smbd: avoid calling SMB_VFS_FGET_NT_ACL() if do_not_check_mask already covers all
[Samba.git] / source3 / smbd / smb2_getinfo.c
blob0320dcc5fdef65b7a4ffe7e3ad67057d4702e157
1 /*
2 Unix SMB/CIFS implementation.
3 Core SMB2 server
5 Copyright (C) Stefan Metzmacher 2009
6 Copyright (C) Jeremy Allison 2010
8 This program is free software; you can redistribute it and/or modify
9 it under the terms of the GNU General Public License as published by
10 the Free Software Foundation; either version 3 of the License, or
11 (at your option) any later version.
13 This program is distributed in the hope that it will be useful,
14 but WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 GNU General Public License for more details.
18 You should have received a copy of the GNU General Public License
19 along with this program. If not, see <http://www.gnu.org/licenses/>.
22 #include "includes.h"
23 #include "smbd/smbd.h"
24 #include "smbd/globals.h"
25 #include "../libcli/smb/smb_common.h"
26 #include "trans2.h"
27 #include "../lib/util/tevent_ntstatus.h"
28 #include "librpc/gen_ndr/ndr_quota.h"
29 #include "librpc/gen_ndr/ndr_security.h"
31 #undef DBGC_CLASS
32 #define DBGC_CLASS DBGC_SMB2
34 static struct tevent_req *smbd_smb2_getinfo_send(TALLOC_CTX *mem_ctx,
35 struct tevent_context *ev,
36 struct smbd_smb2_request *smb2req,
37 struct files_struct *in_fsp,
38 uint8_t in_info_type,
39 uint8_t in_file_info_class,
40 uint32_t in_output_buffer_length,
41 DATA_BLOB in_input_buffer,
42 uint32_t in_additional_information,
43 uint32_t in_flags);
44 static NTSTATUS smbd_smb2_getinfo_recv(struct tevent_req *req,
45 TALLOC_CTX *mem_ctx,
46 DATA_BLOB *out_output_buffer,
47 NTSTATUS *p_call_status);
49 static void smbd_smb2_request_getinfo_done(struct tevent_req *subreq);
50 NTSTATUS smbd_smb2_request_process_getinfo(struct smbd_smb2_request *req)
52 struct smbXsrv_connection *xconn = req->xconn;
53 NTSTATUS status;
54 const uint8_t *inbody;
55 uint8_t in_info_type;
56 uint8_t in_file_info_class;
57 uint32_t in_output_buffer_length;
58 uint16_t in_input_buffer_offset;
59 uint32_t in_input_buffer_length;
60 DATA_BLOB in_input_buffer;
61 uint32_t in_additional_information;
62 uint32_t in_flags;
63 uint64_t in_file_id_persistent;
64 uint64_t in_file_id_volatile;
65 struct files_struct *in_fsp;
66 struct tevent_req *subreq;
68 status = smbd_smb2_request_verify_sizes(req, 0x29);
69 if (!NT_STATUS_IS_OK(status)) {
70 return smbd_smb2_request_error(req, status);
72 inbody = SMBD_SMB2_IN_BODY_PTR(req);
74 in_info_type = CVAL(inbody, 0x02);
75 in_file_info_class = CVAL(inbody, 0x03);
76 in_output_buffer_length = IVAL(inbody, 0x04);
77 in_input_buffer_offset = SVAL(inbody, 0x08);
78 /* 0x0A 2 bytes reserved */
79 in_input_buffer_length = IVAL(inbody, 0x0C);
80 in_additional_information = IVAL(inbody, 0x10);
81 in_flags = IVAL(inbody, 0x14);
82 in_file_id_persistent = BVAL(inbody, 0x18);
83 in_file_id_volatile = BVAL(inbody, 0x20);
85 if (in_input_buffer_offset == 0 && in_input_buffer_length == 0) {
86 /* This is ok */
87 } else if (in_input_buffer_offset !=
88 (SMB2_HDR_BODY + SMBD_SMB2_IN_BODY_LEN(req))) {
89 return smbd_smb2_request_error(req, NT_STATUS_INVALID_PARAMETER);
92 if (in_input_buffer_length > SMBD_SMB2_IN_DYN_LEN(req)) {
93 return smbd_smb2_request_error(req, NT_STATUS_INVALID_PARAMETER);
96 in_input_buffer.data = SMBD_SMB2_IN_DYN_PTR(req);
97 in_input_buffer.length = in_input_buffer_length;
99 if (in_input_buffer.length > xconn->smb2.server.max_trans) {
