2 Unix SMB/CIFS implementation.
4 Copyright (C) Stefan Metzmacher 2012
5 Copyright (C) Michael Adam 2012
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License as published by
9 the Free Software Foundation; either version 3 of the License, or
10 (at your option) any later version.
12 This program is distributed in the hope that it will be useful,
13 but WITHOUT ANY WARRANTY; without even the implied warranty of
14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 GNU General Public License for more details.
17 You should have received a copy of the GNU General Public License
18 along with this program. If not, see <http://www.gnu.org/licenses/>.
21 #include "smbXsrv_open.h"
23 #include "system/filesys.h"
24 #include "lib/util/server_id.h"
25 #include "smbd/smbd.h"
26 #include "smbd/globals.h"
27 #include "dbwrap/dbwrap.h"
28 #include "dbwrap/dbwrap_rbt.h"
29 #include "dbwrap/dbwrap_open.h"
30 #include "../libcli/security/security.h"
32 #include "lib/util/util_tdb.h"
33 #include "librpc/gen_ndr/ndr_smbXsrv.h"
35 #include "source3/include/util_tdb.h"
36 #include "lib/util/idtree_random.h"
37 #include "lib/util/time_basic.h"
39 struct smbXsrv_open_table
{
41 struct idr_context
*idr
;
42 struct db_context
*replay_cache_db_ctx
;
49 struct db_context
*db_ctx
;
53 static struct db_context
*smbXsrv_open_global_db_ctx
= NULL
;
55 NTSTATUS
smbXsrv_open_global_init(void)
57 char *global_path
= NULL
;
58 struct db_context
*db_ctx
= NULL
;
60 if (smbXsrv_open_global_db_ctx
!= NULL
) {
64 global_path
= lock_path(talloc_tos(), "smbXsrv_open_global.tdb");
65 if (global_path
== NULL
) {
66 return NT_STATUS_NO_MEMORY
;
69 db_ctx
= db_open(NULL
, global_path
,
70 SMBD_VOLATILE_TDB_HASH_SIZE
,
71 SMBD_VOLATILE_TDB_FLAGS
,
72 O_RDWR
| O_CREAT
, 0600,
75 TALLOC_FREE(global_path
);
79 status
= map_nt_error_from_unix_common(errno
);
84 smbXsrv_open_global_db_ctx
= db_ctx
;
91 * We need to store the keys in big endian so that dbwrap_rbt's memcmp
92 * has the same result as integer comparison between the uint32_t
95 * TODO: implement string based key
98 struct smbXsrv_open_global_key_buf
{ uint8_t buf
[sizeof(uint32_t)]; };
100 static TDB_DATA
smbXsrv_open_global_id_to_key(
101 uint32_t id
, struct smbXsrv_open_global_key_buf
*key_buf
)
103 RSIVAL(key_buf
->buf
, 0, id
);
106 .dptr
= key_buf
->buf
,
107 .dsize
= sizeof(key_buf
->buf
),
111 static NTSTATUS
smbXsrv_open_table_init(struct smbXsrv_connection
*conn
,
116 struct smbXsrv_client
*client
= conn
->client
;
117 struct smbXsrv_open_table
*table
;
121 if (lowest_id
> highest_id
) {
122 return NT_STATUS_INTERNAL_ERROR
;
125 max_range
= highest_id
;
126 max_range
-= lowest_id
;
129 if (max_opens
> max_range
) {
130 return NT_STATUS_INTERNAL_ERROR
;
133 table
= talloc_zero(client
, struct smbXsrv_open_table
);
135 return NT_STATUS_NO_MEMORY
;
138 table
->local
.idr
= idr_init(table
);
139 if (table
->local
.idr
== NULL
) {
141 return NT_STATUS_NO_MEMORY
;
143 table
->local
.replay_cache_db_ctx
= db_open_rbt(table
);
144 if (table
->local
.replay_cache_db_ctx
== NULL
) {
146 return NT_STATUS_NO_MEMORY
;
148 table
->local
.lowest_id
= lowest_id
;
149 table
->local
.highest_id
= highest_id
;
150 table
->local
.max_opens
= max_opens
;
152 status
= smbXsrv_open_global_init();
153 if (!NT_STATUS_IS_OK(status
)) {
158 table
->global
.db_ctx
= smbXsrv_open_global_db_ctx
;
160 client
->open_table
= table
;
164 static NTSTATUS
smbXsrv_open_local_lookup(struct smbXsrv_open_table
*table
,
165 uint32_t open_local_id
,
166 uint32_t open_global_id
,
168 struct smbXsrv_open
**_open
)
170 struct smbXsrv_open
*op
= NULL
;
174 if (open_local_id
== 0) {
175 return NT_STATUS_FILE_CLOSED
;
179 /* this might happen before the end of negprot */
180 return NT_STATUS_FILE_CLOSED
;
183 if (table
->local
.idr
== NULL
) {
184 return NT_STATUS_INTERNAL_ERROR
;
187 op
= idr_find(table
->local
.idr
, open_local_id
);
189 return NT_STATUS_FILE_CLOSED
;
192 if (open_global_id
== 0) {
193 /* make the global check a no-op for SMB1 */
194 open_global_id
= op
->global
->open_global_id
;
197 if (op
->global
->open_global_id
!= open_global_id
) {
198 return NT_STATUS_FILE_CLOSED
;
209 static NTSTATUS
smbXsrv_open_global_parse_record(
213 struct smbXsrv_open_global0
**global
)
215 DATA_BLOB blob
= data_blob_const(val
.dptr
, val
.dsize
);
216 struct smbXsrv_open_globalB global_blob
;
217 enum ndr_err_code ndr_err
;
219 TALLOC_CTX
*frame
= talloc_stackframe();
221 ndr_err
= ndr_pull_struct_blob(&blob
, frame
, &global_blob
,
222 (ndr_pull_flags_fn_t
)ndr_pull_smbXsrv_open_globalB
);
223 if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err
)) {
224 DEBUG(1,("Invalid record in smbXsrv_open_global.tdb:"
225 "key '%s' ndr_pull_struct_blob - %s\n",
227 ndr_errstr(ndr_err
)));
228 status
= ndr_map_error2ntstatus(ndr_err
);
233 if (CHECK_DEBUGLVL(10)) {
234 NDR_PRINT_DEBUG(smbXsrv_open_globalB
, &global_blob
);
237 if (global_blob
.version
!= SMBXSRV_VERSION_0
) {
238 status
