xref: /titanic_41/usr/src/uts/common/fs/smbsrv/smb_server.c (revision dc86508e0cf00a9f553cad05c9168a9ff8072dc6)
1 /*
2  * CDDL HEADER START
3  *
4  * The contents of this file are subject to the terms of the
5  * Common Development and Distribution License (the "License").
6  * You may not use this file except in compliance with the License.
7  *
8  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
9  * or http://www.opensolaris.org/os/licensing.
10  * See the License for the specific language governing permissions
11  * and limitations under the License.
12  *
13  * When distributing Covered Code, include this CDDL HEADER in each
14  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
15  * If applicable, add the following below this CDDL HEADER, with the
16  * fields enclosed by brackets "[]" replaced with your own identifying
17  * information: Portions Copyright [yyyy] [name of copyright owner]
18  *
19  * CDDL HEADER END
20  */
21 /*
22  * Copyright (c) 2008, 2010, Oracle and/or its affiliates. All rights reserved.
23  */
24 
25 /*
26  * General Structures Layout
27  * -------------------------
28  *
29  * This is a simplified diagram showing the relationship between most of the
30  * main structures.
31  *
32  * +-------------------+
33  * |     SMB_SERVER    |
34  * +-------------------+
35  *          |
36  *          |
37  *          v
38  * +-------------------+       +-------------------+      +-------------------+
39  * |     SESSION       |<----->|     SESSION       |......|      SESSION      |
40  * +-------------------+       +-------------------+      +-------------------+
41  *          |
42  *          |
43  *          v
44  * +-------------------+       +-------------------+      +-------------------+
45  * |       USER        |<----->|       USER        |......|       USER        |
46  * +-------------------+       +-------------------+      +-------------------+
47  *          |
48  *          |
49  *          v
50  * +-------------------+       +-------------------+      +-------------------+
51  * |       TREE        |<----->|       TREE        |......|       TREE        |
52  * +-------------------+       +-------------------+      +-------------------+
53  *      |         |
54  *      |         |
55  *      |         v
56  *      |     +-------+       +-------+      +-------+
57  *      |     | OFILE |<----->| OFILE |......| OFILE |
58  *      |     +-------+       +-------+      +-------+
59  *      |
60  *      |
61  *      v
62  *  +-------+       +------+      +------+
63  *  | ODIR  |<----->| ODIR |......| ODIR |
64  *  +-------+       +------+      +------+
65  *
66  *
67  * Module Interface Overview
68  * -------------------------
69  *
70  *
71  *	    +===================================+
72  *	    |		 smbd daemon		|
73  *	    +===================================+
74  *	      |		     |		      ^
75  *	      |		     |		      |
76  * User	      |		     |		      |
77  * -----------|--------------|----------------|--------------------------------
78  * Kernel     |		     |		      |
79  *            |		     |		      |
80  *	      |		     |		      |
81  *  +=========|==============|================|=================+
82  *  |	      v		     v		      |			|
83  *  | +-----------+ +--------------------+ +------------------+ |
84  *  | |     IO    | | Kernel Door Server | | User Door Servers|	|
85  *  | | Interface | |     Interface      | |   Interface      | |
86  *  | +-----------+ +--------------------+ +------------------+ |
87  *  |		|	     |		      ^		^	|
88  *  |		v	     v		      |		|	|    +=========+
89  *  |	     +-----------------------------------+	|	|    |	       |
90  *  |	     + SMB Server Management (this file) |<------------------|	 ZFS   |
91  *  |	     +-----------------------------------+	|	|    |	       |
92  *  |							|	|    |  Module |
93  *  |	     +-----------------------------------+	|	|    |	       |
94  *  |	     +     SMB Server Internal Layers    |------+	|    +=========+
95  *  |	     +-----------------------------------+		|
96  *  |								|
97  *  |								|
98  *  +===========================================================+
99  *
100  *
101  * Server State Machine
102  * --------------------
103  *                                  |
104  *                                  | T0
105  *                                  |
106  *                                  v
107  *                    +-----------------------------+
108  *		      |   SMB_SERVER_STATE_CREATED  |
109  *		      +-----------------------------+
110  *				    |
111  *				    | T1
112  *				    |
113  *				    v
114  *		      +-----------------------------+
115  *		      | SMB_SERVER_STATE_CONFIGURED |
116  *		      +-----------------------------+
117  *				    |
118  *				    | T2
119  *				    |
120  *				    v
121  *		      +-----------------------------+
122  *		      |  SMB_SERVER_STATE_RUNNING / |
123  *		      |  SMB_SERVER_STATE_STOPPING  |
124  *		      +-----------------------------+
125  *				    |
126  *				    | T3
127  *				    |
128  *				    v
129  *		      +-----------------------------+
130  *		      |  SMB_SERVER_STATE_DELETING  |
131  *                    +-----------------------------+
132  *				    |
133  *				    |
134  *				    |
135  *				    v
136  *
137  * States
138  * ------
139  *
140  * SMB_SERVER_STATE_CREATED
141  *
142  *    This is the state of the server just after creation.
143  *
144  * SMB_SERVER_STATE_CONFIGURED
145  *
146  *    The server has been configured.
147  *
148  * SMB_SERVER_STATE_RUNNING
149  *
150  *    The server has been started. While in this state the threads listening on
151  *    the sockets are started.
152  *
153  *    When a client establishes a connection the thread listening dispatches
154  *    a task with the new session as an argument. If the dispatch fails the new
155  *    session context is destroyed.
156  *
157  * SMB_SERVER_STATE_STOPPING
158  *
159  *    The threads listening on the NBT and TCP sockets are being terminated.
160  *
161  *
162  * Transitions
163  * -----------
164  *
165  * Transition T0
166  *
167  *    The daemon smbd triggers its creation by opening the smbsrv device. If
168  *    the zone where the daemon lives doesn't have an smb server yet it is
169  *    created.
170  *
171  *		smb_drv_open() --> smb_server_create()
172  *
173  * Transition T1
174  *
175  *    This transition occurs in smb_server_configure(). It is triggered by the
176  *    daemon through an Ioctl.
177  *
178  *	smb_drv_ioctl(SMB_IOC_CONFIG) --> smb_server_configure()
179  *
180  * Transition T2
181  *
182  *    This transition occurs in smb_server_start(). It is triggered by the
183  *    daemon through an Ioctl.
184  *
185  *	smb_drv_ioctl(SMB_IOC_START) --> smb_server_start()
186  *
187  * Transition T3
188  *
189  *    This transition occurs in smb_server_delete(). It is triggered by the
190  *    daemon when closing the smbsrv device
191  *
192  *		smb_drv_close() --> smb_server_delete()
193  *
194  * Comments
195  * --------
196  *
197  * This files assumes that there will one SMB server per zone. For now the
198  * smb server works only in global zone. There's nothing in this file preventing
199  * an smb server from being created in a non global zone. That limitation is
200  * enforced in user space.
201  */
202 
203 #include <sys/strsubr.h>
204 #include <sys/cmn_err.h>
205 #include <sys/priv.h>
206 #include <sys/socketvar.h>
207 #include <sys/zone.h>
208 #include <netinet/in.h>
209 #include <netinet/in_systm.h>
210 #include <netinet/ip.h>
211 #include <netinet/ip_icmp.h>
212 #include <netinet/ip_var.h>
213 #include <netinet/tcp.h>
214 #include <smbsrv/smb_kproto.h>
215 #include <smbsrv/string.h>
216 #include <smbsrv/netbios.h>
217 #include <smbsrv/smb_fsops.h>
218 #include <smbsrv/smb_share.h>
219 #include <smbsrv/smb_door.h>
220 #include <smbsrv/smb_kstat.h>
221 
222 extern void smb_reply_notify_change_request(smb_request_t *);
223 
224 typedef struct {
225 	smb_listener_daemon_t	*ra_listener;
226 	smb_session_t		*ra_session;
227 } smb_receiver_arg_t;
228 
229 static void smb_server_kstat_init(smb_server_t *);
230 static void smb_server_kstat_fini(smb_server_t *);
231 static void smb_server_timers(smb_thread_t *, void *);
232 static int smb_server_lookup(smb_server_t **);
233 static void smb_server_release(smb_server_t *);
234 static void smb_server_store_cfg(smb_server_t *, smb_ioc_cfg_t *);
235 static void smb_server_shutdown(smb_server_t *);
236 static int smb_server_fsop_start(smb_server_t *);
237 static void smb_server_fsop_stop(smb_server_t *);
238 static void smb_event_cancel(smb_server_t *, uint32_t);
239 static uint32_t smb_event_alloc_txid(void);
240 
241 static void smb_server_disconnect_share(smb_llist_t *, const char *);
242 static void smb_server_enum_private(smb_llist_t *, smb_svcenum_t *);
243 static int smb_server_session_disconnect(smb_llist_t *, const char *,
244     const char *);
245 static int smb_server_fclose(smb_llist_t *, uint32_t);
246 static int smb_server_kstat_update(kstat_t *, int);
247 static int smb_server_legacy_kstat_update(kstat_t *, int);
248 static void smb_server_listener_init(smb_server_t *, smb_listener_daemon_t *,
249     char *, in_port_t, int);
250 static void smb_server_listener_destroy(smb_listener_daemon_t *);
251 static int smb_server_listener_start(smb_listener_daemon_t *);
252 static void smb_server_listener_stop(smb_listener_daemon_t *);
253 static void smb_server_listener(smb_thread_t *, void *);
254 static void smb_server_receiver(void *);
255 static void smb_server_create_session(smb_listener_daemon_t *, ksocket_t);
256 static void smb_server_destroy_session(smb_listener_daemon_t *,
257     smb_session_t *);
258 
259 int smb_event_debug = 0;
260 
261 static smb_llist_t	smb_servers;
262 
263 /*
264  * *****************************************************************************
265  * **************** Functions called from the device interface *****************
266  * *****************************************************************************
267  *
268  * These functions typically have to determine the relevant smb server
269  * to which the call applies.
270  */
271 
272 /*
273  * smb_server_svc_init
274  *
275  * This function must be called from smb_drv_attach().