100 DEBUG(2,("smbd_smb2_request_process_getinfo: "
101 "client ignored max trans: %s: 0x%08X: 0x%08X\n",
102 __location__, (unsigned)in_input_buffer.length,
103 (unsigned)xconn->smb2.server.max_trans));
104 return smbd_smb2_request_error(req, NT_STATUS_INVALID_PARAMETER);
106 if (in_output_buffer_length > xconn->smb2.server.max_trans) {
107 DEBUG(2,("smbd_smb2_request_process_getinfo: "
108 "client ignored max trans: %s: 0x%08X: 0x%08X\n",
109 __location__, in_output_buffer_length,
110 xconn->smb2.server.max_trans));
111 return smbd_smb2_request_error(req, NT_STATUS_INVALID_PARAMETER);
114 status = smbd_smb2_request_verify_creditcharge(req,
115 MAX(in_input_buffer.length,in_output_buffer_length));
116 if (!NT_STATUS_IS_OK(status)) {
117 return smbd_smb2_request_error(req, status);
120 in_fsp = file_fsp_smb2(req, in_file_id_persistent, in_file_id_volatile);
121 if (in_fsp == NULL) {
122 return smbd_smb2_request_error(req, NT_STATUS_FILE_CLOSED);
125 subreq = smbd_smb2_getinfo_send(req, req->sconn->ev_ctx,
126 req, in_fsp,
127 in_info_type,
128 in_file_info_class,
129 in_output_buffer_length,
130 in_input_buffer,
131 in_additional_information,
132 in_flags);
133 if (subreq == NULL) {
134 return smbd_smb2_request_error(req, NT_STATUS_NO_MEMORY);
136 tevent_req_set_callback(subreq, smbd_smb2_request_getinfo_done, req);
138 return smbd_smb2_request_pending_queue(req, subreq, 500);
141 static void smbd_smb2_request_getinfo_done(struct tevent_req *subreq)
143 struct smbd_smb2_request *req = tevent_req_callback_data(subreq,
144 struct smbd_smb2_request);
145 DATA_BLOB outbody;
146 DATA_BLOB outdyn;
147 uint16_t out_output_buffer_offset;
148 DATA_BLOB out_output_buffer = data_blob_null;
149 NTSTATUS status;
150 NTSTATUS call_status = NT_STATUS_OK;
151 NTSTATUS error; /* transport error */
153 status = smbd_smb2_getinfo_recv(subreq,
154 req,
155 &out_output_buffer,
156 &call_status);
157 TALLOC_FREE(subreq);
158 if (!NT_STATUS_IS_OK(status)) {
159 error = smbd_smb2_request_error(req, status);
160 if (!NT_STATUS_IS_OK(error)) {
161 smbd_server_connection_terminate(req->xconn,
162 nt_errstr(error));
163 return;
165 return;
168 /* some GetInfo responses set STATUS_BUFFER_OVERFLOW and return partial,
169 but valid data */
170 if (!(NT_STATUS_IS_OK(call_status) ||
171 NT_STATUS_EQUAL(call_status, STATUS_BUFFER_OVERFLOW))) {
172 /* Return a specific error with data. */
173 error = smbd_smb2_request_error_ex(req,
174 call_status,
175 &out_output_buffer,
176 __location__);
177 if (!NT_STATUS_IS_OK(error)) {
178 smbd_server_connection_terminate(req->xconn,
179 nt_errstr(error));
180 return;
182 return;
185 out_output_buffer_offset = SMB2_HDR_BODY + 0x08;
187 outbody = smbd_smb2_generate_outbody(req, 0x08);
188 if (outbody.data == NULL) {
189 error = smbd_smb2_request_error(req, NT_STATUS_NO_MEMORY);
190 if (!NT_STATUS_IS_OK(error)) {
191 smbd_server_connection_terminate(req->xconn,
192 nt_errstr(error));
193 return;
195 return;
198 SSVAL(outbody.data, 0x00, 0x08 + 1); /* struct size */
199 SSVAL(outbody.data, 0x02,
200 out_output_buffer_offset); /* output buffer offset */
201 SIVAL(outbody.data, 0x04,
202 out_output_buffer.length); /* output buffer length */
204 outdyn = out_output_buffer;
206 error = smbd_smb2_request_done_ex(req, call_status, outbody, &outdyn, __location__);
207 if (!NT_STATUS_IS_OK(error)) {
208 smbd_server_connection_terminate(req->xconn,
209 nt_errstr(error));
210 return;
214 struct smbd_smb2_getinfo_state {
215 struct smbd_smb2_request *smb2req;
