1139823Simp/*-
275374Sbp * Copyright (c) 2000-2001 Boris Popov
375374Sbp * All rights reserved.
475374Sbp *
575374Sbp * Redistribution and use in source and binary forms, with or without
675374Sbp * modification, are permitted provided that the following conditions
775374Sbp * are met:
875374Sbp * 1. Redistributions of source code must retain the above copyright
975374Sbp *    notice, this list of conditions and the following disclaimer.
1075374Sbp * 2. Redistributions in binary form must reproduce the above copyright
1175374Sbp *    notice, this list of conditions and the following disclaimer in the
1275374Sbp *    documentation and/or other materials provided with the distribution.
1375374Sbp *
1475374Sbp * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
1575374Sbp * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
1675374Sbp * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
1775374Sbp * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
1875374Sbp * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
1975374Sbp * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
2075374Sbp * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
2175374Sbp * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
2275374Sbp * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
2375374Sbp * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
2475374Sbp * SUCH DAMAGE.
2575374Sbp */
2675374Sbp
2775374Sbp/*
2875374Sbp * Connection engine.
2975374Sbp */
3075374Sbp
31116189Sobrien#include <sys/cdefs.h>
32116189Sobrien__FBSDID("$FreeBSD$");
33116189Sobrien
3475374Sbp#include <sys/param.h>
3575374Sbp#include <sys/systm.h>
3675374Sbp#include <sys/kernel.h>
3775374Sbp#include <sys/malloc.h>
38164033Srwatson#include <sys/priv.h>
3975374Sbp#include <sys/proc.h>
4075374Sbp#include <sys/lock.h>
4175374Sbp#include <sys/sysctl.h>
4275374Sbp#include <sys/socketvar.h>
4375374Sbp
4475374Sbp#include <sys/iconv.h>
4575374Sbp
4675374Sbp#include <netsmb/smb.h>
4775374Sbp#include <netsmb/smb_subr.h>
4875374Sbp#include <netsmb/smb_conn.h>
4975374Sbp#include <netsmb/smb_tran.h>
5075374Sbp#include <netsmb/smb_trantcp.h>
5175374Sbp
5275374Sbpstatic struct smb_connobj smb_vclist;
5375374Sbpstatic int smb_vcnext = 1;	/* next unique id for VC */
5475374Sbp
5575374SbpSYSCTL_NODE(_net, OID_AUTO, smb, CTLFLAG_RW, NULL, "SMB protocol");
5675374Sbp
57227293Sedstatic MALLOC_DEFINE(M_SMBCONN, "smb_conn", "SMB connection");
5875374Sbp
59176518Sattiliostatic void smb_co_init(struct smb_connobj *cp, int level, char *ilockname,
60184571Srwatson    char *lockname);
6175374Sbpstatic void smb_co_done(struct smb_connobj *cp);
6275374Sbpstatic int  smb_vc_disconnect(struct smb_vc *vcp);
6375374Sbpstatic void smb_vc_free(struct smb_connobj *cp);
6475374Sbpstatic void smb_vc_gone(struct smb_connobj *cp, struct smb_cred *scred);
6575374Sbpstatic smb_co_free_t smb_share_free;
6675374Sbpstatic smb_co_gone_t smb_share_gone;
6775374Sbp
6875374Sbpstatic int  smb_sysctl_treedump(SYSCTL_HANDLER_ARGS);
6975374Sbp
7075374SbpSYSCTL_PROC(_net_smb, OID_AUTO, treedump, CTLFLAG_RD | CTLTYPE_OPAQUE,
7175374Sbp	    NULL, 0, smb_sysctl_treedump, "S,treedump", "Requester tree");
7275374Sbp
7375374Sbpint
7475374Sbpsmb_sm_init(void)
7575374Sbp{
7675374Sbp
77184571Srwatson	smb_co_init(&smb_vclist, SMBL_SM, "smbsm ilock", "smbsm");
78250237Sdavide	sx_xlock(&smb_vclist.co_interlock);
79250237Sdavide	smb_co_unlock(&smb_vclist);
80250237Sdavide	sx_unlock(&smb_vclist.co_interlock);
8175374Sbp	return 0;
8275374Sbp}
8375374Sbp
8475374Sbpint
8575374Sbpsmb_sm_done(void)
8675374Sbp{
8775374Sbp
8875374Sbp	/* XXX: hold the mutex */
8975374Sbp	if (smb_vclist.co_usecount > 1) {
9075374Sbp		SMBERROR("%d connections still active\n", smb_vclist.co_usecount - 1);
9175374Sbp		return EBUSY;
9275374Sbp	}
9375374Sbp	smb_co_done(&smb_vclist);
9475374Sbp	return 0;
9575374Sbp}
9675374Sbp
9775374Sbpstatic int
98250237Sdavidesmb_sm_lockvclist(void)
9975374Sbp{
100250237Sdavide	int error;
10175374Sbp
102250237Sdavide	sx_xlock(&smb_vclist.co_interlock);
103250237Sdavide	error = smb_co_lock(&smb_vclist);
104250237Sdavide	sx_unlock(&smb_vclist.co_interlock);
105250237Sdavide
106250237Sdavide	return error;
10775374Sbp}
10875374Sbp
10975374Sbpstatic void
110184571Srwatsonsmb_sm_unlockvclist(void)
11175374Sbp{
