * TODO: This is dummy implementation to pass smbtorture 8896 * Need to check correct response later 8897 */ 8898 memset(obj_buf->ObjectId, 0x0, 16); 8899 memset(obj_buf->BirthVolumeId, 0x0, 16); 8900 memset(obj_buf->BirthObjectId, 0x0, 16); 8901 memset(obj_buf->DomainId, 0x0, 16); 8902 8903 break; 8904 } 8905 case FSCTL_PIPE_TRANSCEIVE: 8906 out_buf_len = min_t(u32, KSMBD_IPC_MAX_PAYLOAD, out_buf_len); 8907 nbytes = fsctl_pipe_transceive(work, id, out_buf_len, req, rsp); 8908 break; 8909 case FSCTL_VALIDATE_NEGOTIATE_INFO: 8910 if (conn->dialect < SMB30_PROT_ID) { 8911 ret = -EOPNOTSUPP; 8912 goto out; 8913 } 8914 8915 if (in_buf_len < offsetof(struct validate_negotiate_info_req, 8916 Dialects)) { 8917 ret = -EINVAL; 8918 goto out; 8919 } 8920 8921 if (out_buf_len < sizeof(struct validate_negotiate_info_rsp)) { 8922 ret = -EINVAL; 8923 goto out; 8924 } 8925 8926 ret = fsctl_validate_negotiate_info(conn, 8927 (struct validate_negotiate_info_req *)buffer, 8928 (struct validate_negotiate_info_rsp *)&rsp->Buffer[0], 8929 in_buf_len); 8930 if (ret < 0) 8931 goto out; 8932 8933 nbytes = sizeof(struct validate_negotiate_info_rsp); 8934 rsp->PersistentFileId = SMB2_NO_FID; 8935 rsp->VolatileFileId = SMB2_NO_FID; 8936 break; 8937 case FSCTL_QUERY_NETWORK_INTERFACE_INFO: 8938 ret = fsctl_query_iface_info_ioctl(conn, rsp, out_buf_len); 8939 if (ret < 0) 8940 goto out; 8941 nbytes = ret; 8942 break; 8943 case FSCTL_SRV_REQUEST_RESUME_KEY: 8944 if (out_buf_len < sizeof(struct resume_key_ioctl_rsp)) { 8945 ret = -EINVAL; 8946 goto out; 8947 } 8948 8949 ret = fsctl_request_resume_key(work, req, 8950 (struct resume_key_ioctl_rsp *)&rsp->Buffer[0]); 8951 if (ret < 0) 8952 goto out; 8953 rsp->PersistentFileId = req->PersistentFileId; 8954 rsp->VolatileFileId = req->VolatileFileId; 8955 nbytes = sizeof(struct resume_key_ioctl_rsp); 8956 break; 8957 case FSCTL_SRV_COPYCHUNK: 8958 case FSCTL_SRV_COPYCHUNK_WRITE: 8959 if (!test_tree_conn_flag(work->tcon, KSMBD_TREE_CONN_FLAG_WRITABLE)) { 8960 ksmbd_debug(SMB, 8961 "User does not have write permission\n"); 8962 ret = -EACCES; 8963 goto out; 8964 } 8965 8966 if (in_buf_len <= sizeof(struct copychunk_ioctl_req)) { 8967 ret = -EINVAL; 8968 goto out; 8969 } 8970 8971 if (out_buf_len < sizeof(struct copychunk_ioctl_rsp)) { 8972 ret = -EINVAL; 8973 goto out; 8974 } 8975 8976 nbytes = sizeof(struct copychunk_ioctl_rsp); 8977 rsp->VolatileFileId = req->VolatileFileId; 8978 rsp->PersistentFileId = req->PersistentFileId; 8979 fsctl_copychunk(work, 8980 (struct copychunk_ioctl_req *)buffer, 8981 le32_to_cpu(req->CtlCode), 8982 le32_to_cpu(req->InputCount), 8983 req->VolatileFileId, 8984 req->PersistentFileId, 8985 rsp); 8986 break; 8987 case FSCTL_SET_SPARSE: 8988 if (in_buf_len < sizeof(struct file_sparse)) { 8989 ret = -EINVAL; 8990 goto out; 8991 } 8992 8993 ret = fsctl_set_sparse(work, id, (struct file_sparse *)buffer); 8994 if (ret < 0) 8995 goto out; 8996 break; 8997 case FSCTL_SET_ZERO_DATA: 8998 { 8999 struct file_zero_data_information *zero_data; 9000 struct ksmbd_file *fp; 9001 loff_t off, len, bfz; 9002 9003 if (!test_tree_conn_flag(work->tcon, KSMBD_TREE_CONN_FLAG_WRITABLE)) { 9004 ksmbd_debug(SMB, 9005 "User does not have write permission\n"); 9006 ret = -EACCES; 9007 goto out; 9008 } 9009 9010 if (in_buf_len < sizeof(struct file_zero_data_information)) { 9011 ret = -EINVAL; 9012 goto out; 9013 } 9014 9015 zero_data = 9016 (struct file_zero_data_information *)buffer; 9017 9018 off = le64_to_cpu(zero_data->FileOffset); 9019 bfz = le64_to_cpu(zero_data->BeyondFinalZero); 9020 if (off < 0 || bfz < 0 || off > bfz) { 9021 ret = -EINVAL; 9022 goto out; 9023 } 9024 9025 len = bfz - off; 9026 if (len) { 9027 fp = ksmbd_lookup_fd_fast(work, id); 9028 if (!fp) { 9029 ret = -ENOENT; 9030 goto out; 9031 } 9032 9033 if (!