216 NTSTATUS status;
217 DATA_BLOB out_output_buffer;
220 static void smb2_ipc_getinfo(struct tevent_req *req,
221 struct smbd_smb2_getinfo_state *state,
222 struct tevent_context *ev,
223 uint8_t in_info_type,
224 uint8_t in_file_info_class)
226 /* We want to reply to SMB2_GETINFO_FILE
227 with a class of SMB2_FILE_STANDARD_INFO as
228 otherwise a Win7 client issues this request
229 twice (2xroundtrips) if we return NOT_SUPPORTED.
230 NB. We do the same for SMB1 in call_trans2qpipeinfo() */
232 if (in_info_type == 0x01 && /* SMB2_GETINFO_FILE */
233 in_file_info_class == 0x05) { /* SMB2_FILE_STANDARD_INFO */
234 state->out_output_buffer = data_blob_talloc(state,
235 NULL, 24);
236 if (tevent_req_nomem(state->out_output_buffer.data, req)) {
237 return;
240 memset(state->out_output_buffer.data,0,24);
241 SOFF_T(state->out_output_buffer.data,0,4096LL);
242 SIVAL(state->out_output_buffer.data,16,1);
243 SIVAL(state->out_output_buffer.data,20,1);
244 tevent_req_done(req);
245 } else {
246 tevent_req_nterror(req, NT_STATUS_NOT_SUPPORTED);
250 static struct tevent_req *smbd_smb2_getinfo_send(TALLOC_CTX *mem_ctx,
251 struct tevent_context *ev,
252 struct smbd_smb2_request *smb2req,
253 struct files_struct *fsp,
254 uint8_t in_info_type,
255 uint8_t in_file_info_class,
256 uint32_t in_output_buffer_length,
257 DATA_BLOB in_input_buffer,
258 uint32_t in_additional_information,
259 uint32_t in_flags)
261 struct tevent_req *req;
262 struct smbd_smb2_getinfo_state *state;
263 struct smb_request *smbreq;
264 connection_struct *conn = smb2req->tcon->compat;
265 NTSTATUS status;
267 req = tevent_req_create(mem_ctx, &state,
268 struct smbd_smb2_getinfo_state);
269 if (req == NULL) {
270 return NULL;
272 state->smb2req = smb2req;
273 state->status = NT_STATUS_OK;
274 state->out_output_buffer = data_blob_null;
276 DEBUG(10,("smbd_smb2_getinfo_send: %s - %s\n",
277 fsp_str_dbg(fsp), fsp_fnum_dbg(fsp)));
279 smbreq = smbd_smb2_fake_smb_request(smb2req);
280 if (tevent_req_nomem(smbreq, req)) {
281 return tevent_req_post(req, ev);
284 if (IS_IPC(conn)) {
285 smb2_ipc_getinfo(req, state, ev,
286 in_info_type, in_file_info_class);
287 return tevent_req_post(req, ev);
290 switch (in_info_type) {
291 case SMB2_0_INFO_FILE:
293 uint16_t file_info_level;
294 char *data = NULL;
295 unsigned int data_size = 0;
296 bool delete_pending = false;
297 struct timespec write_time_ts;
298 struct file_id fileid;
299 struct ea_list *ea_list = NULL;
300 int lock_data_count = 0;
301 char *lock_data = NULL;
302 size_t fixed_portion;
304 ZERO_STRUCT(write_time_ts);
306 switch (in_file_info_class) {
307 case FSCC_FILE_FULL_EA_INFORMATION:
308 file_info_level = SMB2_FILE_FULL_EA_INFORMATION;
309 break;
311 case FSCC_FILE_ALL_INFORMATION:
312 file_info_level = SMB2_FILE_ALL_INFORMATION;
313 break;
315 default:
316 /* the levels directly map to the passthru levels */
317 file_info_level = in_file_info_class + 1000;
318 break;
321 switch (file_info_level) {
322 case SMB_FILE_NORMALIZED_NAME_INFORMATION:
323 if (smb2req->xconn->protocol < PROTOCOL_SMB3_11) {
324 tevent_req_nterror(req, NT_STATUS_NOT_SUPPORTED);
325 return tevent_req_post(req, ev);
327 break;
330 if (fsp->fake_file_handle) {
332 * This is actually for the QUOTA_FAKE_FILE --metze
335 /* We know this name is ok, it's already passed the checks. */
337 } else if (fsp_get_pathref_fd(fsp) == -1) {
339 * This is actually a QFILEINFO on a directory
340 * handle (returned from an NT SMB). NT5.0 seems
341 * to do this call. JRA.