276  */
277 int
278 smb_server_svc_init(void)
279 {
280 	int	rc = 0;
281 
282 	while (rc == 0) {
283 		if (rc = smb_mbc_init())
284 			continue;
285 		if (rc = smb_vop_init())
286 			continue;
287 		if (rc = smb_node_init())
288 			continue;
289 		if (rc = smb_oplock_init())
290 			continue;
291 		if (rc = smb_fem_init())
292 			continue;
293 		if (rc = smb_notify_init())
294 			continue;
295 		if (rc = smb_net_init())
296 			continue;
297 		smb_llist_init();
298 		smb_llist_constructor(&smb_servers, sizeof (smb_server_t),
299 		    offsetof(smb_server_t, sv_lnd));
300 		return (0);
301 	}
302 
303 	smb_llist_fini();
304 	smb_net_fini();
305 	smb_notify_fini();
306 	smb_fem_fini();
307 	smb_node_fini();
308 	smb_vop_fini();
309 	smb_mbc_fini();
310 	return (rc);
311 }
312 
313 /*
314  * smb_server_svc_fini
315  *
316  * This function must called from smb_drv_detach(). It will fail if servers
317  * still exist.
318  */
319 int
320 smb_server_svc_fini(void)
321 {
322 	int	rc = EBUSY;
323 
324 	if (smb_llist_get_count(&smb_servers) == 0) {
325 		smb_llist_fini();
326 		smb_net_fini();
327 		smb_notify_fini();
328 		smb_fem_fini();
329 		smb_node_fini();
330 		smb_oplock_fini();
331 		smb_vop_fini();
332 		smb_mbc_fini();
333 		smb_llist_destructor(&smb_servers);
334 		rc = 0;
335 	}
336 	return (rc);
337 }
338 
339 /*
340  * smb_server_create
341  *
342  * This function will fail if there's already a server associated with the
343  * caller's zone.
344  */
345 int
346 smb_server_create(void)
347 {
348 	zoneid_t	zid;
349 	smb_server_t	*sv;
350 
351 	zid = getzoneid();
352 
353 	smb_llist_enter(&smb_servers, RW_WRITER);
354 	sv = smb_llist_head(&smb_servers);
355 	while (sv) {
356 		SMB_SERVER_VALID(sv);
357 		if (sv->sv_zid == zid) {
358 			smb_llist_exit(&smb_servers);
359 			return (EPERM);
360 		}
361 		sv = smb_llist_next(&smb_servers, sv);
362 	}
363 
364 	sv = kmem_zalloc(sizeof (smb_server_t), KM_NOSLEEP);
365 	if (sv == NULL) {
366 		smb_llist_exit(&smb_servers);
367 		return (ENOMEM);
368 	}
369 
370 	smb_llist_constructor(&sv->sv_opipe_list, sizeof (smb_opipe_t),
371 	    offsetof(smb_opipe_t, p_lnd));
372 
373 	smb_llist_constructor(&sv->sv_event_list, sizeof (smb_event_t),
374 	    offsetof(smb_event_t, se_lnd));
375 
376 	smb_llist_constructor(&sv->sp_info.sp_list, sizeof (smb_kspooldoc_t),
377 	    offsetof(smb_kspooldoc_t, sd_lnd));
378 
379 	smb_llist_constructor(&sv->sp_info.sp_fidlist,
380 	    sizeof (smb_spoolfid_t), offsetof(smb_spoolfid_t, sf_lnd));
381 
382 	sv->si_cache_request = kmem_cache_create("smb_request_cache",
383 	    sizeof (smb_request_t), 8, NULL, NULL, NULL, NULL, NULL, 0);
384 	sv->si_cache_session = kmem_cache_create("smb_session_cache",
385 	    sizeof (smb_session_t), 8, NULL, NULL, NULL, NULL, NULL, 0);
386 	sv->si_cache_user = kmem_cache_create("smb_user_cache",
387 	    sizeof (smb_user_t), 8, NULL, NULL, NULL, NULL, NULL, 0);
388 	sv->si_cache_tree = kmem_cache_create("smb_tree_cache",
389 	    sizeof (smb_tree_t), 8, NULL, NULL, NULL, NULL, NULL, 0);
390 	sv->si_cache_ofile = kmem_cache_create("smb_ofile_cache",
391 	    sizeof (smb_ofile_t), 8, NULL, NULL, NULL, NULL, NULL, 0);
392 	sv->si_cache_odir = kmem_cache_create("smb_odir_cache",
393 	    sizeof (smb_odir_t), 8, NULL, NULL, NULL, NULL, NULL, 0);
394 	sv->si_cache_opipe = kmem_cache_create("smb_opipe_cache",
395 	    sizeof (smb_opipe_t), 8, NULL, NULL, NULL, NULL, NULL, 0);
396 	sv->si_cache_event = kmem_cache_create("smb_event_cache",
397 	    sizeof (smb_event_t), 8, NULL, NULL, NULL, NULL, NULL, 0);
398 
399 	smb_thread_init(&sv->si_thread_timers,
400 	    "smb_timers", smb_server_timers, sv);
401 
402 	sv->sv_pid = curproc->p_pid;
403 	smb_srqueue_init(&sv->sv_srqueue);
404 
405 	smb_kdoor_init();
406 	smb_opipe_door_init();
407 	smb_server_kstat_init(sv);
408 
409 	mutex_init(&sv->sv_mutex, NULL, MUTEX_DEFAULT, NULL);
410 	mutex_init(&sv->sp_info.sp_mutex, NULL, MUTEX_DEFAULT, NULL);
411 	cv_init(&sv->sv_cv, NULL, CV_DEFAULT, NULL);
412 	cv_init(&sv->sp_info.sp_cv, NULL, CV_DEFAULT, NULL);
413 
414 	sv->sv_state = SMB_SERVER_STATE_CREATED;
415 	sv->sv_magic = SMB_SERVER_MAGIC;
416 	sv->sv_zid = zid;
417 
418 	smb_llist_insert_tail(&smb_servers, sv);
419 	smb_llist_exit(&smb_servers);
420 
421 	smb_threshold_init(&sv->sv_ssetup_ct, SMB_SSETUP_CMD,
422 	    smb_ssetup_threshold, smb_ssetup_timeout);
423 	smb_threshold_init(&sv->sv_tcon_ct, SMB_TCON_CMD, smb_tcon_threshold,
424 	    smb_tcon_timeout);
425 	smb_threshold_init(&sv->sv_opipe_ct, SMB_OPIPE_CMD, smb_opipe_threshold,
426 	    smb_opipe_timeout);
427 
428 	return (0);
429 }
430 
431 /*
432  * smb_server_delete
433  *
434  * This function will delete the server passed in. It will make sure that all
435  * activity associated that server has ceased before destroying it.
436  */
437 int
438 smb_server_delete(void)
439 {
440 	smb_server_t	*sv;
441 	int		rc;
442 
443 	rc = smb_server_lookup(&sv);
444 	if (rc != 0)
445 		return (rc);
446 
447 	smb_threshold_fini(&sv->sv_ssetup_ct);
448 	smb_threshold_fini(&sv->sv_tcon_ct);
449 	smb_threshold_fini(&sv->sv_opipe_ct);
450 
451 	mutex_enter(&sv->sv_mutex);
452 	switch (sv->sv_state) {
453 	case SMB_SERVER_STATE_RUNNING:
454 		sv->sv_state = SMB_SERVER_STATE_STOPPING;
455 		mutex_exit(&sv->sv_mutex);
456 		smb_server_shutdown(sv);
457 		mutex_enter(&sv->sv_mutex);
458 		cv_broadcast(&sv->sp_info.sp_cv);
459 		sv->sv_state = SMB_SERVER_STATE_DELETING;
460 		break;
461 	case SMB_SERVER_STATE_STOPPING:
462 		sv->sv_state = SMB_SERVER_STATE_DELETING;
463 		break;
464 	case SMB_SERVER_STATE_CONFIGURED:
465 	case SMB_SERVER_STATE_CREATED:
466 		sv->sv_state = SMB_SERVER_STATE_DELETING;
467 		break;
468 	default:
469 		SMB_SERVER_STATE_VALID(sv->sv_state);
470 		mutex_exit(&sv->sv_mutex);
471 		smb_server_release(sv);
472 		return (ENOTTY);
473 	}
474 
475 	ASSERT(sv->sv_state == SMB_SERVER_STATE_DELETING);
476 
477 	sv->sv_refcnt--;
478 	while (sv->sv_refcnt)
479 		cv_wait(&sv->sv_cv, &sv->sv_mutex);
480 
481 	mutex_exit(&sv->sv_mutex);
482 
483 	smb_llist_enter(&smb_servers, RW_WRITER);
484 	smb_llist_remove(&smb_servers, sv);
485 	smb_llist_exit(&smb_servers);
486 
487 	smb_server_listener_destroy(&sv->sv_nbt_daemon);
488 	smb_server_listener_destroy(&sv->sv_tcp_daemon);
489 	rw_destroy(&sv->sv_cfg_lock);
490 	smb_opipe_door_fini();
491 	smb_kdoor_fini();
492 	smb_server_kstat_fini(sv);
493 	smb_llist_destructor(&sv->sv_opipe_list);
494 	smb_llist_destructor(&sv->sv_event_list);
495 
496 	kmem_cache_destroy(sv->si_cache_request);
497 	kmem_cache_destroy(sv->si_cache_session);
498 	kmem_cache_destroy(sv->si_cache_user);
499 	kmem_cache_destroy(sv->si_cache_tree);
500 	kmem_cache_destroy(sv->si_cache_ofile);
501 	kmem_cache_destroy(sv->si_cache_odir);
502 	kmem_cache_destroy(sv->si_cache_opipe);
503 	kmem_cache_destroy(sv->si_cache_event);
504 
505 	smb_srqueue_destroy(&sv->sv_srqueue);
506 
507 	smb_thread_destroy(&sv->si_thread_timers);
508 	mutex_destroy(&sv->sv_mutex);
509 	cv_destroy(&sv->sv_cv);
510 	sv->sv_magic = 0;
511 	kmem_free(sv, sizeof (smb_server_t));
512 
513 	return (0);
514 }
515 
516 /*
517  * smb_server_configure
518  */
519 int
520 smb_server_configure(smb_ioc_cfg_t *ioc)
521 {
522 	int		rc = 0;
523 	smb_server_t	*sv;
524 
525 	rc = smb_server_lookup(&sv);
526 	if (rc)
527 		return (rc);
528 
529 	mutex_enter(&sv->sv_mutex);
530 	switch (sv->sv_state) {
531 	case SMB_SERVER_STATE_CREATED:
532 		smb_server_store_cfg(sv, ioc);
533 		sv->sv_state = SMB_SERVER_STATE_CONFIGURED;
534 		break;
535 
