cifssmb.c 179.1 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3
/*
 *   fs/cifs/cifssmb.c
 *
4
 *   Copyright (C) International Business Machines  Corp., 2002,2010
L
Linus Torvalds 已提交
5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26
 *   Author(s): Steve French (sfrench@us.ibm.com)
 *
 *   Contains the routines for constructing the SMB PDUs themselves
 *
 *   This library is free software; you can redistribute it and/or modify
 *   it under the terms of the GNU Lesser General Public License as published
 *   by the Free Software Foundation; either version 2.1 of the License, or
 *   (at your option) any later version.
 *
 *   This library is distributed in the hope that it will be useful,
 *   but WITHOUT ANY WARRANTY; without even the implied warranty of
 *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See
 *   the GNU Lesser General Public License for more details.
 *
 *   You should have received a copy of the GNU Lesser General Public License
 *   along with this library; if not, write to the Free Software
 *   Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
 */

 /* SMB/CIFS PDU handling routines here - except for leftovers in connect.c   */
 /* These are mostly routines that operate on a pathname, or on a tree id     */
 /* (mounted volume), but there are eight handle based routines which must be */
27 28
 /* treated slightly differently for reconnection purposes since we never     */
 /* want to reuse a stale file handle and only the caller knows the file info */
L
Linus Torvalds 已提交
29 30 31 32

#include <linux/fs.h>
#include <linux/kernel.h>
#include <linux/vfs.h>
33
#include <linux/slab.h>
L
Linus Torvalds 已提交
34
#include <linux/posix_acl_xattr.h>
J
Jeff Layton 已提交
35
#include <linux/pagemap.h>
L
Linus Torvalds 已提交
36 37 38
#include <asm/uaccess.h>
#include "cifspdu.h"
#include "cifsglob.h"
39
#include "cifsacl.h"
L
Linus Torvalds 已提交
40 41 42 43 44 45 46 47 48
#include "cifsproto.h"
#include "cifs_unicode.h"
#include "cifs_debug.h"

#ifdef CONFIG_CIFS_POSIX
static struct {
	int index;
	char *name;
} protocols[] = {
49 50
#ifdef CONFIG_CIFS_WEAK_PW_HASH
	{LANMAN_PROT, "\2LM1.2X002"},
51
	{LANMAN2_PROT, "\2LANMAN2.1"},
52
#endif /* weak password hashing for legacy clients */
53
	{CIFS_PROT, "\2NT LM 0.12"},
54
	{POSIX_PROT, "\2POSIX 2"},
L
Linus Torvalds 已提交
55 56 57 58 59 60 61
	{BAD_PROT, "\2"}
};
#else
static struct {
	int index;
	char *name;
} protocols[] = {
62 63
#ifdef CONFIG_CIFS_WEAK_PW_HASH
	{LANMAN_PROT, "\2LM1.2X002"},
64
	{LANMAN2_PROT, "\2LANMAN2.1"},
65
#endif /* weak password hashing for legacy clients */
S
Steve French 已提交
66
	{CIFS_PROT, "\2NT LM 0.12"},
L
Linus Torvalds 已提交
67 68 69 70
	{BAD_PROT, "\2"}
};
#endif

71 72 73
/* define the number of elements in the cifs dialect array */
#ifdef CONFIG_CIFS_POSIX
#ifdef CONFIG_CIFS_WEAK_PW_HASH
74
#define CIFS_NUM_PROT 4
75 76 77 78 79
#else
#define CIFS_NUM_PROT 2
#endif /* CIFS_WEAK_PW_HASH */
#else /* not posix */
#ifdef CONFIG_CIFS_WEAK_PW_HASH
80
#define CIFS_NUM_PROT 3
81 82 83 84 85
#else
#define CIFS_NUM_PROT 1
#endif /* CONFIG_CIFS_WEAK_PW_HASH */
#endif /* CIFS_POSIX */

L
Linus Torvalds 已提交
86 87
/* Mark as invalid, all open files on tree connections since they
   were closed when session to server was lost */
88
static void mark_open_files_invalid(struct cifs_tcon *pTcon)
L
Linus Torvalds 已提交
89 90
{
	struct cifsFileInfo *open_file = NULL;
S
Steve French 已提交
91 92
	struct list_head *tmp;
	struct list_head *tmp1;
L
Linus Torvalds 已提交
93 94

/* list all files open on tree connection and mark them invalid */
95
	spin_lock(&cifs_file_list_lock);
L
Linus Torvalds 已提交
96
	list_for_each_safe(tmp, tmp1, &pTcon->openFileList) {
S
Steve French 已提交
97
		open_file = list_entry(tmp, struct cifsFileInfo, tlist);
98
		open_file->invalidHandle = true;
99
		open_file->oplock_break_cancelled = true;
L
Linus Torvalds 已提交
100
	}
101
	spin_unlock(&cifs_file_list_lock);
102 103
	/* BB Add call to invalidate_inodes(sb) for all superblocks mounted
	   to this tcon */
L
Linus Torvalds 已提交
104 105
}

106 107
/* reconnect the socket, tcon, and smb session if needed */
static int
108
cifs_reconnect_tcon(struct cifs_tcon *tcon, int smb_command)
109
{
110
	int rc;
111
	struct cifs_ses *ses;
112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133
	struct TCP_Server_Info *server;
	struct nls_table *nls_codepage;

	/*
	 * SMBs NegProt, SessSetup, uLogoff do not have tcon yet so check for
	 * tcp and smb session status done differently for those three - in the
	 * calling routine
	 */
	if (!tcon)
		return 0;

	ses = tcon->ses;
	server = ses->server;

	/*
	 * only tree disconnect, open, and write, (and ulogoff which does not
	 * have tcon) are allowed as we start force umount
	 */
	if (tcon->tidStatus == CifsExiting) {
		if (smb_command != SMB_COM_WRITE_ANDX &&
		    smb_command != SMB_COM_OPEN_ANDX &&
		    smb_command != SMB_COM_TREE_DISCONNECT) {
134 135
			cFYI(1, "can not send cmd %d while umounting",
				smb_command);
136 137 138 139 140 141 142 143 144 145
			return -ENODEV;
		}
	}

	/*
	 * Give demultiplex thread up to 10 seconds to reconnect, should be
	 * greater than cifs socket timeout which is 7 seconds
	 */
	while (server->tcpStatus == CifsNeedReconnect) {
		wait_event_interruptible_timeout(server->response_q,
146
			(server->tcpStatus != CifsNeedReconnect), 10 * HZ);
147

148
		/* are we still trying to reconnect? */
149 150 151 152 153 154 155 156
		if (server->tcpStatus != CifsNeedReconnect)
			break;

		/*
		 * on "soft" mounts we wait once. Hard mounts keep
		 * retrying until process is killed or server comes
		 * back on-line
		 */
157
		if (!tcon->retry) {
158
			cFYI(1, "gave up waiting on reconnect in smb_init");
159 160 161 162 163 164 165 166 167 168 169 170 171
			return -EHOSTDOWN;
		}
	}

	if (!ses->need_reconnect && !tcon->need_reconnect)
		return 0;

	nls_codepage = load_nls_default();

	/*
	 * need to prevent multiple threads trying to simultaneously
	 * reconnect the same SMB session
	 */
172
	mutex_lock(&ses->session_mutex);
173 174
	rc = cifs_negotiate_protocol(0, ses);
	if (rc == 0 && ses->need_reconnect)
175 176 177 178
		rc = cifs_setup_session(0, ses, nls_codepage);

	/* do we need to reconnect tcon? */
	if (rc || !tcon->need_reconnect) {
179
		mutex_unlock(&ses->session_mutex);
180 181 182 183 184
		goto out;
	}

	mark_open_files_invalid(tcon);
	rc = CIFSTCon(0, ses, tcon->treeName, tcon, nls_codepage);
185
	mutex_unlock(&ses->session_mutex);
186
	cFYI(1, "reconnect tcon rc = %d", rc);
187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225

	if (rc)
		goto out;

	/*
	 * FIXME: check if wsize needs updated due to negotiated smb buffer
	 * 	  size shrinking
	 */
	atomic_inc(&tconInfoReconnectCount);

	/* tell server Unix caps we support */
	if (ses->capabilities & CAP_UNIX)
		reset_cifs_unix_caps(0, tcon, NULL, NULL);

	/*
	 * Removed call to reopen open files here. It is safer (and faster) to
	 * reopen files one at a time as needed in read and write.
	 *
	 * FIXME: what about file locks? don't we need to reclaim them ASAP?
	 */

out:
	/*
	 * Check if handle based operation so we know whether we can continue
	 * or not without returning to caller to reset file handle
	 */
	switch (smb_command) {
	case SMB_COM_READ_ANDX:
	case SMB_COM_WRITE_ANDX:
	case SMB_COM_CLOSE:
	case SMB_COM_FIND_CLOSE2:
	case SMB_COM_LOCKING_ANDX:
		rc = -EAGAIN;
	}

	unload_nls(nls_codepage);
	return rc;
}

S
Steve French 已提交
226 227 228
/* Allocate and return pointer to an SMB request buffer, and set basic
   SMB information in the SMB header.  If the return code is zero, this
   function must have filled in request_buf pointer */
L
Linus Torvalds 已提交
229
static int
230
small_smb_init(int smb_command, int wct, struct cifs_tcon *tcon,
S
Steve French 已提交
231
		void **request_buf)
L
Linus Torvalds 已提交
232
{
233
	int rc;
L
Linus Torvalds 已提交
234

235
	rc = cifs_reconnect_tcon(tcon, smb_command);
S
Steve French 已提交
236
	if (rc)
L
Linus Torvalds 已提交
237 238 239 240 241 242 243 244
		return rc;

	*request_buf = cifs_small_buf_get();
	if (*request_buf == NULL) {
		/* BB should we add a retry in here if not a writepage? */
		return -ENOMEM;
	}

245
	header_assemble((struct smb_hdr *) *request_buf, smb_command,
246
			tcon, wct);
L
Linus Torvalds 已提交
247

S
Steve French 已提交
248 249
	if (tcon != NULL)
		cifs_stats_inc(&tcon->num_smbs_sent);
250

251
	return 0;
252 253
}

254
int
255
small_smb_init_no_tc(const int smb_command, const int wct,
256
		     struct cifs_ses *ses, void **request_buf)
257 258
{
	int rc;
259
	struct smb_hdr *buffer;
260

261
	rc = small_smb_init(smb_command, wct, NULL, request_buf);
S
Steve French 已提交
262
	if (rc)
263 264
		return rc;

265
	buffer = (struct smb_hdr *)*request_buf;
266 267 268
	buffer->Mid = GetNextMid(ses->server);
	if (ses->capabilities & CAP_UNICODE)
		buffer->Flags2 |= SMBFLG2_UNICODE;
269
	if (ses->capabilities & CAP_STATUS32)
270 271 272 273
		buffer->Flags2 |= SMBFLG2_ERR_STATUS;

	/* uid, tid can stay at zero as set in header assemble */

274
	/* BB add support for turning on the signing when
275 276 277 278
	this function is used after 1st of session setup requests */

	return rc;
}
L
Linus Torvalds 已提交
279 280 281

/* If the return code is zero, this function must fill in request_buf pointer */
static int
282
__smb_init(int smb_command, int wct, struct cifs_tcon *tcon,
283
			void **request_buf, void **response_buf)
L
Linus Torvalds 已提交
284 285 286 287 288 289 290 291 292 293
{
	*request_buf = cifs_buf_get();
	if (*request_buf == NULL) {
		/* BB should we add a retry in here if not a writepage? */
		return -ENOMEM;
	}
    /* Although the original thought was we needed the response buf for  */
    /* potential retries of smb operations it turns out we can determine */
    /* from the mid flags when the request buffer can be resent without  */
    /* having to use a second distinct buffer for the response */
S
Steve French 已提交
294
	if (response_buf)
295
		*response_buf = *request_buf;
L
Linus Torvalds 已提交
296 297

	header_assemble((struct smb_hdr *) *request_buf, smb_command, tcon,
S
Steve French 已提交
298
			wct);
L
Linus Torvalds 已提交
299

S
Steve French 已提交
300 301
	if (tcon != NULL)
		cifs_stats_inc(&tcon->num_smbs_sent);
302

303 304 305 306 307
	return 0;
}

/* If the return code is zero, this function must fill in request_buf pointer */
static int
308
smb_init(int smb_command, int wct, struct cifs_tcon *tcon,
309 310 311 312 313 314 315 316 317 318 319 320
	 void **request_buf, void **response_buf)
{
	int rc;

	rc = cifs_reconnect_tcon(tcon, smb_command);
	if (rc)
		return rc;

	return __smb_init(smb_command, wct, tcon, request_buf, response_buf);
}

static int
321
smb_init_no_reconnect(int smb_command, int wct, struct cifs_tcon *tcon,
322 323 324 325 326 327
			void **request_buf, void **response_buf)
{
	if (tcon->ses->need_reconnect || tcon->need_reconnect)
		return -EHOSTDOWN;

	return __smb_init(smb_command, wct, tcon, request_buf, response_buf);
L
Linus Torvalds 已提交
328 329
}

330
static int validate_t2(struct smb_t2_rsp *pSMB)
L
Linus Torvalds 已提交
331
{
332 333 334 335 336
	unsigned int total_size;

	/* check for plausible wct */
	if (pSMB->hdr.WordCount < 10)
		goto vt2_err;
L
Linus Torvalds 已提交
337 338