11275374Sbp
113250237Sdavide	sx_xlock(&smb_vclist.co_interlock);
114250237Sdavide	smb_co_unlock(&smb_vclist);
115250237Sdavide	sx_unlock(&smb_vclist.co_interlock);
11675374Sbp}
11775374Sbp
11875374Sbpstatic int
11975374Sbpsmb_sm_lookupint(struct smb_vcspec *vcspec, struct smb_sharespec *shspec,
12075374Sbp	struct smb_cred *scred,	struct smb_vc **vcpp)
12175374Sbp{
122132780Skan	struct smb_connobj *scp;
12375374Sbp	struct smb_vc *vcp;
12475374Sbp	int exact = 1;
12575374Sbp	int error;
12675374Sbp
12775374Sbp	vcspec->shspec = shspec;
12875374Sbp	error = ENOENT;
129132780Skan	vcp = NULL;
130132780Skan	SMBCO_FOREACH(scp, &smb_vclist) {
131132780Skan		vcp = (struct smb_vc *)scp;
132250237Sdavide		error = smb_vc_lock(vcp);
13375374Sbp		if (error)
13475374Sbp			continue;
13575374Sbp
136119376Smarcel		if ((vcp->obj.co_flags & SMBV_PRIVATE) ||
137119376Smarcel		    !CONNADDREQ(vcp->vc_paddr, vcspec->sap) ||
138119376Smarcel		    strcmp(vcp->vc_username, vcspec->username) != 0)
139119376Smarcel			goto err1;
140119376Smarcel		if (vcspec->owner != SMBM_ANY_OWNER) {
141119376Smarcel			if (vcp->vc_uid != vcspec->owner)
142119376Smarcel				goto err1;
143119376Smarcel		} else
144119376Smarcel			exact = 0;
145119376Smarcel		if (vcspec->group != SMBM_ANY_GROUP) {
146119376Smarcel			if (vcp->vc_grp != vcspec->group)
147119376Smarcel				goto err1;
148119376Smarcel		} else
149119376Smarcel			exact = 0;
150119376Smarcel		if (vcspec->mode & SMBM_EXACT) {
151119376Smarcel			if (!exact || (vcspec->mode & SMBM_MASK) !=
152119376Smarcel			    vcp->vc_mode)
153119376Smarcel				goto err1;
154119376Smarcel		}
155119376Smarcel		if (smb_vc_access(vcp, scred, vcspec->mode) != 0)
156119376Smarcel			goto err1;
157119376Smarcel		vcspec->ssp = NULL;
158119376Smarcel		if (shspec) {
159119376Smarcel			error = (int)smb_vc_lookupshare(vcp, shspec, scred,
160119376Smarcel			    &vcspec->ssp);
161119376Smarcel			if (error)
162119376Smarcel				goto fail;
163119376Smarcel		}
164119376Smarcel		error = 0;
165119376Smarcel		break;
166119376Smarcel	err1:
167119376Smarcel		error = 1;
168119376Smarcel	fail:
169250237Sdavide		smb_vc_unlock(vcp);
17075374Sbp	}
17175374Sbp	if (vcp) {
17287192Sbp		smb_vc_ref(vcp);
17375374Sbp		*vcpp = vcp;
17475374Sbp	}
175119376Smarcel	return (error);
17675374Sbp}
17775374Sbp
17875374Sbpint
17975374Sbpsmb_sm_lookup(struct smb_vcspec *vcspec, struct smb_sharespec *shspec,
18075374Sbp	struct smb_cred *scred,	struct smb_vc **vcpp)
18175374Sbp{
18275374Sbp	struct smb_vc *vcp;
18375374Sbp	struct smb_share *ssp = NULL;
18475374Sbp	int error;
18575374Sbp
18675374Sbp	*vcpp = vcp = NULL;
18775374Sbp
188250237Sdavide	error = smb_sm_lockvclist();
18975374Sbp	if (error)
19075374Sbp		return error;
19175374Sbp	error = smb_sm_lookupint(vcspec, shspec, scred, vcpp);
19275374Sbp	if (error == 0 || (vcspec->flags & SMBV_CREATE) == 0) {
193184571Srwatson		smb_sm_unlockvclist();
19475374Sbp		return error;
19575374Sbp	}
19675374Sbp	error = smb_sm_lookupint(vcspec, NULL, scred, &vcp);
19775374Sbp	if (error) {
19875374Sbp		error = smb_vc_create(vcspec, scred, &vcp);
19975374Sbp		if (error)
20075374Sbp			goto out;
20175374Sbp		error = smb_vc_connect(vcp, scred);
20275374Sbp		if (error)
20375374Sbp			goto out;
20475374Sbp	}
20575374Sbp	if (shspec == NULL)
20675374Sbp		goto out;
20775374Sbp	error = smb_share_create(vcp, shspec, scred, &ssp);
20875374Sbp	if (error)
20975374Sbp		goto out;
21075374Sbp	error = smb_smb_treeconnect(ssp, scred);
21175374Sbp	if (error == 0)
21275374Sbp		vcspec->ssp = ssp;
21375374Sbp	else
21475374Sbp		smb_share_put(ssp, scred);
21575374Sbpout:
216184571Srwatson	smb_sm_unlockvclist();
21775374Sbp	if (error == 0)
21875374Sbp		*vcpp = vcp;
219184568Srwatson	else if (vcp) {
220250237Sdavide		smb_vc_lock(vcp);
22175374Sbp		smb_vc_put(vcp, scred);
222184568Srwatson	}
22375374Sbp	return error;
22475374Sbp}
22575374Sbp
22675374Sbp/*
22775374Sbp * Common code for connection object
22875374Sbp */
22975374Sbpstatic void
230184571Srwatsonsmb_co_init(struct smb_connobj *cp, int level, char *ilockname, char *lockname)
23175374Sbp{
23275374Sbp	SLIST_INIT(&cp->co_children);
233250237Sdavide	sx_init_flags(&cp->co_interlock, ilockname, SX_RECURSE);
234250237Sdavide	cv_init(&cp->co_lock, "smblock");
235250237Sdavide	cp->co_lockcnt = 0;
236250237Sdavide	cp->co_locker = NULL;