536 	case SMB_SERVER_STATE_CONFIGURED:
537 		smb_server_store_cfg(sv, ioc);
538 		break;
539 
540 	case SMB_SERVER_STATE_RUNNING:
541 	case SMB_SERVER_STATE_STOPPING:
542 		rw_enter(&sv->sv_cfg_lock, RW_WRITER);
543 		smb_server_store_cfg(sv, ioc);
544 		rw_exit(&sv->sv_cfg_lock);
545 		break;
546 
547 	default:
548 		SMB_SERVER_STATE_VALID(sv->sv_state);
549 		rc = EFAULT;
550 		break;
551 	}
552 	mutex_exit(&sv->sv_mutex);
553 
554 	smb_server_release(sv);
555 
556 	return (rc);
557 }
558 
559 /*
560  * smb_server_start
561  */
562 int
563 smb_server_start(smb_ioc_start_t *ioc)
564 {
565 	int		rc = 0;
566 	int		family;
567 	smb_server_t	*sv;
568 
569 	rc = smb_server_lookup(&sv);
570 	if (rc)
571 		return (rc);
572 
573 	mutex_enter(&sv->sv_mutex);
574 	switch (sv->sv_state) {
575 	case SMB_SERVER_STATE_CONFIGURED:
576 		smb_codepage_init();
577 
578 		sv->sv_worker_pool = taskq_create("smb_workers",
579 		    sv->sv_cfg.skc_maxworkers, SMB_WORKER_PRIORITY,
580 		    sv->sv_cfg.skc_maxworkers, INT_MAX,
581 		    TASKQ_DYNAMIC|TASKQ_PREPOPULATE);
582 
583 		sv->sv_receiver_pool = taskq_create("smb_receivers",
584 		    sv->sv_cfg.skc_maxconnections, SMB_WORKER_PRIORITY,
585 		    sv->sv_cfg.skc_maxconnections, INT_MAX,
586 		    TASKQ_DYNAMIC);
587 
588 		sv->sv_session = smb_session_create(NULL, 0, sv, 0);
589 
590 		if (sv->sv_worker_pool == NULL || sv->sv_session == NULL) {
591 			rc = ENOMEM;
592 			break;
593 		}
594 
595 		if (rc = smb_server_fsop_start(sv))
596 			break;
597 		ASSERT(sv->sv_lmshrd == NULL);
598 		sv->sv_lmshrd = smb_kshare_door_init(ioc->lmshrd);
599 		if (sv->sv_lmshrd == NULL)
600 			break;
601 		if (rc = smb_kdoor_open(ioc->udoor)) {
602 			cmn_err(CE_WARN, "Cannot open smbd door");
603 			break;
604 		}
605 		if (rc = smb_opipe_door_open(ioc->opipe)) {
606 			cmn_err(CE_WARN, "Cannot open opipe door");
607 			break;
608 		}
609 		if (rc = smb_thread_start(&sv->si_thread_timers))
610 			break;
611 
612 		family = AF_INET;
613 		smb_server_listener_init(sv, &sv->sv_nbt_daemon,
614 		    "smb_nbt_listener", IPPORT_NETBIOS_SSN, family);
615 		if (sv->sv_cfg.skc_ipv6_enable)
616 			family = AF_INET6;
617 		smb_server_listener_init(sv, &sv->sv_tcp_daemon,
618 		    "smb_tcp_listener", IPPORT_SMB, family);
619 		rc = smb_server_listener_start(&sv->sv_nbt_daemon);
620 		if (rc != 0)
621 			break;
622 		rc = smb_server_listener_start(&sv->sv_tcp_daemon);
623 		if (rc != 0)
624 			break;
625 
626 		sv->sv_state = SMB_SERVER_STATE_RUNNING;
627 		sv->sv_start_time = gethrtime();
628 		mutex_exit(&sv->sv_mutex);
629 		smb_server_release(sv);
630 		smb_export_start();
631 		return (0);
632 	default:
633 		SMB_SERVER_STATE_VALID(sv->sv_state);
634 		mutex_exit(&sv->sv_mutex);
635 		smb_server_release(sv);
636 		return (ENOTTY);
637 	}
638 
639 	mutex_exit(&sv->sv_mutex);
640 	smb_server_shutdown(sv);
641 	smb_server_release(sv);
642 	return (rc);
643 }
644 
645 /*
646  * An smbd is shutting down.
647  */
648 int
649 smb_server_stop(void)
650 {
651 	smb_server_t	*sv;
652 	int		rc;
653 
654 	if ((rc = smb_server_lookup(&sv)) != 0)
655 		return (rc);
656 
657 	mutex_enter(&sv->sv_mutex);
658 	switch (sv->sv_state) {
659 	case SMB_SERVER_STATE_RUNNING:
660 		sv->sv_state = SMB_SERVER_STATE_STOPPING;
661 		mutex_exit(&sv->sv_mutex);
662 		smb_server_shutdown(sv);
663 		mutex_enter(&sv->sv_mutex);
664 		cv_broadcast(&sv->sp_info.sp_cv);
665 		break;
666 	default:
667 		SMB_SERVER_STATE_VALID(sv->sv_state);
668 		break;
669 	}
670 	mutex_exit(&sv->sv_mutex);
671 
672 	smb_server_release(sv);
673 	return (0);
674 }
675 
676 boolean_t
677 smb_server_is_stopping(void)
678 {
679 	smb_server_t    *sv;
680 	boolean_t	status;
681 
682 	if (smb_server_lookup(&sv) != 0)
683 		return (B_TRUE);
684 
685 	SMB_SERVER_VALID(sv);
686 
687 	mutex_enter(&sv->sv_mutex);
688 
689 	switch (sv->sv_state) {
690 	case SMB_SERVER_STATE_STOPPING:
691 	case SMB_SERVER_STATE_DELETING:
692 		status = B_TRUE;
693 		break;
694 	default:
695 		status = B_FALSE;
696 		break;
697 	}
698 
699 	mutex_exit(&sv->sv_mutex);
700 	smb_server_release(sv);
701 	return (status);
702 }
703 
704 int
705 smb_server_cancel_event(uint32_t txid)
706 {
707 	smb_server_t	*sv;
708 	int		rc;
709 
710 	if ((rc = smb_server_lookup(&sv)) == 0) {
711 		smb_event_cancel(sv, txid);
712 		smb_server_release(sv);
713 	}
714 
715 	return (rc);
716 }
717 
718 int
719 smb_server_notify_event(smb_ioc_event_t *ioc)
720 {
721 	smb_server_t	*sv;
722 	int		rc;
723 
724 	if ((rc = smb_server_lookup(&sv)) == 0) {
725 		smb_event_notify(sv, ioc->txid);
726 		smb_server_release(sv);
727 	}
728 
729 	return (rc);
730 }
731 
732 /*
733  * smb_server_spooldoc
734  *
735  * Waits for print file close broadcast.
736  * Gets the head of the fid list,
737  * then searches the spooldoc list and returns
738  * this info via the ioctl to user land.
739  *
740  * rc - 0 success
741  */
742 
743 int
744 smb_server_spooldoc(smb_ioc_spooldoc_t *ioc)
745 {
746 	smb_server_t	*sv;
747 	int		rc;
748 	smb_kspooldoc_t *spdoc;
749 	uint16_t	fid;
750 
751 	if ((rc = smb_server_lookup(&sv)) == 0) {
752 		if (sv->sv_state != SMB_SERVER_STATE_RUNNING) {
753 			smb_server_release(sv);
754 			return (ECANCELED);
755 		}
756 		mutex_enter(&sv->sp_info.sp_mutex);
757 		spdoc = kmem_zalloc(sizeof (smb_kspooldoc_t), KM_SLEEP);
758 		cv_wait(&sv->sp_info.sp_cv, &sv->sp_info.sp_mutex);
759 		if (sv->sv_state != SMB_SERVER_STATE_RUNNING)
760 			rc = ECANCELED;
761 		else {
762 			fid = smb_spool_get_fid();
763 			atomic_inc_32(&sv->sp_info.sp_cnt);
764 			if (smb_spool_lookup_doc_byfid(fid, spdoc)) {
765 				ioc->spool_num = spdoc->sd_spool_num;
766 				ioc->ipaddr = spdoc->sd_ipaddr;
767 				(void) strlcpy(ioc->path, spdoc->sd_path,
768 				    MAXPATHLEN);
769 				(void) strlcpy(ioc->username,
770 				    spdoc->sd_username, MAXNAMELEN);
771 			}
772 		}
773 		kmem_free(spdoc, sizeof (smb_kspooldoc_t));
774 		mutex_exit(&sv->sp_info.sp_mutex);
775 		smb_server_release(sv);
776 	}
777 	return (rc);
778 }
779 
780 int
781 smb_server_set_gmtoff(smb_ioc_gmt_t *ioc)
782 {
783 	int		rc;
784 	smb_server_t	*sv;
785 
786 	if ((rc = smb_server_lookup(&sv)) == 0) {
787 		sv->si_gmtoff = ioc->offset;
788 		smb_server_release(sv);
789 	}
790 
791 	return (rc);
792 }
793 
794 int
795 smb_server_numopen(smb_ioc_opennum_t *ioc)
796 {
797 	smb_server_t	*sv;
798 	int		rc;
799 
800 	if ((rc = smb_server_lookup(&sv)) == 0) {
801 		ioc->open_users = sv->sv_users;
802 		ioc->open_trees = sv->sv_trees;
803 		ioc->open_files = sv->sv_files + sv->sv_pipes;
804 		smb_server_release(sv);
805 	}
806 	return (rc);
807 }
808 
809 /*
810  * Enumerate objects within the server.  The svcenum provides the
811  * enumeration context, i.e. what the caller want to get back.
812  */
813 int
814 smb_server_enum(smb_ioc_svcenum_t *ioc)
815 {
816 	smb_svcenum_t	*svcenum = &ioc->svcenum;
817 	smb_server_t	*sv;
818 	int		rc;
819 
820 	switch (svcenum->se_type) {
821 	case SMB_SVCENUM_TYPE_USER:
822 	case SMB_SVCENUM_TYPE_TREE:
823 	case SMB_SVCENUM_TYPE_FILE:
824 		break;
825 	default:
826 		return (EINVAL);
827 	}
828 
829 	if ((rc = smb_server_lookup(&sv)) != 0)
830 		return (rc);
831 
832 	svcenum->se_bavail = svcenum->se_buflen;
833 	svcenum->se_bused = 0;
834 	svcenum->se_nitems = 0;
835 
836 	smb_server_enum_private(&sv->sv_nbt_daemon.ld_session_list, svcenum);
837 	smb_server_enum_private(&sv->sv_tcp_daemon.ld_session_list, svcenum);
838 
839 	smb_server_release(sv);
840 	return (0);
841 }
842 
843 /*
844  * Look for sessions to disconnect by client and user name.