= NT_STATUS_INTERNAL_DB_CORRUPTION
;
239 DEBUG(1,("Invalid record in smbXsrv_open_global.tdb:"
240 "key '%s' unsupported version - %d - %s\n",
242 (int)global_blob
.version
,
247 if (global_blob
.info
.info0
== NULL
) {
248 status
= NT_STATUS_INTERNAL_DB_CORRUPTION
;
249 DEBUG(1,("Invalid record in smbXsrv_tcon_global.tdb:"
250 "key '%s' info0 NULL pointer - %s\n",
256 *global
= talloc_move(mem_ctx
, &global_blob
.info
.info0
);
257 status
= NT_STATUS_OK
;
263 static NTSTATUS
smbXsrv_open_global_verify_record(
267 struct smbXsrv_open_global0
**_global0
)
269 struct smbXsrv_open_global0
*global0
= NULL
;
270 struct server_id_buf buf
;
273 if (val
.dsize
== 0) {
274 return NT_STATUS_NOT_FOUND
;
277 status
= smbXsrv_open_global_parse_record(mem_ctx
, key
, val
, &global0
);
278 if (!NT_STATUS_IS_OK(status
)) {
279 DBG_WARNING("smbXsrv_open_global_parse_record for %s failed: "
287 if (server_id_is_disconnected(&global0
->server_id
)) {
290 if (serverid_exists(&global0
->server_id
)) {
294 DBG_WARNING("smbd %s did not clean up record %s\n",
295 server_id_str_buf(global0
->server_id
, &buf
),
298 return NT_STATUS_FATAL_APP_EXIT
;
301 static NTSTATUS
smbXsrv_open_global_store(
302 struct db_record
*rec
,
305 struct smbXsrv_open_global0
*global
)
307 struct smbXsrv_open_globalB global_blob
;
308 DATA_BLOB blob
= data_blob_null
;
309 TDB_DATA val
= { .dptr
= NULL
, };
311 enum ndr_err_code ndr_err
;
314 * TODO: if we use other versions than '0'
315 * we would add glue code here, that would be able to
316 * store the information in the old format.
319 global_blob
= (struct smbXsrv_open_globalB
) {
320 .version
= smbXsrv_version_global_current(),
323 if (oldval
.dsize
>= 8) {
324 global_blob
.seqnum
= IVAL(oldval
.dptr
, 4);
326 global_blob
.seqnum
+= 1;
327 global_blob
.info
.info0
= global
;
329 ndr_err
= ndr_push_struct_blob(&blob
, talloc_tos(), &global_blob
,
330 (ndr_push_flags_fn_t
)ndr_push_smbXsrv_open_globalB
);
331 if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err
)) {
332 DBG_WARNING("key '%s' ndr_push - %s\n",
334 ndr_map_error2string(ndr_err
));
335 return ndr_map_error2ntstatus(ndr_err
);
338 val
= make_tdb_data(blob
.data
, blob
.length
);
339 status
= dbwrap_record_store(rec
, val
, TDB_REPLACE
);
340 TALLOC_FREE(blob
.data
);
341 if (!NT_STATUS_IS_OK(status
)) {
342 DBG_WARNING("key '%s' store - %s\n",
348 if (CHECK_DEBUGLVL(10)) {
349 DBG_DEBUG("key '%s' stored\n", tdb_data_dbg(key
));
350 NDR_PRINT_DEBUG(smbXsrv_open_globalB
, &global_blob
);
356 struct smbXsrv_open_global_allocate_state
{
358 struct smbXsrv_open_global0
*global
;
362 static void smbXsrv_open_global_allocate_fn(
363 struct db_record
*rec
, TDB_DATA oldval
, void *private_data
)
365 struct smbXsrv_open_global_allocate_state
*state
= private_data
;
366 struct smbXsrv_open_global0
*global
= state
->global
;
367 struct smbXsrv_open_global0
*tmp_global0
= NULL
;
368 TDB_DATA key
= dbwrap_record_get_key(rec
);
370 state
->status
= smbXsrv_open_global_verify_record(
371 key
, oldval
, talloc_tos(), &tmp_global0
);
373 if (NT_STATUS_IS_OK(state
->status
)) {
375 * Found an existing record
377 TALLOC_FREE(tmp_global0
);
378 state
->status
= NT_STATUS_RETRY
;
382 if (NT_STATUS_EQUAL(state
->status
, NT_STATUS_NOT_FOUND
)) {
384 * Found an empty slot
386 global
->open_global_id
= state
->id
;
387 global
->open_persistent_id
= state
->id
;
389 state
->status
= smbXsrv_open_global_store(
390 rec
, key
, (TDB_DATA
) { .dsize
= 0, }, state
->global
);
391 if (!NT_STATUS_IS_OK(state
->status
)) {
392 DBG_WARNING("smbXsrv_open_global_store() for "
393 "id %"PRIu32
" failed: %s\n",
395 nt_errstr(state
->status
));
400 if (NT_STATUS_EQUAL(state
->status
, NT_STATUS_FATAL_APP_EXIT
)) {
403 TALLOC_FREE(tmp_global0
);
408 status
= dbwrap_record_delete(rec
);
409 if (!NT_STATUS_IS_OK(status
)) {
410 DBG_WARNING("dbwrap_record_delete() failed "
411 "for record %"PRIu32
": %s\n",
414 state
->status
= NT_STATUS_INTERNAL_DB_CORRUPTION
;
421 static NTSTATUS
smbXsrv_open_global_allocate(
422 struct db_context
*db
, struct smbXsrv_open_global0
*global
)
424 struct smbXsrv_open_global_allocate_state state
= {
428 uint32_t last_free
= 0;
429 const uint32_t min_tries
= 3;
432 * Here we just randomly try the whole 32-bit space
434 * We use just 32-bit, because we want to reuse the
437 for (i
= 0; i
< UINT32_MAX
; i
++) {
438 struct smbXsrv_open_global_key_buf key_buf
;
442 if (i
>= min_tries
&& last_free
!= 0) {
443 state
.id
= last_free
;
445 generate_nonce_buffer(
446 (uint8_t *)&state
.id
, sizeof(state
.id
));
447 state
.id
= MAX(state
.id
, 1);
448 state
.id
= MIN(state
.id
, UINT32_MAX
-1);
451 key
= smbXsrv_open_global_id_to_key(state
.id
, &key_buf
);
453 status
= dbwrap_do_locked(
454 db
, key
, smbXsrv_open_global_allocate_fn
, &state
);
456 if (!NT_STATUS_IS_OK(status
)) {
457 DBG_WARNING("dbwrap_do_locked() failed: %s\n",
459 return NT_STATUS_INTERNAL_DB_ERROR
;
462 if (NT_STATUS_IS_OK(state
.status
)) {
464 * Found an empty slot, done.