23775374Sbp	cp->co_level = level;
23875374Sbp	cp->co_usecount = 1;
239250237Sdavide	sx_xlock(&cp->co_interlock);
240250237Sdavide	smb_co_lock(cp);
241250237Sdavide	sx_unlock(&cp->co_interlock);
24275374Sbp}
24375374Sbp
24475374Sbpstatic void
24575374Sbpsmb_co_done(struct smb_connobj *cp)
24675374Sbp{
247250237Sdavide
248250237Sdavide	sx_destroy(&cp->co_interlock);
249250237Sdavide	cv_destroy(&cp->co_lock);
250250237Sdavide	cp->co_locker = NULL;
251250237Sdavide	cp->co_flags = 0;
252250237Sdavide	cp->co_lockcnt = 0;
25375374Sbp}
25475374Sbp
25575374Sbpstatic void
25675374Sbpsmb_co_gone(struct smb_connobj *cp, struct smb_cred *scred)
25775374Sbp{
25875374Sbp	struct smb_connobj *parent;
25975374Sbp
26075374Sbp	if (cp->co_gone)
26175374Sbp		cp->co_gone(cp, scred);
26275374Sbp	parent = cp->co_parent;
26375374Sbp	if (parent) {
264250237Sdavide		sx_xlock(&parent->co_interlock);
265250237Sdavide		smb_co_lock(parent);
266250237Sdavide		sx_unlock(&parent->co_interlock);
26775374Sbp		SLIST_REMOVE(&parent->co_children, cp, smb_connobj, co_next);
26875374Sbp		smb_co_put(parent, scred);
26975374Sbp	}
27075374Sbp	if (cp->co_free)
27175374Sbp		cp->co_free(cp);
27275374Sbp}
27375374Sbp
27475374Sbpvoid
27587192Sbpsmb_co_ref(struct smb_connobj *cp)
27675374Sbp{
27775374Sbp
278250237Sdavide	sx_xlock(&cp->co_interlock);
27975374Sbp	cp->co_usecount++;
280250237Sdavide	sx_unlock(&cp->co_interlock);
28175374Sbp}
28275374Sbp
28375374Sbpvoid
28475374Sbpsmb_co_rele(struct smb_connobj *cp, struct smb_cred *scred)
28575374Sbp{
28675374Sbp
287250237Sdavide	sx_xlock(&cp->co_interlock);
288250237Sdavide	smb_co_unlock(cp);
28975374Sbp	if (cp->co_usecount > 1) {
29075374Sbp		cp->co_usecount--;
291250237Sdavide		sx_unlock(&cp->co_interlock);
29275374Sbp		return;
29375374Sbp	}
29475374Sbp	if (cp->co_usecount == 0) {
29575374Sbp		SMBERROR("negative use_count for object %d", cp->co_level);
296250237Sdavide		sx_unlock(&cp->co_interlock);
29775374Sbp		return;
29875374Sbp	}
29975374Sbp	cp->co_usecount--;
30075374Sbp	cp->co_flags |= SMBO_GONE;
301250237Sdavide	sx_unlock(&cp->co_interlock);
30275374Sbp	smb_co_gone(cp, scred);
30375374Sbp}
30475374Sbp
30575374Sbpint
306250237Sdavidesmb_co_get(struct smb_connobj *cp, struct smb_cred *scred)
30775374Sbp{
30875374Sbp	int error;
30975374Sbp
310250237Sdavide	MPASS(sx_xholder(&cp->co_interlock) == curthread);
31175374Sbp	cp->co_usecount++;
312250237Sdavide	error = smb_co_lock(cp);
313250237Sdavide	if (error)
31475374Sbp		cp->co_usecount--;
315250237Sdavide	return error;
31675374Sbp}
31775374Sbp
31875374Sbpvoid
31975374Sbpsmb_co_put(struct smb_connobj *cp, struct smb_cred *scred)
32075374Sbp{
32175374Sbp
322250237Sdavide	sx_xlock(&cp->co_interlock);
32375374Sbp	if (cp->co_usecount > 1) {
32475374Sbp		cp->co_usecount--;
32575374Sbp	} else if (cp->co_usecount == 1) {
32675374Sbp		cp->co_usecount--;
32775374Sbp		cp->co_flags |= SMBO_GONE;
32875374Sbp	} else {
32975374Sbp		SMBERROR("negative usecount");
33075374Sbp	}
331250237Sdavide	smb_co_unlock(cp);
332250237Sdavide	sx_unlock(&cp->co_interlock);
33375374Sbp	if ((cp->co_flags & SMBO_GONE) == 0)
33475374Sbp		return;
33575374Sbp	smb_co_gone(cp, scred);
33675374Sbp}
33775374Sbp
33875374Sbpint
339250237Sdavidesmb_co_lock(struct smb_connobj *cp)
34075374Sbp{
34175374Sbp
342250237Sdavide	MPASS(sx_xholder(&cp->co_interlock) == curthread);
343250237Sdavide	for (;;) {
344250237Sdavide		if (cp->co_flags & SMBO_GONE)
345250237Sdavide			return EINVAL;
346250237Sdavide		if (cp->co_locker == NULL) {
347250237Sdavide			cp->co_locker = curthread;
348250237Sdavide			return 0;
349250237Sdavide		}
350250237Sdavide		if (cp->co_locker == curthread) {
351250237Sdavide			cp->co_lockcnt++;
352250237Sdavide			return 0;
353250237Sdavide		}
354250237Sdavide		cv_wait(&cp->co_lock, &cp->co_interlock);
35575374Sbp	}
35675374Sbp}
35775374Sbp
35875374Sbpvoid
359250237Sdavidesmb_co_unlock(struct smb_connobj *cp)
36075374Sbp{
361250237Sdavide
362250237Sdavide	MPASS(sx_xholder(&cp->co_interlock) == curthread);
363250237Sdavide	MPASS(cp->co_locker == curthread);
364250237Sdavide	if (cp->co_lockcnt != 0) {
365250237Sdavide		cp->co_lockcnt--;
366250237Sdavide		return;
367250237Sdavide	}
368250237Sdavide	cp->co_locker = NULL;
369250237Sdavide	cv_signal(&cp->co_lock);
37075374Sbp}
37175374Sbp