845  */
846 int
847 smb_server_session_close(smb_ioc_session_t *ioc)
848 {
849 	smb_llist_t	*ll;
850 	smb_server_t	*sv;
851 	int		nbt_cnt;
852 	int		tcp_cnt;
853 	int		rc;
854 
855 	if ((rc = smb_server_lookup(&sv)) != 0)
856 		return (rc);
857 
858 	ll = &sv->sv_nbt_daemon.ld_session_list;
859 	nbt_cnt = smb_server_session_disconnect(ll, ioc->client, ioc->username);
860 
861 	ll = &sv->sv_tcp_daemon.ld_session_list;
862 	tcp_cnt = smb_server_session_disconnect(ll, ioc->client, ioc->username);
863 
864 	smb_server_release(sv);
865 
866 	if ((nbt_cnt == 0) && (tcp_cnt == 0))
867 		return (ENOENT);
868 	return (0);
869 }
870 
871 /*
872  * Close a file by uniqid.
873  */
874 int
875 smb_server_file_close(smb_ioc_fileid_t *ioc)
876 {
877 	uint32_t	uniqid = ioc->uniqid;
878 	smb_llist_t	*ll;
879 	smb_server_t	*sv;
880 	int		rc;
881 
882 	if ((rc = smb_server_lookup(&sv)) != 0)
883 		return (rc);
884 
885 	ll = &sv->sv_nbt_daemon.ld_session_list;
886 	rc = smb_server_fclose(ll, uniqid);
887 
888 	if (rc == ENOENT) {
889 		ll = &sv->sv_tcp_daemon.ld_session_list;
890 		rc = smb_server_fclose(ll, uniqid);
891 	}
892 
893 	smb_server_release(sv);
894 	return (rc);
895 }
896 
897 /*
898  * These functions determine the relevant smb server to which the call apply.
899  */
900 
901 uint32_t
902 smb_server_get_session_count(void)
903 {
904 	smb_server_t	*sv;
905 	uint32_t	counter = 0;
906 
907 	if (smb_server_lookup(&sv))
908 		return (0);
909 
910 	counter = smb_llist_get_count(&sv->sv_nbt_daemon.ld_session_list);
911 	counter += smb_llist_get_count(&sv->sv_tcp_daemon.ld_session_list);
912 
913 	smb_server_release(sv);
914 
915 	return (counter);
916 }
917 
918 /*
919  * Gets the vnode of the specified share path.
920  *
921  * A hold on the returned vnode pointer is taken so the caller
922  * must call VN_RELE.
923  */
924 int
925 smb_server_sharevp(const char *shr_path, vnode_t **vp)
926 {
927 	smb_server_t	*sv;
928 	smb_request_t	*sr;
929 	smb_node_t	*fnode = NULL;
930 	smb_node_t	*dnode;
931 	char		last_comp[MAXNAMELEN];
932 	int		rc = 0;
933 
934 	ASSERT(shr_path);
935 
936 	if ((rc = smb_server_lookup(&sv)))
937 		return (rc);
938 
939 	mutex_enter(&sv->sv_mutex);
940 	switch (sv->sv_state) {
941 	case SMB_SERVER_STATE_RUNNING:
942 		break;
943 	default:
944 		mutex_exit(&sv->sv_mutex);
945 		smb_server_release(sv);
946 		return (ENOTACTIVE);
947 	}
948 	mutex_exit(&sv->sv_mutex);
949 
950 	if ((sr = smb_request_alloc(sv->sv_session, 0)) == NULL) {
951 		smb_server_release(sv);
952 		return (ENOMEM);
953 	}
954 	sr->user_cr = kcred;
955 
956 	rc = smb_pathname_reduce(sr, sr->user_cr, shr_path,
957 	    NULL, NULL, &dnode, last_comp);
958 
959 	if (rc == 0) {
960 		rc = smb_fsop_lookup(sr, sr->user_cr, SMB_FOLLOW_LINKS,
961 		    sv->si_root_smb_node, dnode, last_comp, &fnode);
962 		smb_node_release(dnode);
963 	}
964 
965 	smb_request_free(sr);
966 	smb_server_release(sv);
967 
968 	if (rc != 0)
969 		return (rc);
970 
971 	ASSERT(fnode->vp && fnode->vp->v_vfsp);
972 
973 	VN_HOLD(fnode->vp);
974 	*vp = fnode->vp;
975 
976 	smb_node_release(fnode);
977 
978 	return (0);
979 }
980 
981 
982 /*
983  * This is a special interface that will be utilized by ZFS to cause a share to
984  * be added/removed.
985  *
986  * arg is either a lmshare_info_t or share_name from userspace.
987  * It will need to be copied into the kernel.   It is lmshare_info_t
988  * for add operations and share_name for delete operations.
989  */
990 int
991 smb_server_share(void *arg, boolean_t add_share)
992 {
993 	smb_server_t	*sv;
994 	int		rc;
995 
996 	if ((rc = smb_server_lookup(&sv)) == 0) {
997 		mutex_enter(&sv->sv_mutex);
998 		switch (sv->sv_state) {
999 		case SMB_SERVER_STATE_RUNNING:
1000 			mutex_exit(&sv->sv_mutex);
1001 			(void) smb_kshare_upcall(sv->sv_lmshrd, arg, add_share);
1002 			break;
1003 		default:
1004 			mutex_exit(&sv->sv_mutex);
1005 			break;
1006 		}
1007 		smb_server_release(sv);
1008 	}
1009 
1010 	return (rc);
1011 }
1012 
1013 int
1014 smb_server_unshare(const char *sharename)
1015 {
1016 	smb_server_t	*sv;
1017 	smb_llist_t	*ll;
1018 	int		rc;
1019 
1020 	if ((rc = smb_server_lookup(&sv)))
1021 		return (rc);
1022 
1023 	mutex_enter(&sv->sv_mutex);
1024 	switch (sv->sv_state) {
1025 	case SMB_SERVER_STATE_RUNNING:
1026 	case SMB_SERVER_STATE_STOPPING:
1027 		break;
1028 	default:
1029 		mutex_exit(&sv->sv_mutex);
1030 		smb_server_release(sv);
1031 		return (ENOTACTIVE);
1032 	}
1033 	mutex_exit(&sv->sv_mutex);
1034 
1035 	ll = &sv->sv_nbt_daemon.ld_session_list;
1036 	smb_server_disconnect_share(ll, sharename);
1037 
1038 	ll = &sv->sv_tcp_daemon.ld_session_list;
1039 	smb_server_disconnect_share(ll, sharename);
1040 
1041 	smb_server_release(sv);
1042 	return (0);
1043 }
1044 
1045 /*
1046  * Disconnect the specified share.
1047  * Typically called when a share has been removed.
1048  */
1049 static void
1050 smb_server_disconnect_share(smb_llist_t *ll, const char *sharename)
1051 {
1052 	smb_session_t	*session;
1053 
1054 	smb_llist_enter(ll, RW_READER);
1055 
1056 	session = smb_llist_head(ll);
1057 	while (session) {
1058 		SMB_SESSION_VALID(session);
1059 		smb_rwx_rwenter(&session->s_lock, RW_READER);
1060 		switch (session->s_state) {
1061 		case SMB_SESSION_STATE_NEGOTIATED:
1062 		case SMB_SESSION_STATE_OPLOCK_BREAKING:
1063 		case SMB_SESSION_STATE_WRITE_RAW_ACTIVE:
1064 			smb_session_disconnect_share(session, sharename);
1065 			break;
1066 		default:
1067 			break;
1068 		}
1069 		smb_rwx_rwexit(&session->s_lock);
1070 		session = smb_llist_next(ll, session);
1071 	}
1072 
1073 	smb_llist_exit(ll);
1074 }
1075 
1076 /*
1077  * *****************************************************************************
1078  * **************** Functions called from the internal layers ******************
1079  * *****************************************************************************
1080  *
1081  * These functions are provided the relevant smb server by the caller.
