r5925: adding FindNext() fix from 3.0; setting version to 3.0.13
[Samba.git] / source / smbd / dir.c
blob1ec35d839c24718b07f76fd71e07ff5cf9d5f8ae
1 /*
2 Unix SMB/CIFS implementation.
3 Directory handling routines
4 Copyright (C) Andrew Tridgell 1992-1998
6 This program is free software; you can redistribute it and/or modify
7 it under the terms of the GNU General Public License as published by
8 the Free Software Foundation; either version 2 of the License, or
9 (at your option) any later version.
11 This program is distributed in the hope that it will be useful,
12 but WITHOUT ANY WARRANTY; without even the implied warranty of
13 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 GNU General Public License for more details.
16 You should have received a copy of the GNU General Public License
17 along with this program; if not, write to the Free Software
18 Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
21 #include "includes.h"
24 This module implements directory related functions for Samba.
27 /* Make directory handle internals available. */
29 #define NAME_CACHE_SIZE 100
31 struct name_cache_entry {
32 char *name;
33 long offset;
36 struct smb_Dir {
37 connection_struct *conn;
38 DIR *dir;
39 long offset;
40 char *dir_path;
41 struct name_cache_entry *name_cache;
42 unsigned int name_cache_index;
45 struct dptr_struct {
46 struct dptr_struct *next, *prev;
47 int dnum;
48 uint16 spid;
49 struct connection_struct *conn;
50 struct smb_Dir *dir_hnd;
51 BOOL expect_close;
52 char *wcard;
53 uint16 attr;
54 char *path;
55 BOOL has_wild; /* Set to true if the wcard entry has MS wildcard characters in it. */
58 static struct bitmap *dptr_bmap;
59 static struct dptr_struct *dirptrs;
60 static int dirhandles_open = 0;
62 #define INVALID_DPTR_KEY (-3)
64 /****************************************************************************
65 Initialise the dir bitmap.
66 ****************************************************************************/
68 void init_dptrs(void)
70 static BOOL dptrs_init=False;
72 if (dptrs_init)
73 return;
75 dptr_bmap = bitmap_allocate(MAX_DIRECTORY_HANDLES);
77 if (!dptr_bmap)
78 exit_server("out of memory in init_dptrs");
80 dptrs_init = True;
83 /****************************************************************************
84 Idle a dptr - the directory is closed but the control info is kept.
85 ****************************************************************************/
87 static void dptr_idle(struct dptr_struct *dptr)
89 if (dptr->dir_hnd) {
90 DEBUG(4,("Idling dptr dnum %d\n",dptr->dnum));
91 CloseDir(dptr->dir_hnd);
92 dptr->dir_hnd = NULL;
96 /****************************************************************************
97 Idle the oldest dptr.
98 ****************************************************************************/
100 static void dptr_idleoldest(void)
102 struct dptr_struct *dptr;
105 * Go to the end of the list.
107 for(dptr = dirptrs; dptr && dptr->next; dptr = dptr->next)
110 if(!dptr) {
111 DEBUG(0,("No dptrs available to idle ?\n"));
112 return;
116 * Idle the oldest pointer.
119 for(; dptr; dptr = dptr->prev) {
120 if (dptr->dir_hnd) {
121 dptr_idle(dptr);
122 return;
127 /****************************************************************************
128 Get the struct dptr_struct for a dir index.
129 ****************************************************************************/
131 static struct dptr_struct *dptr_get(int key, BOOL forclose)
133 struct dptr_struct *dptr;
135 for(dptr = dirptrs; dptr; dptr = dptr->next) {
136 if(dptr->dnum == key) {
137 if (!forclose && !dptr->dir_hnd) {
138 if (dirhandles_open >= MAX_OPEN_DIRECTORIES)
139 dptr_idleoldest();
140 DEBUG(4,("dptr_get: Reopening dptr key %d\n",key));
141 if (!(dptr->dir_hnd = OpenDir(dptr->conn, dptr->path))) {
142 DEBUG(4,("dptr_get: Failed to open %s (%s)\n",dptr->path,
143 strerror(errno)));
144 return False;
147 DLIST_PROMOTE(dirptrs,dptr);
148 return dptr;
151 return(NULL);
154 /****************************************************************************
155 Get the dir path for a dir index.
156 ****************************************************************************/
158 char *dptr_path(int key)
160 struct dptr_struct *dptr = dptr_get(key, False);
161 if (dptr)
162 return(dptr->path);
163 return(NULL);
166 /****************************************************************************