37275374Sbpstatic void
37375374Sbpsmb_co_addchild(struct smb_connobj *parent, struct smb_connobj *child)
37475374Sbp{
37575374Sbp
37687192Sbp	smb_co_ref(parent);
37775374Sbp	SLIST_INSERT_HEAD(&parent->co_children, child, co_next);
37875374Sbp	child->co_parent = parent;
37975374Sbp}
38075374Sbp
38175374Sbp/*
38275374Sbp * Session implementation
38375374Sbp */
38475374Sbp
38575374Sbpint
38675374Sbpsmb_vc_create(struct smb_vcspec *vcspec,
38775374Sbp	struct smb_cred *scred, struct smb_vc **vcpp)
38875374Sbp{
38975374Sbp	struct smb_vc *vcp;
39075374Sbp	struct ucred *cred = scred->scr_cred;
39175374Sbp	uid_t uid = vcspec->owner;
39275374Sbp	gid_t gid = vcspec->group;
39375374Sbp	uid_t realuid = cred->cr_uid;
39475374Sbp	char *domain = vcspec->domain;
39575374Sbp	int error, isroot;
39675374Sbp
39775374Sbp	isroot = smb_suser(cred) == 0;
39875374Sbp	/*
39975374Sbp	 * Only superuser can create VCs with different uid and gid
40075374Sbp	 */
40175374Sbp	if (uid != SMBM_ANY_OWNER && uid != realuid && !isroot)
40275374Sbp		return EPERM;
40375374Sbp	if (gid != SMBM_ANY_GROUP && !groupmember(gid, cred) && !isroot)
40475374Sbp		return EPERM;
40575374Sbp
406111119Simp	vcp = smb_zmalloc(sizeof(*vcp), M_SMBCONN, M_WAITOK);
407184571Srwatson	smb_co_init(VCTOCP(vcp), SMBL_VC, "smb_vc ilock", "smb_vc");
40875374Sbp	vcp->obj.co_free = smb_vc_free;
40975374Sbp	vcp->obj.co_gone = smb_vc_gone;
41075374Sbp	vcp->vc_number = smb_vcnext++;
41175374Sbp	vcp->vc_timo = SMB_DEFRQTIMO;
41275374Sbp	vcp->vc_smbuid = SMB_UID_UNKNOWN;
41375374Sbp	vcp->vc_mode = vcspec->rights & SMBM_MASK;
41475374Sbp	vcp->obj.co_flags = vcspec->flags & (SMBV_PRIVATE | SMBV_SINGLESHARE);
41575374Sbp	vcp->vc_tdesc = &smb_tran_nbtcp_desc;
416124087Stjr	vcp->vc_seqno = 0;
417124087Stjr	vcp->vc_mackey = NULL;
418124087Stjr	vcp->vc_mackeylen = 0;
41975374Sbp
42075374Sbp	if (uid == SMBM_ANY_OWNER)
42175374Sbp		uid = realuid;
42275374Sbp	if (gid == SMBM_ANY_GROUP)
42375374Sbp		gid = cred->cr_groups[0];
42475374Sbp	vcp->vc_uid = uid;
42575374Sbp	vcp->vc_grp = gid;
42675374Sbp
42775374Sbp	smb_sl_init(&vcp->vc_stlock, "vcstlock");
428119376Smarcel	error = ENOMEM;
42975374Sbp
430126425Srwatson	vcp->vc_paddr = sodupsockaddr(vcspec->sap, M_WAITOK);
431119376Smarcel	if (vcp->vc_paddr == NULL)
432119376Smarcel		goto fail;
433126425Srwatson	vcp->vc_laddr = sodupsockaddr(vcspec->lap, M_WAITOK);
434119376Smarcel	if (vcp->vc_laddr == NULL)
435119376Smarcel		goto fail;
436119376Smarcel	vcp->vc_pass = smb_strdup(vcspec->pass);
437119376Smarcel	if (vcp->vc_pass == NULL)
438119376Smarcel		goto fail;
439119376Smarcel	vcp->vc_domain = smb_strdup((domain && domain[0]) ? domain :
440119376Smarcel	    "NODOMAIN");
441119376Smarcel	if (vcp->vc_domain == NULL)
442119376Smarcel		goto fail;
443119376Smarcel	vcp->vc_srvname = smb_strdup(vcspec->srvname);
444119376Smarcel	if (vcp->vc_srvname == NULL)
445119376Smarcel		goto fail;
446119376Smarcel	vcp->vc_username = smb_strdup(vcspec->username);
447119376Smarcel	if (vcp->vc_username == NULL)
448119376Smarcel		goto fail;
449119376Smarcel	error = (int)iconv_open("tolower", vcspec->localcs, &vcp->vc_tolower);
450119376Smarcel	if (error)
451119376Smarcel		goto fail;
452119376Smarcel	error = (int)iconv_open("toupper", vcspec->localcs, &vcp->vc_toupper);
453119376Smarcel	if (error)
454119376Smarcel		goto fail;
455119376Smarcel	if (vcspec->servercs[0]) {
456119376Smarcel		error = (int)iconv_open(vcspec->servercs, vcspec->localcs,
457227650Skevlo		    &vcp->vc_cp_toserver);
458119376Smarcel		if (error)
459119376Smarcel			goto fail;
460119376Smarcel		error = (int)iconv_open(vcspec->localcs, vcspec->servercs,
461227650Skevlo		    &vcp->vc_cp_tolocal);
462119376Smarcel		if (error)
463119376Smarcel			goto fail;
464227650Skevlo		vcp->vc_toserver = vcp->vc_cp_toserver;
465227650Skevlo		vcp->vc_tolocal = vcp->vc_cp_tolocal;
466227650Skevlo		iconv_add(ENCODING_UNICODE, ENCODING_UNICODE, SMB_UNICODE_NAME);
467227650Skevlo		iconv_add(ENCODING_UNICODE, SMB_UNICODE_NAME, ENCODING_UNICODE);
468227650Skevlo		error = (int)iconv_open(SMB_UNICODE_NAME, vcspec->localcs,
469227650Skevlo		    &vcp->vc_ucs_toserver);
470227650Skevlo		if (!error) {
471227650Skevlo			error = (int)iconv_open(vcspec->localcs, SMB_UNICODE_NAME,
472227650Skevlo			    &vcp->vc_ucs_tolocal);
473227650Skevlo		}