1082  */
1083 
1084 void
1085 smb_server_reconnection_check(smb_server_t *sv, smb_session_t *session)
1086 {
1087 	ASSERT(sv == session->s_server);
1088 
1089 	smb_session_reconnection_check(&sv->sv_nbt_daemon.ld_session_list,
1090 	    session);
1091 	smb_session_reconnection_check(&sv->sv_tcp_daemon.ld_session_list,
1092 	    session);
1093 }
1094 
1095 void
1096 smb_server_get_cfg(smb_server_t *sv, smb_kmod_cfg_t *cfg)
1097 {
1098 	rw_enter(&sv->sv_cfg_lock, RW_READER);
1099 	bcopy(&sv->sv_cfg, cfg, sizeof (*cfg));
1100 	rw_exit(&sv->sv_cfg_lock);
1101 }
1102 
1103 /*
1104  *
1105  */
1106 void
1107 smb_server_inc_nbt_sess(smb_server_t *sv)
1108 {
1109 	SMB_SERVER_VALID(sv);
1110 	atomic_inc_32(&sv->sv_nbt_sess);
1111 }
1112 
1113 void
1114 smb_server_dec_nbt_sess(smb_server_t *sv)
1115 {
1116 	SMB_SERVER_VALID(sv);
1117 	atomic_dec_32(&sv->sv_nbt_sess);
1118 }
1119 
1120 void
1121 smb_server_inc_tcp_sess(smb_server_t *sv)
1122 {
1123 	SMB_SERVER_VALID(sv);
1124 	atomic_inc_32(&sv->sv_tcp_sess);
1125 }
1126 
1127 void
1128 smb_server_dec_tcp_sess(smb_server_t *sv)
1129 {
1130 	SMB_SERVER_VALID(sv);
1131 	atomic_dec_32(&sv->sv_tcp_sess);
1132 }
1133 
1134 void
1135 smb_server_inc_users(smb_server_t *sv)
1136 {
1137 	SMB_SERVER_VALID(sv);
1138 	atomic_inc_32(&sv->sv_users);
1139 }
1140 
1141 void
1142 smb_server_dec_users(smb_server_t *sv)
1143 {
1144 	SMB_SERVER_VALID(sv);
1145 	atomic_dec_32(&sv->sv_users);
1146 }
1147 
1148 void
1149 smb_server_inc_trees(smb_server_t *sv)
1150 {
1151 	SMB_SERVER_VALID(sv);
1152 	atomic_inc_32(&sv->sv_trees);
1153 }
1154 
1155 void
1156 smb_server_dec_trees(smb_server_t *sv)
1157 {
1158 	SMB_SERVER_VALID(sv);
1159 	atomic_dec_32(&sv->sv_trees);
1160 }
1161 
1162 void
1163 smb_server_inc_files(smb_server_t *sv)
1164 {
1165 	SMB_SERVER_VALID(sv);
1166 	atomic_inc_32(&sv->sv_files);
1167 }
1168 
1169 void
1170 smb_server_dec_files(smb_server_t *sv)
1171 {
1172 	SMB_SERVER_VALID(sv);
1173 	atomic_dec_32(&sv->sv_files);
1174 }
1175 
1176 void
1177 smb_server_inc_pipes(smb_server_t *sv)
1178 {
1179 	SMB_SERVER_VALID(sv);
1180 	atomic_inc_32(&sv->sv_pipes);
1181 }
1182 
1183 void
1184 smb_server_dec_pipes(smb_server_t *sv)
1185 {
1186 	SMB_SERVER_VALID(sv);
1187 	atomic_dec_32(&sv->sv_pipes);
1188 }
1189 
1190 void
1191 smb_server_add_rxb(smb_server_t *sv, int64_t value)
1192 {
1193 	SMB_SERVER_VALID(sv);
1194 	atomic_add_64(&sv->sv_rxb, value);
1195 }
1196 
1197 void
1198 smb_server_add_txb(smb_server_t *sv, int64_t value)
1199 {
1200 	SMB_SERVER_VALID(sv);
1201 	atomic_add_64(&sv->sv_txb, value);
1202 }
1203 
1204 void
1205 smb_server_inc_req(smb_server_t *sv)
1206 {
1207 	SMB_SERVER_VALID(sv);
1208 	atomic_inc_64(&sv->sv_nreq);
1209 }
1210 
1211 /*
1212  * *****************************************************************************
1213  * *************************** Static Functions ********************************
1214  * *****************************************************************************
1215  */
1216 
1217 static void
1218 smb_server_timers(smb_thread_t *thread, void *arg)
1219 {
1220 	smb_server_t	*sv = (smb_server_t *)arg;
1221 
1222 	ASSERT(sv != NULL);
1223 
1224 	while (smb_thread_continue_timedwait(thread, 1 /* Seconds */)) {
1225 		smb_session_timers(&sv->sv_nbt_daemon.ld_session_list);
1226 		smb_session_timers(&sv->sv_tcp_daemon.ld_session_list);
1227 	}
1228 }
1229 
1230 /*
1231  * smb_server_kstat_init
1232  */
1233 static void
1234 smb_server_kstat_init(smb_server_t *sv)
1235 {
1236 	char	name[KSTAT_STRLEN];
1237 
1238 	sv->sv_ksp = kstat_create_zone(SMBSRV_KSTAT_MODULE, sv->sv_zid,
1239 	    SMBSRV_KSTAT_STATISTICS, SMBSRV_KSTAT_CLASS, KSTAT_TYPE_RAW,
1240 	    sizeof (smbsrv_kstats_t), 0, sv->sv_zid);
1241 
1242 	if (sv->sv_ksp != NULL) {
1243 		sv->sv_ksp->ks_update = smb_server_kstat_update;
1244 		sv->sv_ksp->ks_private = sv;
1245 		((smbsrv_kstats_t *)sv->sv_ksp->ks_data)->ks_start_time =
1246 		    sv->sv_start_time;
1247 		smb_dispatch_stats_init(
1248 		    ((smbsrv_kstats_t *)sv->sv_ksp->ks_data)->ks_reqs);
1249 		kstat_install(sv->sv_ksp);
1250 	} else {
1251 		cmn_err(CE_WARN, "SMB Server: Statistics unavailable");
1252 	}
1253 
1254 	(void) snprintf(name, sizeof (name), "%s%d",
1255 	    SMBSRV_KSTAT_NAME, sv->sv_zid);
1256 
1257 	sv->sv_legacy_ksp = kstat_create(SMBSRV_KSTAT_MODULE, sv->sv_zid,
1258 	    name, SMBSRV_KSTAT_CLASS, KSTAT_TYPE_NAMED,
1259 	    sizeof (smb_server_legacy_kstat_t) / sizeof (kstat_named_t), 0);
1260 
1261 	if (sv->sv_legacy_ksp != NULL) {
1262 		smb_server_legacy_kstat_t *ksd;
1263 
1264 		ksd = sv->sv_legacy_ksp->ks_data;
1265 
1266 		(void) strlcpy(ksd->ls_files.name, "open_files",
1267 		    sizeof (ksd->ls_files.name));
1268 		ksd->ls_files.data_type = KSTAT_DATA_UINT32;
1269 
1270 		(void) strlcpy(ksd->ls_trees.name, "connections",
1271 		    sizeof (ksd->ls_trees.name));
1272 		ksd->ls_trees.data_type = KSTAT_DATA_UINT32;
1273 
1274 		(void) strlcpy(ksd->ls_users.name, "connections",
1275 		    sizeof (ksd->ls_users.name));
1276 		ksd->ls_users.data_type = KSTAT_DATA_UINT32;
1277 
1278 		mutex_init(&sv->sv_legacy_ksmtx, NULL, MUTEX_DEFAULT, NULL);
1279 		sv->sv_legacy_ksp->ks_lock = &sv->sv_legacy_ksmtx;
1280 		sv->sv_legacy_ksp->ks_update = smb_server_legacy_kstat_update;
1281 		kstat_install(sv->sv_legacy_ksp);
1282 	}
1283 }
1284 
1285 /*
1286  * smb_server_kstat_fini
1287  */
1288 static void
1289 smb_server_kstat_fini(smb_server_t *sv)
1290 {
1291 	if (sv->sv_legacy_ksp != NULL) {
1292 		kstat_delete(sv->sv_legacy_ksp);
1293 		mutex_destroy(&sv->sv_legacy_ksmtx);
1294 		sv->sv_legacy_ksp = NULL;
1295 	}
1296 
1297 	if (sv->sv_ksp != NULL) {
1298 		kstat_delete(sv->sv_ksp);
1299 		sv->sv_ksp = NULL;
1300 		smb_dispatch_stats_fini();
1301 	}
1302 }
1303 
1304 /*
1305  * smb_server_kstat_update
1306  */
1307 static int
1308 smb_server_kstat_update(kstat_t *ksp, int rw)
1309 {
1310 	smb_server_t	*sv;
1311 	smbsrv_kstats_t	*ksd;
1312 
1313 	if (rw == KSTAT_READ) {
1314 		sv = ksp->ks_private;
1315 		SMB_SERVER_VALID(sv);
1316 		ksd = (smbsrv_kstats_t *)ksp->ks_data;
1317 		/*
1318 		 * Counters
1319 		 */
1320 		ksd->ks_nbt_sess = sv->sv_nbt_sess;
1321 		ksd->ks_tcp_sess = sv->sv_tcp_sess;
1322 		ksd->ks_users = sv->sv_users;
1323 		ksd->ks_trees = sv->sv_trees;
1324 		ksd->ks_files = sv->sv_files;
1325 		ksd->ks_pipes = sv->sv_pipes;
1326 		/*
1327 		 * Throughput
1328 		 */
1329 		ksd->ks_txb = sv->sv_txb;
1330 		ksd->ks_rxb = sv->sv_rxb;
1331 		ksd->ks_nreq = sv->sv_nreq;
1332 		/*
1333 		 * Busyness
1334 		 */
1335 		ksd->ks_maxreqs = sv->sv_cfg.skc_maxworkers;
1336 		smb_srqueue_update(&sv->sv_srqueue,
1337 		    &ksd->ks_utilization);
1338 		/*
1339 		 * Latency & Throughput of the requests
1340 		 */
1341 		smb_dispatch_stats_update(ksd->ks_reqs, 0, SMB_COM_NUM);
1342 		return (0);
1343 	}
1344 	if (rw == KSTAT_WRITE)
1345 		return (EACCES);
1346 
1347 	return (EIO);
1348 }
1349 
1350 static int
1351 smb_server_legacy_kstat_update(kstat_t *ksp, int rw)
1352 {
1353 	smb_server_t			*sv;
1354 	smb_server_legacy_kstat_t	*ksd;
1355 	int				rc;
1356 
1357 	switch (rw) {
1358 	case KSTAT_WRITE:
1359 		rc = EACCES;
1360 		break;
1361 	case KSTAT_READ:
1362 		if (!smb_server_lookup(&sv)) {
1363 			ASSERT(MUTEX_HELD(ksp->ks_lock));
1364 			ASSERT(sv->sv_legacy_ksp == ksp);
1365 			ksd = (smb_server_legacy_kstat_t *)ksp->ks_data;
1366 			ksd->ls_files.value.ui32 = sv->sv_files + sv->sv_pipes;
1367 			ksd->ls_trees.value.ui32 = sv->sv_trees;
1368 			ksd->ls_users.value.ui32 = sv->sv_users;
1369 			smb_server_release(sv);
1370 			rc = 0;
1371 			break;
1372 		}
1373 		_NOTE(FALLTHRU)
1374 	default:
1375 		rc = EIO;
1376 		break;
1377 	}
1378 	return (rc);
1379 
1380 }
1381 
1382 /*
1383  * smb_server_shutdown
1384  */
1385 static void
1386 smb_server_shutdown(smb_server_t *sv)
1387 {
1388 	SMB_SERVER_VALID(sv);
1389 
1390 	smb_opipe_door_close();
1391 	smb_thread_stop(&sv->si_thread_timers);
1392 	smb_kdoor_close();
1393 	smb_kshare_door_fini(sv->sv_lmshrd);
1394 	sv->sv_lmshrd = NULL;
1395 	smb_export_stop();
1396 	smb_server_fsop_stop(sv);
1397 
1398 	smb_server_listener_stop(&sv->sv_nbt_daemon);
1399 	smb_server_listener_stop(&sv->sv_tcp_daemon);
1400 
1401 	if (sv->sv_session != NULL) {
1402 		smb_session_delete(sv->sv_session);
1403 		sv->sv_session = NULL;
1404 	}
1405 
1406 	if (sv->sv_receiver_pool != NULL) {
1407 		taskq_destroy(sv->sv_receiver_pool);
1408 		sv->sv_receiver_pool = NULL;
1409 	}
1410 
1411 	if (sv->sv_worker_pool != NULL) {
1412 		taskq_destroy(sv->sv_worker_pool);
1413 		sv->sv_worker_pool = NULL;
1414 	}
1415 }
1416 
1417 /*
1418  * smb_server_listener_init
1419  *
1420  * Initializes listener contexts.