466 DBG_DEBUG("Found slot %"PRIu32
"\n", state
.id
);
470 if (NT_STATUS_EQUAL(state
.status
, NT_STATUS_FATAL_APP_EXIT
)) {
472 if ((i
< min_tries
) && (last_free
== 0)) {
474 * Remember "id" as free but also try
475 * others to not recycle ids too
478 last_free
= state
.id
;
483 if (NT_STATUS_EQUAL(state
.status
, NT_STATUS_RETRY
)) {
485 * Normal collision, try next
487 DBG_DEBUG("Found record for id %"PRIu32
"\n",
492 DBG_WARNING("smbXsrv_open_global_allocate_fn() failed: %s\n",
493 nt_errstr(state
.status
));
497 /* should not be reached */
498 return NT_STATUS_INTERNAL_ERROR
;
501 static int smbXsrv_open_destructor(struct smbXsrv_open
*op
)
505 status
= smbXsrv_open_close(op
, 0);
506 if (!NT_STATUS_IS_OK(status
)) {
507 DEBUG(0, ("smbXsrv_open_destructor: "
508 "smbXsrv_open_close() failed - %s\n",
512 TALLOC_FREE(op
->global
);
517 NTSTATUS
smbXsrv_open_create(struct smbXsrv_connection
*conn
,
518 struct auth_session_info
*session_info
,
520 struct smbXsrv_open
**_open
)
522 struct smbXsrv_open_table
*table
= conn
->client
->open_table
;
523 struct smbXsrv_open
*op
= NULL
;
524 struct smbXsrv_open_global0
*global
= NULL
;
526 struct dom_sid
*current_sid
= NULL
;
527 struct security_token
*current_token
= NULL
;
530 if (session_info
== NULL
) {
531 return NT_STATUS_INVALID_HANDLE
;
533 current_token
= session_info
->security_token
;
535 if (current_token
== NULL
) {
536 return NT_STATUS_INVALID_HANDLE
;
539 if (current_token
->num_sids
> PRIMARY_USER_SID_INDEX
) {
540 current_sid
= ¤t_token
->sids
[PRIMARY_USER_SID_INDEX
];
543 if (current_sid
== NULL
) {
544 return NT_STATUS_INVALID_HANDLE
;
547 if (table
->local
.num_opens
>= table
->local
.max_opens
) {
548 return NT_STATUS_INSUFFICIENT_RESOURCES
;
551 op
= talloc_zero(table
, struct smbXsrv_open
);
553 return NT_STATUS_NO_MEMORY
;
556 op
->status
= NT_STATUS_OK
; /* TODO: start with INTERNAL_ERROR */
559 global
= talloc_zero(op
, struct smbXsrv_open_global0
);
560 if (global
== NULL
) {
562 return NT_STATUS_NO_MEMORY
;
567 * We mark every slot as invalid using 0xFF.
568 * Valid values are masked with 0xF.