474227650Skevlo		if (error) {
475227650Skevlo			if (vcp->vc_ucs_toserver)
476227650Skevlo				iconv_close(vcp->vc_ucs_toserver);
477227650Skevlo			vcp->vc_ucs_toserver = NULL;
478227650Skevlo			vcp->vc_ucs_tolocal = NULL;
479227650Skevlo		}
480119376Smarcel	}
481119376Smarcel	error = (int)smb_iod_create(vcp);
482119376Smarcel	if (error)
483119376Smarcel		goto fail;
484119376Smarcel	*vcpp = vcp;
485119376Smarcel	smb_co_addchild(&smb_vclist, VCTOCP(vcp));
486119376Smarcel	return (0);
48775374Sbp
488119376Smarcel fail:
489119376Smarcel	smb_vc_put(vcp, scred);
490119376Smarcel	return (error);
49175374Sbp}
49275374Sbp
49375374Sbpstatic void
49475374Sbpsmb_vc_free(struct smb_connobj *cp)
49575374Sbp{
49675374Sbp	struct smb_vc *vcp = CPTOVC(cp);
49775374Sbp
49875374Sbp	if (vcp->vc_iod)
49975374Sbp		smb_iod_destroy(vcp->vc_iod);
50075374Sbp	SMB_STRFREE(vcp->vc_username);
50175374Sbp	SMB_STRFREE(vcp->vc_srvname);
50275374Sbp	SMB_STRFREE(vcp->vc_pass);
50375374Sbp	SMB_STRFREE(vcp->vc_domain);
504124087Stjr	if (vcp->vc_mackey)
505124087Stjr		free(vcp->vc_mackey, M_SMBTEMP);
50675374Sbp	if (vcp->vc_paddr)
50775374Sbp		free(vcp->vc_paddr, M_SONAME);
50875374Sbp	if (vcp->vc_laddr)
50975374Sbp		free(vcp->vc_laddr, M_SONAME);
51075374Sbp	if (vcp->vc_tolower)
51175374Sbp		iconv_close(vcp->vc_tolower);
51275374Sbp	if (vcp->vc_toupper)
51375374Sbp		iconv_close(vcp->vc_toupper);
51475374Sbp	if (vcp->vc_tolocal)
515227650Skevlo		vcp->vc_tolocal = NULL;
51675374Sbp	if (vcp->vc_toserver)
517227650Skevlo		vcp->vc_toserver = NULL;
518227650Skevlo	if (vcp->vc_cp_tolocal)
519227650Skevlo		iconv_close(vcp->vc_cp_tolocal);
520227650Skevlo	if (vcp->vc_cp_toserver)
521227650Skevlo		iconv_close(vcp->vc_cp_toserver);
522227650Skevlo	if (vcp->vc_ucs_tolocal)
523227650Skevlo		iconv_close(vcp->vc_ucs_tolocal);
524227650Skevlo	if (vcp->vc_ucs_toserver)
525227650Skevlo		iconv_close(vcp->vc_ucs_toserver);
52675374Sbp	smb_co_done(VCTOCP(vcp));
52775374Sbp	smb_sl_destroy(&vcp->vc_stlock);
52875374Sbp	free(vcp, M_SMBCONN);
52975374Sbp}
53075374Sbp
53175374Sbp/*
53275374Sbp * Called when use count of VC dropped to zero.
53375374Sbp */
53475374Sbpstatic void
53575374Sbpsmb_vc_gone(struct smb_connobj *cp, struct smb_cred *scred)
53675374Sbp{
53775374Sbp	struct smb_vc *vcp = CPTOVC(cp);
53875374Sbp
53975374Sbp	smb_vc_disconnect(vcp);
54075374Sbp}
54175374Sbp
54275374Sbpvoid
54387192Sbpsmb_vc_ref(struct smb_vc *vcp)
54475374Sbp{
54587192Sbp	smb_co_ref(VCTOCP(vcp));
54675374Sbp}
54775374Sbp
54875374Sbpvoid
54975374Sbpsmb_vc_rele(struct smb_vc *vcp, struct smb_cred *scred)
55075374Sbp{
55175374Sbp	smb_co_rele(VCTOCP(vcp), scred);
55275374Sbp}
55375374Sbp
55475374Sbpint
555250237Sdavidesmb_vc_get(struct smb_vc *vcp, struct smb_cred *scred)
55675374Sbp{
557250237Sdavide	struct smb_connobj *cp;
558250237Sdavide	int error;
559250237Sdavide
560250237Sdavide	cp = VCTOCP(vcp);
561250237Sdavide	sx_xlock(&cp->co_interlock);
562250237Sdavide	error = smb_co_get(cp, scred);
563250237Sdavide	sx_unlock(&cp->co_interlock);
564250237Sdavide	return error;
56575374Sbp}
56675374Sbp
56775374Sbpvoid
56875374Sbpsmb_vc_put(struct smb_vc *vcp, struct smb_cred *scred)
56975374Sbp{
57075374Sbp	smb_co_put(VCTOCP(vcp), scred);
57175374Sbp}
57275374Sbp
57375374Sbpint
574250237Sdavidesmb_vc_lock(struct smb_vc *vcp)
57575374Sbp{
576250237Sdavide	struct smb_connobj *cp;
577250237Sdavide	int error;
578250237Sdavide
579250237Sdavide	cp = VCTOCP(vcp);
580250237Sdavide	sx_xlock(&cp->co_interlock);
581250237Sdavide	error = smb_co_lock(cp);
582250237Sdavide	sx_unlock(&cp->co_interlock);
583250237Sdavide	return error;
58475374Sbp}
58575374Sbp
58675374Sbpvoid
587250237Sdavidesmb_vc_unlock(struct smb_vc *vcp)
58875374Sbp{
589250237Sdavide
590250237Sdavide	struct smb_connobj *cp;
591250237Sdavide
592250237Sdavide	cp = VCTOCP(vcp);
593250237Sdavide	sx_xlock(&cp->co_interlock);
594250237Sdavide	smb_co_unlock(cp);
595250237Sdavide	sx_unlock(&cp->co_interlock);
59675374Sbp}
59775374Sbp
59875374Sbpint
59975374Sbpsmb_vc_access(struct smb_vc *vcp, struct smb_cred *scred, mode_t mode)
60075374Sbp{
60175374Sbp	struct ucred *cred = scred->scr_cred;
60275374Sbp
60375374Sbp	if (smb_suser(cred) == 0 || cred->cr_uid == vcp->vc_uid)
60475374Sbp		return 0;
60575374Sbp	mode >>= 3;
60675374Sbp	if (!groupmember(vcp->vc_grp, cred))