(fp->daccess & FILE_WRITE_DATA_LE)) { 9034 ksmbd_fd_put(work, fp); 9035 ret = -EACCES; 9036 goto out; 9037 } 9038 9039 ret = ksmbd_vfs_zero_data(work, fp, off, len); 9040 ksmbd_fd_put(work, fp); 9041 if (ret < 0) 9042 goto out; 9043 } 9044 break; 9045 } 9046 case FSCTL_QUERY_ALLOCATED_RANGES: 9047 if (in_buf_len < sizeof(struct file_allocated_range_buffer)) { 9048 ret = -EINVAL; 9049 goto out; 9050 } 9051 9052 ret = fsctl_query_allocated_ranges(work, id, 9053 (struct file_allocated_range_buffer *)buffer, 9054 (struct file_allocated_range_buffer *)&rsp->Buffer[0], 9055 out_buf_len / 9056 sizeof(struct file_allocated_range_buffer), &nbytes); 9057 if (ret == -E2BIG) { 9058 rsp->hdr.Status = STATUS_BUFFER_OVERFLOW; 9059 } else if (ret < 0) { 9060 nbytes = 0; 9061 goto out; 9062 } 9063 9064 nbytes *= sizeof(struct file_allocated_range_buffer); 9065 break; 9066 case FSCTL_GET_REPARSE_POINT: 9067 { 9068 struct reparse_data_buffer *reparse_ptr; 9069 struct ksmbd_file *fp; 9070 9071 reparse_ptr = (struct reparse_data_buffer *)&rsp->Buffer[0]; 9072 fp = ksmbd_lookup_fd_fast(work, id); 9073 if (!fp) { 9074 pr_err("not found fp!!\n"); 9075 ret = -ENOENT; 9076 goto out; 9077 } 9078 9079 reparse_ptr->ReparseTag = 9080 smb2_get_reparse_tag_special_file(file_inode(fp->filp)->i_mode); 9081 reparse_ptr->ReparseDataLength = 0; 9082 ksmbd_fd_put(work, fp); 9083 nbytes = sizeof(struct reparse_data_buffer); 9084 break; 9085 } 9086 case FSCTL_DUPLICATE_EXTENTS_TO_FILE: 9087 { 9088 struct ksmbd_file *fp_in, *fp_out = NULL; 9089 struct duplicate_extents_to_file *dup_ext; 9090 loff_t src_off, dst_off, length, cloned; 9091 9092 if (in_buf_len < sizeof(struct duplicate_extents_to_file)) { 9093 ret = -EINVAL; 9094 goto out; 9095 } 9096 9097 dup_ext = (struct duplicate_extents_to_file *)buffer; 9098 9099 fp_in = ksmbd_lookup_fd_slow(work, dup_ext->VolatileFileHandle, 9100 dup_ext->PersistentFileHandle); 9101 if (!fp_in) { 9102 pr_err("not found file handle in duplicate extent to file\n"); 9103 ret = -ENOENT; 9104 goto out; 9105 } 9106 9107 fp_out = ksmbd_lookup_fd_fast(work, id); 9108 if (!fp_out) { 9109 pr_err("not found fp\n"); 9110 ret = -ENOENT; 9111 goto dup_ext_out; 9112 } 9113 9114 if (!test_tree_conn_flag(work->tcon, 9115 KSMBD_TREE_CONN_FLAG_WRITABLE)) { 9116 ret = -EACCES; 9117 goto dup_ext_out; 9118 } 9119 9120 if (!(fp_out->daccess & FILE_WRITE_DATA_LE)) { 9121 ret = -EACCES; 9122 goto dup_ext_out; 9123 } 9124 if (!(fp_in->daccess & FILE_READ_DATA_LE)) { 9125 ret = -EACCES; 9126 goto dup_ext_out; 9127 } 9128 9129 src_off = le64_to_cpu(dup_ext->SourceFileOffset); 9130 dst_off = le64_to_cpu(dup_ext->TargetFileOffset); 9131 length = le64_to_cpu(dup_ext->ByteCount); 9132 /* 9133 * XXX: It is not clear if FSCTL_DUPLICATE_EXTENTS_TO_FILE 9134 * should fall back to vfs_copy_file_range(). This could be 9135 * beneficial when re-exporting nfs/smb mount, but note that 9136 * this can result in partial copy that returns an error status. 