570 memset(global
->lock_sequence_array
, 0xFF,
571 sizeof(global
->lock_sequence_array
));
573 local_id
= idr_get_new_random(
576 table
->local
.lowest_id
,
577 table
->local
.highest_id
);
578 if (local_id
== -1) {
580 return NT_STATUS_INSUFFICIENT_RESOURCES
;
582 op
->local_id
= local_id
;
584 global
->open_volatile_id
= op
->local_id
;
586 global
->server_id
= messaging_server_id(conn
->client
->msg_ctx
);
587 global
->open_time
= now
;
588 global
->open_owner
= *current_sid
;
589 if (conn
->protocol
>= PROTOCOL_SMB2_10
) {
590 global
->client_guid
= conn
->smb2
.client
.guid
;
593 status
= smbXsrv_open_global_allocate(table
->global
.db_ctx
,
595 if (!NT_STATUS_IS_OK(status
)) {
596 int ret
= idr_remove(table
->local
.idr
, local_id
);
597 SMB_ASSERT(ret
== 0);
599 DBG_WARNING("smbXsrv_open_global_allocate() failed: %s\n",
605 table
->local
.num_opens
+= 1;
606 talloc_set_destructor(op
, smbXsrv_open_destructor
);
608 if (CHECK_DEBUGLVL(10)) {
609 struct smbXsrv_openB open_blob
= {
610 .version
= SMBXSRV_VERSION_0
,
614 DEBUG(10,("smbXsrv_open_create: global_id (0x%08x) stored\n",
615 op
->global
->open_global_id
));
616 NDR_PRINT_DEBUG(smbXsrv_openB
, &open_blob
);
623 static NTSTATUS
smbXsrv_open_set_replay_cache(struct smbXsrv_open
*op
)
625 struct GUID
*create_guid
;
626 struct GUID_txt_buf buf
;
628 struct db_context
*db
= op
->table
->local
.replay_cache_db_ctx
;
629 struct smbXsrv_open_replay_cache rc
= {
630 .idle_time
= op
->idle_time
,
631 .local_id
= op
->local_id
,
633 uint8_t data
[SMBXSRV_OPEN_REPLAY_CACHE_FIXED_SIZE
] = { 0 };
634 DATA_BLOB blob
= { .data
= data
, .length
= sizeof(data
), };
635 enum ndr_err_code ndr_err
;
639 if (!(op
->flags
& SMBXSRV_OPEN_NEED_REPLAY_CACHE
)) {
643 if (op
->flags
& SMBXSRV_OPEN_HAVE_REPLAY_CACHE
) {
647 create_guid
= &op
->global
->create_guid
;
648 guid_string
= GUID_buf_string(create_guid
, &buf
);
650 ndr_err
= ndr_push_struct_into_fixed_blob(&blob
, &rc
,
651 (ndr_push_flags_fn_t
)ndr_push_smbXsrv_open_replay_cache
);
652 if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err
)) {
653 status
= ndr_map_error2ntstatus(ndr_err
);
656 val
= make_tdb_data(blob
.data
, blob
.length
);
658 status
= dbwrap_store_bystring(db
, guid_string
, val
, TDB_REPLACE
);
660 if (NT_STATUS_IS_OK(status
)) {
661 op
->flags
|= SMBXSRV_OPEN_HAVE_REPLAY_CACHE
;
662 op
->flags
&= ~SMBXSRV_OPEN_NEED_REPLAY_CACHE
;
668 NTSTATUS
smbXsrv_open_purge_replay_cache(struct smbXsrv_client
*client
,
669 const struct GUID
*create_guid
)
671 struct GUID_txt_buf buf
;
673 struct db_context
*db
;
675 if (client
->open_table
== NULL
) {
679 db
= client
->open_table
->local
.replay_cache_db_ctx
;
681 guid_string
= GUID_buf_string(create_guid
, &buf
);
682 if (guid_string
== NULL
) {
683 return NT_STATUS_INVALID_PARAMETER
;
686 return dbwrap_purge_bystring(db
, guid_string
);
689 static NTSTATUS
smbXsrv_open_clear_replay_cache(struct smbXsrv_open
*op
)
691 struct GUID
*create_guid
;
692 struct GUID_txt_buf buf
;
694 struct db_context
*db
;
697 if (op
->table
== NULL
) {
701 db
= op
->table
->local
.replay_cache_db_ctx
;
703 if (!(op
->flags
& SMBXSRV_OPEN_HAVE_REPLAY_CACHE
)) {
707 create_guid
= &op
->global
->create_guid
;
708 if (GUID_all_zero(create_guid
)) {
712 guid_string
= GUID_buf_string(create_guid
, &buf
);
713 if (guid_string
== NULL
) {
714 return NT_STATUS_INVALID_PARAMETER
;
717 status
= dbwrap_purge_bystring(db
, guid_string
);
719 if (NT_STATUS_IS_OK(status
)) {
720 op
->flags
&= ~SMBXSRV_OPEN_HAVE_REPLAY_CACHE
;
726 struct smbXsrv_open_update_state
{
727 struct smbXsrv_open_global0
*global
;
731 static void smbXsrv_open_update_fn(
732 struct db_record
*rec
, TDB_DATA oldval
, void *private_data
)
734 struct smbXsrv_open_update_state
*state
= private_data
;
735 TDB_DATA key
= dbwrap_record_get_key(rec
);
737 state
->status
= smbXsrv_open_global_store(
738 rec
, key
, oldval
, state
->global
);
741 NTSTATUS
smbXsrv_open_update(struct smbXsrv_open
*op
)
743 struct smbXsrv_open_update_state state
= { .global
= op
->global
, };
744 struct smbXsrv_open_table
*table
= op
->table
;
745 struct smbXsrv_open_global_key_buf key_buf
;
746 TDB_DATA key
= smbXsrv_open_global_id_to_key(
747 op
->global
->open_global_id
, &key_buf
);
750 status
= dbwrap_do_locked(
751 table
->global
.db_ctx
, key
, smbXsrv_open_update_fn
, &state
);
752 if (!NT_STATUS_IS_OK(status
)) {
753 DBG_WARNING("global_id (0x%08x) dbwrap_do_locked failed: %s\n",
754 op
->global
->open_global_id
,
756 return NT_STATUS_INTERNAL_DB_ERROR
;
759 if (!NT_STATUS_IS_OK(state
.status
)) {
760 DBG_WARNING("global_id (0x%08x) smbXsrv_open_global_store "
762 op
->global
->open_global_id
,
763 nt_errstr(state
.status
));
767 status
= smbXsrv_open_set_replay_cache(op
);
768 if (!NT_STATUS_IS_OK(status
)) {
769 DBG_ERR("smbXsrv_open_set_replay_cache failed: %s\n",
774 if (CHECK_DEBUGLVL(10)) {
775 struct smbXsrv_openB open_blob
= {
776 .version
= SMBXSRV_VERSION_0
,
780 DEBUG(10,("smbXsrv_open_update: global_id (0x%08x) stored\n",