	/* check for parm and data offset going beyond end of smb */
339 340 341 342 343 344 345 346
	if (get_unaligned_le16(&pSMB->t2_rsp.ParameterOffset) > 1024 ||
	    get_unaligned_le16(&pSMB->t2_rsp.DataOffset) > 1024)
		goto vt2_err;

	total_size = get_unaligned_le16(&pSMB->t2_rsp.ParameterCount);
	if (total_size >= 512)
		goto vt2_err;

J
Jeff Layton 已提交
347 348 349
	/* check that bcc is at least as big as parms + data, and that it is
	 * less than negotiated smb buffer
	 */
350 351 352 353 354 355 356
	total_size += get_unaligned_le16(&pSMB->t2_rsp.DataCount);
	if (total_size > get_bcc(&pSMB->hdr) ||
	    total_size >= CIFSMaxBufSize + MAX_CIFS_HDR_SIZE)
		goto vt2_err;

	return 0;
vt2_err:
357
	cifs_dump_mem("Invalid transact2 SMB: ", (char *)pSMB,
L
Linus Torvalds 已提交
358
		sizeof(struct smb_t2_rsp) + 16);
359
	return -EINVAL;
L
Linus Torvalds 已提交
360
}
361

362 363 364 365 366 367 368
static inline void inc_rfc1001_len(void *pSMB, int count)
{
	struct smb_hdr *hdr = (struct smb_hdr *)pSMB;

	be32_add_cpu(&hdr->smb_buf_length, count);
}

L
Linus Torvalds 已提交
369
int
370
CIFSSMBNegotiate(unsigned int xid, struct cifs_ses *ses)
L
Linus Torvalds 已提交
371 372 373 374 375
{
	NEGOTIATE_REQ *pSMB;
	NEGOTIATE_RSP *pSMBr;
	int rc = 0;
	int bytes_returned;
376
	int i;
377
	struct TCP_Server_Info *server;
L
Linus Torvalds 已提交
378
	u16 count;
379
	unsigned int secFlags;
L
Linus Torvalds 已提交
380

S
Steve French 已提交
381
	if (ses->server)
L
Linus Torvalds 已提交
382 383 384 385 386 387 388 389 390
		server = ses->server;
	else {
		rc = -EIO;
		return rc;
	}
	rc = smb_init(SMB_COM_NEGOTIATE, 0, NULL /* no tcon yet */ ,
		      (void **) &pSMB, (void **) &pSMBr);
	if (rc)
		return rc;
391 392

	/* if any of auth flags (ie not sign or seal) are overriden use them */
S
Steve French 已提交
393
	if (ses->overrideSecFlg & (~(CIFSSEC_MUST_SIGN | CIFSSEC_MUST_SEAL)))
394
		secFlags = ses->overrideSecFlg;  /* BB FIXME fix sign flags? */
395
	else /* if override flags set only sign/seal OR them with global auth */
396
		secFlags = global_secflags | ses->overrideSecFlg;
397

398
	cFYI(1, "secFlags 0x%x", secFlags);
399

400
	pSMB->hdr.Mid = GetNextMid(server);
401
	pSMB->hdr.Flags2 |= (SMBFLG2_UNICODE | SMBFLG2_ERR_STATUS);
402

403
	if ((secFlags & CIFSSEC_MUST_KRB5) == CIFSSEC_MUST_KRB5)
404
		pSMB->hdr.Flags2 |= SMBFLG2_EXT_SEC;
405
	else if ((secFlags & CIFSSEC_AUTH_MASK) == CIFSSEC_MAY_KRB5) {
406
		cFYI(1, "Kerberos only mechanism, enable extended security");
407
		pSMB->hdr.Flags2 |= SMBFLG2_EXT_SEC;
408
	} else if ((secFlags & CIFSSEC_MUST_NTLMSSP) == CIFSSEC_MUST_NTLMSSP)
409 410
		pSMB->hdr.Flags2 |= SMBFLG2_EXT_SEC;
	else if ((secFlags & CIFSSEC_AUTH_MASK) == CIFSSEC_MAY_NTLMSSP) {
411
		cFYI(1, "NTLMSSP only mechanism, enable extended security");
412 413
		pSMB->hdr.Flags2 |= SMBFLG2_EXT_SEC;
	}
414

415
	count = 0;
416
	for (i = 0; i < CIFS_NUM_PROT; i++) {
417 418 419 420
		strncpy(pSMB->DialectsArray+count, protocols[i].name, 16);
		count += strlen(protocols[i].name) + 1;
		/* null at end of source and target buffers anyway */
	}
421
	inc_rfc1001_len(pSMB, count);
L
Linus Torvalds 已提交
422 423 424 425
	pSMB->ByteCount = cpu_to_le16(count);

	rc = SendReceive(xid, ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
426
	if (rc != 0)
427 428
		goto neg_err_exit;

429 430
	server->dialect = le16_to_cpu(pSMBr->DialectIndex);
	cFYI(1, "Dialect: %d", server->dialect);
431
	/* Check wct = 1 error case */
432
	if ((pSMBr->hdr.WordCount < 13) || (server->dialect == BAD_PROT)) {
433
		/* core returns wct = 1, but we do not ask for core - otherwise
434
		small wct just comes when dialect index is -1 indicating we
435 436 437
		could not negotiate a common dialect */
		rc = -EOPNOTSUPP;
		goto neg_err_exit;
438
#ifdef CONFIG_CIFS_WEAK_PW_HASH
S
Steve French 已提交
439
	} else if ((pSMBr->hdr.WordCount == 13)
440 441
			&& ((server->dialect == LANMAN_PROT)
				|| (server->dialect == LANMAN2_PROT))) {
442
		__s16 tmp;
443
		struct lanman_neg_rsp *rsp = (struct lanman_neg_rsp *)pSMBr;
444

S
Steve French 已提交
445
		if ((secFlags & CIFSSEC_MAY_LANMAN) ||
446
			(secFlags & CIFSSEC_MAY_PLNTXT))
447 448
			server->secType = LANMAN;
		else {
449 450
			cERROR(1, "mount failed weak security disabled"
				   " in /proc/fs/cifs/SecurityFlags");
451 452
			rc = -EOPNOTSUPP;
			goto neg_err_exit;
453
		}
454
		server->sec_mode = (__u8)le16_to_cpu(rsp->SecurityMode);
455
		server->maxReq = le16_to_cpu(rsp->MaxMpxCount);
456
		server->maxBuf = le16_to_cpu(rsp->MaxBufSize);
457
		server->max_vcs = le16_to_cpu(rsp->MaxNumberVcs);
458 459
		/* even though we do not use raw we might as well set this
		accurately, in case we ever find a need for it */
S
Steve French 已提交
460
		if ((le16_to_cpu(rsp->RawMode) & RAW_ENABLE) == RAW_ENABLE) {
461
			server->max_rw = 0xFF00;
462 463
			server->capabilities = CAP_MPX_MODE | CAP_RAW_MODE;
		} else {
464
			server->max_rw = 0;/* do not need to use raw anyway */
465 466
			server->capabilities = CAP_MPX_MODE;
		}
467
		tmp = (__s16)le16_to_cpu(rsp->ServerTimeZone);
468
		if (tmp == -1) {
469 470
			/* OS/2 often does not set timezone therefore
			 * we must use server time to calc time zone.
471 472 473 474
			 * Could deviate slightly from the right zone.
			 * Smallest defined timezone difference is 15 minutes
			 * (i.e. Nepal).  Rounding up/down is done to match
			 * this requirement.
475
			 */
476
			int val, seconds, remain, result;
477 478
			struct timespec ts, utc;
			utc = CURRENT_TIME;
479 480
			ts = cnvrtDosUnixTm(rsp->SrvTime.Date,
					    rsp->SrvTime.Time, 0);
481
			cFYI(1, "SrvTime %d sec since 1970 (utc: %d) diff: %d",
482
				(int)ts.tv_sec, (int)utc.tv_sec,
483
				(int)(utc.tv_sec - ts.tv_sec));
484
			val = (int)(utc.tv_sec - ts.tv_sec);
485
			seconds = abs(val);
S
Steve French 已提交
486
			result = (seconds / MIN_TZ_ADJ) * MIN_TZ_ADJ;
487
			remain = seconds % MIN_TZ_ADJ;
S
Steve French 已提交
488
			if (remain >= (MIN_TZ_ADJ / 2))
489
				result += MIN_TZ_ADJ;
S
Steve French 已提交
490
			if (val < 0)
S
Steve French 已提交
491
				result = -result;
492
			server->timeAdj = result;
493
		} else {
494 495
			server->timeAdj = (int)tmp;
			server->timeAdj *= 60; /* also in seconds */
496
		}
497
		cFYI(1, "server->timeAdj: %d seconds", server->timeAdj);
498

499

500
		/* BB get server time for time conversions and add
501
		code to use it and timezone since this is not UTC */
502

503
		if (rsp->EncryptionKeyLength ==
504
				cpu_to_le16(CIFS_CRYPTO_KEY_SIZE)) {
505
			memcpy(ses->server->cryptkey, rsp->EncryptionKey,
506
				CIFS_CRYPTO_KEY_SIZE);
507
		} else if (server->sec_mode & SECMODE_PW_ENCRYPT) {
508 509 510
			rc = -EIO; /* need cryptkey unless plain text */
			goto neg_err_exit;
		}
511

512
		cFYI(1, "LANMAN negotiated");
513 514 515
		/* we will not end up setting signing flags - as no signing
		was in LANMAN and server did not return the flags on */
		goto signing_check;
516
#else /* weak security disabled */
S
Steve French 已提交
517
	} else if (pSMBr->hdr.WordCount == 13) {
518 519
		cERROR(1, "mount failed, cifs module not built "
			  "with CIFS_WEAK_PW_HASH support");
D
Dan Carpenter 已提交
520
		rc = -EOPNOTSUPP;
521
#endif /* WEAK_PW_HASH */
522
		goto neg_err_exit;
S
Steve French 已提交
523
	} else if (pSMBr->hdr.WordCount != 17) {
524 525 526 527 528
		/* unknown wct */
		rc = -EOPNOTSUPP;
		goto neg_err_exit;
	}
	/* else wct == 17 NTLM */
529 530
	server->sec_mode = pSMBr->SecurityMode;
	if ((server->sec_mode & SECMODE_USER) == 0)
531
		cFYI(1, "share mode security");
532

533
	if ((server->sec_mode & SECMODE_PW_ENCRYPT) == 0)
534
#ifdef CONFIG_CIFS_WEAK_PW_HASH
535
		if ((secFlags & CIFSSEC_MAY_PLNTXT) == 0)
536
#endif /* CIFS_WEAK_PW_HASH */
537 538
			cERROR(1, "Server requests plain text password"
				  " but client support disabled");
539

S
Steve French 已提交
540
	if ((secFlags & CIFSSEC_MUST_NTLMV2) == CIFSSEC_MUST_NTLMV2)
541
		server->secType = NTLMv2;
S
Steve French 已提交
542
	else if (secFlags & CIFSSEC_MAY_NTLM)
543
		server->secType = NTLM;
S
Steve French 已提交
544
	else if (secFlags & CIFSSEC_MAY_NTLMV2)
545
		server->secType = NTLMv2;
546 547
	else if (secFlags & CIFSSEC_MAY_KRB5)
		server->secType = Kerberos;
548
	else if (secFlags & CIFSSEC_MAY_NTLMSSP)
549
		server->secType = RawNTLMSSP;
550 551 552 553
	else if (secFlags & CIFSSEC_MAY_LANMAN)
		server->secType = LANMAN;
	else {
		rc = -EOPNOTSUPP;
554
		cERROR(1, "Invalid security type");
555 556 557
		goto neg_err_exit;
	}
	/* else ... any others ...? */
558 559 560 561 562

	/* one byte, so no need to convert this or EncryptionKeyLen from
	   little endian */
	server->maxReq = le16_to_cpu(pSMBr->MaxMpxCount);
	/* probably no need to store and check maxvcs */
563
	server->maxBuf = le32_to_cpu(pSMBr->MaxBufferSize);
564
	server->max_rw = le32_to_cpu(pSMBr->MaxRawSize);
565
	cFYI(DBG2, "Max buf = %d", ses->server->maxBuf);
566
	server->capabilities = le32_to_cpu(pSMBr->Capabilities);
567 568
	server->timeAdj = (int)(__s16)le16_to_cpu(pSMBr->ServerTimeZone);
	server->timeAdj *= 60;
569
	if (pSMBr->EncryptionKeyLength == CIFS_CRYPTO_KEY_SIZE) {
570
		memcpy(ses->server->cryptkey, pSMBr->u.EncryptionKey,
571
		       CIFS_CRYPTO_KEY_SIZE);
572 573 574
	} else if ((pSMBr->hdr.Flags2 & SMBFLG2_EXT_SEC ||
			server->capabilities & CAP_EXTENDED_SECURITY) &&
				(pSMBr->EncryptionKeyLength == 0)) {
575
		/* decode security blob */
576
		count = get_bcc(&pSMBr->hdr);
577
		if (count < 16) {
578
			rc = -EIO;
579 580
			goto neg_err_exit;
		}
581
		spin_lock(&cifs_tcp_ses_lock);
582
		if (server->srv_count > 1) {
583
			spin_unlock(&cifs_tcp_ses_lock);
584 585 586
			if (memcmp(server->server_GUID,
				   pSMBr->u.extended_response.
				   GUID, 16) != 0) {
587
				cFYI(1, "server UID changed");
588
				memcpy(server->server_GUID,
589 590 591
					pSMBr->u.extended_response.GUID,
					16);
			}
592
		} else {
593
			spin_unlock(&cifs_tcp_ses_lock);
594 595
			memcpy(server->server_GUID,
			       pSMBr->u.extended_response.GUID, 16);
596
		}
597 598 599

		if (count == 16) {
			server->secType = RawNTLMSSP;
600 601
		} else {
			rc = decode_negTokenInit(pSMBr->u.extended_response.
602 603
						 SecurityBlob, count - 16,
						 server);
604
			if (rc == 1)
605
				rc = 0;
606
			else
607
				rc = -EINVAL;
608 609 610 611 612 613 614 615 616
			if (server->secType == Kerberos) {
				if (!server->sec_kerberos &&
						!server->sec_mskerberos)
					rc = -EOPNOTSUPP;
			} else if (server->secType == RawNTLMSSP) {
				if (!server->sec_ntlmssp)
					rc = -EOPNOTSUPP;
			} else
					rc = -EOPNOTSUPP;
L
Linus Torvalds 已提交
617
		}
618
	} else if (server->sec_mode & SECMODE_PW_ENCRYPT) {
619 620
		rc = -EIO; /* no crypt key only if plain text pwd */
		goto neg_err_exit;
621 622 623
	} else
		server->capabilities &= ~CAP_EXTENDED_SECURITY;