9137 * If/when FSCTL_DUPLICATE_EXTENTS_TO_FILE_EX is implemented, 9138 * fall back to vfs_copy_file_range(), should be avoided when 9139 * the flag DUPLICATE_EXTENTS_DATA_EX_SOURCE_ATOMIC is set. 9140 */ 9141 cloned = vfs_clone_file_range(fp_in->filp, src_off, 9142 fp_out->filp, dst_off, length, 0); 9143 if (cloned == -EXDEV || cloned == -EOPNOTSUPP) { 9144 ret = -EOPNOTSUPP; 9145 goto dup_ext_out; 9146 } else if (cloned != length) { 9147 cloned = vfs_copy_file_range(fp_in->filp, src_off, 9148 fp_out->filp, dst_off, 9149 length, 0); 9150 if (cloned != length) { 9151 if (cloned < 0) 9152 ret = cloned; 9153 else 9154 ret = -EINVAL; 9155 } 9156 } 9157 9158 dup_ext_out: 9159 ksmbd_fd_put(work, fp_in); 9160 ksmbd_fd_put(work, fp_out); 9161 if (ret < 0) 9162 goto out; 9163 break; 9164 } 9165 default: 9166 ksmbd_debug(SMB, "not implemented yet ioctl command 0x%x\n", 9167 cnt_code); 9168 ret = -EOPNOTSUPP; 9169 goto out; 9170 } 9171 9172 rsp->CtlCode = cpu_to_le32(cnt_code); 9173 rsp->InputCount = cpu_to_le32(0); 9174 rsp->InputOffset = cpu_to_le32(112); 9175 rsp->OutputOffset = cpu_to_le32(112); 9176 rsp->OutputCount = cpu_to_le32(nbytes); 9177 rsp->StructureSize = cpu_to_le16(49); 9178 rsp->Reserved = cpu_to_le16(0); 9179 rsp->Flags = cpu_to_le32(0); 9180 rsp->Reserved2 = cpu_to_le32(0); 9181 ret = ksmbd_iov_pin_rsp(work, rsp, sizeof(struct smb2_ioctl_rsp) + nbytes); 9182 if (!ret) 9183 return ret; 9184 9185 out: 9186 if (ret == -EACCES) 9187 rsp->hdr.Status = STATUS_ACCESS_DENIED; 9188 else if (ret == -ENOENT) 9189 rsp->hdr.Status = STATUS_OBJECT_NAME_NOT_FOUND; 9190 else if (ret == -EOPNOTSUPP) 9191 rsp->hdr.Status = STATUS_NOT_SUPPORTED; 9192 else if (ret == -ENOSPC) 9193 rsp->hdr.Status = STATUS_BUFFER_TOO_SMALL; 9194 else if (ret < 0 || rsp->hdr.Status == 0) 9195 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 9196 9197 out2: 9198 smb2_set_err_rsp(work); 9199 return ret; 9200 } 9201 9202 /** 9203 * smb20_oplock_break_ack() - handler for smb2.0 oplock break command 9204 * @work: smb work containing oplock break command buffer 9205 * 9206 * Return: 0 9207 */ 9208 static void smb20_oplock_break_ack(struct ksmbd_work *work) 9209 { 9210 struct smb2_oplock_break *req; 9211 struct smb2_oplock_break *rsp; 9212 struct ksmbd_file *fp; 9213 struct oplock_info *opinfo = NULL; 9214 __le32 status = STATUS_SUCCESS; 9215 int ret; 9216 u64 volatile_id, persistent_id; 9217 char req_oplevel = 0, rsp_oplevel = 0; 9218 9219 WORK_BUFFERS(work, req, rsp); 9220 9221 volatile_id = req->VolatileFid; 9222 persistent_id = req->PersistentFid; 9223 req_oplevel = req->OplockLevel; 9224 ksmbd_debug(OPLOCK, "v_id %llu, p_id %llu request oplock level %d\n", 9225 volatile_id, persistent_id, req_oplevel); 9226 9227 fp = ksmbd_lookup_fd_slow(work, volatile_id, persistent_id); 9228 if (!fp) { 9229 rsp->hdr.Status = STATUS_FILE_CLOSED; 9230 smb2_set_err_rsp(work); 9231 return; 9232 } 9233 9234 opinfo = opinfo_get(fp); 9235 if (!opinfo) { 9236 pr_err("unexpected null oplock_info\n"); 9237 rsp->hdr.Status = STATUS_INVALID_OPLOCK_PROTOCOL; 9238 smb2_set_err_rsp(work); 9239 ksmbd_fd_put(work, fp); 9240 return; 9241 } 9242 9243 if (opinfo->op_state != OPLOCK_ACK_WAIT) { 9244 ksmbd_debug(SMB, "unexpected oplock state 0x%x\n", 9245 opinfo->op_state); 9246 if (opinfo->level == SMB2_OPLOCK_LEVEL_NONE) 9247 