781 op
->global
->open_global_id
));
782 NDR_PRINT_DEBUG(smbXsrv_openB
, &open_blob
);
788 struct smbXsrv_open_close_state
{
789 struct smbXsrv_open
*op
;
793 static void smbXsrv_open_close_fn(
794 struct db_record
*rec
, TDB_DATA oldval
, void *private_data
)
796 struct smbXsrv_open_close_state
*state
= private_data
;
797 struct smbXsrv_open_global0
*global
= state
->op
->global
;
798 TDB_DATA key
= dbwrap_record_get_key(rec
);
800 if (global
->durable
) {
802 * Durable open -- we need to update the global part
803 * instead of deleting it
805 state
->status
= smbXsrv_open_global_store(
806 rec
, key
, oldval
, global
);
807 if (!NT_STATUS_IS_OK(state
->status
)) {
808 DBG_WARNING("failed to store global key '%s': %s\n",
810 nt_errstr(state
->status
));
814 if (CHECK_DEBUGLVL(10)) {
815 struct smbXsrv_openB open_blob
= {
816 .version
= SMBXSRV_VERSION_0
,
817 .info
.info0
= state
->op
,
820 DBG_DEBUG("(0x%08x) stored disconnect\n",
821 global
->open_global_id
);
822 NDR_PRINT_DEBUG(smbXsrv_openB
, &open_blob
);
827 state
->status
= dbwrap_record_delete(rec
);
828 if (!NT_STATUS_IS_OK(state
->status
)) {
829 DBG_WARNING("failed to delete global key '%s': %s\n",
831 nt_errstr(state
->status
));
835 NTSTATUS
smbXsrv_open_close(struct smbXsrv_open
*op
, NTTIME now
)
837 struct smbXsrv_open_close_state state
= { .op
= op
, };
838 struct smbXsrv_open_global0
*global
= op
->global
;
839 struct smbXsrv_open_table
*table
;
841 NTSTATUS error
= NT_STATUS_OK
;
842 struct smbXsrv_open_global_key_buf key_buf
;
843 TDB_DATA key
= smbXsrv_open_global_id_to_key(
844 global
->open_global_id
, &key_buf
);
847 error
= smbXsrv_open_clear_replay_cache(op
);
848 if (!NT_STATUS_IS_OK(error
)) {
849 DBG_ERR("smbXsrv_open_clear_replay_cache failed: %s\n",
853 if (op
->table
== NULL
) {
860 op
->status
= NT_STATUS_FILE_CLOSED
;
861 global
->disconnect_time
= now
;
862 server_id_set_disconnected(&global
->server_id
);
864 status
= dbwrap_do_locked(
865 table
->global
.db_ctx
, key
, smbXsrv_open_close_fn
, &state
);
866 if (!NT_STATUS_IS_OK(status
)) {
867 DBG_WARNING("dbwrap_do_locked() for %s failed: %s\n",
871 } else if (!NT_STATUS_IS_OK(state
.status
)) {
872 DBG_WARNING("smbXsrv_open_close_fn() for %s failed: %s\n",
874 nt_errstr(state
.status
));
875 error
= state
.status
;
878 ret
= idr_remove(table
->local
.idr
, op
->local_id
);
879 SMB_ASSERT(ret
== 0);
881 table
->local
.num_opens
-= 1;
884 op
->compat
->op
= NULL
;
885 file_free(NULL
, op
->compat
);
892 NTSTATUS
smb1srv_open_table_init(struct smbXsrv_connection
*conn
)
897 * Allow a range from 1..65534.
899 * With real_max_open_files possible ids,
900 * truncated to the SMB1 limit of 16-bit.
902 * 0 and 0xFFFF are no valid ids.
904 max_opens
= conn
->client
->sconn
->real_max_open_files
;
905 max_opens
= MIN(max_opens
, UINT16_MAX
- 1);
907 return smbXsrv_open_table_init(conn
, 1, UINT16_MAX
- 1, max_opens
);
910 NTSTATUS
smb1srv_open_lookup(struct smbXsrv_connection
*conn
,
911 uint16_t fnum
, NTTIME now
,
912 struct smbXsrv_open
**_open
)
914 struct smbXsrv_open_table
*table
= conn
->client
->open_table
;
915 uint32_t local_id
= fnum
;
916 uint32_t global_id
= 0;
918 return smbXsrv_open_local_lookup(table
, local_id
, global_id
, now
, _open
);
921 NTSTATUS
smb2srv_open_table_init(struct smbXsrv_connection
*conn
)
927 * Allow a range from 1..4294967294.
929 * With real_max_open_files possible ids,
930 * truncated to 16-bit (the same as SMB1 for now).
932 * 0 and 0xFFFFFFFF are no valid ids.
934 * The usage of conn->sconn->real_max_open_files
935 * is the reason that we use one open table per
936 * transport connection (as we still have a 1:1 mapping
937 * between process and transport connection).
939 max_opens
= conn
->client
->sconn
->real_max_open_files
;
940 max_opens
= MIN(max_opens
, UINT16_MAX
- 1);
943 * idtree uses "int" for local IDs. Limit the maximum ID to
944 * what "int" can hold.
946 highest_id
= UINT32_MAX
-1;
947 highest_id
= MIN(highest_id
, INT_MAX
);
949 return smbXsrv_open_table_init(conn
, 1, highest_id
, max_opens
);
952 NTSTATUS
smb2srv_open_lookup(struct smbXsrv_connection
*conn
,
953 uint64_t persistent_id
,
954 uint64_t volatile_id
,
956 struct smbXsrv_open
**_open
)
958 struct smbXsrv_open_table
*table
= conn
->client
->open_table
;
959 uint32_t local_id
= volatile_id
& UINT32_MAX
;
960 uint64_t local_zeros
= volatile_id
& 0xFFFFFFFF00000000LLU
;
961 uint32_t global_id
= persistent_id
& UINT32_MAX
;
962 uint64_t global_zeros
= persistent_id
& 0xFFFFFFFF00000000LLU
;
965 if (local_zeros
!= 0) {
966 return NT_STATUS_FILE_CLOSED
;
969 if (global_zeros
!= 0) {
970 return NT_STATUS_FILE_CLOSED
;
973 if (global_id
== 0) {
974 return NT_STATUS_FILE_CLOSED
;
977 status
= smbXsrv_open_local_lookup(table
, local_id
, global_id
, now
,
979 if (!NT_STATUS_IS_OK(status
)) {
984 * Clear the replay cache for this create_guid if it exists:
985 * This is based on the assumption that this lookup will be
986 * triggered by a client request using the file-id for lookup.