167 Get the dir wcard for a dir index.
168 ****************************************************************************/
170 char *dptr_wcard(int key)
172 struct dptr_struct *dptr = dptr_get(key, False);
173 if (dptr)
174 return(dptr->wcard);
175 return(NULL);
178 /****************************************************************************
179 Get the dir attrib for a dir index.
180 ****************************************************************************/
182 uint16 dptr_attr(int key)
184 struct dptr_struct *dptr = dptr_get(key, False);
185 if (dptr)
186 return(dptr->attr);
187 return(0);
190 /****************************************************************************
191 Set the dir wcard for a dir index.
192 Returns 0 on ok, 1 on fail.
193 ****************************************************************************/
195 BOOL dptr_set_wcard_and_attributes(int key, const char *wcard, uint16 attr)
197 struct dptr_struct *dptr = dptr_get(key, False);
199 if (dptr) {
200 dptr->attr = attr;
201 dptr->wcard = SMB_STRDUP(wcard);
202 if (!dptr->wcard)
203 return False;
204 if (wcard[0] == '.' && wcard[1] == 0) {
205 dptr->has_wild = True;
206 } else {
207 dptr->has_wild = ms_has_wild(wcard);
209 return True;
211 return False;
214 /****************************************************************************
215 Close a dptr (internal func).
216 ****************************************************************************/
218 static void dptr_close_internal(struct dptr_struct *dptr)
220 DEBUG(4,("closing dptr key %d\n",dptr->dnum));
222 DLIST_REMOVE(dirptrs, dptr);
225 * Free the dnum in the bitmap. Remember the dnum value is always
226 * biased by one with respect to the bitmap.
229 if(bitmap_query( dptr_bmap, dptr->dnum - 1) != True) {
230 DEBUG(0,("dptr_close_internal : Error - closing dnum = %d and bitmap not set !\n",
231 dptr->dnum ));
234 bitmap_clear(dptr_bmap, dptr->dnum - 1);
236 if (dptr->dir_hnd) {
237 CloseDir(dptr->dir_hnd);
240 /* Lanman 2 specific code */
241 SAFE_FREE(dptr->wcard);
242 string_set(&dptr->path,"");
243 SAFE_FREE(dptr);
246 /****************************************************************************
247 Close a dptr given a key.
248 ****************************************************************************/
250 void dptr_close(int *key)
252 struct dptr_struct *dptr;
254 if(*key == INVALID_DPTR_KEY)
255 return;
257 /* OS/2 seems to use -1 to indicate "close all directories" */
258 if (*key == -1) {
259 struct dptr_struct *next;
260 for(dptr = dirptrs; dptr; dptr = next) {
261 next = dptr->next;
262 dptr_close_internal(dptr);
264 *key = INVALID_DPTR_KEY;
265 return;
268 dptr = dptr_get(*key, True);
270 if (!dptr) {
271 DEBUG(0,("Invalid key %d given to dptr_close\n", *key));
272 return;
275 dptr_close_internal(dptr);
277 *key = INVALID_DPTR_KEY;
280 /****************************************************************************
281 Close all dptrs for a cnum.
282 ****************************************************************************/
284 void dptr_closecnum(connection_struct *conn)
286 struct dptr_struct *dptr, *next;
287 for(dptr = dirptrs; dptr; dptr = next) {
288 next = dptr->next;
289 if (dptr->conn == conn)
290 dptr_close_internal(dptr);
294 /****************************************************************************
295 Idle all dptrs for a cnum.
296 ****************************************************************************/
298 void dptr_idlecnum(connection_struct *conn)
300 struct dptr_struct *dptr;
301 for(dptr = dirptrs; dptr; dptr = dptr->next) {
302 if (dptr->conn == conn && dptr->dir_hnd)
303 dptr_idle(dptr);
307 /****************************************************************************
308 Close a dptr that matches a given path, only if it matches the spid also.
309 ****************************************************************************/
311 void dptr_closepath(char *path,uint16 spid)
313 struct dptr_struct *dptr, *next;
314 for(dptr = dirptrs; dptr; dptr = next) {
315 next = dptr->next;
316 if (spid == dptr->spid && strequal(dptr->path,path))
317 dptr_close_internal(dptr);
321 /****************************************************************************
322 Try and close the oldest handle not marked for
323 expect close in the hope that the client has
324 finished with that one.