status = STATUS_INVALID_OPLOCK_PROTOCOL; 9248 else 9249 status = STATUS_INVALID_DEVICE_STATE; 9250 goto err_out; 9251 } 9252 9253 if (req_oplevel == SMB2_OPLOCK_LEVEL_LEASE) { 9254 opinfo->level = SMB2_OPLOCK_LEVEL_NONE; 9255 status = STATUS_INVALID_PARAMETER; 9256 goto err_out; 9257 } 9258 9259 if (opinfo->level == SMB2_OPLOCK_LEVEL_NONE) { 9260 status = STATUS_INVALID_OPLOCK_PROTOCOL; 9261 goto err_out; 9262 } 9263 9264 if (opinfo->level == SMB2_OPLOCK_LEVEL_EXCLUSIVE && 9265 req_oplevel != SMB2_OPLOCK_LEVEL_II && 9266 req_oplevel != SMB2_OPLOCK_LEVEL_NONE) { 9267 opinfo->level = SMB2_OPLOCK_LEVEL_NONE; 9268 status = STATUS_INVALID_OPLOCK_PROTOCOL; 9269 goto err_out; 9270 } 9271 9272 if (opinfo->level == SMB2_OPLOCK_LEVEL_BATCH && 9273 req_oplevel != SMB2_OPLOCK_LEVEL_II && 9274 req_oplevel != SMB2_OPLOCK_LEVEL_NONE && 9275 req_oplevel != SMB2_OPLOCK_LEVEL_EXCLUSIVE) { 9276 opinfo->level = SMB2_OPLOCK_LEVEL_NONE; 9277 status = STATUS_INVALID_OPLOCK_PROTOCOL; 9278 goto err_out; 9279 } 9280 9281 if (opinfo->level == SMB2_OPLOCK_LEVEL_II && 9282 req_oplevel != SMB2_OPLOCK_LEVEL_NONE) { 9283 opinfo->level = SMB2_OPLOCK_LEVEL_NONE; 9284 status = STATUS_INVALID_OPLOCK_PROTOCOL; 9285 goto err_out; 9286 } 9287 9288 if (req_oplevel == SMB2_OPLOCK_LEVEL_EXCLUSIVE) 9289 rsp_oplevel = SMB2_OPLOCK_LEVEL_NONE; 9290 else 9291 rsp_oplevel = req_oplevel; 9292 9293 opinfo->level = rsp_oplevel; 9294 9295 rsp->StructureSize = cpu_to_le16(24); 9296 rsp->OplockLevel = rsp_oplevel; 9297 rsp->Reserved = 0; 9298 rsp->Reserved2 = 0; 9299 rsp->VolatileFid = volatile_id; 9300 rsp->PersistentFid = persistent_id; 9301 ret = ksmbd_iov_pin_rsp(work, rsp, sizeof(struct smb2_oplock_break)); 9302 if (ret) 9303 ksmbd_debug(SMB, "failed to pin oplock break response: %d\n", 9304 ret); 9305 goto out; 9306 9307 err_out: 9308 rsp->hdr.Status = status; 9309 smb2_set_err_rsp(work); 9310 9311 out: 9312 opinfo->op_state = OPLOCK_STATE_NONE; 9313 wake_up_interruptible_all(&opinfo->oplock_q); 9314 opinfo_put(opinfo); 9315 ksmbd_fd_put(work, fp); 9316 } 9317 9318 static bool smb2_lease_state_valid(__le32 state) 9319 { 9320 return !(state & ~(SMB2_LEASE_READ_CACHING_LE | 9321 SMB2_LEASE_HANDLE_CACHING_LE | 9322 SMB2_LEASE_WRITE_CACHING_LE)); 9323 } 9324 9325 static int check_lease_state(struct lease *lease, __le32 req_state) 9326 { 9327 if (smb2_lease_state_valid(req_state) && 9328 !(req_state & ~lease->new_state)) 9329 return 0; 9330 9331 return 1; 9332 } 9333 9334 /** 9335 * smb21_lease_break_ack() - handler for smb2.1 lease break command 9336 * @work: smb work containing lease break command buffer 9337 * 9338 * Return: 0 9339 */ 9340 static void smb21_lease_break_ack(struct ksmbd_work *work) 9341 { 9342 struct ksmbd_conn *conn = work->conn; 9343 struct smb2_lease_ack *req; 9344 struct smb2_lease_ack *rsp; 9345 struct oplock_info *opinfo; 9346 int ret = 0; 9347 __le32 lease_state; 9348 struct lease *lease; 9349 9350 WORK_BUFFERS(work, req, rsp); 9351 9352 ksmbd_debug(OPLOCK, "smb21 lease break, lease state(0x%x)\n", 9353 le32_to_cpu(req->LeaseState)); 9354 opinfo = lookup_lease_in_table(conn, req->LeaseKey); 9355 if (!opinfo) { 9356 ksmbd_debug(OPLOCK, "file not opened\n"); 9357 smb2_set_err_rsp(work); 9358 rsp->hdr.Status = STATUS_UNSUCCESSFUL; 9359 return; 9360 } 9361 lease = opinfo->o_lease; 9362 9363 if (opinfo->op_state == OPLOCK_STATE_NONE) { 