624
#ifdef CONFIG_CIFS_WEAK_PW_HASH
625
signing_check:
626
#endif
627 628 629
	if ((secFlags & CIFSSEC_MAY_SIGN) == 0) {
		/* MUST_SIGN already includes the MAY_SIGN FLAG
		   so if this is zero it means that signing is disabled */
630
		cFYI(1, "Signing disabled");
631
		if (server->sec_mode & SECMODE_SIGN_REQUIRED) {
632
			cERROR(1, "Server requires "
J
[CIFS]  
Jeff Layton 已提交
633
				   "packet signing to be enabled in "
634
				   "/proc/fs/cifs/SecurityFlags.");
635 636
			rc = -EOPNOTSUPP;
		}
637
		server->sec_mode &=
638
			~(SECMODE_SIGN_ENABLED | SECMODE_SIGN_REQUIRED);
639 640
	} else if ((secFlags & CIFSSEC_MUST_SIGN) == CIFSSEC_MUST_SIGN) {
		/* signing required */
641
		cFYI(1, "Must sign - secFlags 0x%x", secFlags);
642
		if ((server->sec_mode &
643
			(SECMODE_SIGN_ENABLED | SECMODE_SIGN_REQUIRED)) == 0) {
644
			cERROR(1, "signing required but server lacks support");
645
			rc = -EOPNOTSUPP;
646
		} else
647
			server->sec_mode |= SECMODE_SIGN_REQUIRED;
648 649
	} else {
		/* signing optional ie CIFSSEC_MAY_SIGN */
650 651
		if ((server->sec_mode & SECMODE_SIGN_REQUIRED) == 0)
			server->sec_mode &=
652
				~(SECMODE_SIGN_ENABLED | SECMODE_SIGN_REQUIRED);
L
Linus Torvalds 已提交
653
	}
654 655

neg_err_exit:
656
	cifs_buf_release(pSMB);
657

658
	cFYI(1, "negprot rc %d", rc);
L
Linus Torvalds 已提交
659 660 661 662
	return rc;
}

int
663
CIFSSMBTDis(const int xid, struct cifs_tcon *tcon)
L
Linus Torvalds 已提交
664 665 666 667
{
	struct smb_hdr *smb_buffer;
	int rc = 0;

668
	cFYI(1, "In tree disconnect");
L
Linus Torvalds 已提交
669

670 671 672
	/* BB: do we need to check this? These should never be NULL. */
	if ((tcon->ses == NULL) || (tcon->ses->server == NULL))
		return -EIO;
L
Linus Torvalds 已提交
673

674 675 676 677 678 679
	/*
	 * No need to return error on this operation if tid invalidated and
	 * closed on server already e.g. due to tcp session crashing. Also,
	 * the tcon is no longer on the list, so no need to take lock before
	 * checking this.
	 */
680
	if ((tcon->need_reconnect) || (tcon->ses->need_reconnect))
681
		return 0;
L
Linus Torvalds 已提交
682

683
	rc = small_smb_init(SMB_COM_TREE_DISCONNECT, 0, tcon,
684
			    (void **)&smb_buffer);
685
	if (rc)
L
Linus Torvalds 已提交
686
		return rc;
687 688

	rc = SendReceiveNoRsp(xid, tcon->ses, smb_buffer, 0);
L
Linus Torvalds 已提交
689
	if (rc)
690
		cFYI(1, "Tree disconnect failed %d", rc);
L
Linus Torvalds 已提交
691

692
	/* No need to return error on this operation if tid invalidated and
693
	   closed on server already e.g. due to tcp session crashing */
L
Linus Torvalds 已提交
694 695 696 697 698 699
	if (rc == -EAGAIN)
		rc = 0;

	return rc;
}

700 701 702 703 704 705 706 707 708 709 710 711 712 713 714 715 716 717 718 719 720 721
/*
 * This is a no-op for now. We're not really interested in the reply, but
 * rather in the fact that the server sent one and that server->lstrp
 * gets updated.
 *
 * FIXME: maybe we should consider checking that the reply matches request?
 */
static void
cifs_echo_callback(struct mid_q_entry *mid)
{
	struct TCP_Server_Info *server = mid->callback_data;

	DeleteMidQEntry(mid);
	atomic_dec(&server->inFlight);
	wake_up(&server->request_q);
}

int
CIFSSMBEcho(struct TCP_Server_Info *server)
{
	ECHO_REQ *smb;
	int rc = 0;
722
	struct kvec iov;
723 724 725 726 727 728 729 730

	cFYI(1, "In echo request");

	rc = small_smb_init(SMB_COM_ECHO, 0, NULL, (void **)&smb);
	if (rc)
		return rc;

	/* set up echo request */
S
Steve French 已提交
731
	smb->hdr.Tid = 0xffff;
732 733
	smb->hdr.WordCount = 1;
	put_unaligned_le16(1, &smb->EchoCount);
734
	put_bcc(1, &smb->hdr);
735
	smb->Data[0] = 'a';
736
	inc_rfc1001_len(smb, 3);
737 738
	iov.iov_base = smb;
	iov.iov_len = be32_to_cpu(smb->hdr.smb_buf_length) + 4;
739

740
	rc = cifs_call_async(server, &iov, 1, cifs_echo_callback, server, true);
741 742 743 744 745 746 747 748
	if (rc)
		cFYI(1, "Echo request failed: %d", rc);

	cifs_small_buf_release(smb);

	return rc;
}

L
Linus Torvalds 已提交
749
int
750
CIFSSMBLogoff(const int xid, struct cifs_ses *ses)
L
Linus Torvalds 已提交
751 752 753 754
{
	LOGOFF_ANDX_REQ *pSMB;
	int rc = 0;

755
	cFYI(1, "In SMBLogoff for session disconnect");
S
Steve French 已提交
756

757 758 759 760 761 762
	/*
	 * BB: do we need to check validity of ses and server? They should
	 * always be valid since we have an active reference. If not, that
	 * should probably be a BUG()
	 */
	if (!ses || !ses->server)
S
Steve French 已提交
763 764
		return -EIO;

765
	mutex_lock(&ses->session_mutex);
S
Steve French 已提交
766 767 768
	if (ses->need_reconnect)
		goto session_already_dead; /* no need to send SMBlogoff if uid
					      already closed due to reconnect */
L
Linus Torvalds 已提交
769 770
	rc = small_smb_init(SMB_COM_LOGOFF_ANDX, 2, NULL, (void **)&pSMB);
	if (rc) {
771
		mutex_unlock(&ses->session_mutex);
L
Linus Torvalds 已提交
772 773 774
		return rc;
	}

S
Steve French 已提交
775
	pSMB->hdr.Mid = GetNextMid(ses->server);
776

777
	if (ses->server->sec_mode &
L
Linus Torvalds 已提交
778 779 780 781 782 783
		   (SECMODE_SIGN_REQUIRED | SECMODE_SIGN_ENABLED))
			pSMB->hdr.Flags2 |= SMBFLG2_SECURITY_SIGNATURE;

	pSMB->hdr.Uid = ses->Suid;

	pSMB->AndXCommand = 0xFF;
784
	rc = SendReceiveNoRsp(xid, ses, (struct smb_hdr *) pSMB, 0);
S
Steve French 已提交
785
session_already_dead:
786
	mutex_unlock(&ses->session_mutex);
L
Linus Torvalds 已提交
787 788

	/* if session dead then we do not need to do ulogoff,
789
		since server closed smb session, no sense reporting
L
Linus Torvalds 已提交
790 791 792 793 794 795
		error */
	if (rc == -EAGAIN)
		rc = 0;
	return rc;
}

796
int
797
CIFSPOSIXDelFile(const int xid, struct cifs_tcon *tcon, const char *fileName,
798 799 800 801 802 803 804 805 806 807
		 __u16 type, const struct nls_table *nls_codepage, int remap)
{
	TRANSACTION2_SPI_REQ *pSMB = NULL;
	TRANSACTION2_SPI_RSP *pSMBr = NULL;
	struct unlink_psx_rq *pRqD;
	int name_len;
	int rc = 0;
	int bytes_returned = 0;
	__u16 params, param_offset, offset, byte_count;

808
	cFYI(1, "In POSIX delete");
809 810 811 812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854
PsxDelete:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		name_len =
		    cifsConvertToUCS((__le16 *) pSMB->FileName, fileName,
				     PATH_MAX, nls_codepage, remap);
		name_len++;	/* trailing null */
		name_len *= 2;
	} else { /* BB add path length overrun check */
		name_len = strnlen(fileName, PATH_MAX);
		name_len++;	/* trailing null */
		strncpy(pSMB->FileName, fileName, name_len);
	}

	params = 6 + name_len;
	pSMB->MaxParameterCount = cpu_to_le16(2);
	pSMB->MaxDataCount = 0; /* BB double check this with jra */
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	param_offset = offsetof(struct smb_com_transaction2_spi_req,
				InformationLevel) - 4;
	offset = param_offset + params;

	/* Setup pointer to Request Data (inode type) */
	pRqD = (struct unlink_psx_rq *)(((char *)&pSMB->hdr.Protocol) + offset);
	pRqD->type = cpu_to_le16(type);
	pSMB->ParameterOffset = cpu_to_le16(param_offset);
	pSMB->DataOffset = cpu_to_le16(offset);
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_SET_PATH_INFORMATION);
	byte_count = 3 /* pad */  + params + sizeof(struct unlink_psx_rq);

	pSMB->DataCount = cpu_to_le16(sizeof(struct unlink_psx_rq));
	pSMB->TotalDataCount = cpu_to_le16(sizeof(struct unlink_psx_rq));
	pSMB->ParameterCount = cpu_to_le16(params);
	pSMB->TotalParameterCount = pSMB->ParameterCount;
	pSMB->InformationLevel = cpu_to_le16(SMB_POSIX_UNLINK);
	pSMB->Reserved4 = 0;
855
	inc_rfc1001_len(pSMB, byte_count);
856 857 858
	pSMB->ByteCount = cpu_to_le16(byte_count);
	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
S
Steve French 已提交
859
	if (rc)
860
		cFYI(1, "Posix delete returned %d", rc);
861 862 863 864 865 866 867 868 869 870
	cifs_buf_release(pSMB);

	cifs_stats_inc(&tcon->num_deletes);

	if (rc == -EAGAIN)
		goto PsxDelete;

	return rc;
}

L
Linus Torvalds 已提交
871
int
872
CIFSSMBDelFile(const int xid, struct cifs_tcon *tcon, const char *fileName,
873
	       const struct nls_table *nls_codepage, int remap)
L
Linus Torvalds 已提交
874 875 876 877 878 879 880 881 882 883 884 885 886 887 888
{
	DELETE_FILE_REQ *pSMB = NULL;
	DELETE_FILE_RSP *pSMBr = NULL;
	int rc = 0;
	int bytes_returned;
	int name_len;

DelFileRetry:
	rc = smb_init(SMB_COM_DELETE, 1, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		name_len =
889
		    cifsConvertToUCS((__le16 *) pSMB->fileName, fileName,
890
				     PATH_MAX, nls_codepage, remap);
L
Linus Torvalds 已提交
891 892
		name_len++;	/* trailing null */
		name_len *= 2;
893
	} else {		/* BB improve check for buffer overruns BB */
L
Linus Torvalds 已提交
894 895 896 897 898 899 900
		name_len = strnlen(fileName, PATH_MAX);
		name_len++;	/* trailing null */
		strncpy(pSMB->fileName, fileName, name_len);
	}
	pSMB->SearchAttributes =
	    cpu_to_le16(ATTR_READONLY | ATTR_HIDDEN | ATTR_SYSTEM);
	pSMB->BufferFormat = 0x04;
901
	inc_rfc1001_len(pSMB, name_len + 1);
L
Linus Torvalds 已提交
902 903 904
	pSMB->ByteCount = cpu_to_le16(name_len + 1);
	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
905
	cifs_stats_inc(&tcon->num_deletes);
S
Steve French 已提交
906
	if (rc)
907
		cFYI(1, "Error in RMFile = %d", rc);
L
Linus Torvalds 已提交
908 909 910 911 912 913 914 915 916

	cifs_buf_release(pSMB);
	if (rc == -EAGAIN)
		goto DelFileRetry;

	return rc;
}

int
917
CIFSSMBRmDir(const int xid, struct cifs_tcon *tcon, const char *dirName,
918
	     const struct nls_table *nls_codepage, int remap)
L
Linus Torvalds 已提交
919 920 921 922 923 924 925
{
	DELETE_DIRECTORY_REQ *pSMB = NULL;
	DELETE_DIRECTORY_RSP *pSMBr = NULL;
	int rc = 0;
	int bytes_returned;
	int name_len;