343 int ret = vfs_stat(conn, fsp->fsp_name);
344 if (ret != 0) {
345 DBG_NOTICE("vfs_stat of %s failed (%s)\n",
346 fsp_str_dbg(fsp),
347 strerror(errno));
348 status = map_nt_error_from_unix(errno);
349 tevent_req_nterror(req, status);
350 return tevent_req_post(req, ev);
353 if (lp_smbd_getinfo_ask_sharemode(SNUM(conn))) {
354 fileid = vfs_file_id_from_sbuf(
355 conn, &fsp->fsp_name->st);
356 get_file_infos(fileid, fsp->name_hash,
357 &delete_pending,
358 &write_time_ts);
360 } else {
362 * Original code - this is an open file.
365 status = vfs_stat_fsp(fsp);
366 if (!NT_STATUS_IS_OK(status)) {
367 DEBUG(3, ("smbd_smb2_getinfo_send: "
368 "fstat of %s failed (%s)\n",
369 fsp_fnum_dbg(fsp), nt_errstr(status)));
370 tevent_req_nterror(req, status);
371 return tevent_req_post(req, ev);
373 if (lp_smbd_getinfo_ask_sharemode(SNUM(conn))) {
374 fileid = vfs_file_id_from_sbuf(
375 conn, &fsp->fsp_name->st);
376 get_file_infos(fileid, fsp->name_hash,
377 &delete_pending,
378 &write_time_ts);
382 status = smbd_do_qfilepathinfo(conn, state,
383 smbreq,
384 file_info_level,
385 fsp,
386 fsp->fsp_name,
387 delete_pending,
388 write_time_ts,
389 ea_list,
390 lock_data_count,
391 lock_data,
392 STR_UNICODE,
393 in_output_buffer_length,
394 &fixed_portion,
395 &data,
396 &data_size);
397 if (!NT_STATUS_IS_OK(status)) {
398 SAFE_FREE(data);
399 if (NT_STATUS_EQUAL(status, NT_STATUS_INVALID_LEVEL)) {
400 status = NT_STATUS_INVALID_INFO_CLASS;
402 tevent_req_nterror(req, status);
403 return tevent_req_post(req, ev);
405 if (in_output_buffer_length < fixed_portion) {
406 SAFE_FREE(data);
407 tevent_req_nterror(
408 req, NT_STATUS_INFO_LENGTH_MISMATCH);
409 return tevent_req_post(req, ev);
411 if (data_size > 0) {
412 state->out_output_buffer = data_blob_talloc(state,
413 data,
414 data_size);
415 SAFE_FREE(data);
416 if (tevent_req_nomem(state->out_output_buffer.data, req)) {
417 return tevent_req_post(req, ev);
419 if (data_size > in_output_buffer_length) {
420 state->out_output_buffer.length =
421 in_output_buffer_length;
422 status = STATUS_BUFFER_OVERFLOW;
425 SAFE_FREE(data);
426 break;
429 case SMB2_0_INFO_FILESYSTEM:
431 uint16_t file_info_level;
432 char *data = NULL;
433 int data_size = 0;
434 size_t fixed_portion;
436 /* the levels directly map to the passthru levels */
437 file_info_level = in_file_info_class + 1000;
439 status = smbd_do_qfsinfo(smb2req->xconn, conn, state,
440 file_info_level,
441 STR_UNICODE,
442 in_output_buffer_length,
443 &fixed_portion,
444 fsp->fsp_name,
445 &data,
446 &data_size);
447 /* some responses set STATUS_BUFFER_OVERFLOW and return
448 partial, but valid data */
449 if (!(NT_STATUS_IS_OK(status) ||
450 NT_STATUS_EQUAL(status, STATUS_BUFFER_OVERFLOW))) {
451 SAFE_FREE(data);