1421  */
1422 static void
1423 smb_server_listener_init(
1424     smb_server_t		*sv,
1425     smb_listener_daemon_t	*ld,
1426     char			*name,
1427     in_port_t			port,
1428     int				family)
1429 {
1430 	ASSERT(ld->ld_magic != SMB_LISTENER_MAGIC);
1431 
1432 	bzero(ld, sizeof (*ld));
1433 
1434 	ld->ld_sv = sv;
1435 	ld->ld_family = family;
1436 	ld->ld_port = port;
1437 
1438 	if (family == AF_INET) {
1439 		ld->ld_sin.sin_family = (uint32_t)family;
1440 		ld->ld_sin.sin_port = htons(port);
1441 		ld->ld_sin.sin_addr.s_addr = htonl(INADDR_ANY);
1442 	} else {
1443 		ld->ld_sin6.sin6_family = (uint32_t)family;
1444 		ld->ld_sin6.sin6_port = htons(port);
1445 		(void) memset(&ld->ld_sin6.sin6_addr.s6_addr, 0,
1446 		    sizeof (ld->ld_sin6.sin6_addr.s6_addr));
1447 	}
1448 
1449 	smb_llist_constructor(&ld->ld_session_list, sizeof (smb_session_t),
1450 	    offsetof(smb_session_t, s_lnd));
1451 	smb_thread_init(&ld->ld_thread, name, smb_server_listener, ld);
1452 	ld->ld_magic = SMB_LISTENER_MAGIC;
1453 }
1454 
1455 /*
1456  * smb_server_listener_destroy
1457  *
1458  * Destroyes listener contexts.
1459  */
1460 static void
1461 smb_server_listener_destroy(smb_listener_daemon_t *ld)
1462 {
1463 	SMB_LISTENER_VALID(ld);
1464 	ASSERT(ld->ld_so == NULL);
1465 	smb_thread_destroy(&ld->ld_thread);
1466 	smb_llist_destructor(&ld->ld_session_list);
1467 	ld->ld_magic = 0;
1468 }
1469 
1470 /*
1471  * smb_server_listener_start
1472  *
1473  * Starts the listener associated with the context passed in.
1474  *
1475  * Return:	0	Success
1476  *		not 0	Failure
1477  */
1478 static int
1479 smb_server_listener_start(smb_listener_daemon_t *ld)
1480 {
1481 	int		rc;
1482 	uint32_t	on;
1483 	uint32_t	off;
1484 
1485 	SMB_LISTENER_VALID(ld);
1486 
1487 	if (ld->ld_so != NULL)
1488 		return (EINVAL);
1489 
1490 	ld->ld_so = smb_socreate(ld->ld_family, SOCK_STREAM, 0);
1491 	if (ld->ld_so == NULL) {
1492 		cmn_err(CE_WARN, "port %d: socket create failed", ld->ld_port);
1493 		return (ENOMEM);
1494 	}
1495 
1496 	off = 0;
1497 	(void) ksocket_setsockopt(ld->ld_so, SOL_SOCKET,
1498 	    SO_MAC_EXEMPT, &off, sizeof (off), CRED());
1499 
1500 	on = 1;
1501 	(void) ksocket_setsockopt(ld->ld_so, SOL_SOCKET,
1502 	    SO_REUSEADDR, &on, sizeof (on), CRED());
1503 
1504 	if (ld->ld_family == AF_INET) {
1505 		rc = ksocket_bind(ld->ld_so,
1506 		    (struct sockaddr *)&ld->ld_sin,
1507 		    sizeof (ld->ld_sin), CRED());
1508 	} else {
1509 		rc = ksocket_bind(ld->ld_so,
1510 		    (struct sockaddr *)&ld->ld_sin6,
1511 		    sizeof (ld->ld_sin6), CRED());
1512 	}
1513 
1514 	if (rc != 0) {
1515 		cmn_err(CE_WARN, "port %d: bind failed", ld->ld_port);
1516 		return (rc);
1517 	}
1518 
1519 	rc =  ksocket_listen(ld->ld_so, 20, CRED());
1520 	if (rc < 0) {
1521 		cmn_err(CE_WARN, "port %d: listen failed", ld->ld_port);
1522 		return (rc);
1523 	}
1524 
1525 	ksocket_hold(ld->ld_so);
1526 	rc = smb_thread_start(&ld->ld_thread);
1527 	if (rc != 0) {
1528 		ksocket_rele(ld->ld_so);
1529 		cmn_err(CE_WARN, "port %d: listener failed to start",
1530 		    ld->ld_port);
1531 		return (rc);
1532 	}
1533 	return (0);
1534 }
1535 
1536 /*
1537  * smb_server_listener_stop
1538  *
1539  * Stops the listener associated with the context passed in.
1540  */
1541 static void
1542 smb_server_listener_stop(smb_listener_daemon_t *ld)
1543 {
1544 	SMB_LISTENER_VALID(ld);
1545 
1546 	if (ld->ld_so != NULL) {
1547 		smb_soshutdown(ld->ld_so);
1548 		smb_sodestroy(ld->ld_so);
1549 		smb_thread_stop(&ld->ld_thread);
1550 		ld->ld_so = NULL;
1551 	}
1552 }
1553 
1554 /*
1555  * smb_server_listener
1556  *
1557  * Entry point of the listeners.
1558  */
1559 static void
1560 smb_server_listener(smb_thread_t *thread, void *arg)
1561 {
1562 	_NOTE(ARGUNUSED(thread))
1563 	smb_listener_daemon_t	*ld;
1564 	smb_session_t		*session;
1565 	ksocket_t		s_so;
1566 	int			on;
1567 	int			txbuf_size;
1568 
1569 	ld = (smb_listener_daemon_t *)arg;
1570 
1571 	SMB_LISTENER_VALID(ld);
1572 
1573 	DTRACE_PROBE1(so__wait__accept, struct sonode *, ld->ld_so);
1574 
1575 	while (ksocket_accept(ld->ld_so, NULL, NULL, &s_so, CRED())
1576 	    == 0) {
1577 		DTRACE_PROBE1(so__accept, struct sonode *, s_so);
1578 
1579 		on = 1;
1580 		(void) ksocket_setsockopt(s_so, IPPROTO_TCP, TCP_NODELAY,
1581 		    &on, sizeof (on), CRED());
1582 
1583 		on = 1;
1584 		(void) ksocket_setsockopt(s_so, SOL_SOCKET, SO_KEEPALIVE,
1585 		    &on, sizeof (on), CRED());
1586 
1587 		txbuf_size = 128*1024;
1588 		(void) ksocket_setsockopt(s_so, SOL_SOCKET, SO_SNDBUF,
1589 		    (const void *)&txbuf_size, sizeof (txbuf_size), CRED());
1590 
1591 		/*
1592 		 * Create a session for this connection.
1593 		 */
1594 		smb_server_create_session(ld, s_so);
1595 	}
1596 	/* Disconnect all the sessions this listener created. */
1597 	smb_llist_enter(&ld->ld_session_list, RW_READER);
1598 	session = smb_llist_head(&ld->ld_session_list);
1599 	while (session != NULL) {
1600 		smb_session_disconnect(session);
1601 		session = smb_llist_next(&ld->ld_session_list, session);
1602 	}
1603 	smb_llist_exit(&ld->ld_session_list);
1604 	ksocket_rele(ld->ld_so);
1605 }
1606 
1607 /*
1608  * smb_server_receiver
1609  *
1610  * Entry point of the receiver threads.
1611  */
1612 static void
1613 smb_server_receiver(void *arg)
1614 {
1615 	smb_listener_daemon_t	*ld;
1616 	smb_session_t		*session;
1617 
1618 	ld = ((smb_receiver_arg_t *)arg)->ra_listener;
1619 	session = ((smb_receiver_arg_t *)arg)->ra_session;
1620 	smb_mem_free(arg);
1621 	smb_session_receiver(session);
1622 	smb_server_destroy_session(ld, session);
1623 }
1624 
1625 /*
1626  * smb_server_lookup
1627  *
1628  * This function tries to find the server associated with the zone of the
1629  * caller.
1630  */
1631 static int
1632 smb_server_lookup(smb_server_t **psv)
1633 {
1634 	zoneid_t	zid;
1635 	smb_server_t	*sv;
1636 
1637 	zid = getzoneid();
1638 
1639 	smb_llist_enter(&smb_servers, RW_READER);
1640 	sv = smb_llist_head(&smb_servers);
1641 	while (sv) {
1642 		SMB_SERVER_VALID(sv);
1643 		if (sv->sv_zid == zid) {
1644 			mutex_enter(&sv->sv_mutex);
1645 			if (sv->sv_state != SMB_SERVER_STATE_DELETING) {
1646 				sv->sv_refcnt++;
1647 				mutex_exit(&sv->sv_mutex);
1648 				smb_llist_exit(&smb_servers);
1649 				*psv = sv;
1650 				return (0);
1651 			}
1652 			mutex_exit(&sv->sv_mutex);
1653 			break;
1654 		}
1655 		sv = smb_llist_next(&smb_servers, sv);
1656 	}
1657 	smb_llist_exit(&smb_servers);
1658 	return (EPERM);
1659 }
1660 
1661 /*
1662  * smb_server_release
1663  *
1664  * This function decrements the reference count of the server and signals its
1665  * condition variable if the state of the server is SMB_SERVER_STATE_DELETING.
1666  */
1667 static void
1668 smb_server_release(smb_server_t *sv)
1669 {
1670 	SMB_SERVER_VALID(sv);
1671 
1672 	mutex_enter(&sv->sv_mutex);
1673 	ASSERT(sv->sv_refcnt);
1674 	sv->sv_refcnt--;
1675 	if ((sv->sv_refcnt == 0) && (sv->sv_state == SMB_SERVER_STATE_DELETING))
1676 		cv_signal(&sv->sv_cv);
1677 	mutex_exit(&sv->sv_mutex);
1678 }
1679 
1680 /*
1681  * Enumerate the users associated with a session list.