926
	cFYI(1, "In CIFSSMBRmDir");
L
Linus Torvalds 已提交
927 928 929 930 931 932 933
RmDirRetry:
	rc = smb_init(SMB_COM_DELETE_DIRECTORY, 0, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
934 935
		name_len = cifsConvertToUCS((__le16 *) pSMB->DirName, dirName,
					 PATH_MAX, nls_codepage, remap);
L
Linus Torvalds 已提交
936 937
		name_len++;	/* trailing null */
		name_len *= 2;
938
	} else {		/* BB improve check for buffer overruns BB */
L
Linus Torvalds 已提交
939 940 941 942 943 944
		name_len = strnlen(dirName, PATH_MAX);
		name_len++;	/* trailing null */
		strncpy(pSMB->DirName, dirName, name_len);
	}

	pSMB->BufferFormat = 0x04;
945
	inc_rfc1001_len(pSMB, name_len + 1);
L
Linus Torvalds 已提交
946 947 948
	pSMB->ByteCount = cpu_to_le16(name_len + 1);
	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
949
	cifs_stats_inc(&tcon->num_rmdirs);
S
Steve French 已提交
950
	if (rc)
951
		cFYI(1, "Error in RMDir = %d", rc);
L
Linus Torvalds 已提交
952 953 954 955 956 957 958 959

	cifs_buf_release(pSMB);
	if (rc == -EAGAIN)
		goto RmDirRetry;
	return rc;
}

int
960
CIFSSMBMkDir(const int xid, struct cifs_tcon *tcon,
961
	     const char *name, const struct nls_table *nls_codepage, int remap)
L
Linus Torvalds 已提交
962 963 964 965 966 967 968
{
	int rc = 0;
	CREATE_DIRECTORY_REQ *pSMB = NULL;
	CREATE_DIRECTORY_RSP *pSMBr = NULL;
	int bytes_returned;
	int name_len;

969
	cFYI(1, "In CIFSSMBMkDir");
L
Linus Torvalds 已提交
970 971 972 973 974 975 976
MkDirRetry:
	rc = smb_init(SMB_COM_CREATE_DIRECTORY, 0, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
977
		name_len = cifsConvertToUCS((__le16 *) pSMB->DirName, name,
978
					    PATH_MAX, nls_codepage, remap);
L
Linus Torvalds 已提交
979 980
		name_len++;	/* trailing null */
		name_len *= 2;
981
	} else {		/* BB improve check for buffer overruns BB */
L
Linus Torvalds 已提交
982 983 984 985 986 987
		name_len = strnlen(name, PATH_MAX);
		name_len++;	/* trailing null */
		strncpy(pSMB->DirName, name, name_len);
	}

	pSMB->BufferFormat = 0x04;
988
	inc_rfc1001_len(pSMB, name_len + 1);
L
Linus Torvalds 已提交
989 990 991
	pSMB->ByteCount = cpu_to_le16(name_len + 1);
	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
992
	cifs_stats_inc(&tcon->num_mkdirs);
S
Steve French 已提交
993
	if (rc)
994
		cFYI(1, "Error in Mkdir = %d", rc);
995

L
Linus Torvalds 已提交
996 997 998 999 1000 1001
	cifs_buf_release(pSMB);
	if (rc == -EAGAIN)
		goto MkDirRetry;
	return rc;
}

1002
int
1003
CIFSPOSIXCreate(const int xid, struct cifs_tcon *tcon, __u32 posix_flags,
S
Steve French 已提交
1004
		__u64 mode, __u16 *netfid, FILE_UNIX_BASIC_INFO *pRetData,
1005
		__u32 *pOplock, const char *name,
1006 1007 1008 1009 1010 1011 1012 1013
		const struct nls_table *nls_codepage, int remap)
{
	TRANSACTION2_SPI_REQ *pSMB = NULL;
	TRANSACTION2_SPI_RSP *pSMBr = NULL;
	int name_len;
	int rc = 0;
	int bytes_returned = 0;
	__u16 params, param_offset, offset, byte_count, count;
S
Steve French 已提交
1014 1015
	OPEN_PSX_REQ *pdata;
	OPEN_PSX_RSP *psx_rsp;
1016

1017
	cFYI(1, "In POSIX Create");
1018 1019 1020 1021 1022 1023 1024 1025 1026 1027 1028 1029 1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045
PsxCreat:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		name_len =
		    cifsConvertToUCS((__le16 *) pSMB->FileName, name,
				     PATH_MAX, nls_codepage, remap);
		name_len++;	/* trailing null */
		name_len *= 2;
	} else {	/* BB improve the check for buffer overruns BB */
		name_len = strnlen(name, PATH_MAX);
		name_len++;	/* trailing null */
		strncpy(pSMB->FileName, name, name_len);
	}

	params = 6 + name_len;
	count = sizeof(OPEN_PSX_REQ);
	pSMB->MaxParameterCount = cpu_to_le16(2);
	pSMB->MaxDataCount = cpu_to_le16(1000);	/* large enough */
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	param_offset = offsetof(struct smb_com_transaction2_spi_req,
1046
				InformationLevel) - 4;
1047 1048
	offset = param_offset + params;
	pdata = (OPEN_PSX_REQ *)(((char *)&pSMB->hdr.Protocol) + offset);
1049
	pdata->Level = cpu_to_le16(SMB_QUERY_FILE_UNIX_BASIC);
1050
	pdata->Permissions = cpu_to_le64(mode);
1051
	pdata->PosixOpenFlags = cpu_to_le32(posix_flags);
1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065
	pdata->OpenFlags =  cpu_to_le32(*pOplock);
	pSMB->ParameterOffset = cpu_to_le16(param_offset);
	pSMB->DataOffset = cpu_to_le16(offset);
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_SET_PATH_INFORMATION);
	byte_count = 3 /* pad */  + params + count;

	pSMB->DataCount = cpu_to_le16(count);
	pSMB->ParameterCount = cpu_to_le16(params);
	pSMB->TotalDataCount = pSMB->DataCount;
	pSMB->TotalParameterCount = pSMB->ParameterCount;
	pSMB->InformationLevel = cpu_to_le16(SMB_POSIX_OPEN);
	pSMB->Reserved4 = 0;
1066
	inc_rfc1001_len(pSMB, byte_count);
1067 1068 1069 1070
	pSMB->ByteCount = cpu_to_le16(byte_count);
	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
	if (rc) {
1071
		cFYI(1, "Posix create returned %d", rc);
1072 1073 1074
		goto psx_create_err;
	}

1075
	cFYI(1, "copying inode info");
1076 1077
	rc = validate_t2((struct smb_t2_rsp *)pSMBr);

1078
	if (rc || get_bcc(&pSMBr->hdr) < sizeof(OPEN_PSX_RSP)) {
1079 1080 1081 1082 1083
		rc = -EIO;	/* bad smb */
		goto psx_create_err;
	}

	/* copy return information to pRetData */
1084
	psx_rsp = (OPEN_PSX_RSP *)((char *) &pSMBr->hdr.Protocol
1085
			+ le16_to_cpu(pSMBr->t2.DataOffset));
1086

1087
	*pOplock = le16_to_cpu(psx_rsp->OplockFlags);
S
Steve French 已提交
1088
	if (netfid)
1089 1090 1091
		*netfid = psx_rsp->Fid;   /* cifs fid stays in le */
	/* Let caller know file was created so we can set the mode. */
	/* Do we care about the CreateAction in any other cases? */
S
Steve French 已提交
1092
	if (cpu_to_le32(FILE_CREATE) == psx_rsp->CreateAction)
1093 1094
		*pOplock |= CIFS_CREATE_ACTION;
	/* check to make sure response data is there */
1095 1096
	if (psx_rsp->ReturnedLevel != cpu_to_le16(SMB_QUERY_FILE_UNIX_BASIC)) {
		pRetData->Type = cpu_to_le32(-1); /* unknown */
1097
		cFYI(DBG2, "unknown type");
1098
	} else {
1099
		if (get_bcc(&pSMBr->hdr) < sizeof(OPEN_PSX_RSP)
1100
					+ sizeof(FILE_UNIX_BASIC_INFO)) {
1101
			cERROR(1, "Open response data too small");
1102
			pRetData->Type = cpu_to_le32(-1);
1103 1104
			goto psx_create_err;
		}
1105
		memcpy((char *) pRetData,
1106
			(char *)psx_rsp + sizeof(OPEN_PSX_RSP),
1107
			sizeof(FILE_UNIX_BASIC_INFO));
1108 1109 1110 1111 1112
	}

psx_create_err:
	cifs_buf_release(pSMB);

1113 1114 1115 1116
	if (posix_flags & SMB_O_DIRECTORY)
		cifs_stats_inc(&tcon->num_posixmkdirs);
	else
		cifs_stats_inc(&tcon->num_posixopens);
1117 1118 1119 1120

	if (rc == -EAGAIN)
		goto PsxCreat;

1121
	return rc;
1122 1123
}

1124 1125 1126 1127 1128 1129 1130 1131 1132 1133 1134 1135 1136 1137 1138 1139 1140 1141 1142 1143 1144 1145 1146 1147
static __u16 convert_disposition(int disposition)
{
	__u16 ofun = 0;

	switch (disposition) {
		case FILE_SUPERSEDE:
			ofun = SMBOPEN_OCREATE | SMBOPEN_OTRUNC;
			break;
		case FILE_OPEN:
			ofun = SMBOPEN_OAPPEND;
			break;
		case FILE_CREATE:
			ofun = SMBOPEN_OCREATE;
			break;
		case FILE_OPEN_IF:
			ofun = SMBOPEN_OCREATE | SMBOPEN_OAPPEND;
			break;
		case FILE_OVERWRITE:
			ofun = SMBOPEN_OTRUNC;
			break;
		case FILE_OVERWRITE_IF:
			ofun = SMBOPEN_OCREATE | SMBOPEN_OTRUNC;
			break;
		default:
1148
			cFYI(1, "unknown disposition %d", disposition);
1149 1150 1151 1152 1153
			ofun =  SMBOPEN_OAPPEND; /* regular open */
	}
	return ofun;
}

1154 1155 1156 1157 1158 1159 1160 1161 1162 1163 1164 1165 1166 1167
static int
access_flags_to_smbopen_mode(const int access_flags)
{
	int masked_flags = access_flags & (GENERIC_READ | GENERIC_WRITE);

	if (masked_flags == GENERIC_READ)
		return SMBOPEN_READ;
	else if (masked_flags == GENERIC_WRITE)
		return SMBOPEN_WRITE;

	/* just go for read/write */
	return SMBOPEN_READWRITE;
}

1168
int
1169
SMBLegacyOpen(const int xid, struct cifs_tcon *tcon,
1170
	    const char *fileName, const int openDisposition,
S
Steve French 已提交
1171 1172
	    const int access_flags, const int create_options, __u16 *netfid,
	    int *pOplock, FILE_ALL_INFO *pfile_info,
1173 1174 1175 1176 1177 1178 1179 1180 1181 1182 1183 1184 1185 1186 1187 1188 1189 1190 1191 1192 1193 1194 1195 1196 1197 1198 1199 1200 1201 1202 1203 1204
	    const struct nls_table *nls_codepage, int remap)
{
	int rc = -EACCES;
	OPENX_REQ *pSMB = NULL;
	OPENX_RSP *pSMBr = NULL;
	int bytes_returned;
	int name_len;
	__u16 count;

OldOpenRetry:
	rc = smb_init(SMB_COM_OPEN_ANDX, 15, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	pSMB->AndXCommand = 0xFF;       /* none */

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		count = 1;      /* account for one byte pad to word boundary */
		name_len =
		   cifsConvertToUCS((__le16 *) (pSMB->fileName + 1),
				    fileName, PATH_MAX, nls_codepage, remap);
		name_len++;     /* trailing null */
		name_len *= 2;
	} else {                /* BB improve check for buffer overruns BB */
		count = 0;      /* no pad */
		name_len = strnlen(fileName, PATH_MAX);
		name_len++;     /* trailing null */
		strncpy(pSMB->fileName, fileName, name_len);
	}
	if (*pOplock & REQ_OPLOCK)
		pSMB->OpenFlags = cpu_to_le16(REQ_OPLOCK);
1205
	else if (*pOplock & REQ_BATCHOPLOCK)
1206
		pSMB->OpenFlags = cpu_to_le16(REQ_BATCHOPLOCK);
1207

1208
	pSMB->OpenFlags |= cpu_to_le16(REQ_MORE_INFO);
1209
	pSMB->Mode = cpu_to_le16(access_flags_to_smbopen_mode(access_flags));
1210 1211 1212 1213 1214
	pSMB->Mode |= cpu_to_le16(0x40); /* deny none */
	/* set file as system file if special file such
	   as fifo and server expecting SFU style and
	   no Unix extensions */

S
Steve French 已提交
1215 1216
	if (create_options & CREATE_OPTION_SPECIAL)
		pSMB->FileAttributes = cpu_to_le16(ATTR_SYSTEM);
S
Steve French 已提交
1217 1218
	else /* BB FIXME BB */
		pSMB->FileAttributes = cpu_to_le16(0/*ATTR_NORMAL*/);
1219

1220 1221
	if (create_options & CREATE_OPTION_READONLY)
		pSMB->FileAttributes |= cpu_to_le16(ATTR_READONLY);
1222 1223