452 if (NT_STATUS_EQUAL(status, NT_STATUS_INVALID_LEVEL)) {
453 status = NT_STATUS_INVALID_INFO_CLASS;
455 tevent_req_nterror(req, status);
456 return tevent_req_post(req, ev);
458 if (in_output_buffer_length < fixed_portion) {
459 SAFE_FREE(data);
460 tevent_req_nterror(
461 req, NT_STATUS_INFO_LENGTH_MISMATCH);
462 return tevent_req_post(req, ev);
464 if (data_size > 0) {
465 state->out_output_buffer = data_blob_talloc(state,
466 data,
467 data_size);
468 SAFE_FREE(data);
469 if (tevent_req_nomem(state->out_output_buffer.data, req)) {
470 return tevent_req_post(req, ev);
472 if (data_size > in_output_buffer_length) {
473 state->out_output_buffer.length =
474 in_output_buffer_length;
475 status = STATUS_BUFFER_OVERFLOW;
478 SAFE_FREE(data);
479 break;
482 case SMB2_0_INFO_SECURITY:
484 uint8_t *p_marshalled_sd = NULL;
485 size_t sd_size = 0;
487 status = smbd_do_query_security_desc(conn,
488 state,
489 fsp,
490 /* Security info wanted. */
491 in_additional_information &
492 SMB_SUPPORTED_SECINFO_FLAGS,
493 in_output_buffer_length,
494 &p_marshalled_sd,
495 &sd_size);
497 if (NT_STATUS_EQUAL(status, NT_STATUS_BUFFER_TOO_SMALL)) {
498 /* Return needed size. */
499 state->out_output_buffer = data_blob_talloc(state,
500 NULL,
502 if (tevent_req_nomem(state->out_output_buffer.data, req)) {
503 return tevent_req_post(req, ev);
505 SIVAL(state->out_output_buffer.data,0,(uint32_t)sd_size);
506 state->status = NT_STATUS_BUFFER_TOO_SMALL;
507 break;
509 if (!NT_STATUS_IS_OK(status)) {
510 DEBUG(10,("smbd_smb2_getinfo_send: "
511 "smbd_do_query_security_desc of %s failed "
512 "(%s)\n", fsp_str_dbg(fsp),
513 nt_errstr(status)));
514 tevent_req_nterror(req, status);
515 return tevent_req_post(req, ev);
518 if (sd_size > 0) {
519 state->out_output_buffer = data_blob_talloc(state,
520 p_marshalled_sd,
521 sd_size);
522 if (tevent_req_nomem(state->out_output_buffer.data, req)) {
523 return tevent_req_post(req, ev);
526 break;
529 case SMB2_0_INFO_QUOTA: {
530 #ifdef HAVE_SYS_QUOTAS
531 struct smb2_query_quota_info info;
532 enum ndr_err_code err;
533 uint8_t *data = NULL;
534 uint32_t data_size = 0;
535 struct ndr_pull *ndr_pull = NULL;
536 DATA_BLOB sid_buf = data_blob_null;
537 TALLOC_CTX *tmp_ctx = talloc_init("geninfo_quota");
538 bool ok;
540 if (!tmp_ctx) {
541 tevent_req_nterror(req, NT_STATUS_NO_MEMORY);
542 return tevent_req_post(req, ev);
545 ok = check_fsp_ntquota_handle(conn, smbreq, fsp);
546 if (!ok) {
547 DBG_INFO("no valid QUOTA HANDLE\n");
548 TALLOC_FREE(tmp_ctx);
549 tevent_req_nterror(req, NT_STATUS_INVALID_HANDLE);
550 return tevent_req_post(req, ev);
553 ndr_pull = ndr_pull_init_blob(&in_input_buffer, tmp_ctx);
554 if (!ndr_pull) {
555 TALLOC_FREE(tmp_ctx);
556 tevent_req_nterror(req, NT_STATUS_NO_MEMORY);
557 return tevent_req_post(req, ev);