9364 pr_err("unexpected lease break state 0x%x\n", 9365 opinfo->op_state); 9366 rsp->hdr.Status = STATUS_UNSUCCESSFUL; 9367 goto err_out; 9368 } 9369 9370 if (!atomic_read(&opinfo->breaking_cnt)) { 9371 rsp->hdr.Status = STATUS_UNSUCCESSFUL; 9372 goto err_out; 9373 } 9374 9375 if (check_lease_state(lease, req->LeaseState)) { 9376 rsp->hdr.Status = STATUS_REQUEST_NOT_ACCEPTED; 9377 ksmbd_debug(OPLOCK, 9378 "req lease state: 0x%x, expected state: 0x%x\n", 9379 req->LeaseState, lease->new_state); 9380 goto err_out; 9381 } 9382 9383 lease_state = req->LeaseState; 9384 lease->state = lease_state; 9385 lease->new_state = SMB2_LEASE_NONE_LE; 9386 lease_update_oplock_levels(lease); 9387 9388 rsp->StructureSize = cpu_to_le16(36); 9389 rsp->Reserved = 0; 9390 rsp->Flags = 0; 9391 memcpy(rsp->LeaseKey, req->LeaseKey, 16); 9392 rsp->LeaseState = lease_state; 9393 rsp->LeaseDuration = 0; 9394 ret = ksmbd_iov_pin_rsp(work, rsp, sizeof(struct smb2_lease_ack)); 9395 if (ret) 9396 goto err_out; 9397 9398 opinfo->op_state = OPLOCK_STATE_NONE; 9399 wake_up_interruptible_all(&opinfo->oplock_q); 9400 atomic_dec(&opinfo->breaking_cnt); 9401 wake_up_interruptible_all(&opinfo->oplock_brk); 9402 opinfo_put(opinfo); 9403 return; 9404 9405 err_out: 9406 smb2_set_err_rsp(work); 9407 opinfo_put(opinfo); 9408 return; 9409 } 9410 9411 /** 9412 * smb2_oplock_break() - dispatcher for smb2.0 and 2.1 oplock/lease break 9413 * @work: smb work containing oplock/lease break command buffer 9414 * 9415 * Return: 0 on success, otherwise error 9416 */ 9417 int smb2_oplock_break(struct ksmbd_work *work) 9418 { 9419 struct smb2_oplock_break *req; 9420 struct smb2_oplock_break *rsp; 9421 9422 ksmbd_debug(SMB, "Received smb2 oplock break acknowledgment request\n"); 9423 9424 WORK_BUFFERS(work, req, rsp); 9425 9426 switch (le16_to_cpu(req->StructureSize)) { 9427 case OP_BREAK_STRUCT_SIZE_20: 9428 smb20_oplock_break_ack(work); 9429 break; 9430 case OP_BREAK_STRUCT_SIZE_21: 9431 smb21_lease_break_ack(work); 9432 break; 9433 default: 9434 ksmbd_debug(OPLOCK, "invalid break cmd %d\n", 9435 le16_to_cpu(req->StructureSize)); 9436 rsp->hdr.Status = STATUS_INVALID_PARAMETER; 9437 smb2_set_err_rsp(work); 9438 return -EINVAL; 9439 } 9440 9441 return 0; 9442 } 9443 9444 /** 9445 * smb2_notify() - handler for smb2 notify request 9446 * @work: smb work containing notify command buffer 9447 * 9448 * Return: 0 on success, otherwise error 9449 */ 9450 int smb2_notify(struct ksmbd_work *work) 9451 { 9452 struct smb2_change_notify_req *req; 9453 struct smb2_change_notify_rsp *rsp; 9454 9455 ksmbd_debug(SMB, "Received smb2 notify\n"); 9456 9457 WORK_BUFFERS(work, req, rsp); 9458 9459 if (smb2_compound_has_failed(work, &rsp->hdr)) 9460 return -EACCES; 9461 9462 if (work->next_smb2_rcv_hdr_off && req->hdr.NextCommand) { 9463 rsp->hdr.Status = STATUS_INTERNAL_ERROR; 9464 smb2_set_err_rsp(work); 9465 return -EIO; 9466 } 9467 9468 smb2_set_err_rsp(work); 9469 rsp->hdr.Status = STATUS_NOT_IMPLEMENTED; 9470 return -EOPNOTSUPP; 9471 } 9472 9473 /** 9474 * smb2_is_sign_req() - handler for checking packet signing status 9475 * @work: smb work containing notify command buffer 9476 * @command: SMB2 command id 9477 * 9478 * Return: true if packed is signed, false otherwise 9479 */ 9480 bool smb2_is_sign_req(struct ksmbd_work *work, unsigned int command) 9481 { 9482 struct smb2_hdr *rcv_hdr2 = smb_get_msg(work->request_buf); 9483 9484 if ((rcv_hdr2->Flags & SMB2_FLAGS_SIGNED) && 9485 command != SMB2_NEGOTIATE_HE && 9486 command != SMB2_SESSION_SETUP_HE && 9487 command != SMB2_OPLOCK_BREAK_HE) 9488 return true; 9489 9490 return false; 9491 } 9492 9493 /** 9494 * smb2_check_sign_req() - handler for req packet sign processing 9495 * @work: smb work containing notify command buffer 9496 * 9497 * Return: 1 on success, 0 otherwise 9498 */ 9499 int smb2_check_sign_req(struct ksmbd_work *work) 9500 { 9501 struct smb2_hdr *hdr; 9502 char signature_req[SMB2_SIGNATURE_SIZE]; 9503 char signature[SMB2_HMACSHA256_SIZE]; 9504 struct kvec iov[1]; 9505 size_t len; 9506 9507 hdr = smb_get_msg(work->request_buf); 9508 if (work->next_smb2_rcv_hdr_off) 9509 hdr = ksmbd_req_buf_next(work); 9510 9511 if (!hdr->NextCommand && !work->next_smb2_rcv_hdr_off) 9512 len = get_rfc1002_len(work->request_buf); 9513 else if (hdr->NextCommand) 9514 len = le32_to_cpu(hdr->NextCommand); 9515 else 9516 len = get_rfc1002_len(work->request_buf) - 9517 work->next_smb2_rcv_hdr_off; 9518 9519 memcpy(signature_req, hdr->Signature, SMB2_SIGNATURE_SIZE); 9520 memset(hdr->Signature, 0, SMB2_SIGNATURE_SIZE); 9521 9522 iov[0].iov_base = (char *)&hdr->ProtocolId; 9523 iov[0].iov_len = len; 9524 9525 ksmbd_sign_smb2_pdu(work->conn, work->sess->sess_key, iov, 1, 9526 signature); 9527 9528 if (crypto_memneq(signature, signature_req, SMB2_SIGNATURE_SIZE)) { 9529 pr_err("bad smb2 signature\n"); 9530 return 0; 9531 } 9532 9533 return 1; 9534 } 9535 9536 /** 9537 * smb2_set_sign_rsp() - handler for rsp packet sign processing 9538 * @work: smb work containing notify command buffer 9539 * 9540 */ 9541 void smb2_set_sign_rsp(struct ksmbd_work *work) 9542 { 9543 struct smb2_hdr *hdr; 9544 char signature[SMB2_HMACSHA256_SIZE]; 9545 struct kvec *iov; 9546 int n_vec = 1; 9547 9548 hdr = ksmbd_resp_buf_curr(work); 9549 hdr->Flags |= SMB2_FLAGS_SIGNED; 9550 memset(hdr->Signature, 0, SMB2_SIGNATURE_SIZE); 9551 9552 if (hdr->Command == SMB2_READ) { 9553 iov = &work->iov[work->iov_idx - 1]; 9554 n_vec++; 9555 } else { 9556 iov = &work->iov[work->iov_idx]; 9557 } 9558 9559 ksmbd_sign_smb2_pdu(work->conn, work->sess->sess_key, iov, n_vec, 9560 signature); 9561 memcpy(hdr->Signature, signature, SMB2_SIGNATURE_SIZE); 9562 } 9563 9564 /** 9565 * smb3_check_sign_req() - handler for req packet sign processing 9566 * @work: smb work containing notify command buffer 9567 * 9568 * Return: 1 on success, 0 otherwise 9569 */ 9570 int smb3_check_sign_req(struct ksmbd_work *work) 9571 { 9572 struct ksmbd_conn *conn = work->conn; 9573 char *signing_key; 9574 struct smb2_hdr *hdr; 9575 struct channel *chann; 9576 char signature_req[SMB2_SIGNATURE_SIZE]; 9577 char signature[SMB2_CMACAES_SIZE]; 9578 struct kvec iov[1]; 9579 size_t len; 9580 9581 hdr = smb_get_msg(work->request_buf); 9582 if (work->next_smb2_rcv_hdr_off) 9583 hdr = ksmbd_req_buf_next(work); 9584 9585 if (!hdr->NextCommand && !work->next_smb2_rcv_hdr_off) 9586 len = get_rfc1002_len(work->request_buf); 9587 else if (hdr->NextCommand) 9588 len = le32_to_cpu(hdr->NextCommand); 9589 else 9590 len = get_rfc1002_len(work->request_buf) - 9591 work->next_smb2_rcv_hdr_off; 9592 9593 if (le16_to_cpu(hdr->Command) == SMB2_SESSION_SETUP_HE) { 9594 signing_key = work->sess->smb3signingkey; 9595 } else { 9596 chann = lookup_chann_list(work->sess, conn); 9597 if (!chann) { 9598 return 0; 9599 } 9600 signing_key = chann->smb3signingkey; 9601 } 9602 9603 if (!signing_key) { 9604 pr_err("SMB3 signing key is not generated\n"); 9605 return 0; 9606 } 9607 9608 memcpy(signature_req, hdr->Signature, SMB2_SIGNATURE_SIZE); 9609 memset(hdr->Signature, 0, SMB2_SIGNATURE_SIZE); 9610 iov[0].iov_base = (char *)&hdr->ProtocolId; 9611 iov[0].iov_len = len; 9612 9613 ksmbd_sign_smb3_pdu(conn, signing_key, iov, 1, signature); 9614 9615 if (crypto_memneq(signature, signature_req, SMB2_SIGNATURE_SIZE)) { 9616 pr_err("bad smb2 signature\n"); 9617 return 0; 9618 } 9619 9620 return 1; 9621 } 9622 9623 /** 9624 * smb3_set_sign_rsp() - handler for rsp packet sign processing 9625 * @work: smb work containing notify command buffer 9626 * 9627 */ 9628 void smb3_set_sign_rsp(struct ksmbd_work *work) 9629 { 9630 struct ksmbd_conn *conn = work->conn; 9631 struct smb2_hdr *hdr; 9632 struct channel *chann; 9633 char signature[SMB2_CMACAES_SIZE]; 9634 struct kvec *iov; 9635 int n_vec = 1; 9636 char *signing_key; 9637 9638 hdr = ksmbd_resp_buf_curr(work); 9639 9640 if (conn->binding == false && 9641 le16_to_cpu(hdr->Command) == SMB2_SESSION_SETUP_HE) { 9642 signing_key = work->sess->smb3signingkey; 9643 } else { 9644 chann = lookup_chann_list(work->sess, work->conn); 9645 if (!chann) { 9646 return; 9647 } 9648 signing_key = chann->smb3signingkey; 9649 } 9650 9651 if (!signing_key) 9652 return; 9653 9654 hdr->Flags |= SMB2_FLAGS_SIGNED; 9655 memset(hdr->Signature, 0, SMB2_SIGNATURE_SIZE); 9656 9657 if (hdr->Command == SMB2_READ) { 9658 iov = &work->iov[work->iov_idx - 1]; 9659 n_vec++; 9660 } else { 9661 iov = &work->iov[work->iov_idx]; 9662 } 9663 9664 ksmbd_sign_smb3_pdu(conn, signing_key, iov, n_vec, signature); 9665 memcpy(hdr->Signature, signature, SMB2_SIGNATURE_SIZE); 9666 } 9667 9668 /** 9669 * smb3_preauth_hash_rsp() - handler for computing preauth hash on response 9670 * @work: smb work containing response buffer 9671 * 9672 */ 9673 void smb3_preauth_hash_rsp(struct ksmbd_work *work) 9674 { 9675 struct ksmbd_conn *conn = work->conn; 9676 struct ksmbd_session *sess = work->sess; 9677 struct smb2_hdr *req, *rsp; 9678 9679 if (conn->dialect != SMB311_PROT_ID) 9680 return; 9681 9682 WORK_BUFFERS(work, req, rsp); 9683 9684 if (le16_to_cpu(req->Command) == SMB2_NEGOTIATE_HE) { 9685 ksmbd_conn_lock(conn); 9686 if (conn->preauth_info) 9687 ksmbd_gen_preauth_integrity_hash(conn, work->response_buf, 9688 conn->preauth_info->Preauth_HashValue); 9689 ksmbd_conn_unlock(conn); 9690 } 9691 9692 if (le16_to_cpu(rsp->Command) == SMB2_SESSION_SETUP_HE && sess) { 9693 __u8 *hash_value; 9694 9695 if (conn->binding) { 9696 struct preauth_session *preauth_sess; 9697 9698 preauth_sess = ksmbd_preauth_session_lookup(conn, sess->id); 9699 if (!preauth_sess) 9700 return; 9701 hash_value = preauth_sess->Preauth_HashValue; 9702 } else { 9703 hash_value = sess->Preauth_HashValue; 9704 if (!hash_value) 9705 return; 9706 } 9707 ksmbd_gen_preauth_integrity_hash(conn, work->response_buf, 9708 hash_value); 9709 } 9710 } 9711 9712 static void fill_transform_hdr(void *tr_buf, char *old_buf, __le16 cipher_type) 9713 { 9714 struct smb2_transform_hdr *tr_hdr = tr_buf + 4; 9715 struct smb2_hdr *hdr = smb_get_msg(old_buf); 9716 unsigned int orig_len = get_rfc1002_len(old_buf); 9717 