325 ****************************************************************************/
327 static void dptr_close_oldest(BOOL old)
329 struct dptr_struct *dptr;
332 * Go to the end of the list.
334 for(dptr = dirptrs; dptr && dptr->next; dptr = dptr->next)
337 if(!dptr) {
338 DEBUG(0,("No old dptrs available to close oldest ?\n"));
339 return;
343 * If 'old' is true, close the oldest oldhandle dnum (ie. 1 < dnum < 256) that
344 * does not have expect_close set. If 'old' is false, close
345 * one of the new dnum handles.
348 for(; dptr; dptr = dptr->prev) {
349 if ((old && (dptr->dnum < 256) && !dptr->expect_close) ||
350 (!old && (dptr->dnum > 255))) {
351 dptr_close_internal(dptr);
352 return;
357 /****************************************************************************
358 Create a new dir ptr. If the flag old_handle is true then we must allocate
359 from the bitmap range 0 - 255 as old SMBsearch directory handles are only
360 one byte long. If old_handle is false we allocate from the range
361 256 - MAX_DIRECTORY_HANDLES. We bias the number we return by 1 to ensure
362 a directory handle is never zero.
363 ****************************************************************************/
365 int dptr_create(connection_struct *conn, pstring path, BOOL old_handle, BOOL expect_close,uint16 spid)
367 struct dptr_struct *dptr = NULL;
368 struct smb_Dir *dir_hnd;
369 const char *dir2;
371 DEBUG(5,("dptr_create dir=%s\n", path));
373 if (!check_name(path,conn))
374 return(-2); /* Code to say use a unix error return code. */
376 /* use a const pointer from here on */
377 dir2 = path;
378 if (!*dir2)
379 dir2 = ".";
381 dir_hnd = OpenDir(conn, dir2);
382 if (!dir_hnd) {
383 return (-2);
386 string_set(&conn->dirpath,dir2);
388 if (dirhandles_open >= MAX_OPEN_DIRECTORIES)
389 dptr_idleoldest();
391 dptr = SMB_MALLOC_P(struct dptr_struct);
392 if(!dptr) {
393 DEBUG(0,("malloc fail in dptr_create.\n"));
394 CloseDir(dir_hnd);
395 return -1;
398 ZERO_STRUCTP(dptr);
400 if(old_handle) {
403 * This is an old-style SMBsearch request. Ensure the
404 * value we return will fit in the range 1-255.
407 dptr->dnum = bitmap_find(dptr_bmap, 0);
409 if(dptr->dnum == -1 || dptr->dnum > 254) {
412 * Try and close the oldest handle not marked for
413 * expect close in the hope that the client has
414 * finished with that one.
417 dptr_close_oldest(True);
419 /* Now try again... */
420 dptr->dnum = bitmap_find(dptr_bmap, 0);
421 if(dptr->dnum == -1 || dptr->dnum > 254) {
422 DEBUG(0,("dptr_create: returned %d: Error - all old dirptrs in use ?\n", dptr->dnum));
423 SAFE_FREE(dptr);
424 CloseDir(dir_hnd);
425 return -1;
428 } else {
431 * This is a new-style trans2 request. Allocate from
432 * a range that will return 256 - MAX_DIRECTORY_HANDLES.
435 dptr->dnum = bitmap_find(dptr_bmap, 255);
437 if(dptr->dnum == -1 || dptr->dnum < 255) {
440 * Try and close the oldest handle close in the hope that
441 * the client has finished with that one. This will only
442 * happen in the case of the Win98 client bug where it leaks
443 * directory handles.
446 dptr_close_oldest(False);
448 /* Now try again... */
449 dptr->dnum = bitmap_find(dptr_bmap, 255);
451 if(dptr->dnum == -1 || dptr->dnum < 255) {
452 DEBUG(0,("dptr_create: returned %d: Error - all new dirptrs in use ?\n", dptr->dnum));
453 SAFE_FREE(dptr);
454 CloseDir(dir_hnd);
455 return -1;
460 bitmap_set(dptr_bmap, dptr->dnum);
462 dptr->dnum += 1; /* Always bias the dnum by one - no zero dnums allowed. */
464 string_set(&dptr->path,dir2);
465 dptr->conn = conn;
466 dptr->dir_hnd = dir_hnd;
467 dptr->spid = spid;
468 dptr->expect_close = expect_close;
469 dptr->wcard = NULL; /* Only used in lanman2 searches */
470 dptr->attr = 0; /* Only used in lanman2 searches */
471 dptr->has_wild = True; /* Only used in lanman2 searches */
473 DLIST_ADD(dirptrs, dptr);
475 DEBUG(3,("creating new dirptr %d for path %s, expect_close = %d\n",
476 dptr->dnum,path,expect_close));
478 conn->dirptr = dptr;
480 return(dptr->dnum);
484 /****************************************************************************