60775374Sbp		mode >>= 3;
60875374Sbp	return (vcp->vc_mode & mode) == mode ? 0 : EACCES;
60975374Sbp}
61075374Sbp
61175374Sbpstatic int
61275374Sbpsmb_vc_cmpshare(struct smb_share *ssp, struct smb_sharespec *dp)
61375374Sbp{
61475374Sbp	int exact = 1;
61575374Sbp
61675374Sbp	if (strcmp(ssp->ss_name, dp->name) != 0)
61775374Sbp		return 1;
61875374Sbp	if (dp->owner != SMBM_ANY_OWNER) {
61975374Sbp		if (ssp->ss_uid != dp->owner)
62075374Sbp			return 1;
62175374Sbp	} else
62275374Sbp		exact = 0;
62375374Sbp	if (dp->group != SMBM_ANY_GROUP) {
62475374Sbp		if (ssp->ss_grp != dp->group)
62575374Sbp			return 1;
62675374Sbp	} else
62775374Sbp		exact = 0;
62875374Sbp
62975374Sbp	if (dp->mode & SMBM_EXACT) {
63075374Sbp		if (!exact)
63175374Sbp			return 1;
63275374Sbp		return (dp->mode & SMBM_MASK) == ssp->ss_mode ? 0 : 1;
63375374Sbp	}
63475374Sbp	if (smb_share_access(ssp, dp->scred, dp->mode) != 0)
63575374Sbp		return 1;
63675374Sbp	return 0;
63775374Sbp}
63875374Sbp
63975374Sbp/*
64075374Sbp * Lookup share in the given VC. Share referenced and locked on return.
64175374Sbp * VC expected to be locked on entry and will be left locked on exit.
64275374Sbp */
64375374Sbpint
64475374Sbpsmb_vc_lookupshare(struct smb_vc *vcp, struct smb_sharespec *dp,
64575374Sbp	struct smb_cred *scred,	struct smb_share **sspp)
64675374Sbp{
647132780Skan	struct smb_connobj *scp = NULL;
64875374Sbp	struct smb_share *ssp = NULL;
64975374Sbp	int error;
65075374Sbp
65175374Sbp	*sspp = NULL;
65275374Sbp	dp->scred = scred;
653132780Skan	SMBCO_FOREACH(scp, VCTOCP(vcp)) {
654132780Skan		ssp = (struct smb_share *)scp;
655250237Sdavide		error = smb_share_lock(ssp);
65675374Sbp		if (error)
65775374Sbp			continue;
65875374Sbp		if (smb_vc_cmpshare(ssp, dp) == 0)
65975374Sbp			break;
660250237Sdavide		smb_share_unlock(ssp);
66175374Sbp	}
66275374Sbp	if (ssp) {
66387192Sbp		smb_share_ref(ssp);
66475374Sbp		*sspp = ssp;
66575374Sbp		error = 0;
66675374Sbp	} else
66775374Sbp		error = ENOENT;
66875374Sbp	return error;
66975374Sbp}
67075374Sbp
67175374Sbpint
67275374Sbpsmb_vc_connect(struct smb_vc *vcp, struct smb_cred *scred)
67375374Sbp{
67475374Sbp
67575374Sbp	return smb_iod_request(vcp->vc_iod, SMBIOD_EV_CONNECT | SMBIOD_EV_SYNC, NULL);
67675374Sbp}
67775374Sbp
67875374Sbp/*
67975374Sbp * Destroy VC to server, invalidate shares linked with it.
68075374Sbp * Transport should be locked on entry.
68175374Sbp */
68275374Sbpint
68375374Sbpsmb_vc_disconnect(struct smb_vc *vcp)
68475374Sbp{
68575374Sbp
686291655Srmacklem	if (vcp->vc_iod != NULL)
687291655Srmacklem		smb_iod_request(vcp->vc_iod, SMBIOD_EV_DISCONNECT |
688291655Srmacklem		    SMBIOD_EV_SYNC, NULL);
68975374Sbp	return 0;
69075374Sbp}
69175374Sbp
69275374Sbpstatic char smb_emptypass[] = "";
69375374Sbp
69475374Sbpconst char *
69575374Sbpsmb_vc_getpass(struct smb_vc *vcp)
69675374Sbp{
69775374Sbp	if (vcp->vc_pass)
69875374Sbp		return vcp->vc_pass;
69975374Sbp	return smb_emptypass;
70075374Sbp}
70175374Sbp
70275374Sbpstatic int
70375374Sbpsmb_vc_getinfo(struct smb_vc *vcp, struct smb_vc_info *vip)
70475374Sbp{
70575374Sbp	bzero(vip, sizeof(struct smb_vc_info));
70675374Sbp	vip->itype = SMB_INFO_VC;
70775374Sbp	vip->usecount = vcp->obj.co_usecount;
70875374Sbp	vip->uid = vcp->vc_uid;
70975374Sbp	vip->gid = vcp->vc_grp;
71075374Sbp	vip->mode = vcp->vc_mode;
71175374Sbp	vip->flags = vcp->obj.co_flags;
71275374Sbp	vip->sopt = vcp->vc_sopt;
71375374Sbp	vip->iodstate = vcp->vc_iod->iod_state;
71475374Sbp	bzero(&vip->sopt.sv_skey, sizeof(vip->sopt.sv_skey));
71575374Sbp	snprintf(vip->srvname, sizeof(vip->srvname), "%s", vcp->vc_srvname);
71675374Sbp	snprintf(vip->vcname, sizeof(vip->vcname), "%s", vcp->vc_username);
71775374Sbp	return 0;
71875374Sbp}
71975374Sbp
72075374Sbpu_short
72175374Sbpsmb_vc_nextmid(struct smb_vc *vcp)
72275374Sbp{
72375374Sbp	u_short r;
724250237Sdavide
725250237Sdavide	sx_xlock(&vcp->obj.co_interlock);
72675374Sbp	r = vcp->vc_mid++;
727250237Sdavide	sx_unlock(&vcp->obj.co_interlock);
72875374Sbp	return r;
72975374Sbp}
73075374Sbp
73175374Sbp/*
73275374Sbp * Share implementation
73375374Sbp */
73475374Sbp/*
73575374Sbp * Allocate share structure and attach it to the given VC
73675374Sbp * Connection expected to be locked on entry. Share will be returned
73775374Sbp * in locked state.
