Fix string overflow due to wrong size calculation
[Samba/gebeck_regimport.git] / source3 / printing / printing_db.c
blobd402aa366f4e3f7a0dacc0887b7b730a2f9eb3d4
1 /*
2 Unix SMB/Netbios implementation.
3 Version 3.0
4 printing backend routines
5 Copyright (C) Andrew Tridgell 1992-2000
6 Copyright (C) Jeremy Allison 2002
8 This program is free software; you can redistribute it and/or modify
9 it under the terms of the GNU General Public License as published by
10 the Free Software Foundation; either version 2 of the License, or
11 (at your option) any later version.
13 This program is distributed in the hope that it will be useful,
14 but WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 GNU General Public License for more details.
18 You should have received a copy of the GNU General Public License
19 along with this program; if not, write to the Free Software
20 Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
23 #include "includes.h"
24 #include "printing.h"
26 static struct tdb_print_db *print_db_head;
28 /****************************************************************************
29 Function to find or create the printer specific job tdb given a printername.
30 Limits the number of tdb's open to MAX_PRINT_DBS_OPEN.
31 ****************************************************************************/
33 struct tdb_print_db *get_print_db_byname(const char *printername)
35 struct tdb_print_db *p = NULL, *last_entry = NULL;
36 int num_open = 0;
37 pstring printdb_path;
38 BOOL done_become_root = False;
40 for (p = print_db_head, last_entry = print_db_head; p; p = p->next) {
41 /* Ensure the list terminates... JRA. */
42 SMB_ASSERT(p->next != print_db_head);
44 if (p->tdb && strequal(p->printer_name, printername)) {
45 DLIST_PROMOTE(print_db_head, p);
46 p->ref_count++;
47 return p;
49 num_open++;
50 last_entry = p;
53 /* Not found. */
54 if (num_open >= MAX_PRINT_DBS_OPEN) {
55 /* Try and recycle the last entry. */
56 DLIST_PROMOTE(print_db_head, last_entry);
58 for (p = print_db_head; p; p = p->next) {
59 if (p->ref_count)
60 continue;
61 if (p->tdb) {
62 if (tdb_close(print_db_head->tdb)) {
63 DEBUG(0,("get_print_db: Failed to close tdb for printer %s\n",
64 print_db_head->printer_name ));
65 return NULL;
68 p->tdb = NULL;
69 p->ref_count = 0;
70 memset(p->printer_name, '\0', sizeof(p->printer_name));
71 break;
73 if (p) {
74 DLIST_PROMOTE(print_db_head, p);
75 p = print_db_head;
79 if (!p) {
80 /* Create one. */
81 p = (struct tdb_print_db *)malloc(sizeof(struct tdb_print_db));
82 if (!p) {
83 DEBUG(0,("get_print_db: malloc fail !\n"));
84 return NULL;
86 ZERO_STRUCTP(p);
87 DLIST_ADD(print_db_head, p);
90 pstrcpy(printdb_path, lock_path("printing/"));
91 pstrcat(printdb_path, printername);
92 pstrcat(printdb_path, ".tdb");
94 if (geteuid() != 0) {
95 become_root();
96 done_become_root = True;
99 p->tdb = tdb_open_ex(printdb_path, 5000, TDB_DEFAULT, O_RDWR|O_CREAT,
100 0600, smbd_tdb_log);
102 if (done_become_root)
103 unbecome_root();
105 if (!p->tdb) {
106 DEBUG(0,("get_print_db: Failed to open printer backend database %s.\n",
107 printdb_path ));
108 DLIST_REMOVE(print_db_head, p);
109 SAFE_FREE(p);
110 return NULL;
112 fstrcpy(p->printer_name, printername);
113 p->ref_count++;
114 return p;
117 /***************************************************************************
118 Remove a reference count.
119 ****************************************************************************/
121 void release_print_db( struct tdb_print_db *pdb)
123 pdb->ref_count--;
124 SMB_ASSERT(pdb->ref_count >= 0);
127 /***************************************************************************
128 Close all open print db entries.
129 ****************************************************************************/
131 void close_all_print_db(void)
133 struct tdb_print_db *p = NULL, *next_p = NULL;
135 for (p = print_db_head; p; p = next_p) {
136 next_p = p->next;
138 if (p->tdb)
139 tdb_close(p->tdb);
140 DLIST_REMOVE(print_db_head, p);
141 ZERO_STRUCTP(p);
142 SAFE_FREE(p);
147 /****************************************************************************
148 Fetch and clean the pid_t record list for all pids interested in notify
149 messages. data needs freeing on exit.
150 ****************************************************************************/
152 TDB_DATA get_printer_notify_pid_list(TDB_CONTEXT *tdb, const char *printer_name, BOOL cleanlist)
154 TDB_DATA data;
155 size_t i;
157 ZERO_STRUCT(data);
159 data = tdb_fetch_bystring( tdb, NOTIFY_PID_LIST_KEY );
161 if (!data.dptr) {
162 ZERO_STRUCT(data);
163 return data;
166 if (data.dsize % 8) {
167 DEBUG(0,("get_printer_notify_pid_list: Size of record for printer %s not a multiple of 8 !\n", printer_name ));
168 tdb_delete_bystring(tdb, NOTIFY_PID_LIST_KEY );
169 SAFE_FREE(data.dptr);
170 ZERO_STRUCT(data);
171 return data;
174 if (!cleanlist)
175 return data;
178 * Weed out all dead entries.
181 for( i = 0; i < data.dsize; i += 8) {
182 pid_t pid = (pid_t)IVAL(data.dptr, i);
184 if (pid == sys_getpid())
185 continue;
187 /* Entry is dead if process doesn't exist or refcount is zero. */
189 while ((i < data.dsize) && ((IVAL(data.dptr, i + 4) == 0) || !process_exists(pid))) {
191 /* Refcount == zero is a logic error and should never happen. */
192 if (IVAL(data.dptr, i + 4) == 0) {
193 DEBUG(0,("get_printer_notify_pid_list: Refcount == 0 for pid = %u printer %s !\n",
194 (unsigned int)pid, printer_name ));
197 if (data.dsize - i > 8)
198 memmove( &data.dptr[i], &data.dptr[i+8], data.dsize - i - 8);
199 data.dsize -= 8;
203 return data;