485 Wrapper functions to access the lower level directory handles.
486 ****************************************************************************/
488 int dptr_CloseDir(struct dptr_struct *dptr)
490 return CloseDir(dptr->dir_hnd);
493 void dptr_SeekDir(struct dptr_struct *dptr, long offset)
495 SeekDir(dptr->dir_hnd, offset);
498 long dptr_TellDir(struct dptr_struct *dptr)
500 return TellDir(dptr->dir_hnd);
503 /****************************************************************************
504 Return the next visible file name, skipping veto'd and invisible files.
505 ****************************************************************************/
507 static const char *dptr_normal_ReadDirName(struct dptr_struct *dptr, long *poffset, SMB_STRUCT_STAT *pst)
509 /* Normal search for the next file. */
510 const char *name;
511 while ((name = ReadDirName(dptr->dir_hnd, poffset)) != NULL) {
512 if (is_visible_file(dptr->conn, dptr->path, name, pst, True)) {
513 return name;
516 return NULL;
519 /****************************************************************************
520 Return the next visible file name, skipping veto'd and invisible files.
521 ****************************************************************************/
523 const char *dptr_ReadDirName(struct dptr_struct *dptr, long *poffset, SMB_STRUCT_STAT *pst)
525 pstring pathreal;
527 ZERO_STRUCTP(pst);
529 if (dptr->has_wild) {
530 return dptr_normal_ReadDirName(dptr, poffset, pst);
533 /* If poffset is -1 then we know we returned this name before and we have
534 no wildcards. We're at the end of the directory. */
535 if (*poffset == -1) {
536 return NULL;
539 /* We know the stored wcard contains no wildcard characters. See if we can match
540 with a stat call. If we can't, then set has_wild to true to
541 prevent us from doing this on every call. */
543 /* First check if it should be visible. */
544 if (!is_visible_file(dptr->conn, dptr->path, dptr->wcard, pst, True)) {
545 dptr->has_wild = True;
546 return dptr_normal_ReadDirName(dptr, poffset, pst);
549 if (VALID_STAT(*pst)) {
550 /* We need to set the underlying dir_hdn offset to -1 also as
551 this function is usually called with the output from TellDir. */
552 dptr->dir_hnd->offset = *poffset = -1;
553 return dptr->wcard;
556 pstrcpy(pathreal,dptr->path);
557 pstrcat(pathreal,"/");
558 pstrcat(pathreal,dptr->wcard);
560 if (SMB_VFS_STAT(dptr->conn,pathreal,pst) == 0) {
561 /* We need to set the underlying dir_hdn offset to -1 also as
562 this function is usually called with the output from TellDir. */
563 dptr->dir_hnd->offset = *poffset = -1;
564 return dptr->wcard;
565 } else {
566 /* If we get any other error than ENOENT or ENOTDIR
567 then the file exists we just can't stat it. */
568 if (errno != ENOENT && errno != ENOTDIR) {
569 /* We need to set the underlying dir_hdn offset to -1 also as
570 this function is usually called with the output from TellDir. */
571 dptr->dir_hnd->offset = *poffset = -1;
572 return dptr->wcard;
576 dptr->has_wild = True;
578 /* In case sensitive mode we don't search - we know if it doesn't exist
579 with a stat we will fail. */
581 if (dptr->conn->case_sensitive) {
582 /* We need to set the underlying dir_hdn offset to -1 also as
583 this function is usually called with the output from TellDir. */
584 dptr->dir_hnd->offset = *poffset = -1;
585 return NULL;
586 } else {
587 return dptr_normal_ReadDirName(dptr, poffset, pst);
591 /****************************************************************************