	/* BB FIXME BB */
1224 1225
/*	pSMB->CreateOptions = cpu_to_le32(create_options &
						 CREATE_OPTIONS_MASK); */
1226
	/* BB FIXME END BB */
1227 1228

	pSMB->Sattr = cpu_to_le16(ATTR_HIDDEN | ATTR_SYSTEM | ATTR_DIRECTORY);
1229
	pSMB->OpenFunction = cpu_to_le16(convert_disposition(openDisposition));
1230
	count += name_len;
1231
	inc_rfc1001_len(pSMB, count);
1232 1233 1234 1235

	pSMB->ByteCount = cpu_to_le16(count);
	/* long_op set to 1 to allow for oplock break timeouts */
	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
1236
			(struct smb_hdr *)pSMBr, &bytes_returned, 0);
1237 1238
	cifs_stats_inc(&tcon->num_opens);
	if (rc) {
1239
		cFYI(1, "Error in Open = %d", rc);
1240 1241 1242
	} else {
	/* BB verify if wct == 15 */

1243
/*		*pOplock = pSMBr->OplockLevel; */ /* BB take from action field*/
1244 1245 1246 1247 1248

		*netfid = pSMBr->Fid;   /* cifs fid stays in le */
		/* Let caller know file was created so we can set the mode. */
		/* Do we care about the CreateAction in any other cases? */
	/* BB FIXME BB */
S
Steve French 已提交
1249
/*		if (cpu_to_le32(FILE_CREATE) == pSMBr->CreateAction)
1250 1251 1252
			*pOplock |= CIFS_CREATE_ACTION; */
	/* BB FIXME END */

S
Steve French 已提交
1253
		if (pfile_info) {
1254 1255 1256 1257
			pfile_info->CreationTime = 0; /* BB convert CreateTime*/
			pfile_info->LastAccessTime = 0; /* BB fixme */
			pfile_info->LastWriteTime = 0; /* BB fixme */
			pfile_info->ChangeTime = 0;  /* BB fixme */
1258
			pfile_info->Attributes =
1259
				cpu_to_le32(le16_to_cpu(pSMBr->FileAttributes));
1260
			/* the file_info buf is endian converted by caller */
1261 1262 1263
			pfile_info->AllocationSize =
				cpu_to_le64(le32_to_cpu(pSMBr->EndOfFile));
			pfile_info->EndOfFile = pfile_info->AllocationSize;
1264
			pfile_info->NumberOfLinks = cpu_to_le32(1);
1265
			pfile_info->DeletePending = 0;
1266 1267 1268 1269 1270 1271 1272 1273 1274
		}
	}

	cifs_buf_release(pSMB);
	if (rc == -EAGAIN)
		goto OldOpenRetry;
	return rc;
}

L
Linus Torvalds 已提交
1275
int
1276
CIFSSMBOpen(const int xid, struct cifs_tcon *tcon,
L
Linus Torvalds 已提交
1277
	    const char *fileName, const int openDisposition,
S
Steve French 已提交
1278 1279
	    const int access_flags, const int create_options, __u16 *netfid,
	    int *pOplock, FILE_ALL_INFO *pfile_info,
1280
	    const struct nls_table *nls_codepage, int remap)
L
Linus Torvalds 已提交
1281 1282 1283 1284 1285 1286 1287 1288 1289 1290 1291 1292 1293 1294 1295 1296 1297 1298 1299
{
	int rc = -EACCES;
	OPEN_REQ *pSMB = NULL;
	OPEN_RSP *pSMBr = NULL;
	int bytes_returned;
	int name_len;
	__u16 count;

openRetry:
	rc = smb_init(SMB_COM_NT_CREATE_ANDX, 24, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	pSMB->AndXCommand = 0xFF;	/* none */

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		count = 1;	/* account for one byte pad to word boundary */
		name_len =
1300
		    cifsConvertToUCS((__le16 *) (pSMB->fileName + 1),
1301
				     fileName, PATH_MAX, nls_codepage, remap);
L
Linus Torvalds 已提交
1302 1303 1304
		name_len++;	/* trailing null */
		name_len *= 2;
		pSMB->NameLength = cpu_to_le16(name_len);
1305
	} else {		/* BB improve check for buffer overruns BB */
L
Linus Torvalds 已提交
1306 1307 1308 1309 1310 1311 1312 1313
		count = 0;	/* no pad */
		name_len = strnlen(fileName, PATH_MAX);
		name_len++;	/* trailing null */
		pSMB->NameLength = cpu_to_le16(name_len);
		strncpy(pSMB->fileName, fileName, name_len);
	}
	if (*pOplock & REQ_OPLOCK)
		pSMB->OpenFlags = cpu_to_le32(REQ_OPLOCK);
1314
	else if (*pOplock & REQ_BATCHOPLOCK)
L
Linus Torvalds 已提交
1315 1316 1317
		pSMB->OpenFlags = cpu_to_le32(REQ_BATCHOPLOCK);
	pSMB->DesiredAccess = cpu_to_le32(access_flags);
	pSMB->AllocationSize = 0;
1318 1319 1320
	/* set file as system file if special file such
	   as fifo and server expecting SFU style and
	   no Unix extensions */
S
Steve French 已提交
1321
	if (create_options & CREATE_OPTION_SPECIAL)
1322 1323 1324
		pSMB->FileAttributes = cpu_to_le32(ATTR_SYSTEM);
	else
		pSMB->FileAttributes = cpu_to_le32(ATTR_NORMAL);
1325

L
Linus Torvalds 已提交
1326 1327 1328 1329 1330 1331
	/* XP does not handle ATTR_POSIX_SEMANTICS */
	/* but it helps speed up case sensitive checks for other
	servers such as Samba */
	if (tcon->ses->capabilities & CAP_UNIX)
		pSMB->FileAttributes |= cpu_to_le32(ATTR_POSIX_SEMANTICS);

1332 1333 1334
	if (create_options & CREATE_OPTION_READONLY)
		pSMB->FileAttributes |= cpu_to_le32(ATTR_READONLY);

L
Linus Torvalds 已提交
1335 1336
	pSMB->ShareAccess = cpu_to_le32(FILE_SHARE_ALL);
	pSMB->CreateDisposition = cpu_to_le32(openDisposition);
1337
	pSMB->CreateOptions = cpu_to_le32(create_options & CREATE_OPTIONS_MASK);
1338 1339
	/* BB Expirement with various impersonation levels and verify */
	pSMB->ImpersonationLevel = cpu_to_le32(SECURITY_IMPERSONATION);
L
Linus Torvalds 已提交
1340 1341 1342 1343
	pSMB->SecurityFlags =
	    SECURITY_CONTEXT_TRACKING | SECURITY_EFFECTIVE_ONLY;

	count += name_len;
1344
	inc_rfc1001_len(pSMB, count);
L
Linus Torvalds 已提交
1345 1346 1347 1348

	pSMB->ByteCount = cpu_to_le16(count);
	/* long_op set to 1 to allow for oplock break timeouts */
	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
1349
			(struct smb_hdr *)pSMBr, &bytes_returned, 0);
1350
	cifs_stats_inc(&tcon->num_opens);
L
Linus Torvalds 已提交
1351
	if (rc) {
1352
		cFYI(1, "Error in Open = %d", rc);
L
Linus Torvalds 已提交
1353
	} else {
1354
		*pOplock = pSMBr->OplockLevel; /* 1 byte no need to le_to_cpu */
L
Linus Torvalds 已提交
1355 1356 1357
		*netfid = pSMBr->Fid;	/* cifs fid stays in le */
		/* Let caller know file was created so we can set the mode. */
		/* Do we care about the CreateAction in any other cases? */
S
Steve French 已提交
1358
		if (cpu_to_le32(FILE_CREATE) == pSMBr->CreateAction)
1359
			*pOplock |= CIFS_CREATE_ACTION;
S
Steve French 已提交
1360
		if (pfile_info) {
1361 1362 1363 1364 1365 1366 1367
			memcpy((char *)pfile_info, (char *)&pSMBr->CreationTime,
				36 /* CreationTime to Attributes */);
			/* the file_info buf is endian converted by caller */
			pfile_info->AllocationSize = pSMBr->AllocationSize;
			pfile_info->EndOfFile = pSMBr->EndOfFile;
			pfile_info->NumberOfLinks = cpu_to_le32(1);
			pfile_info->DeletePending = 0;
L
Linus Torvalds 已提交
1368 1369
		}
	}
1370

L
Linus Torvalds 已提交
1371 1372 1373 1374 1375 1376 1377
	cifs_buf_release(pSMB);
	if (rc == -EAGAIN)
		goto openRetry;
	return rc;
}

int
1378
CIFSSMBRead(const int xid, struct cifs_io_parms *io_parms, unsigned int *nbytes,
1379
	    char **buf, int *pbuf_type)
L
Linus Torvalds 已提交
1380 1381 1382 1383 1384
{
	int rc = -EACCES;
	READ_REQ *pSMB = NULL;
	READ_RSP *pSMBr = NULL;
	char *pReadData = NULL;
1385
	int wct;
1386 1387
	int resp_buf_type = 0;
	struct kvec iov[1];
1388 1389 1390
	__u32 pid = io_parms->pid;
	__u16 netfid = io_parms->netfid;
	__u64 offset = io_parms->offset;
1391
	struct cifs_tcon *tcon = io_parms->tcon;
1392
	unsigned int count = io_parms->length;
L
Linus Torvalds 已提交
1393

1394
	cFYI(1, "Reading %d bytes on fid %d", count, netfid);
S
Steve French 已提交
1395
	if (tcon->ses->capabilities & CAP_LARGE_FILES)
1396
		wct = 12;
1397
	else {
1398
		wct = 10; /* old style read */
1399
		if ((offset >> 32) > 0)  {
1400 1401 1402 1403
			/* can not handle this big offset for old */
			return -EIO;
		}
	}
L
Linus Torvalds 已提交
1404 1405

	*nbytes = 0;
1406
	rc = small_smb_init(SMB_COM_READ_ANDX, wct, tcon, (void **) &pSMB);
L
Linus Torvalds 已提交
1407 1408 1409
	if (rc)
		return rc;

1410 1411 1412
	pSMB->hdr.Pid = cpu_to_le16((__u16)pid);
	pSMB->hdr.PidHigh = cpu_to_le16((__u16)(pid >> 16));

L
Linus Torvalds 已提交
1413 1414 1415 1416
	/* tcon and ses pointer are checked in smb_init */
	if (tcon->ses->server == NULL)
		return -ECONNABORTED;

1417
	pSMB->AndXCommand = 0xFF;       /* none */
L
Linus Torvalds 已提交
1418
	pSMB->Fid = netfid;
1419
	pSMB->OffsetLow = cpu_to_le32(offset & 0xFFFFFFFF);
S
Steve French 已提交
1420
	if (wct == 12)
1421
		pSMB->OffsetHigh = cpu_to_le32(offset >> 32);
1422

L
Linus Torvalds 已提交
1423 1424 1425
	pSMB->Remaining = 0;
	pSMB->MaxCount = cpu_to_le16(count & 0xFFFF);
	pSMB->MaxCountHigh = cpu_to_le32(count >> 16);
S
Steve French 已提交
1426
	if (wct == 12)
1427 1428 1429
		pSMB->ByteCount = 0;  /* no need to do le conversion since 0 */
	else {
		/* old style read */
1430
		struct smb_com_readx_req *pSMBW =
1431
			(struct smb_com_readx_req *)pSMB;
1432
		pSMBW->ByteCount = 0;
1433
	}
1434 1435

	iov[0].iov_base = (char *)pSMB;
1436
	iov[0].iov_len = be32_to_cpu(pSMB->hdr.smb_buf_length) + 4;
1437
	rc = SendReceive2(xid, tcon->ses, iov, 1 /* num iovecs */,
1438
			 &resp_buf_type, CIFS_LOG_ERROR);
1439
	cifs_stats_inc(&tcon->num_reads);
1440
	pSMBr = (READ_RSP *)iov[0].iov_base;
L
Linus Torvalds 已提交
1441
	if (rc) {
1442
		cERROR(1, "Send error in read = %d", rc);
L
Linus Torvalds 已提交
1443 1444 1445 1446 1447 1448 1449
	} else {
		int data_length = le16_to_cpu(pSMBr->DataLengthHigh);
		data_length = data_length << 16;
		data_length += le16_to_cpu(pSMBr->DataLength);
		*nbytes = data_length;

		/*check that DataLength would not go beyond end of SMB */
1450
		if ((data_length > CIFSMaxBufSize)
L
Linus Torvalds 已提交
1451
				|| (data_length > count)) {
1452 1453
			cFYI(1, "bad length %d for count %d",
				 data_length, count);
L
Linus Torvalds 已提交
1454 1455 1456
			rc = -EIO;
			*nbytes = 0;
		} else {
1457
			pReadData = (char *) (&pSMBr->hdr.Protocol) +
1458 1459
					le16_to_cpu(pSMBr->DataOffset);
/*			if (rc = copy_to_user(buf, pReadData, data_length)) {
1460
				cERROR(1, "Faulting on read rc = %d",rc);
1461
				rc = -EFAULT;
1462
			}*/ /* can not use copy_to_user when using page cache*/
S
Steve French 已提交
1463
			if (*buf)
1464
				memcpy(*buf, pReadData, data_length);
L
Linus Torvalds 已提交
1465 1466 1467
		}
	}