1682  */
1683 static void
1684 smb_server_enum_private(smb_llist_t *ll, smb_svcenum_t *svcenum)
1685 {
1686 	smb_session_t	*sn;
1687 	smb_llist_t	*ulist;
1688 	smb_user_t	*user;
1689 	int		rc = 0;
1690 
1691 	smb_llist_enter(ll, RW_READER);
1692 	sn = smb_llist_head(ll);
1693 
1694 	while (sn != NULL) {
1695 		SMB_SESSION_VALID(sn);
1696 		ulist = &sn->s_user_list;
1697 		smb_llist_enter(ulist, RW_READER);
1698 		user = smb_llist_head(ulist);
1699 
1700 		while (user != NULL) {
1701 			if (smb_user_hold(user)) {
1702 				rc = smb_user_enum(user, svcenum);
1703 				smb_user_release(user);
1704 			}
1705 
1706 			user = smb_llist_next(ulist, user);
1707 		}
1708 
1709 		smb_llist_exit(ulist);
1710 
1711 		if (rc != 0)
1712 			break;
1713 
1714 		sn = smb_llist_next(ll, sn);
1715 	}
1716 
1717 	smb_llist_exit(ll);
1718 }
1719 
1720 /*
1721  * Disconnect sessions associated with the specified client and username.
1722  * Empty strings are treated as wildcards.
1723  */
1724 static int
1725 smb_server_session_disconnect(smb_llist_t *ll,
1726     const char *client, const char *name)
1727 {
1728 	smb_session_t	*sn;
1729 	smb_llist_t	*ulist;
1730 	smb_user_t	*user;
1731 	boolean_t	match;
1732 	int		count = 0;
1733 
1734 	smb_llist_enter(ll, RW_READER);
1735 	sn = smb_llist_head(ll);
1736 
1737 	while (sn != NULL) {
1738 		SMB_SESSION_VALID(sn);
1739 
1740 		if ((*client != '\0') && (!smb_session_isclient(sn, client))) {
1741 			sn = smb_llist_next(ll, sn);
1742 			continue;
1743 		}
1744 
1745 		ulist = &sn->s_user_list;
1746 		smb_llist_enter(ulist, RW_READER);
1747 		user = smb_llist_head(ulist);
1748 
1749 		while (user != NULL) {
1750 			if (smb_user_hold(user)) {
1751 				match = (*name == '\0');
1752 				if (!match)
1753 					match = smb_user_namecmp(user, name);
1754 
1755 				if (match) {
1756 					smb_llist_exit(ulist);
1757 					smb_user_logoff(user);
1758 					++count;
1759 					smb_user_release(user);
1760 					smb_llist_enter(ulist, RW_READER);
1761 					user = smb_llist_head(ulist);
1762 					continue;
1763 				}
1764 
1765 				smb_user_release(user);
1766 			}
1767 
1768 			user = smb_llist_next(ulist, user);
1769 		}
1770 
1771 		smb_llist_exit(ulist);
1772 		sn = smb_llist_next(ll, sn);
1773 	}
1774 
1775 	smb_llist_exit(ll);
1776 	return (count);
1777 }
1778 
1779 /*
1780  * Close a file by its unique id.
1781  */
1782 static int
1783 smb_server_fclose(smb_llist_t *ll, uint32_t uniqid)
1784 {
1785 	smb_session_t	*sn;
1786 	smb_llist_t	*ulist;
1787 	smb_user_t	*user;
1788 	int		rc = ENOENT;
1789 
1790 	smb_llist_enter(ll, RW_READER);
1791 	sn = smb_llist_head(ll);
1792 
1793 	while ((sn != NULL) && (rc == ENOENT)) {
1794 		SMB_SESSION_VALID(sn);
1795 		ulist = &sn->s_user_list;
1796 		smb_llist_enter(ulist, RW_READER);
1797 		user = smb_llist_head(ulist);
1798 
1799 		while ((user != NULL) && (rc == ENOENT)) {
1800 			if (smb_user_hold(user)) {
1801 				rc = smb_user_fclose(user, uniqid);
1802 				smb_user_release(user);
1803 			}
1804 
1805 			user = smb_llist_next(ulist, user);
1806 		}
1807 
1808 		smb_llist_exit(ulist);
1809 		sn = smb_llist_next(ll, sn);
1810 	}
1811 
1812 	smb_llist_exit(ll);
1813 	return (rc);
1814 }
1815 
1816 static void
1817 smb_server_store_cfg(smb_server_t *sv, smb_ioc_cfg_t *ioc)
1818 {
1819 	if (ioc->maxconnections == 0)
1820 		ioc->maxconnections = 0xFFFFFFFF;
1821 
1822 	smb_session_correct_keep_alive_values(
1823 	    &sv->sv_nbt_daemon.ld_session_list, ioc->keepalive);
1824 	smb_session_correct_keep_alive_values(
1825 	    &sv->sv_tcp_daemon.ld_session_list, ioc->keepalive);
1826 
1827 	sv->sv_cfg.skc_maxworkers = ioc->maxworkers;
1828 	sv->sv_cfg.skc_maxconnections = ioc->maxconnections;
1829 	sv->sv_cfg.skc_keepalive = ioc->keepalive;
1830 	sv->sv_cfg.skc_restrict_anon = ioc->restrict_anon;
1831 	sv->sv_cfg.skc_signing_enable = ioc->signing_enable;
1832 	sv->sv_cfg.skc_signing_required = ioc->signing_required;
1833 	sv->sv_cfg.skc_oplock_enable = ioc->oplock_enable;
1834 	sv->sv_cfg.skc_sync_enable = ioc->sync_enable;
1835 	sv->sv_cfg.skc_secmode = ioc->secmode;
1836 	sv->sv_cfg.skc_ipv6_enable = ioc->ipv6_enable;
1837 	sv->sv_cfg.skc_print_enable = ioc->print_enable;
1838 	sv->sv_cfg.skc_execflags = ioc->exec_flags;
1839 	sv->sv_cfg.skc_version = ioc->version;
1840 	(void) strlcpy(sv->sv_cfg.skc_nbdomain, ioc->nbdomain,
1841 	    sizeof (sv->sv_cfg.skc_nbdomain));
1842 	(void) strlcpy(sv->sv_cfg.skc_fqdn, ioc->fqdn,
1843 	    sizeof (sv->sv_cfg.skc_fqdn));
1844 	(void) strlcpy(sv->sv_cfg.skc_hostname, ioc->hostname,
1845 	    sizeof (sv->sv_cfg.skc_hostname));
1846 	(void) strlcpy(sv->sv_cfg.skc_system_comment, ioc->system_comment,
1847 	    sizeof (sv->sv_cfg.skc_system_comment));
1848 }
1849 
1850 static int
1851 smb_server_fsop_start(smb_server_t *sv)
1852 {
1853 	int	error;
1854 
1855 	error = smb_node_root_init(rootdir, sv, &sv->si_root_smb_node);
1856 	if (error != 0)
1857 		sv->si_root_smb_node = NULL;
1858 
1859 	return (error);
1860 }
1861 
1862 static void
1863 smb_server_fsop_stop(smb_server_t *sv)
1864 {
1865 	if (sv->si_root_smb_node != NULL) {
1866 		smb_node_release(sv->si_root_smb_node);
1867 		sv->si_root_smb_node = NULL;
1868 	}
1869 }
1870 
1871 smb_event_t *
1872 smb_event_create(int timeout)
1873 {
1874 	smb_server_t	*sv;
1875 	smb_event_t	*event;
1876 
1877 	if (smb_server_is_stopping())
1878 		return (NULL);
1879 
1880 	if (smb_server_lookup(&sv) != 0) {
1881 		cmn_err(CE_NOTE, "smb_event_create failed");
1882 		return (NULL);
1883 	}
1884 
1885 	event = kmem_cache_alloc(sv->si_cache_event, KM_SLEEP);
1886 
1887 	bzero(event, sizeof (smb_event_t));
1888 	mutex_init(&event->se_mutex, NULL, MUTEX_DEFAULT, NULL);
1889 	cv_init(&event->se_cv, NULL, CV_DEFAULT, NULL);
1890 	event->se_magic = SMB_EVENT_MAGIC;
1891 	event->se_txid = smb_event_alloc_txid();
1892 	event->se_server = sv;
1893 	event->se_timeout = timeout;
1894 
1895 	smb_llist_enter(&sv->sv_event_list, RW_WRITER);
1896 	smb_llist_insert_tail(&sv->sv_event_list, event);
1897 	smb_llist_exit(&sv->sv_event_list);
1898 
1899 	smb_server_release(sv);
1900 	return (event);
1901 }
1902 
1903 void
1904 smb_event_destroy(smb_event_t *event)
1905 {
1906 	smb_server_t	*sv;
1907 
1908 	if (event == NULL)
1909 		return;
1910 
1911 	SMB_EVENT_VALID(event);
1912 	ASSERT(event->se_waittime == 0);
1913 
1914 	if (smb_server_lookup(&sv) != 0)
1915 		return;
1916 
1917 	smb_llist_enter(&sv->sv_event_list, RW_WRITER);
1918 	smb_llist_remove(&sv->sv_event_list, event);
1919 	smb_llist_exit(&sv->sv_event_list);
1920 
1921 	event->se_magic = (uint32_t)~SMB_EVENT_MAGIC;
1922 	cv_destroy(&event->se_cv);
1923 	mutex_destroy(&event->se_mutex);
1924 
1925 	kmem_cache_free(sv->si_cache_event, event);
1926 	smb_server_release(sv);
1927 }
1928 
1929 /*
1930  * Get the txid for the specified event.
1931  */
1932 uint32_t
1933 smb_event_txid(smb_event_t *event)
1934 {
1935 	if (event != NULL) {
1936 		SMB_EVENT_VALID(event);
1937 		return (event->se_txid);
1938 	}
1939 
1940 	cmn_err(CE_NOTE, "smb_event_txid failed");
1941 	return ((uint32_t)-1);
1942 }
1943 
1944 /*
1945  * Wait for event notification.