592 Search for a file by name, skipping veto'ed and not visible files.
593 ****************************************************************************/
595 BOOL dptr_SearchDir(struct dptr_struct *dptr, const char *name, long *poffset, SMB_STRUCT_STAT *pst)
597 ZERO_STRUCTP(pst);
599 if (!dptr->has_wild && (dptr->dir_hnd->offset == -1)) {
600 /* This is a singleton directory and we're already at the end. */
601 *poffset = -1;
602 return False;
605 while (SearchDir(dptr->dir_hnd, name, poffset) == True) {
606 if (is_visible_file(dptr->conn, dptr->path, name, pst, True)) {
607 return True;
610 return False;
613 /****************************************************************************
614 Fill the 5 byte server reserved dptr field.
615 ****************************************************************************/
617 BOOL dptr_fill(char *buf1,unsigned int key)
619 unsigned char *buf = (unsigned char *)buf1;
620 struct dptr_struct *dptr = dptr_get(key, False);
621 uint32 offset;
622 if (!dptr) {
623 DEBUG(1,("filling null dirptr %d\n",key));
624 return(False);
626 offset = TellDir(dptr->dir_hnd);
627 DEBUG(6,("fill on key %u dirptr 0x%lx now at %d\n",key,
628 (long)dptr->dir_hnd,(int)offset));
629 buf[0] = key;
630 SIVAL(buf,1,offset | DPTR_MASK);
631 return(True);
634 /****************************************************************************
635 Fetch the dir ptr and seek it given the 5 byte server field.
636 ****************************************************************************/
638 struct dptr_struct *dptr_fetch(char *buf,int *num)
640 unsigned int key = *(unsigned char *)buf;
641 struct dptr_struct *dptr = dptr_get(key, False);
642 uint32 offset;
644 if (!dptr) {
645 DEBUG(3,("fetched null dirptr %d\n",key));
646 return(NULL);
648 *num = key;
649 offset = IVAL(buf,1)&~DPTR_MASK;
650 SeekDir(dptr->dir_hnd,(long)offset);
651 DEBUG(3,("fetching dirptr %d for path %s at offset %d\n",
652 key,dptr_path(key),offset));
653 return(dptr);
656 /****************************************************************************
657 Fetch the dir ptr.
658 ****************************************************************************/
660 struct dptr_struct *dptr_fetch_lanman2(int dptr_num)
662 struct dptr_struct *dptr = dptr_get(dptr_num, False);
664 if (!dptr) {
665 DEBUG(3,("fetched null dirptr %d\n",dptr_num));
666 return(NULL);
668 DEBUG(3,("fetching dirptr %d for path %s\n",dptr_num,dptr_path(dptr_num)));
669 return(dptr);
672 /****************************************************************************
673 Check a filetype for being valid.
674 ****************************************************************************/
676 BOOL dir_check_ftype(connection_struct *conn,int mode,int dirtype)
678 int mask;
680 /* Check the "may have" search bits. */
681 if (((mode & ~dirtype) & (aHIDDEN | aSYSTEM | aDIR)) != 0)
682 return False;
684 /* Check the "must have" bits, which are the may have bits shifted eight */
685 /* If must have bit is set, the file/dir can not be returned in search unless the matching
686 file attribute is set */
687 mask = ((dirtype >> 8) & (aDIR|aARCH|aRONLY|aHIDDEN|aSYSTEM)); /* & 0x37 */
688 if(mask) {
689 if((mask & (mode & (aDIR|aARCH|aRONLY|aHIDDEN|aSYSTEM))) == mask) /* check if matching attribute present */
690 return True;
691 else
692 return False;
695 return True;
698 static BOOL mangle_mask_match(connection_struct *conn, fstring filename, char *mask)
700 mangle_map(filename,True,False,SNUM(conn));
701 return mask_match(filename,mask,False);
704 /****************************************************************************
705 Get an 8.3 directory entry.
706 ****************************************************************************/
708 BOOL get_dir_entry(connection_struct *conn,char *mask,int dirtype, pstring fname,
709 SMB_OFF_T *size,int *mode,time_t *date,BOOL check_descend)
711 const char *dname;
712 BOOL found = False;
713 SMB_STRUCT_STAT sbuf;
714 pstring path;
715 pstring pathreal;
716 BOOL isrootdir;
717 pstring filename;
718 BOOL needslash;
720 *path = *pathreal = *filename = 0;
722 isrootdir = (strequal(conn->dirpath,"./") ||
723 strequal(conn->dirpath,".") ||
724 strequal(conn->dirpath,"/"));
726 needslash = ( conn->dirpath[strlen(conn->dirpath) -1] != '/');
728 if (!conn->dirptr)
729 return(False);
731 while (!found) {
732 long curoff = dptr_TellDir(conn->dirptr);
733 dname = dptr_ReadDirName(conn->dirptr, &curoff, &sbuf);
735 DEBUG(6,("readdir on dirptr 0x%lx now at offset %ld\n",
736 (long)conn->dirptr,TellDir(conn->dirptr->dir_hnd)));
738 if (dname == NULL)
739 return(False);
741 pstrcpy(filename,dname);
743 /* notice the special *.* handling. This appears to be the only difference
744 between the wildcard handling in this routine and in the trans2 routines.