987 * Hence the client has proven that it has in fact seen the
988 * reply to its initial create call. So subsequent create replays
989 * should be treated as invalid. Hence the index for create_guid
990 * lookup needs to be removed.
992 status
= smbXsrv_open_clear_replay_cache(*_open
);
998 * This checks or marks the replay cache, we have the following
1001 * 1. There is no record in the cache
1002 * => we add the passes caller_req_guid as holder_req_guid
1003 * together with local_id as 0.
1004 * => We return STATUS_FWP_RESERVED in order to indicate
1005 * that the caller holds the current reservation
1007 * 2. There is a record in the cache and holder_req_guid
1008 * is already the same as caller_req_guid and local_id is 0
1009 * => We return STATUS_FWP_RESERVED in order to indicate
1010 * that the caller holds the current reservation
1012 * 3. There is a record in the cache with a holder_req_guid
1013 * other than caller_req_guid (and local_id is 0):
1014 * => We return NT_STATUS_FILE_NOT_AVAILABLE to indicate
1015 * the original request is still pending
1017 * 4. There is a record in the cache with a zero holder_req_guid
1018 * and a valid local_id:
1019 * => We lookup the existing open by local_id
1020 * => We return NT_STATUS_OK together with the smbXsrv_open
1023 * With NT_STATUS_OK the caller can continue the replay processing.
1025 * With STATUS_FWP_RESERVED the caller should continue the normal
1028 * - smbXsrv_open_update()/smbXsrv_open_set_replay_cache()
1029 * will convert the record to a zero holder_req_guid
1030 * with a valid local_id.
1032 * - smbXsrv_open_purge_replay_cache() should cleanup
1035 * All other values should be returned to the client,
1036 * while NT_STATUS_FILE_NOT_AVAILABLE will trigger the
1037 * retry loop on the client.
1039 NTSTATUS
smb2srv_open_lookup_replay_cache(struct smbXsrv_connection
*conn
,
1040 struct GUID caller_req_guid
,
1041 struct GUID create_guid
,
1044 struct smbXsrv_open
**_open
)
1046 TALLOC_CTX
*frame
= talloc_stackframe();
1048 struct smbXsrv_open_table
*table
= conn
->client
->open_table
;
1049 struct db_context
*db
= table
->local
.replay_cache_db_ctx
;
1050 struct GUID_txt_buf tmp_guid_buf
;
1051 struct GUID_txt_buf _create_guid_buf
;
1052 const char *create_guid_str
= GUID_buf_string(&create_guid
, &_create_guid_buf
);
1053 TDB_DATA create_guid_key
= string_term_tdb_data(create_guid_str
);
1054 struct db_record
*db_rec
= NULL
;
1055 struct smbXsrv_open
*op
= NULL
;
1056 struct smbXsrv_open_replay_cache rc
= {
1057 .holder_req_guid
= caller_req_guid
,
1061 enum ndr_err_code ndr_err
;
1062 DATA_BLOB blob
= data_blob_null
;
1067 db_rec
= dbwrap_fetch_locked(db
, frame
, create_guid_key
);
1068 if (db_rec
== NULL
) {
1070 return NT_STATUS_INTERNAL_DB_ERROR
;
1073 val
= dbwrap_record_get_value(db_rec
);
1074 if (val
.dsize
== 0) {
1075 uint8_t data
[SMBXSRV_OPEN_REPLAY_CACHE_FIXED_SIZE
];
1077 blob
= data_blob_const(data
, ARRAY_SIZE(data
));
1078 ndr_err
= ndr_push_struct_into_fixed_blob(&blob
, &rc
,
1079 (ndr_push_flags_fn_t
)ndr_push_smbXsrv_open_replay_cache
);
1080 if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err
)) {
1081 status
= ndr_map_error2ntstatus(ndr_err
);
1086 val
= make_tdb_data(blob
.data
, blob
.length
);
1087 status
= dbwrap_record_store(db_rec
, val
, TDB_REPLACE
);
1088 if (!NT_STATUS_IS_OK(status
)) {
1094 * We're the new holder
1098 return NT_STATUS_FWP_RESERVED
;
1101 if (val
.dsize
!= SMBXSRV_OPEN_REPLAY_CACHE_FIXED_SIZE
) {
1103 return NT_STATUS_INTERNAL_DB_CORRUPTION
;
1106 blob
= data_blob_const(val
.dptr
, val
.dsize
);
1107 ndr_err
= ndr_pull_struct_blob_all_noalloc(&blob
, &rc
,
1108 (ndr_pull_flags_fn_t
)ndr_pull_smbXsrv_open_replay_cache
);
1109 if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err
)) {
1110 status
= ndr_map_error2ntstatus(ndr_err
);
1114 if (rc
.local_id
!= 0) {
1115 if (GUID_equal(&rc
.holder_req_guid
, &caller_req_guid
)) {
1117 * This should not happen
1119 status
= NT_STATUS_INTERNAL_ERROR
;
1120 DBG_ERR("caller %s already holds local_id %u for create %s [%s] - %s\n",
1121 GUID_buf_string(&caller_req_guid
, &tmp_guid_buf
),
1122 (unsigned)rc
.local_id
,
1131 status
= smbXsrv_open_local_lookup(table
,
1136 if (!NT_STATUS_IS_OK(status
)) {
1137 DBG_ERR("holder %s stale for local_id %u for create %s [%s] - %s\n",
1138 GUID_buf_string(&rc
.holder_req_guid
, &tmp_guid_buf
),
1139 (unsigned)rc
.local_id
,
1149 * We found an open the caller can reuse.
1151 SMB_ASSERT(op
!= NULL
);
1154 return NT_STATUS_OK
;
1157 if (GUID_equal(&rc
.holder_req_guid
, &caller_req_guid
)) {
1159 * We're still the holder
1163 return NT_STATUS_FWP_RESERVED
;
1167 * The original request (or a former replay) is still
1168 * pending, ask the client to retry by sending FILE_NOT_AVAILABLE.