1946  */
1947 int
1948 smb_event_wait(smb_event_t *event)
1949 {
1950 	int	seconds = 1;
1951 	int	ticks;
1952 
1953 	if (event == NULL)
1954 		return (EINVAL);
1955 
1956 	SMB_EVENT_VALID(event);
1957 
1958 	mutex_enter(&event->se_mutex);
1959 	event->se_waittime = 1;
1960 	event->se_errno = 0;
1961 
1962 	while (!(event->se_notified)) {
1963 		if (smb_event_debug && ((event->se_waittime % 30) == 0))
1964 			cmn_err(CE_NOTE, "smb_event_wait[%d] (%d sec)",
1965 			    event->se_txid, event->se_waittime);
1966 
1967 		if (event->se_errno != 0)
1968 			break;
1969 
1970 		if (event->se_waittime > event->se_timeout) {
1971 			event->se_errno = ETIME;
1972 			break;
1973 		}
1974 
1975 		ticks = SEC_TO_TICK(seconds);
1976 		(void) cv_reltimedwait(&event->se_cv,
1977 		    &event->se_mutex, (clock_t)ticks, TR_CLOCK_TICK);
1978 		++event->se_waittime;
1979 	}
1980 
1981 	event->se_waittime = 0;
1982 	event->se_notified = B_FALSE;
1983 	cv_signal(&event->se_cv);
1984 	mutex_exit(&event->se_mutex);
1985 	return (event->se_errno);
1986 }
1987 
1988 /*
1989  * If txid is non-zero, cancel the specified event.
1990  * Otherwise, cancel all events.
1991  */
1992 static void
1993 smb_event_cancel(smb_server_t *sv, uint32_t txid)
1994 {
1995 	smb_event_t	*event;
1996 	smb_llist_t	*event_list;
1997 
1998 	SMB_SERVER_VALID(sv);
1999 
2000 	event_list = &sv->sv_event_list;
2001 	smb_llist_enter(event_list, RW_WRITER);
2002 
2003 	event = smb_llist_head(event_list);
2004 	while (event) {
2005 		SMB_EVENT_VALID(event);
2006 
2007 		if (txid == 0 || event->se_txid == txid) {
2008 			mutex_enter(&event->se_mutex);
2009 			event->se_errno = ECANCELED;
2010 			event->se_notified = B_TRUE;
2011 			cv_signal(&event->se_cv);
2012 			mutex_exit(&event->se_mutex);
2013 
2014 			if (txid != 0)
2015 				break;
2016 		}
2017 
2018 		event = smb_llist_next(event_list, event);
2019 	}
2020 
2021 	smb_llist_exit(event_list);
2022 }
2023 
2024 /*
2025  * If txid is non-zero, notify the specified event.
2026  * Otherwise, notify all events.
2027  */
2028 void
2029 smb_event_notify(smb_server_t *sv, uint32_t txid)
2030 {
2031 	smb_event_t	*event;
2032 	smb_llist_t	*event_list;
2033 
2034 	SMB_SERVER_VALID(sv);
2035 
2036 	event_list = &sv->sv_event_list;
2037 	smb_llist_enter(event_list, RW_READER);
2038 
2039 	event = smb_llist_head(event_list);
2040 	while (event) {
2041 		SMB_EVENT_VALID(event);
2042 
2043 		if (txid == 0 || event->se_txid == txid) {
2044 			mutex_enter(&event->se_mutex);
2045 			event->se_notified = B_TRUE;
2046 			cv_signal(&event->se_cv);
2047 			mutex_exit(&event->se_mutex);
2048 
2049 			if (txid != 0)
2050 				break;
2051 		}
2052 
2053 		event = smb_llist_next(event_list, event);
2054 	}
2055 
2056 	smb_llist_exit(event_list);
2057 }
2058 
2059 /*
2060  * Allocate a new transaction id (txid).
2061  *
2062  * 0 or -1 are not assigned because they are used to detect invalid
2063  * conditions or to indicate all open id's.
2064  */
2065 static uint32_t
2066 smb_event_alloc_txid(void)
2067 {
2068 	static kmutex_t	txmutex;
2069 	static uint32_t	txid;
2070 	uint32_t	txid_ret;
2071 
2072 	mutex_enter(&txmutex);
2073 
2074 	if (txid == 0)
2075 		txid = ddi_get_lbolt() << 11;
2076 
2077 	do {
2078 		++txid;
2079 	} while (txid == 0 || txid == (uint32_t)-1);
2080 
2081 	txid_ret = txid;
2082 	mutex_exit(&txmutex);
2083 
2084 	return (txid_ret);
2085 }
2086 
2087 /*
2088  * Called by the ioctl to find the corresponding
2089  * spooldoc node.  removes node on success
2090  *
2091  * Return values
2092  * rc
2093  * B_FALSE - not found
2094  * B_TRUE  - found
2095  *
2096  */
2097 
2098 boolean_t
2099 smb_spool_lookup_doc_byfid(uint16_t fid, smb_kspooldoc_t *spdoc)
2100 {
2101 	smb_kspooldoc_t *sp;
2102 	smb_llist_t	*splist;
2103 	smb_server_t	*sv;
2104 	int		rc;
2105 
2106 	rc = smb_server_lookup(&sv);
2107 	if (rc)
2108 		return (B_FALSE);
2109 
2110 	splist = &sv->sp_info.sp_list;
2111 	smb_llist_enter(splist, RW_WRITER);
2112 	sp = smb_llist_head(splist);
2113 	while (sp != NULL) {
2114 		/*
2115 		 * check for a matching fid
2116 		 */
2117 		if (sp->sd_fid == fid) {
2118 			*spdoc = *sp;
2119 			smb_llist_remove(splist, sp);
2120 			smb_llist_exit(splist);
2121 			kmem_free(sp, sizeof (smb_kspooldoc_t));
2122 			smb_server_release(sv);
2123 			return (B_TRUE);
2124 		}
2125 		sp = smb_llist_next(splist, sp);
2126 	}
2127 	cmn_err(CE_WARN, "smb_spool_lookup_user_byfid: no fid:%d", fid);
2128 	smb_llist_exit(splist);
2129 	smb_server_release(sv);
2130 	return (B_FALSE);
2131 }
2132 
2133 /*
2134  * Adds the spool fid to a linked list to be used
2135  * as a search key in the spooldoc queue
2136  *
2137  * Return values
2138  *      rc non-zero error
2139  *	rc zero success
2140  *
2141  */
2142 
2143 int
2144 smb_spool_add_fid(uint16_t fid)
2145 {
2146 	smb_llist_t	*fidlist;
2147 	smb_server_t	*sv;
2148 	smb_spoolfid_t  *sf;
2149 	int rc = 0;
2150 
2151 	rc = smb_server_lookup(&sv);
2152 	if (rc)
2153 		return (rc);
2154 
2155 	sf = kmem_zalloc(sizeof (smb_spoolfid_t), KM_SLEEP);
2156 	fidlist = &sv->sp_info.sp_fidlist;
2157 	smb_llist_enter(fidlist, RW_WRITER);
2158 	sf->sf_fid = fid;
2159 	smb_llist_insert_tail(fidlist, sf);
2160 	smb_llist_exit(fidlist);
2161 	smb_server_release(sv);
2162 	return (rc);
2163 }
2164 
2165 /*
2166  * Called by the ioctl to get and remove the head of the fid list
2167  *
2168  * Return values
2169  * int fd
2170  * greater than 0 success
2171  * 0 - error
2172  *
2173  */
2174 
2175 uint16_t
2176 smb_spool_get_fid()
2177 {
2178 	smb_spoolfid_t	*spfid;
2179 	smb_llist_t	*splist;
2180 	smb_server_t	*sv;
2181 	int 		rc = 0;
2182 	uint16_t	fid;
2183 
2184 	rc = smb_server_lookup(&sv);
2185 	if (rc)
2186 		return (0);
2187 
2188 	splist = &sv->sp_info.sp_fidlist;
2189 	smb_llist_enter(splist, RW_WRITER);
2190 	spfid = smb_llist_head(splist);
2191 	if (spfid != NULL) {
2192 		fid = spfid->sf_fid;
2193 		smb_llist_remove(&sv->sp_info.sp_fidlist, spfid);
2194 		kmem_free(spfid, sizeof (smb_spoolfid_t));
2195 	} else {
2196 		fid = 0;
2197 	}
2198 	smb_llist_exit(splist);
2199 	smb_server_release(sv);
2200 	return (fid);
2201 }
2202 
2203 /*
2204  * Adds the spooldoc to the tail of the spooldoc list
2205  *
2206  * Return values
2207  *      rc non-zero error
2208  *	rc zero success
2209  */
2210 int
2211 smb_spool_add_doc(smb_kspooldoc_t *sp)
2212 {
2213 	smb_llist_t	*splist;
2214 	smb_server_t	*sv;
2215 	int rc = 0;
2216 
2217 	rc = smb_server_lookup(&sv);
2218 	if (rc)
2219 		return (rc);
2220 
2221 	splist = &sv->sp_info.sp_list;
2222 	smb_llist_enter(splist, RW_WRITER);
2223 	sp->sd_spool_num = sv->sp_info.sp_cnt;
2224 	smb_llist_insert_tail(splist, sp);
2225 	smb_llist_exit(splist);
2226 	smb_server_release(sv);
2227 	return (rc);
2228 }
2229 
2230 /*
2231  * smb_server_create_session
2232  */
2233 static void
2234 smb_server_create_session(smb_listener_daemon_t *ld, ksocket_t s_so)
2235 {
2236 	smb_session_t		*session;
2237 	smb_receiver_arg_t	*rarg;
2238 
2239 	session = smb_session_create(s_so, ld->ld_port, ld->ld_sv,
2240 	    ld->ld_family);
2241 
2242 	if (session != NULL) {
2243 		smb_llist_enter(&ld->ld_session_list, RW_WRITER);
2244 		smb_llist_insert_tail(&ld->ld_session_list, session);
2245 		smb_llist_exit(&ld->ld_session_list);
2246 
2247 		rarg = (smb_receiver_arg_t *)smb_mem_alloc(
2248 		    sizeof (smb_receiver_arg_t));
2249 		rarg->ra_listener = ld;
2250 		rarg->ra_session = session;
2251 
2252 		if (taskq_dispatch(ld->ld_sv->sv_receiver_pool,
2253 		    smb_server_receiver, rarg, TQ_NOQUEUE) != 0)
2254 			return;
2255 
2256 		smb_mem_free(rarg);
2257 		smb_session_disconnect(session);
2258 		smb_server_destroy_session(ld, session);
2259 	} else {
2260 		smb_soshutdown(s_so);
2261 		smb_sodestroy(s_so);
2262 	}
2263 	cmn_err(CE_WARN, "SMB Session: creation failed");
2264 }
2265 
2266 static void
2267 smb_server_destroy_session(smb_listener_daemon_t *ld, smb_session_t *session)
2268 {
2269 	smb_llist_enter(&ld->ld_session_list, RW_WRITER);
2270 	smb_llist_remove(&ld->ld_session_list, session);
2271 	smb_llist_exit(&ld->ld_session_list);
2272 	smb_session_delete(session);
2273 }
2274