745 see masktest for a demo
747 if ((strcmp(mask,"*.*") == 0) ||
748 mask_match(filename,mask,False) ||
749 mangle_mask_match(conn,filename,mask)) {
750 if (isrootdir && (strequal(filename,"..") || strequal(filename,".")))
751 continue;
753 if (!mangle_is_8_3(filename, False))
754 mangle_map(filename,True,False,SNUM(conn));
756 pstrcpy(fname,filename);
757 *path = 0;
758 pstrcpy(path,conn->dirpath);
759 if(needslash)
760 pstrcat(path,"/");
761 pstrcpy(pathreal,path);
762 pstrcat(path,fname);
763 pstrcat(pathreal,dname);
764 if (!VALID_STAT(sbuf) && (SMB_VFS_STAT(conn, pathreal, &sbuf)) != 0) {
765 DEBUG(5,("Couldn't stat 1 [%s]. Error = %s\n",path, strerror(errno) ));
766 continue;
769 *mode = dos_mode(conn,pathreal,&sbuf);
771 if (!dir_check_ftype(conn,*mode,dirtype)) {
772 DEBUG(5,("[%s] attribs didn't match %x\n",filename,dirtype));
773 continue;
776 *size = sbuf.st_size;
777 *date = sbuf.st_mtime;
779 DEBUG(3,("get_dir_entry mask=[%s] found %s fname=%s\n",mask, pathreal,fname));
781 found = True;
785 return(found);
788 /*******************************************************************
789 Check to see if a user can read a file. This is only approximate,
790 it is used as part of the "hide unreadable" option. Don't
791 use it for anything security sensitive.
792 ********************************************************************/
794 static BOOL user_can_read_file(connection_struct *conn, char *name, SMB_STRUCT_STAT *pst)
796 extern struct current_user current_user;
797 SEC_DESC *psd = NULL;
798 size_t sd_size;
799 files_struct *fsp;
800 int smb_action;
801 NTSTATUS status;
802 uint32 access_granted;
805 * If user is a member of the Admin group
806 * we never hide files from them.
809 if (conn->admin_user)
810 return True;
812 /* If we can't stat it does not show it */
813 if (!VALID_STAT(*pst) && (SMB_VFS_STAT(conn, name, pst) != 0))
814 return False;
816 /* Pseudo-open the file (note - no fd's created). */
818 if(S_ISDIR(pst->st_mode))
819 fsp = open_directory(conn, name, pst, 0, SET_DENY_MODE(DENY_NONE), (FILE_FAIL_IF_NOT_EXIST|FILE_EXISTS_OPEN),
820 &smb_action);
821 else
822 fsp = open_file_stat(conn, name, pst);
824 if (!fsp)
825 return False;
827 /* Get NT ACL -allocated in main loop talloc context. No free needed here. */
828 sd_size = SMB_VFS_FGET_NT_ACL(fsp, fsp->fd,
829 (OWNER_SECURITY_INFORMATION|GROUP_SECURITY_INFORMATION|DACL_SECURITY_INFORMATION), &psd);
830 close_file(fsp, True);
832 /* No access if SD get failed. */
833 if (!sd_size)
834 return False;
836 return se_access_check(psd, current_user.nt_user_token, FILE_READ_DATA,
837 &access_granted, &status);
840 /*******************************************************************
841 Check to see if a user can write a file (and only files, we do not
842 check dirs on this one). This is only approximate,
843 it is used as part of the "hide unwriteable" option. Don't
844 use it for anything security sensitive.
845 ********************************************************************/
847 static BOOL user_can_write_file(connection_struct *conn, char *name, SMB_STRUCT_STAT *pst)
849 extern struct current_user current_user;
850 SEC_DESC *psd = NULL;
851 size_t sd_size;
852 files_struct *fsp;
853 int smb_action;
854 int access_mode;
855 NTSTATUS status;
856 uint32 access_granted;
859 * If user is a member of the Admin group
860 * we never hide files from them.