9718 /* tr_buf must be cleared by the caller */ 9719 tr_hdr->ProtocolId = SMB2_TRANSFORM_PROTO_NUM; 9720 tr_hdr->OriginalMessageSize = cpu_to_le32(orig_len); 9721 tr_hdr->Flags = cpu_to_le16(TRANSFORM_FLAG_ENCRYPTED); 9722 if (cipher_type == SMB2_ENCRYPTION_AES128_GCM || 9723 cipher_type == SMB2_ENCRYPTION_AES256_GCM) 9724 get_random_bytes(&tr_hdr->Nonce, SMB3_AES_GCM_NONCE); 9725 else 9726 get_random_bytes(&tr_hdr->Nonce, SMB3_AES_CCM_NONCE); 9727 memcpy(&tr_hdr->SessionId, &hdr->SessionId, 8); 9728 inc_rfc1001_len(tr_buf, sizeof(struct smb2_transform_hdr)); 9729 inc_rfc1001_len(tr_buf, orig_len); 9730 } 9731 9732 int smb3_encrypt_resp(struct ksmbd_work *work) 9733 { 9734 struct kvec *iov = work->iov; 9735 int rc = -ENOMEM; 9736 void *tr_buf; 9737 9738 tr_buf = kzalloc(sizeof(struct smb2_transform_hdr) + 4, KSMBD_DEFAULT_GFP); 9739 if (!tr_buf) 9740 return rc; 9741 9742 /* fill transform header */ 9743 fill_transform_hdr(tr_buf, work->response_buf, work->conn->cipher_type); 9744 9745 iov[0].iov_base = tr_buf; 9746 iov[0].iov_len = sizeof(struct smb2_transform_hdr) + 4; 9747 work->tr_buf = tr_buf; 9748 9749 return ksmbd_crypt_message(work, iov, work->iov_idx + 1, 1); 9750 } 9751 9752 bool smb3_is_transform_hdr(void *buf) 9753 { 9754 struct smb2_transform_hdr *trhdr = smb_get_msg(buf); 9755 9756 return trhdr->ProtocolId == SMB2_TRANSFORM_PROTO_NUM; 9757 } 9758 9759 int smb3_decrypt_req(struct ksmbd_work *work) 9760 { 9761 struct ksmbd_session *sess; 9762 char *buf = work->request_buf; 9763 unsigned int pdu_length = get_rfc1002_len(buf); 9764 struct kvec iov[2]; 9765 int buf_data_size = pdu_length - sizeof(struct smb2_transform_hdr); 9766 struct smb2_transform_hdr *tr_hdr = smb_get_msg(buf); 9767 int rc = 0; 9768 9769 if (pdu_length < sizeof(struct smb2_transform_hdr) || 9770 buf_data_size < sizeof(struct smb2_hdr)) { 9771 pr_err("Transform message is too small (%u)\n", 9772 pdu_length); 9773 return -ECONNABORTED; 9774 } 9775 9776 if (buf_data_size < le32_to_cpu(tr_hdr->OriginalMessageSize)) { 9777 pr_err("Transform message is broken\n"); 9778 return -ECONNABORTED; 9779 } 9780 9781 sess = ksmbd_session_lookup_all(work->conn, le64_to_cpu(tr_hdr->SessionId)); 9782 if (!sess) { 9783 pr_err("invalid session id(%llx) in transform header\n", 9784 le64_to_cpu(tr_hdr->SessionId)); 9785 return -ECONNABORTED; 9786 } 9787 ksmbd_user_session_put(sess); 9788 9789 iov[0].iov_base = buf; 9790 iov[0].iov_len = sizeof(struct smb2_transform_hdr) + 4; 9791 iov[1].iov_base = buf + sizeof(struct smb2_transform_hdr) + 4; 9792 iov[1].iov_len = buf_data_size; 9793 rc = ksmbd_crypt_message(work, iov, 2, 0); 9794 if (rc) 9795 return rc; 9796 9797 memmove(buf + 4, iov[1].iov_base, buf_data_size); 9798 *(__be32 *)buf = cpu_to_be32(buf_data_size); 9799 9800 return rc; 9801 } 9802 9803 bool smb3_11_final_sess_setup_resp(struct ksmbd_work *work) 9804 { 9805 struct ksmbd_conn *conn = work->conn; 9806 struct ksmbd_session *sess = work->sess; 9807 struct smb2_hdr *rsp = smb_get_msg(work->response_buf); 9808 9809 if (conn->dialect < SMB30_PROT_ID) 9810 return false; 9811 9812 if (work->next_smb2_rcv_hdr_off) 9813 rsp = ksmbd_resp_buf_next(work); 9814 9815 if (le16_to_cpu(rsp->Command) == SMB2_SESSION_SETUP_HE && 9816 sess->user && !user_guest(sess->user) && 9817 rsp->Status == STATUS_SUCCESS) 9818 return true; 9819 return false; 9820 } 9821