1170 status
= NT_STATUS_FILE_NOT_AVAILABLE
;
1171 DBG_DEBUG("holder %s still pending for create %s [%s] - %s\n",
1172 GUID_buf_string(&rc
.holder_req_guid
, &tmp_guid_buf
),
1180 struct smb2srv_open_recreate_state
{
1181 struct smbXsrv_open
*op
;
1182 const struct GUID
*create_guid
;
1183 struct security_token
*current_token
;
1184 struct server_id me
;
1189 static void smb2srv_open_recreate_fn(
1190 struct db_record
*rec
, TDB_DATA oldval
, void *private_data
)
1192 struct smb2srv_open_recreate_state
*state
= private_data
;
1193 TDB_DATA key
= dbwrap_record_get_key(rec
);
1194 struct smbXsrv_open_global0
*global
= NULL
;
1196 state
->status
= smbXsrv_open_global_verify_record(
1197 key
, oldval
, state
->op
, &state
->op
->global
);
1198 if (!NT_STATUS_IS_OK(state
->status
)) {
1199 DBG_WARNING("smbXsrv_open_global_verify_record for %s "
1202 nt_errstr(state
->status
));
1205 global
= state
->op
->global
;
1208 * If the provided create_guid is NULL, this means that
1209 * the reconnect request was a v1 request. In that case
1210 * we should skip the create GUID verification, since
1211 * it is valid to v1-reconnect a v2-opened handle.
1213 if ((state
->create_guid
!= NULL
) &&
1214 !GUID_equal(&global
->create_guid
, state
->create_guid
)) {
1215 struct GUID_txt_buf buf1
, buf2
;
1216 DBG_NOTICE("%s != %s in %s\n",
1217 GUID_buf_string(&global
->create_guid
, &buf1
),
1218 GUID_buf_string(state
->create_guid
, &buf2
),
1223 if (!security_token_is_sid(
1224 state
->current_token
, &global
->open_owner
)) {
1225 struct dom_sid_buf buf
;
1226 DBG_NOTICE("global owner %s not in our token in %s\n",
1227 dom_sid_str_buf(&global
->open_owner
, &buf
),
1232 if (!global
->durable
) {
1233 DBG_NOTICE("%"PRIu64
"/%"PRIu64
" not durable in %s\n",
1234 global
->open_persistent_id
,
1235 global
->open_volatile_id
,
1240 global
->open_volatile_id
= state
->op
->local_id
;
1241 global
->server_id
= state
->me
;
1243 state
->status
= smbXsrv_open_global_store(rec
, key
, oldval
, global
);
1244 if (!NT_STATUS_IS_OK(state
->status
)) {
1245 DBG_WARNING("smbXsrv_open_global_store for %s failed: %s\n",
1247 nt_errstr(state
->status
));
1253 state
->status
= NT_STATUS_OBJECT_NAME_NOT_FOUND
;
1256 NTSTATUS
smb2srv_open_recreate(struct smbXsrv_connection
*conn
,
1257 struct auth_session_info
*session_info
,
1258 uint64_t persistent_id
,
1259 const struct GUID
*create_guid
,
1261 struct smbXsrv_open
**_open
)
1263 struct smbXsrv_open_table
*table
= conn
->client
->open_table
;
1264 struct smb2srv_open_recreate_state state
= {
1265 .create_guid
= create_guid
,
1266 .me
= messaging_server_id(conn
->client
->msg_ctx
),
1268 struct smbXsrv_open_global_key_buf key_buf
;
1269 TDB_DATA key
= smbXsrv_open_global_id_to_key(
1270 persistent_id
& UINT32_MAX
, &key_buf
);
1274 if (session_info
== NULL
) {
1275 DEBUG(10, ("session_info=NULL\n"));
1276 return NT_STATUS_INVALID_HANDLE
;
1278 state
.current_token
= session_info
->security_token
;
1280 if (state
.current_token
== NULL
) {
1281 DEBUG(10, ("current_token=NULL\n"));
1282 return NT_STATUS_INVALID_HANDLE
;
1285 if ((persistent_id
& 0xFFFFFFFF00000000LLU
) != 0) {
1287 * We only use 32 bit for the persistent ID
1289 DBG_DEBUG("persistent_id=%"PRIx64
"\n", persistent_id
);
1290 return NT_STATUS_OBJECT_NAME_NOT_FOUND
;
1293 if (table
->local
.num_opens
>= table
->local
.max_opens
) {
1294 return NT_STATUS_INSUFFICIENT_RESOURCES
;
1297 state
.op
= talloc_zero(table
, struct smbXsrv_open
);
1298 if (state
.op
== NULL
) {
1299 return NT_STATUS_NO_MEMORY
;
1301 state
.op
->table
= table
;
1303 local_id
= idr_get_new_random(
1306 table
->local
.lowest_id
,
1307 table
->local
.highest_id
);
1308 if (local_id
== -1) {
1309 TALLOC_FREE(state
.op
);
1310 return NT_STATUS_INSUFFICIENT_RESOURCES
;
1312 state
.op
->local_id
= local_id
;
1313 SMB_ASSERT(state
.op
->local_id
== local_id
); /* No coercion loss */
1315 table
->local
.num_opens
+= 1;
1317 state
.op
->idle_time
= now
;
1318 state
.op
->status
= NT_STATUS_FILE_CLOSED
;
1320 status
= dbwrap_do_locked(
1321 table
->global
.db_ctx
, key
, smb2srv_open_recreate_fn
, &state
);
1322 if (!NT_STATUS_IS_OK(status
)) {
1323 DBG_DEBUG("dbwrap_do_locked() for %s failed: %s\n",
1329 if (!NT_STATUS_IS_OK(state
.status
)) {
1330 status
= state
.status
;
1331 DBG_DEBUG("smb2srv_open_recreate_fn for %s failed: %s\n",