1468
/*	cifs_small_buf_release(pSMB); */ /* Freed earlier now in SendReceive2 */
S
Steve French 已提交
1469 1470
	if (*buf) {
		if (resp_buf_type == CIFS_SMALL_BUFFER)
1471
			cifs_small_buf_release(iov[0].iov_base);
S
Steve French 已提交
1472
		else if (resp_buf_type == CIFS_LARGE_BUFFER)
1473
			cifs_buf_release(iov[0].iov_base);
S
Steve French 已提交
1474
	} else if (resp_buf_type != CIFS_NO_BUFFER) {
1475 1476
		/* return buffer to caller to free */
		*buf = iov[0].iov_base;
S
Steve French 已提交
1477
		if (resp_buf_type == CIFS_SMALL_BUFFER)
1478
			*pbuf_type = CIFS_SMALL_BUFFER;
S
Steve French 已提交
1479
		else if (resp_buf_type == CIFS_LARGE_BUFFER)
1480
			*pbuf_type = CIFS_LARGE_BUFFER;
1481
	} /* else no valid buffer on return - leave as null */
1482 1483

	/* Note: On -EAGAIN error only caller can retry on handle based calls
L
Linus Torvalds 已提交
1484 1485 1486 1487
		since file handle passed in no longer valid */
	return rc;
}

1488

L
Linus Torvalds 已提交
1489
int
1490 1491
CIFSSMBWrite(const int xid, struct cifs_io_parms *io_parms,
	     unsigned int *nbytes, const char *buf,
1492
	     const char __user *ubuf, const int long_op)
L
Linus Torvalds 已提交
1493 1494 1495 1496
{
	int rc = -EACCES;
	WRITE_REQ *pSMB = NULL;
	WRITE_RSP *pSMBr = NULL;
1497
	int bytes_returned, wct;
L
Linus Torvalds 已提交
1498 1499
	__u32 bytes_sent;
	__u16 byte_count;
1500 1501 1502
	__u32 pid = io_parms->pid;
	__u16 netfid = io_parms->netfid;
	__u64 offset = io_parms->offset;
1503
	struct cifs_tcon *tcon = io_parms->tcon;
1504
	unsigned int count = io_parms->length;
L
Linus Torvalds 已提交
1505

1506 1507
	*nbytes = 0;

1508
	/* cFYI(1, "write at %lld %d bytes", offset, count);*/
S
Steve French 已提交
1509
	if (tcon->ses == NULL)
1510 1511
		return -ECONNABORTED;

S
Steve French 已提交
1512
	if (tcon->ses->capabilities & CAP_LARGE_FILES)
1513
		wct = 14;
1514
	else {
1515
		wct = 12;
1516 1517 1518 1519 1520
		if ((offset >> 32) > 0) {
			/* can not handle big offset for old srv */
			return -EIO;
		}
	}
1521 1522

	rc = smb_init(SMB_COM_WRITE_ANDX, wct, tcon, (void **) &pSMB,
L
Linus Torvalds 已提交
1523 1524 1525
		      (void **) &pSMBr);
	if (rc)
		return rc;
1526 1527 1528 1529

	pSMB->hdr.Pid = cpu_to_le16((__u16)pid);
	pSMB->hdr.PidHigh = cpu_to_le16((__u16)(pid >> 16));

L
Linus Torvalds 已提交
1530 1531 1532 1533 1534 1535 1536
	/* tcon and ses pointer are checked in smb_init */
	if (tcon->ses->server == NULL)
		return -ECONNABORTED;

	pSMB->AndXCommand = 0xFF;	/* none */
	pSMB->Fid = netfid;
	pSMB->OffsetLow = cpu_to_le32(offset & 0xFFFFFFFF);
S
Steve French 已提交
1537
	if (wct == 14)
1538
		pSMB->OffsetHigh = cpu_to_le32(offset >> 32);
1539

L
Linus Torvalds 已提交
1540 1541 1542 1543
	pSMB->Reserved = 0xFFFFFFFF;
	pSMB->WriteMode = 0;
	pSMB->Remaining = 0;

1544
	/* Can increase buffer size if buffer is big enough in some cases ie we
L
Linus Torvalds 已提交
1545 1546 1547
	can send more if LARGE_WRITE_X capability returned by the server and if
	our buffer is big enough or if we convert to iovecs on socket writes
	and eliminate the copy to the CIFS buffer */
S
Steve French 已提交
1548
	if (tcon->ses->capabilities & CAP_LARGE_WRITE_X) {
L
Linus Torvalds 已提交
1549 1550 1551 1552 1553 1554 1555 1556 1557
		bytes_sent = min_t(const unsigned int, CIFSMaxBufSize, count);
	} else {
		bytes_sent = (tcon->ses->server->maxBuf - MAX_CIFS_HDR_SIZE)
			 & ~0xFF;
	}

	if (bytes_sent > count)
		bytes_sent = count;
	pSMB->DataOffset =
1558
		cpu_to_le16(offsetof(struct smb_com_write_req, Data) - 4);
S
Steve French 已提交
1559
	if (buf)
1560
		memcpy(pSMB->Data, buf, bytes_sent);
S
Steve French 已提交
1561 1562
	else if (ubuf) {
		if (copy_from_user(pSMB->Data, ubuf, bytes_sent)) {
L
Linus Torvalds 已提交
1563 1564 1565
			cifs_buf_release(pSMB);
			return -EFAULT;
		}
1566
	} else if (count != 0) {
L
Linus Torvalds 已提交
1567 1568 1569
		/* No buffer */
		cifs_buf_release(pSMB);
		return -EINVAL;
1570
	} /* else setting file size with write of zero bytes */
S
Steve French 已提交
1571
	if (wct == 14)
1572
		byte_count = bytes_sent + 1; /* pad */
S
Steve French 已提交
1573
	else /* wct == 12 */
1574
		byte_count = bytes_sent + 5; /* bigger pad, smaller smb hdr */
S
Steve French 已提交
1575

L
Linus Torvalds 已提交
1576 1577
	pSMB->DataLengthLow = cpu_to_le16(bytes_sent & 0xFFFF);
	pSMB->DataLengthHigh = cpu_to_le16(bytes_sent >> 16);
1578
	inc_rfc1001_len(pSMB, byte_count);
1579

S
Steve French 已提交
1580
	if (wct == 14)
1581
		pSMB->ByteCount = cpu_to_le16(byte_count);
1582 1583 1584
	else { /* old style write has byte count 4 bytes earlier
		  so 4 bytes pad  */
		struct smb_com_writex_req *pSMBW =
1585 1586 1587
			(struct smb_com_writex_req *)pSMB;
		pSMBW->ByteCount = cpu_to_le16(byte_count);
	}
L
Linus Torvalds 已提交
1588 1589 1590

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, long_op);
1591
	cifs_stats_inc(&tcon->num_writes);
L
Linus Torvalds 已提交
1592
	if (rc) {
1593
		cFYI(1, "Send error in write = %d", rc);
L
Linus Torvalds 已提交
1594 1595 1596 1597
	} else {
		*nbytes = le16_to_cpu(pSMBr->CountHigh);
		*nbytes = (*nbytes) << 16;
		*nbytes += le16_to_cpu(pSMBr->Count);
1598 1599 1600 1601 1602 1603 1604 1605

		/*
		 * Mask off high 16 bits when bytes written as returned by the
		 * server is greater than bytes requested by the client. Some
		 * OS/2 servers are known to set incorrect CountHigh values.
		 */
		if (*nbytes > count)
			*nbytes &= 0xFFFF;
L
Linus Torvalds 已提交
1606 1607 1608 1609
	}

	cifs_buf_release(pSMB);

1610
	/* Note: On -EAGAIN error only caller can retry on handle based calls
L
Linus Torvalds 已提交
1611 1612 1613 1614 1615
		since file handle passed in no longer valid */

	return rc;
}

J
Jeff Layton 已提交
1616 1617 1618 1619 1620 1621 1622 1623 1624 1625 1626 1627 1628 1629 1630 1631 1632 1633 1634 1635 1636 1637 1638 1639 1640 1641 1642 1643 1644 1645 1646 1647 1648 1649 1650 1651 1652 1653 1654 1655 1656 1657 1658 1659 1660 1661 1662 1663 1664 1665 1666 1667 1668 1669 1670 1671 1672 1673 1674 1675 1676 1677 1678 1679 1680 1681 1682 1683 1684 1685 1686 1687 1688 1689 1690 1691 1692 1693 1694 1695 1696 1697 1698 1699 1700 1701 1702 1703 1704 1705 1706 1707 1708 1709 1710 1711 1712 1713 1714
void
cifs_writedata_release(struct kref *refcount)
{
	struct cifs_writedata *wdata = container_of(refcount,
					struct cifs_writedata, refcount);

	if (wdata->cfile)
		cifsFileInfo_put(wdata->cfile);

	kfree(wdata);
}

/*
 * Write failed with a retryable error. Resend the write request. It's also
 * possible that the page was redirtied so re-clean the page.
 */
static void
cifs_writev_requeue(struct cifs_writedata *wdata)
{
	int i, rc;
	struct inode *inode = wdata->cfile->dentry->d_inode;

	for (i = 0; i < wdata->nr_pages; i++) {
		lock_page(wdata->pages[i]);
		clear_page_dirty_for_io(wdata->pages[i]);
	}

	do {
		rc = cifs_async_writev(wdata);
	} while (rc == -EAGAIN);

	for (i = 0; i < wdata->nr_pages; i++) {
		if (rc != 0)
			SetPageError(wdata->pages[i]);
		unlock_page(wdata->pages[i]);
	}

	mapping_set_error(inode->i_mapping, rc);
	kref_put(&wdata->refcount, cifs_writedata_release);
}

static void
cifs_writev_complete(struct work_struct *work)
{
	struct cifs_writedata *wdata = container_of(work,
						struct cifs_writedata, work);
	struct inode *inode = wdata->cfile->dentry->d_inode;
	int i = 0;

	if (wdata->result == 0) {
		cifs_update_eof(CIFS_I(inode), wdata->offset, wdata->bytes);
		cifs_stats_bytes_written(tlink_tcon(wdata->cfile->tlink),
					 wdata->bytes);
	} else if (wdata->sync_mode == WB_SYNC_ALL && wdata->result == -EAGAIN)
		return cifs_writev_requeue(wdata);

	for (i = 0; i < wdata->nr_pages; i++) {
		struct page *page = wdata->pages[i];
		if (wdata->result == -EAGAIN)
			__set_page_dirty_nobuffers(page);
		else if (wdata->result < 0)
			SetPageError(page);
		end_page_writeback(page);
		page_cache_release(page);
	}
	if (wdata->result != -EAGAIN)
		mapping_set_error(inode->i_mapping, wdata->result);
	kref_put(&wdata->refcount, cifs_writedata_release);
}

struct cifs_writedata *
cifs_writedata_alloc(unsigned int nr_pages)
{
	struct cifs_writedata *wdata;

	/* this would overflow */
	if (nr_pages == 0) {
		cERROR(1, "%s: called with nr_pages == 0!", __func__);
		return NULL;
	}

	/* writedata + number of page pointers */
	wdata = kzalloc(sizeof(*wdata) +
			sizeof(struct page *) * (nr_pages - 1), GFP_NOFS);
	if (wdata != NULL) {
		INIT_WORK(&wdata->work, cifs_writev_complete);
		kref_init(&wdata->refcount);
	}
	return wdata;
}

/*
 * Check the midState and signature on received buffer (if any), and queue the
 * workqueue completion task.
 */
static void
cifs_writev_callback(struct mid_q_entry *mid)
{
	struct cifs_writedata *wdata = mid->callback_data;
1715
	struct cifs_tcon *tcon = tlink_tcon(wdata->cfile->tlink);
J
Jeff Layton 已提交
1716 1717 1718 1719 1720 1721 1722 1723 1724 1725 1726 1727 1728 1729 1730 1731 1732 1733 1734 1735 1736 1737 1738 1739 1740 1741 1742 1743 1744 1745 1746 1747 1748 1749 1750 1751 1752 1753 1754 1755 1756 1757 1758 1759 1760 1761 1762 1763
	unsigned int written;
	WRITE_RSP *smb = (WRITE_RSP *)mid->resp_buf;

	switch (mid->midState) {
	case MID_RESPONSE_RECEIVED:
		wdata->result = cifs_check_receive(mid, tcon->ses->server, 0);
		if (wdata->result != 0)
			break;

		written = le16_to_cpu(smb->CountHigh);
		written <<= 16;
		written += le16_to_cpu(smb->Count);
		/*
		 * Mask off high 16 bits when bytes written as returned
		 * by the server is greater than bytes requested by the
		 * client. OS/2 servers are known to set incorrect
		 * CountHigh values.
		 */
		if (written > wdata->bytes)
			written &= 0xFFFF;

		if (written < wdata->bytes)
			wdata->result = -ENOSPC;
		else
			wdata->bytes = written;
		break;
	case MID_REQUEST_SUBMITTED:
	case MID_RETRY_NEEDED:
		wdata->result = -EAGAIN;
		break;
	default:
		wdata->result = -EIO;
		break;
	}

	queue_work(system_nrt_wq, &wdata->work);
	DeleteMidQEntry(mid);
	atomic_dec(&tcon->ses->server->inFlight);
	wake_up(&tcon->ses->server->request_q);
}