863 if (conn->admin_user)
864 return True;
866 /* If we can't stat it does not show it */
867 if (!VALID_STAT(*pst) && (SMB_VFS_STAT(conn, name, pst) != 0))
868 return False;
870 /* Pseudo-open the file (note - no fd's created). */
872 if(S_ISDIR(pst->st_mode))
873 return True;
874 else
875 fsp = open_file_shared1(conn, name, pst, FILE_WRITE_ATTRIBUTES, SET_DENY_MODE(DENY_NONE),
876 (FILE_FAIL_IF_NOT_EXIST|FILE_EXISTS_OPEN), FILE_ATTRIBUTE_NORMAL, INTERNAL_OPEN_ONLY,
877 &access_mode, &smb_action);
879 if (!fsp)
880 return False;
882 /* Get NT ACL -allocated in main loop talloc context. No free needed here. */
883 sd_size = SMB_VFS_FGET_NT_ACL(fsp, fsp->fd,
884 (OWNER_SECURITY_INFORMATION|GROUP_SECURITY_INFORMATION|DACL_SECURITY_INFORMATION), &psd);
885 close_file(fsp, False);
887 /* No access if SD get failed. */
888 if (!sd_size)
889 return False;
891 return se_access_check(psd, current_user.nt_user_token, FILE_WRITE_DATA,
892 &access_granted, &status);
895 /*******************************************************************
896 Is a file a "special" type ?
897 ********************************************************************/
899 static BOOL file_is_special(connection_struct *conn, char *name, SMB_STRUCT_STAT *pst)
902 * If user is a member of the Admin group
903 * we never hide files from them.
906 if (conn->admin_user)
907 return False;
909 /* If we can't stat it does not show it */
910 if (!VALID_STAT(*pst) && (SMB_VFS_STAT(conn, name, pst) != 0))
911 return True;
913 if (S_ISREG(pst->st_mode) || S_ISDIR(pst->st_mode) || S_ISLNK(pst->st_mode))
914 return False;
916 return True;
919 /*******************************************************************
920 Should the file be seen by the client ?
921 ********************************************************************/
923 BOOL is_visible_file(connection_struct *conn, const char *dir_path, const char *name, SMB_STRUCT_STAT *pst, BOOL use_veto)
925 BOOL hide_unreadable = lp_hideunreadable(SNUM(conn));
926 BOOL hide_unwriteable = lp_hideunwriteable_files(SNUM(conn));
927 BOOL hide_special = lp_hide_special_files(SNUM(conn));
929 ZERO_STRUCTP(pst);
931 if ((strcmp(".",name) == 0) || (strcmp("..",name) == 0)) {
932 return True; /* . and .. are always visible. */
935 /* If it's a vetoed file, pretend it doesn't even exist */
936 if (use_veto && IS_VETO_PATH(conn, name)) {
937 return False;
940 if (hide_unreadable || hide_unwriteable || hide_special) {
941 char *entry = NULL;
943 if (asprintf(&entry, "%s/%s", dir_path, name) == -1) {
944 return False;
946 /* Honour _hide unreadable_ option */
947 if (hide_unreadable && !user_can_read_file(conn, entry, pst)) {
948 SAFE_FREE(entry);
949 return False;
951 /* Honour _hide unwriteable_ option */
952 if (hide_unwriteable && !user_can_write_file(conn, entry, pst)) {
953 SAFE_FREE(entry);
954 return False;
956 /* Honour _hide_special_ option */
957 if (hide_special && !file_is_special(conn, entry, pst)) {
958 SAFE_FREE(entry);
959 return False;
961 SAFE_FREE(entry);
963 return True;
966 /*******************************************************************
967 Open a directory.
968 ********************************************************************/
970 struct smb_Dir *OpenDir(connection_struct *conn, const char *name)
972 struct smb_Dir *dirp = SMB_MALLOC_P(struct smb_Dir);
973 if (!dirp) {
974 return NULL;
976 ZERO_STRUCTP(dirp);
978 dirp->conn = conn;
980 dirp->dir_path = SMB_STRDUP(name);
981 if (!dirp->dir_path) {
982 goto fail;
984 dirp->dir = SMB_VFS_OPENDIR(conn, dirp->dir_path);
985 if (!dirp->dir) {
986 DEBUG(5,("OpenDir: Can't open %s. %s\n", dirp->dir_path, strerror(errno) ));
987 goto fail;
990 dirp->name_cache = SMB_CALLOC_ARRAY(struct name_cache_entry, NAME_CACHE_SIZE);
991 if (!dirp->name_cache) {
992 goto fail;
995 dirhandles_open++;
996 return dirp;
998 fail:
1000 if (dirp) {
1001 if (dirp->dir) {
1002 SMB_VFS_CLOSEDIR(conn,dirp->dir);
1004 SAFE_FREE(dirp->dir_path);
1005 SAFE_FREE(dirp->name_cache);
1006 SAFE_FREE(dirp);
1008 return NULL;