73875374Sbp */
73975374Sbpint
74075374Sbpsmb_share_create(struct smb_vc *vcp, struct smb_sharespec *shspec,
74175374Sbp	struct smb_cred *scred, struct smb_share **sspp)
74275374Sbp{
74375374Sbp	struct smb_share *ssp;
74475374Sbp	struct ucred *cred = scred->scr_cred;
74575374Sbp	uid_t realuid = cred->cr_uid;
74675374Sbp	uid_t uid = shspec->owner;
74775374Sbp	gid_t gid = shspec->group;
74875374Sbp	int error, isroot;
74975374Sbp
75075374Sbp	isroot = smb_suser(cred) == 0;
75175374Sbp	/*
75275374Sbp	 * Only superuser can create shares with different uid and gid
75375374Sbp	 */
75475374Sbp	if (uid != SMBM_ANY_OWNER && uid != realuid && !isroot)
75575374Sbp		return EPERM;
75675374Sbp	if (gid != SMBM_ANY_GROUP && !groupmember(gid, cred) && !isroot)
75775374Sbp		return EPERM;
75875374Sbp	error = smb_vc_lookupshare(vcp, shspec, scred, &ssp);
75975374Sbp	if (!error) {
76075374Sbp		smb_share_put(ssp, scred);
76175374Sbp		return EEXIST;
76275374Sbp	}
76375374Sbp	if (uid == SMBM_ANY_OWNER)
76475374Sbp		uid = realuid;
76575374Sbp	if (gid == SMBM_ANY_GROUP)
76675374Sbp		gid = cred->cr_groups[0];
767111119Simp	ssp = smb_zmalloc(sizeof(*ssp), M_SMBCONN, M_WAITOK);
768184571Srwatson	smb_co_init(SSTOCP(ssp), SMBL_SHARE, "smbss ilock", "smbss");
76975374Sbp	ssp->obj.co_free = smb_share_free;
77075374Sbp	ssp->obj.co_gone = smb_share_gone;
77175374Sbp	smb_sl_init(&ssp->ss_stlock, "ssstlock");
77275374Sbp	ssp->ss_name = smb_strdup(shspec->name);
77375374Sbp	if (shspec->pass && shspec->pass[0])
77475374Sbp		ssp->ss_pass = smb_strdup(shspec->pass);
77575374Sbp	ssp->ss_type = shspec->stype;
77675374Sbp	ssp->ss_tid = SMB_TID_UNKNOWN;
77775374Sbp	ssp->ss_uid = uid;
77875374Sbp	ssp->ss_grp = gid;
77975374Sbp	ssp->ss_mode = shspec->rights & SMBM_MASK;
78075374Sbp	smb_co_addchild(VCTOCP(vcp), SSTOCP(ssp));
78175374Sbp	*sspp = ssp;
78275374Sbp	return 0;
78375374Sbp}
78475374Sbp
78575374Sbpstatic void
78675374Sbpsmb_share_free(struct smb_connobj *cp)
78775374Sbp{
78875374Sbp	struct smb_share *ssp = CPTOSS(cp);
78975374Sbp
79075374Sbp	SMB_STRFREE(ssp->ss_name);
79175374Sbp	SMB_STRFREE(ssp->ss_pass);
79275374Sbp	smb_sl_destroy(&ssp->ss_stlock);
79375374Sbp	smb_co_done(SSTOCP(ssp));
79475374Sbp	free(ssp, M_SMBCONN);
79575374Sbp}
79675374Sbp
79775374Sbpstatic void
79875374Sbpsmb_share_gone(struct smb_connobj *cp, struct smb_cred *scred)
79975374Sbp{
80075374Sbp	struct smb_share *ssp = CPTOSS(cp);
80175374Sbp
80275374Sbp	smb_smb_treedisconnect(ssp, scred);
80375374Sbp}
80475374Sbp
80575374Sbpvoid
80687192Sbpsmb_share_ref(struct smb_share *ssp)
80775374Sbp{
80887192Sbp	smb_co_ref(SSTOCP(ssp));
80975374Sbp}
81075374Sbp
81175374Sbpvoid
81275374Sbpsmb_share_rele(struct smb_share *ssp, struct smb_cred *scred)
81375374Sbp{
81475374Sbp	smb_co_rele(SSTOCP(ssp), scred);
81575374Sbp}
81675374Sbp
81775374Sbpint
818250237Sdavidesmb_share_get(struct smb_share *ssp, struct smb_cred *scred)
81975374Sbp{
820250237Sdavide	struct smb_connobj *cp = SSTOCP(ssp);
821250237Sdavide	int error;
822250237Sdavide
823250237Sdavide	sx_xlock(&cp->co_interlock);
824250237Sdavide	error = smb_co_get(cp, scred);
825250237Sdavide	sx_unlock(&cp->co_interlock);
826250237Sdavide	return error;
82775374Sbp}
82875374Sbp
82975374Sbpvoid
83075374Sbpsmb_share_put(struct smb_share *ssp, struct smb_cred *scred)
83175374Sbp{
832250237Sdavide
83375374Sbp	smb_co_put(SSTOCP(ssp), scred);
83475374Sbp}
83575374Sbp
83675374Sbpint
837250237Sdavidesmb_share_lock(struct smb_share *ssp)
83875374Sbp{
839250237Sdavide	struct smb_connobj *cp;
840250237Sdavide	int error;
841250237Sdavide
842250237Sdavide	cp = SSTOCP(ssp);
843250237Sdavide	sx_xlock(&cp->co_interlock);
844250237Sdavide	error = smb_co_lock(cp);
845250237Sdavide	sx_unlock(&cp->co_interlock);
846250237Sdavide	return error;
84775374Sbp}
84875374Sbp
84975374Sbpvoid
850250237Sdavidesmb_share_unlock(struct smb_share *ssp)