/* cifs_async_writev - send an async write, and set up mid to handle result */
int
cifs_async_writev(struct cifs_writedata *wdata)
{
	int i, rc = -EACCES;
	WRITE_REQ *smb = NULL;
	int wct;
1764
	struct cifs_tcon *tcon = tlink_tcon(wdata->cfile->tlink);
J
Jeff Layton 已提交
1765 1766 1767 1768 1769 1770 1771 1772 1773 1774 1775 1776 1777 1778 1779 1780 1781 1782 1783 1784 1785 1786 1787 1788
	struct inode *inode = wdata->cfile->dentry->d_inode;
	struct kvec *iov = NULL;

	if (tcon->ses->capabilities & CAP_LARGE_FILES) {
		wct = 14;
	} else {
		wct = 12;
		if (wdata->offset >> 32 > 0) {
			/* can not handle big offset for old srv */
			return -EIO;
		}
	}

	rc = small_smb_init(SMB_COM_WRITE_ANDX, wct, tcon, (void **)&smb);
	if (rc)
		goto async_writev_out;

	/* 1 iov per page + 1 for header */
	iov = kzalloc((wdata->nr_pages + 1) * sizeof(*iov), GFP_NOFS);
	if (iov == NULL) {
		rc = -ENOMEM;
		goto async_writev_out;
	}

1789 1790 1791
	smb->hdr.Pid = cpu_to_le16((__u16)wdata->cfile->pid);
	smb->hdr.PidHigh = cpu_to_le16((__u16)(wdata->cfile->pid >> 16));

J
Jeff Layton 已提交
1792 1793 1794 1795 1796 1797 1798 1799 1800 1801 1802 1803 1804 1805 1806 1807 1808 1809 1810 1811 1812 1813 1814 1815 1816 1817 1818 1819 1820 1821 1822 1823 1824 1825 1826 1827 1828 1829 1830 1831 1832 1833 1834 1835 1836 1837 1838 1839 1840 1841 1842 1843 1844 1845 1846 1847 1848 1849 1850 1851 1852 1853
	smb->AndXCommand = 0xFF;	/* none */
	smb->Fid = wdata->cfile->netfid;
	smb->OffsetLow = cpu_to_le32(wdata->offset & 0xFFFFFFFF);
	if (wct == 14)
		smb->OffsetHigh = cpu_to_le32(wdata->offset >> 32);
	smb->Reserved = 0xFFFFFFFF;
	smb->WriteMode = 0;
	smb->Remaining = 0;

	smb->DataOffset =
	    cpu_to_le16(offsetof(struct smb_com_write_req, Data) - 4);

	/* 4 for RFC1001 length + 1 for BCC */
	iov[0].iov_len = be32_to_cpu(smb->hdr.smb_buf_length) + 4 + 1;
	iov[0].iov_base = smb;

	/* marshal up the pages into iov array */
	wdata->bytes = 0;
	for (i = 0; i < wdata->nr_pages; i++) {
		iov[i + 1].iov_len = min(inode->i_size -
				      page_offset(wdata->pages[i]),
					(loff_t)PAGE_CACHE_SIZE);
		iov[i + 1].iov_base = kmap(wdata->pages[i]);
		wdata->bytes += iov[i + 1].iov_len;
	}

	cFYI(1, "async write at %llu %u bytes", wdata->offset, wdata->bytes);

	smb->DataLengthLow = cpu_to_le16(wdata->bytes & 0xFFFF);
	smb->DataLengthHigh = cpu_to_le16(wdata->bytes >> 16);

	if (wct == 14) {
		inc_rfc1001_len(&smb->hdr, wdata->bytes + 1);
		put_bcc(wdata->bytes + 1, &smb->hdr);
	} else {
		/* wct == 12 */
		struct smb_com_writex_req *smbw =
				(struct smb_com_writex_req *)smb;
		inc_rfc1001_len(&smbw->hdr, wdata->bytes + 5);
		put_bcc(wdata->bytes + 5, &smbw->hdr);
		iov[0].iov_len += 4; /* pad bigger by four bytes */
	}

	kref_get(&wdata->refcount);
	rc = cifs_call_async(tcon->ses->server, iov, wdata->nr_pages + 1,
			     cifs_writev_callback, wdata, false);

	if (rc == 0)
		cifs_stats_inc(&tcon->num_writes);
	else
		kref_put(&wdata->refcount, cifs_writedata_release);

	/* send is done, unmap pages */
	for (i = 0; i < wdata->nr_pages; i++)
		kunmap(wdata->pages[i]);

async_writev_out:
	cifs_small_buf_release(smb);
	kfree(iov);
	return rc;
}

1854
int
1855 1856 1857
CIFSSMBWrite2(const int xid, struct cifs_io_parms *io_parms,
	      unsigned int *nbytes, struct kvec *iov, int n_vec,
	      const int long_op)
L
Linus Torvalds 已提交
1858 1859 1860
{
	int rc = -EACCES;
	WRITE_REQ *pSMB = NULL;
1861
	int wct;
1862
	int smb_hdr_len;
1863
	int resp_buf_type = 0;
1864 1865 1866
	__u32 pid = io_parms->pid;
	__u16 netfid = io_parms->netfid;
	__u64 offset = io_parms->offset;
1867
	struct cifs_tcon *tcon = io_parms->tcon;
1868
	unsigned int count = io_parms->length;
L
Linus Torvalds 已提交
1869

1870 1871
	*nbytes = 0;

1872
	cFYI(1, "write2 at %lld %d bytes", (long long)offset, count);
1873

1874
	if (tcon->ses->capabilities & CAP_LARGE_FILES) {
1875
		wct = 14;
1876
	} else {
1877
		wct = 12;
1878 1879 1880 1881 1882
		if ((offset >> 32) > 0) {
			/* can not handle big offset for old srv */
			return -EIO;
		}
	}
1883
	rc = small_smb_init(SMB_COM_WRITE_ANDX, wct, tcon, (void **) &pSMB);
L
Linus Torvalds 已提交
1884 1885
	if (rc)
		return rc;
1886 1887 1888 1889

	pSMB->hdr.Pid = cpu_to_le16((__u16)pid);
	pSMB->hdr.PidHigh = cpu_to_le16((__u16)(pid >> 16));

L
Linus Torvalds 已提交
1890 1891 1892 1893
	/* tcon and ses pointer are checked in smb_init */
	if (tcon->ses->server == NULL)
		return -ECONNABORTED;

1894
	pSMB->AndXCommand = 0xFF;	/* none */
L
Linus Torvalds 已提交
1895 1896
	pSMB->Fid = netfid;
	pSMB->OffsetLow = cpu_to_le32(offset & 0xFFFFFFFF);
S
Steve French 已提交
1897
	if (wct == 14)
1898
		pSMB->OffsetHigh = cpu_to_le32(offset >> 32);
L
Linus Torvalds 已提交
1899 1900 1901
	pSMB->Reserved = 0xFFFFFFFF;
	pSMB->WriteMode = 0;
	pSMB->Remaining = 0;
1902

L
Linus Torvalds 已提交
1903
	pSMB->DataOffset =
1904
	    cpu_to_le16(offsetof(struct smb_com_write_req, Data) - 4);
L
Linus Torvalds 已提交
1905

1906 1907
	pSMB->DataLengthLow = cpu_to_le16(count & 0xFFFF);
	pSMB->DataLengthHigh = cpu_to_le16(count >> 16);
1908 1909
	/* header + 1 byte pad */
	smb_hdr_len = be32_to_cpu(pSMB->hdr.smb_buf_length) + 1;
S
Steve French 已提交
1910
	if (wct == 14)
1911
		inc_rfc1001_len(pSMB, count + 1);
1912
	else /* wct == 12 */
1913
		inc_rfc1001_len(pSMB, count + 5); /* smb data starts later */
S
Steve French 已提交
1914
	if (wct == 14)
1915 1916
		pSMB->ByteCount = cpu_to_le16(count + 1);
	else /* wct == 12 */ /* bigger pad, smaller smb hdr, keep offset ok */ {
1917
		struct smb_com_writex_req *pSMBW =
1918 1919 1920
				(struct smb_com_writex_req *)pSMB;
		pSMBW->ByteCount = cpu_to_le16(count + 5);
	}
1921
	iov[0].iov_base = pSMB;
S
Steve French 已提交
1922
	if (wct == 14)
1923 1924 1925
		iov[0].iov_len = smb_hdr_len + 4;
	else /* wct == 12 pad bigger by four bytes */
		iov[0].iov_len = smb_hdr_len + 8;
1926

L
Linus Torvalds 已提交
1927

1928
	rc = SendReceive2(xid, tcon->ses, iov, n_vec + 1, &resp_buf_type,
1929
			  long_op);
1930
	cifs_stats_inc(&tcon->num_writes);
L
Linus Torvalds 已提交
1931
	if (rc) {
1932
		cFYI(1, "Send error Write2 = %d", rc);
S
Steve French 已提交
1933
	} else if (resp_buf_type == 0) {
1934 1935
		/* presumably this can not happen, but best to be safe */
		rc = -EIO;
1936
	} else {
S
Steve French 已提交
1937
		WRITE_RSP *pSMBr = (WRITE_RSP *)iov[0].iov_base;
1938 1939 1940
		*nbytes = le16_to_cpu(pSMBr->CountHigh);
		*nbytes = (*nbytes) << 16;
		*nbytes += le16_to_cpu(pSMBr->Count);
1941 1942 1943 1944 1945 1946 1947 1948

		/*
		 * Mask off high 16 bits when bytes written as returned by the
		 * server is greater than bytes requested by the client. OS/2
		 * servers are known to set incorrect CountHigh values.
		 */
		if (*nbytes > count)
			*nbytes &= 0xFFFF;
1949
	}
L
Linus Torvalds 已提交
1950

1951
/*	cifs_small_buf_release(pSMB); */ /* Freed earlier now in SendReceive2 */
S
Steve French 已提交
1952
	if (resp_buf_type == CIFS_SMALL_BUFFER)
1953
		cifs_small_buf_release(iov[0].iov_base);
S
Steve French 已提交
1954
	else if (resp_buf_type == CIFS_LARGE_BUFFER)
1955
		cifs_buf_release(iov[0].iov_base);
L
Linus Torvalds 已提交
1956

1957
	/* Note: On -EAGAIN error only caller can retry on handle based calls
L
Linus Torvalds 已提交
1958 1959 1960 1961
		since file handle passed in no longer valid */

	return rc;
}
1962 1963


L
Linus Torvalds 已提交
1964
int
1965
CIFSSMBLock(const int xid, struct cifs_tcon *tcon,
1966
	    const __u16 smb_file_id, const __u32 netpid, const __u64 len,
L
Linus Torvalds 已提交
1967
	    const __u64 offset, const __u32 numUnlock,
1968 1969
	    const __u32 numLock, const __u8 lockType,
	    const bool waitFlag, const __u8 oplock_level)
L
Linus Torvalds 已提交
1970 1971 1972
{
	int rc = 0;
	LOCK_REQ *pSMB = NULL;
S
Steve French 已提交
1973
/*	LOCK_RSP *pSMBr = NULL; */ /* No response data other than rc to parse */
L
Linus Torvalds 已提交
1974 1975 1976 1977
	int bytes_returned;
	int timeout = 0;
	__u16 count;

1978
	cFYI(1, "CIFSSMBLock timeout %d numLock %d", (int)waitFlag, numLock);
1979 1980
	rc = small_smb_init(SMB_COM_LOCKING_ANDX, 8, tcon, (void **) &pSMB);

L
Linus Torvalds 已提交
1981 1982 1983
	if (rc)
		return rc;

S
Steve French 已提交
1984
	if (lockType == LOCKING_ANDX_OPLOCK_RELEASE) {
1985
		timeout = CIFS_ASYNC_OP; /* no response expected */
L
Linus Torvalds 已提交
1986
		pSMB->Timeout = 0;
1987
	} else if (waitFlag) {
1988
		timeout = CIFS_BLOCKING_OP; /* blocking operation, no timeout */
L
Linus Torvalds 已提交
1989 1990 1991 1992 1993 1994 1995 1996
		pSMB->Timeout = cpu_to_le32(-1);/* blocking - do not time out */
	} else {
		pSMB->Timeout = 0;
	}

	pSMB->NumberOfLocks = cpu_to_le16(numLock);
	pSMB->NumberOfUnlocks = cpu_to_le16(numUnlock);
	pSMB->LockType = lockType;
1997
	pSMB->OplockLevel = oplock_level;
L
Linus Torvalds 已提交
1998 1999 2000
	pSMB->AndXCommand = 0xFF;	/* none */
	pSMB->Fid = smb_file_id; /* netfid stays le */

S
Steve French 已提交
2001
	if ((numLock != 0) || (numUnlock != 0)) {
2002
		pSMB->Locks[0].Pid = cpu_to_le16(netpid);
L
Linus Torvalds 已提交
2003 2004 2005 2006 2007 2008 2009 2010 2011 2012
		/* BB where to store pid high? */
		pSMB->Locks[0].LengthLow = cpu_to_le32((u32)len);
		pSMB->Locks[0].LengthHigh = cpu_to_le32((u32)(len>>32));
		pSMB->Locks[0].OffsetLow = cpu_to_le32((u32)offset);
		pSMB->Locks[0].OffsetHigh = cpu_to_le32((u32)(offset>>32));
		count = sizeof(LOCKING_ANDX_RANGE);
	} else {
		/* oplock break */
		count = 0;
	}
2013
	inc_rfc1001_len(pSMB, count);
L
Linus Torvalds 已提交
2014 2015
	pSMB->ByteCount = cpu_to_le16(count);