1337 talloc_set_destructor(state
.op
, smbXsrv_open_destructor
);
1339 if (CHECK_DEBUGLVL(10)) {
1340 struct smbXsrv_openB open_blob
= {
1341 .info
.info0
= state
.op
,
1343 DBG_DEBUG("global_id (0x%08x) stored\n",
1344 state
.op
->global
->open_global_id
);
1345 NDR_PRINT_DEBUG(smbXsrv_openB
, &open_blob
);
1350 return NT_STATUS_OK
;
1352 table
->local
.num_opens
-= 1;
1354 ret
= idr_remove(table
->local
.idr
, state
.op
->local_id
);
1355 SMB_ASSERT(ret
== 0);
1356 TALLOC_FREE(state
.op
);
1360 struct smbXsrv_open_global_traverse_state
{
1361 int (*fn
)(struct db_record
*rec
, struct smbXsrv_open_global0
*, void *);
1365 static int smbXsrv_open_global_traverse_fn(struct db_record
*rec
, void *data
)
1367 struct smbXsrv_open_global_traverse_state
*state
=
1368 (struct smbXsrv_open_global_traverse_state
*)data
;
1369 struct smbXsrv_open_global0
*global
= NULL
;
1370 TDB_DATA key
= dbwrap_record_get_key(rec
);
1371 TDB_DATA val
= dbwrap_record_get_value(rec
);
1375 status
= smbXsrv_open_global_parse_record(
1376 talloc_tos(), key
, val
, &global
);
1377 if (!NT_STATUS_IS_OK(status
)) {
1381 ret
= state
->fn(rec
, global
, state
->private_data
);
1382 talloc_free(global
);
1386 NTSTATUS
smbXsrv_open_global_traverse(
1387 int (*fn
)(struct db_record
*rec
, struct smbXsrv_open_global0
*, void *),
1393 struct smbXsrv_open_global_traverse_state state
= {
1395 .private_data
= private_data
,
1399 status
= smbXsrv_open_global_init();
1400 if (!NT_STATUS_IS_OK(status
)) {
1402 DEBUG(0, ("Failed to initialize open_global: %s\n",
1403 nt_errstr(status
)));
1407 status
= dbwrap_traverse_read(smbXsrv_open_global_db_ctx
,
1408 smbXsrv_open_global_traverse_fn
,
1416 struct smbXsrv_open_cleanup_state
{
1421 static void smbXsrv_open_cleanup_fn(
1422 struct db_record
*rec
, TDB_DATA oldval
, void *private_data
)
1424 struct smbXsrv_open_cleanup_state
*state
= private_data
;
1425 struct smbXsrv_open_global0
*global
= NULL
;
1426 TDB_DATA key
= dbwrap_record_get_key(rec
);
1427 bool delete_open
= false;
1429 if (oldval
.dsize
== 0) {
1430 DBG_DEBUG("[global: 0x%08x] "
1431 "empty record in %s, skipping...\n",
1433 dbwrap_name(dbwrap_record_get_db(rec
)));
1434 state
->status
= NT_STATUS_OK
;
1438 state
->status
= smbXsrv_open_global_parse_record(
1439 talloc_tos(), key
, oldval
, &global
);
1440 if (!NT_STATUS_IS_OK(state
->status
)) {
1441 DBG_WARNING("[global: %x08x] "
1442 "smbXsrv_open_global_parse_record() in %s "
1443 "failed: %s, deleting record\n",
1445 dbwrap_name(dbwrap_record_get_db(rec
)),
1446 nt_errstr(state
->status
));
1451 if (server_id_is_disconnected(&global
->server_id
)) {
1452 struct timeval now
= timeval_current();
1453 struct timeval disconnect_time
;
1454 struct timeval_buf buf
;
1457 nttime_to_timeval(&disconnect_time
, global
->disconnect_time
);
1458 tdiff
= usec_time_diff(&now
, &disconnect_time
);
1459 delete_open
= (tdiff
>= 1000*global
->durable_timeout_msec
);
1461 DBG_DEBUG("[global: 0x%08x] "
1462 "disconnected at [%s] %"PRIi64
"s ago with "
1463 "timeout of %"PRIu32
"s -%s reached\n",
1465 timeval_str_buf(&disconnect_time
,
1470 global
->durable_timeout_msec
/ 1000,
1471 delete_open
? "" : " not");
1472 } else if (!serverid_exists(&global
->server_id
)) {
1473 struct server_id_buf idbuf
;
1474 DBG_DEBUG("[global: 0x%08x] "
1475 "server[%s] does not exist\n",
1477 server_id_str_buf(global
->server_id
, &idbuf
));
1482 state
->status
= NT_STATUS_OK
;
1486 state
->status
= dbwrap_record_delete(rec
);
1487 if (!NT_STATUS_IS_OK(state
->status
)) {
1488 DBG_WARNING("[global: 0x%08x] "
1489 "failed to delete record"
1492 dbwrap_name(dbwrap_record_get_db(rec
)),
1493 nt_errstr(state
->status
));
1497 DBG_DEBUG("[global: 0x%08x] "
1498 "deleted record from %s\n",
1500 dbwrap_name(dbwrap_record_get_db(rec
)));
1503 NTSTATUS
smbXsrv_open_cleanup(uint64_t persistent_id
)
1505 struct smbXsrv_open_cleanup_state state
= {
1506 .global_id
= persistent_id
& UINT32_MAX
,
1508 struct smbXsrv_open_global_key_buf key_buf
;
1509 TDB_DATA key
= smbXsrv_open_global_id_to_key(
1510 state
.global_id
, &key_buf
);
1513 status
= dbwrap_do_locked(
1514 smbXsrv_open_global_db_ctx
,
1516 smbXsrv_open_cleanup_fn
,
1518 if (!NT_STATUS_IS_OK(status
)) {
1519 DBG_DEBUG("[global: 0x%08x] dbwrap_do_locked failed: %s\n",
1525 return state
.status
;