85175374Sbp{
852250237Sdavide	struct smb_connobj *cp;
853250237Sdavide
854250237Sdavide	cp = SSTOCP(ssp);
855250237Sdavide	sx_xlock(&cp->co_interlock);
856250237Sdavide	smb_co_unlock(cp);
857250237Sdavide	sx_unlock(&cp->co_interlock);
85875374Sbp}
85975374Sbp
86075374Sbpint
86175374Sbpsmb_share_access(struct smb_share *ssp, struct smb_cred *scred, mode_t mode)
86275374Sbp{
86375374Sbp	struct ucred *cred = scred->scr_cred;
86475374Sbp
86575374Sbp	if (smb_suser(cred) == 0 || cred->cr_uid == ssp->ss_uid)
86675374Sbp		return 0;
86775374Sbp	mode >>= 3;
86875374Sbp	if (!groupmember(ssp->ss_grp, cred))
86975374Sbp		mode >>= 3;
87075374Sbp	return (ssp->ss_mode & mode) == mode ? 0 : EACCES;
87175374Sbp}
87275374Sbp
87375374Sbpvoid
87475374Sbpsmb_share_invalidate(struct smb_share *ssp)
87575374Sbp{
87675374Sbp	ssp->ss_tid = SMB_TID_UNKNOWN;
87775374Sbp}
87875374Sbp
87975374Sbpint
88075374Sbpsmb_share_valid(struct smb_share *ssp)
88175374Sbp{
88275374Sbp	return ssp->ss_tid != SMB_TID_UNKNOWN &&
88375374Sbp	    ssp->ss_vcgenid == SSTOVC(ssp)->vc_genid;
88475374Sbp}
88575374Sbp
88675374Sbpconst char*
88775374Sbpsmb_share_getpass(struct smb_share *ssp)
88875374Sbp{
88975374Sbp	struct smb_vc *vcp;
89075374Sbp
89175374Sbp	if (ssp->ss_pass)
89275374Sbp		return ssp->ss_pass;
89375374Sbp	vcp = SSTOVC(ssp);
89475374Sbp	if (vcp->vc_pass)
89575374Sbp		return vcp->vc_pass;
89675374Sbp	return smb_emptypass;
89775374Sbp}
89875374Sbp
89975374Sbpstatic int
90075374Sbpsmb_share_getinfo(struct smb_share *ssp, struct smb_share_info *sip)
90175374Sbp{
90275374Sbp	bzero(sip, sizeof(struct smb_share_info));
90375374Sbp	sip->itype = SMB_INFO_SHARE;
90475374Sbp	sip->usecount = ssp->obj.co_usecount;
90575374Sbp	sip->tid  = ssp->ss_tid;
90675374Sbp	sip->type= ssp->ss_type;
90775374Sbp	sip->uid = ssp->ss_uid;
90875374Sbp	sip->gid = ssp->ss_grp;
90975374Sbp	sip->mode= ssp->ss_mode;
91075374Sbp	sip->flags = ssp->obj.co_flags;
91175374Sbp	snprintf(sip->sname, sizeof(sip->sname), "%s", ssp->ss_name);
91275374Sbp	return 0;
91375374Sbp}
91475374Sbp
91575374Sbp/*
91675374Sbp * Dump an entire tree into sysctl call
91775374Sbp */
91875374Sbpstatic int
91975374Sbpsmb_sysctl_treedump(SYSCTL_HANDLER_ARGS)
92075374Sbp{
921132780Skan	struct smb_connobj *scp1, *scp2;
92275374Sbp	struct smb_vc *vcp;
92375374Sbp	struct smb_share *ssp;
92475374Sbp	struct smb_vc_info vci;
92575374Sbp	struct smb_share_info ssi;
92675374Sbp	int error, itype;
92775374Sbp
928126253Struckman	error = sysctl_wire_old_buffer(req, 0);
929126253Struckman	if (error)
930126253Struckman		return (error);
931250237Sdavide	error = smb_sm_lockvclist();
93275374Sbp	if (error)
93375374Sbp		return error;
934132780Skan	SMBCO_FOREACH(scp1, &smb_vclist) {
935132780Skan		vcp = (struct smb_vc *)scp1;
936250237Sdavide		error = smb_vc_lock(vcp);
93775374Sbp		if (error)
93875374Sbp			continue;
93975374Sbp		smb_vc_getinfo(vcp, &vci);
94075374Sbp		error = SYSCTL_OUT(req, &vci, sizeof(struct smb_vc_info));
94175374Sbp		if (error) {
942250237Sdavide			smb_vc_unlock(vcp);
94375374Sbp			break;
94475374Sbp		}
945132780Skan		SMBCO_FOREACH(scp2, VCTOCP(vcp)) {
946132780Skan			ssp = (struct smb_share *)scp2;
947250237Sdavide			error = smb_share_lock(ssp);
94875374Sbp			if (error) {
94975374Sbp				error = 0;
95075374Sbp				continue;
95175374Sbp			}
95275374Sbp			smb_share_getinfo(ssp, &ssi);
953250237Sdavide			smb_share_unlock(ssp);
95475374Sbp			error = SYSCTL_OUT(req, &ssi, sizeof(struct smb_share_info));
95575374Sbp			if (error)
95675374Sbp				break;
95775374Sbp		}
958250237Sdavide		smb_vc_unlock(vcp);
95975374Sbp		if (error)
96075374Sbp			break;
96175374Sbp	}
96275374Sbp	if (!error) {
96375374Sbp		itype = SMB_INFO_NONE;
96475374Sbp		error = SYSCTL_OUT(req, &itype, sizeof(itype));
96575374Sbp	}
966184571Srwatson	smb_sm_unlockvclist();
96775374Sbp	return error;
96875374Sbp}
969