1012 /*******************************************************************
1013 Close a directory.
1014 ********************************************************************/
1016 int CloseDir(struct smb_Dir *dirp)
1018 int i, ret = 0;
1020 if (dirp->dir) {
1021 ret = SMB_VFS_CLOSEDIR(dirp->conn,dirp->dir);
1023 SAFE_FREE(dirp->dir_path);
1024 if (dirp->name_cache) {
1025 for (i = 0; i < NAME_CACHE_SIZE; i++) {
1026 SAFE_FREE(dirp->name_cache[i].name);
1029 SAFE_FREE(dirp->name_cache);
1030 SAFE_FREE(dirp);
1031 dirhandles_open--;
1032 return ret;
1035 /*******************************************************************
1036 Read from a directory. Also return current offset.
1037 Don't check for veto or invisible files.
1038 ********************************************************************/
1040 const char *ReadDirName(struct smb_Dir *dirp, long *poffset)
1042 const char *n;
1043 connection_struct *conn = dirp->conn;
1045 SeekDir(dirp, *poffset);
1046 while ((n = vfs_readdirname(conn, dirp->dir))) {
1047 struct name_cache_entry *e;
1048 dirp->offset = SMB_VFS_TELLDIR(conn, dirp->dir);
1049 if (dirp->offset == -1) {
1050 return NULL;
1052 dirp->name_cache_index = (dirp->name_cache_index+1) % NAME_CACHE_SIZE;
1054 e = &dirp->name_cache[dirp->name_cache_index];
1055 SAFE_FREE(e->name);
1056 e->name = SMB_STRDUP(n);
1057 *poffset = e->offset= dirp->offset;
1058 return e->name;
1060 dirp->offset = -1;
1061 return NULL;
1064 /*******************************************************************
1065 Seek a dir.
1066 ********************************************************************/
1068 void SeekDir(struct smb_Dir *dirp, long offset)
1070 if (offset != dirp->offset) {
1071 SMB_VFS_SEEKDIR(dirp->conn, dirp->dir, offset);
1072 dirp->offset = offset;
1076 /*******************************************************************
1077 Tell a dir position.
1078 ********************************************************************/
1080 long TellDir(struct smb_Dir *dirp)
1082 return(dirp->offset);
1085 /*******************************************************************
1086 Find an entry by name. Leave us at the offset after it.
1087 Don't check for veto or invisible files.
1088 ********************************************************************/
1090 BOOL SearchDir(struct smb_Dir *dirp, const char *name, long *poffset)
1092 int i;
1093 const char *entry;
1094 connection_struct *conn = dirp->conn;
1096 /* Search back in the name cache. */
1097 for (i = dirp->name_cache_index; i >= 0; i--) {
1098 struct name_cache_entry *e = &dirp->name_cache[i];
1099 if (e->name && (conn->case_sensitive ? (strcmp(e->name, name) == 0) : strequal(e->name, name))) {
1100 *poffset = e->offset;
1101 SeekDir(dirp, e->offset);
1102 return True;
1105 for (i = NAME_CACHE_SIZE-1; i > dirp->name_cache_index; i--) {
1106 struct name_cache_entry *e = &dirp->name_cache[i];
1107 if (e->name && (conn->case_sensitive ? (strcmp(e->name, name) == 0) : strequal(e->name, name))) {
1108 *poffset = e->offset;
1109 SeekDir(dirp, e->offset);
1110 return True;
1114 /* Not found in the name cache. Rewind directory and start from scratch. */
1115 SMB_VFS_REWINDDIR(conn, dirp->dir);
1116 *poffset = 0;
1117 while ((entry = ReadDirName(dirp, poffset))) {
1118 if (conn->case_sensitive ? (strcmp(entry, name) == 0) : strequal(entry, name)) {
1119 return True;
1122 return False;