560 err = ndr_pull_smb2_query_quota_info(ndr_pull,
561 NDR_SCALARS | NDR_BUFFERS,
562 &info);
564 if (!NDR_ERR_CODE_IS_SUCCESS(err)) {
565 DBG_DEBUG("failed to pull smb2_query_quota_info\n");
566 TALLOC_FREE(tmp_ctx);
567 tevent_req_nterror(req, NT_STATUS_INTERNAL_ERROR);
568 return tevent_req_post(req, ev);
571 DBG_DEBUG("quota list returnsingle %u, restartscan %u, "
572 "sid_list_length %u, start_sid_length %u, "
573 "startsidoffset %u\n",
574 (unsigned int)info.return_single,
575 (unsigned int)info.restart_scan,
576 (unsigned int)info.sid_list_length,
577 (unsigned int)info.start_sid_length,
578 (unsigned int)info.start_sid_offset);
580 /* Currently we do not support the single start sid format */
581 if (info.start_sid_length != 0 || info.start_sid_offset != 0 ) {
582 DBG_INFO("illegal single sid query\n");
583 TALLOC_FREE(tmp_ctx);
584 tevent_req_nterror(req, NT_STATUS_INVALID_PARAMETER);
585 return tevent_req_post(req, ev);
588 if (in_input_buffer.length < ndr_pull->offset) {
589 DBG_INFO("Invalid buffer length\n");
590 TALLOC_FREE(tmp_ctx);
591 tevent_req_nterror(req, NT_STATUS_INVALID_PARAMETER);
592 return tevent_req_post(req, ev);
595 sid_buf.data = in_input_buffer.data + ndr_pull->offset;
596 sid_buf.length = in_input_buffer.length - ndr_pull->offset;
598 status = smbd_do_query_getinfo_quota(tmp_ctx,
599 fsp,
600 info.restart_scan,
601 info.return_single,
602 info.sid_list_length,
603 &sid_buf,
604 in_output_buffer_length,
605 &data,
606 &data_size);
608 if (!NT_STATUS_IS_OK(status)) {
609 TALLOC_FREE(tmp_ctx);
610 tevent_req_nterror(req, status);
611 return tevent_req_post(req, ev);
614 state->out_output_buffer =
615 data_blob_talloc(state, data, data_size);
616 status = NT_STATUS_OK;
617 TALLOC_FREE(tmp_ctx);
618 break;
619 #else
620 tevent_req_nterror(req, NT_STATUS_NOT_SUPPORTED);
621 return tevent_req_post(req, ev);
622 #endif
625 default:
626 DEBUG(10,("smbd_smb2_getinfo_send: "
627 "unknown in_info_type of %u "
628 " for file %s\n",
629 (unsigned int)in_info_type,
630 fsp_str_dbg(fsp) ));
632 tevent_req_nterror(req, NT_STATUS_INVALID_PARAMETER);
633 return tevent_req_post(req, ev);
636 state->status = status;
637 tevent_req_done(req);
638 return tevent_req_post(req, ev);
641 static NTSTATUS smbd_smb2_getinfo_recv(struct tevent_req *req,
642 TALLOC_CTX *mem_ctx,
643 DATA_BLOB *out_output_buffer,
644 NTSTATUS *pstatus)
646 NTSTATUS status;
647 struct smbd_smb2_getinfo_state *state = tevent_req_data(req,
648 struct smbd_smb2_getinfo_state);
650 if (tevent_req_is_nterror(req, &status)) {
651 tevent_req_received(req);
652 return status;
655 *out_output_buffer = state->out_output_buffer;
656 talloc_steal(mem_ctx, out_output_buffer->data);
657 *pstatus = state->status;
659 tevent_req_received(req);
660 return NT_STATUS_OK;