J
[CIFS]  
Jeremy Allison 已提交
2016 2017
	if (waitFlag) {
		rc = SendReceiveBlockingLock(xid, tcon, (struct smb_hdr *) pSMB,
S
Steve French 已提交
2018
			(struct smb_hdr *) pSMB, &bytes_returned);
2019
		cifs_small_buf_release(pSMB);
J
[CIFS]  
Jeremy Allison 已提交
2020
	} else {
2021 2022 2023
		rc = SendReceiveNoRsp(xid, tcon->ses, (struct smb_hdr *)pSMB,
				      timeout);
		/* SMB buffer freed by function above */
J
[CIFS]  
Jeremy Allison 已提交
2024
	}
2025
	cifs_stats_inc(&tcon->num_locks);
S
Steve French 已提交
2026
	if (rc)
2027
		cFYI(1, "Send error in Lock = %d", rc);
L
Linus Torvalds 已提交
2028

2029
	/* Note: On -EAGAIN error only caller can retry on handle based calls
L
Linus Torvalds 已提交
2030 2031 2032 2033
	since file handle passed in no longer valid */
	return rc;
}

2034
int
2035
CIFSSMBPosixLock(const int xid, struct cifs_tcon *tcon,
2036
		const __u16 smb_file_id, const int get_flag, const __u64 len,
2037
		struct file_lock *pLockData, const __u16 lock_type,
2038
		const bool waitFlag)
2039 2040 2041 2042 2043
{
	struct smb_com_transaction2_sfi_req *pSMB  = NULL;
	struct smb_com_transaction2_sfi_rsp *pSMBr = NULL;
	struct cifs_posix_lock *parm_data;
	int rc = 0;
2044
	int timeout = 0;
2045
	int bytes_returned = 0;
2046
	int resp_buf_type = 0;
2047
	__u16 params, param_offset, offset, byte_count, count;
2048
	struct kvec iov[1];
2049

2050
	cFYI(1, "Posix Lock");
2051

S
Steve French 已提交
2052
	if (pLockData == NULL)
2053
		return -EINVAL;
2054

2055 2056 2057 2058 2059 2060 2061
	rc = small_smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB);

	if (rc)
		return rc;

	pSMBr = (struct smb_com_transaction2_sfi_rsp *)pSMB;

2062
	params = 6;
2063 2064 2065 2066 2067 2068 2069 2070 2071
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Reserved2 = 0;
	param_offset = offsetof(struct smb_com_transaction2_sfi_req, Fid) - 4;
	offset = param_offset + params;

	count = sizeof(struct cifs_posix_lock);
	pSMB->MaxParameterCount = cpu_to_le16(2);
S
Steve French 已提交
2072
	pSMB->MaxDataCount = cpu_to_le16(1000); /* BB find max SMB from sess */
2073 2074
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
S
Steve French 已提交
2075
	if (get_flag)
2076 2077 2078 2079 2080 2081 2082 2083 2084
		pSMB->SubCommand = cpu_to_le16(TRANS2_QUERY_FILE_INFORMATION);
	else
		pSMB->SubCommand = cpu_to_le16(TRANS2_SET_FILE_INFORMATION);
	byte_count = 3 /* pad */  + params + count;
	pSMB->DataCount = cpu_to_le16(count);
	pSMB->ParameterCount = cpu_to_le16(params);
	pSMB->TotalDataCount = pSMB->DataCount;
	pSMB->TotalParameterCount = pSMB->ParameterCount;
	pSMB->ParameterOffset = cpu_to_le16(param_offset);
2085
	parm_data = (struct cifs_posix_lock *)
2086 2087 2088
			(((char *) &pSMB->hdr.Protocol) + offset);

	parm_data->lock_type = cpu_to_le16(lock_type);
S
Steve French 已提交
2089
	if (waitFlag) {
2090
		timeout = CIFS_BLOCKING_OP; /* blocking operation, no timeout */
2091
		parm_data->lock_flags = cpu_to_le16(1);
2092 2093 2094 2095
		pSMB->Timeout = cpu_to_le32(-1);
	} else
		pSMB->Timeout = 0;

2096
	parm_data->pid = cpu_to_le32(current->tgid);
2097
	parm_data->start = cpu_to_le64(pLockData->fl_start);
2098
	parm_data->length = cpu_to_le64(len);  /* normalize negative numbers */
2099 2100

	pSMB->DataOffset = cpu_to_le16(offset);
2101
	pSMB->Fid = smb_file_id;
2102 2103
	pSMB->InformationLevel = cpu_to_le16(SMB_SET_POSIX_LOCK);
	pSMB->Reserved4 = 0;
2104
	inc_rfc1001_len(pSMB, byte_count);
2105
	pSMB->ByteCount = cpu_to_le16(byte_count);
J
[CIFS]  
Jeremy Allison 已提交
2106 2107 2108 2109
	if (waitFlag) {
		rc = SendReceiveBlockingLock(xid, tcon, (struct smb_hdr *) pSMB,
			(struct smb_hdr *) pSMBr, &bytes_returned);
	} else {
2110
		iov[0].iov_base = (char *)pSMB;
2111
		iov[0].iov_len = be32_to_cpu(pSMB->hdr.smb_buf_length) + 4;
2112 2113 2114 2115 2116
		rc = SendReceive2(xid, tcon->ses, iov, 1 /* num iovecs */,
				&resp_buf_type, timeout);
		pSMB = NULL; /* request buf already freed by SendReceive2. Do
				not try to free it twice below on exit */
		pSMBr = (struct smb_com_transaction2_sfi_rsp *)iov[0].iov_base;
J
[CIFS]  
Jeremy Allison 已提交
2117 2118
	}

2119
	if (rc) {
2120
		cFYI(1, "Send error in Posix Lock = %d", rc);
2121 2122 2123 2124 2125 2126
	} else if (get_flag) {
		/* lock structure can be returned on get */
		__u16 data_offset;
		__u16 data_count;
		rc = validate_t2((struct smb_t2_rsp *)pSMBr);

2127
		if (rc || get_bcc(&pSMBr->hdr) < sizeof(*parm_data)) {
2128 2129 2130 2131 2132
			rc = -EIO;      /* bad smb */
			goto plk_err_exit;
		}
		data_offset = le16_to_cpu(pSMBr->t2.DataOffset);
		data_count  = le16_to_cpu(pSMBr->t2.DataCount);
S
Steve French 已提交
2133
		if (data_count < sizeof(struct cifs_posix_lock)) {
2134 2135 2136 2137 2138
			rc = -EIO;
			goto plk_err_exit;
		}
		parm_data = (struct cifs_posix_lock *)
			((char *)&pSMBr->hdr.Protocol + data_offset);
2139
		if (parm_data->lock_type == __constant_cpu_to_le16(CIFS_UNLCK))
2140
			pLockData->fl_type = F_UNLCK;
2141 2142 2143 2144 2145 2146 2147 2148
		else {
			if (parm_data->lock_type ==
					__constant_cpu_to_le16(CIFS_RDLCK))
				pLockData->fl_type = F_RDLCK;
			else if (parm_data->lock_type ==
					__constant_cpu_to_le16(CIFS_WRLCK))
				pLockData->fl_type = F_WRLCK;

S
Steve French 已提交
2149 2150 2151 2152
			pLockData->fl_start = le64_to_cpu(parm_data->start);
			pLockData->fl_end = pLockData->fl_start +
					le64_to_cpu(parm_data->length) - 1;
			pLockData->fl_pid = le32_to_cpu(parm_data->pid);
2153
		}
2154
	}
2155

2156
plk_err_exit:
2157 2158 2159
	if (pSMB)
		cifs_small_buf_release(pSMB);

2160 2161 2162 2163 2164
	if (resp_buf_type == CIFS_SMALL_BUFFER)
		cifs_small_buf_release(iov[0].iov_base);
	else if (resp_buf_type == CIFS_LARGE_BUFFER)
		cifs_buf_release(iov[0].iov_base);

2165 2166 2167 2168 2169 2170 2171
	/* Note: On -EAGAIN error only caller can retry on handle based calls
	   since file handle passed in no longer valid */

	return rc;
}


L
Linus Torvalds 已提交
2172
int
2173
CIFSSMBClose(const int xid, struct cifs_tcon *tcon, int smb_file_id)
L
Linus Torvalds 已提交
2174 2175 2176
{
	int rc = 0;
	CLOSE_REQ *pSMB = NULL;
2177
	cFYI(1, "In CIFSSMBClose");
L
Linus Torvalds 已提交
2178 2179 2180

/* do not retry on dead session on close */
	rc = small_smb_init(SMB_COM_CLOSE, 3, tcon, (void **) &pSMB);
S
Steve French 已提交
2181
	if (rc == -EAGAIN)
L
Linus Torvalds 已提交
2182 2183 2184 2185 2186
		return 0;
	if (rc)
		return rc;

	pSMB->FileID = (__u16) smb_file_id;
2187
	pSMB->LastWriteTime = 0xFFFFFFFF;
L
Linus Torvalds 已提交
2188
	pSMB->ByteCount = 0;
2189
	rc = SendReceiveNoRsp(xid, tcon->ses, (struct smb_hdr *) pSMB, 0);
2190
	cifs_stats_inc(&tcon->num_closes);
L
Linus Torvalds 已提交
2191
	if (rc) {
S
Steve French 已提交
2192
		if (rc != -EINTR) {
L
Linus Torvalds 已提交
2193
			/* EINTR is expected when user ctl-c to kill app */
2194
			cERROR(1, "Send error in Close = %d", rc);
L
Linus Torvalds 已提交
2195 2196 2197 2198
		}
	}

	/* Since session is dead, file will be closed on server already */
S
Steve French 已提交
2199
	if (rc == -EAGAIN)
L
Linus Torvalds 已提交
2200 2201 2202 2203 2204
		rc = 0;

	return rc;
}

2205
int
2206
CIFSSMBFlush(const int xid, struct cifs_tcon *tcon, int smb_file_id)
2207 2208 2209
{
	int rc = 0;
	FLUSH_REQ *pSMB = NULL;
2210
	cFYI(1, "In CIFSSMBFlush");
2211 2212 2213 2214 2215 2216 2217 2218 2219 2220

	rc = small_smb_init(SMB_COM_FLUSH, 1, tcon, (void **) &pSMB);
	if (rc)
		return rc;

	pSMB->FileID = (__u16) smb_file_id;
	pSMB->ByteCount = 0;
	rc = SendReceiveNoRsp(xid, tcon->ses, (struct smb_hdr *) pSMB, 0);
	cifs_stats_inc(&tcon->num_flushes);
	if (rc)
2221
		cERROR(1, "Send error in Flush = %d", rc);
2222 2223 2224 2225

	return rc;
}

L
Linus Torvalds 已提交
2226
int
2227
CIFSSMBRename(const int xid, struct cifs_tcon *tcon,
L
Linus Torvalds 已提交
2228
	      const char *fromName, const char *toName,
2229
	      const struct nls_table *nls_codepage, int remap)
L
Linus Torvalds 已提交
2230 2231 2232 2233 2234 2235 2236 2237
{
	int rc = 0;
	RENAME_REQ *pSMB = NULL;
	RENAME_RSP *pSMBr = NULL;
	int bytes_returned;
	int name_len, name_len2;
	__u16 count;

2238
	cFYI(1, "In CIFSSMBRename");
L
Linus Torvalds 已提交
2239 2240 2241 2242 2243 2244 2245 2246 2247 2248 2249 2250 2251
renameRetry:
	rc = smb_init(SMB_COM_RENAME, 1, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	pSMB->BufferFormat = 0x04;
	pSMB->SearchAttributes =
	    cpu_to_le16(ATTR_READONLY | ATTR_HIDDEN | ATTR_SYSTEM |
			ATTR_DIRECTORY);

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		name_len =
2252
		    cifsConvertToUCS((__le16 *) pSMB->OldFileName, fromName,
2253
				     PATH_MAX, nls_codepage, remap);
L
Linus Torvalds 已提交
2254 2255 2256 2257 2258 2259
		name_len++;	/* trailing null */
		name_len *= 2;
		pSMB->OldFileName[name_len] = 0x04;	/* pad */
	/* protocol requires ASCII signature byte on Unicode string */
		pSMB->OldFileName[name_len + 1] = 0x00;
		name_len2 =
2260
		    cifsConvertToUCS((__le16 *)&pSMB->OldFileName[name_len + 2],
2261
				     toName, PATH_MAX, nls_codepage, remap);
L
Linus Torvalds 已提交
2262 2263
		name_len2 += 1 /* trailing null */  + 1 /* Signature word */ ;
		name_len2 *= 2;	/* convert to bytes */
2264
	} else {	/* BB improve the check for buffer overruns BB */
L
Linus Torvalds 已提交
2265 2266 2267 2268 2269 2270 2271 2272 2273 2274 2275 2276
		name_len = strnlen(fromName, PATH_MAX);
		name_len++;	/* trailing null */
		strncpy(pSMB->OldFileName, fromName, name_len);
		name_len2 = strnlen(toName, PATH_MAX);
		name_len2++;	/* trailing null */
		pSMB->OldFileName[name_len] = 0x04;  /* 2nd buffer format */
		strncpy(&pSMB->OldFileName[name_len + 1], toName, name_len2);
		name_len2++;	/* trailing null */
		name_len2++;	/* signature byte */
	}

	count = 1 /* 1st signature byte */  + name_len + name_len2;
2277
	inc_rfc1001_len(pSMB, count);
L
Linus Torvalds 已提交
2278 2279 2280 2281
	pSMB->ByteCount = cpu_to_le16(count);

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
2282
	cifs_stats_inc(&tcon->num_renames);
S
Steve French 已提交
2283
	if (rc)
2284
		cFYI(1, "Send error in rename = %d", rc);
L
Linus Torvalds 已提交
2285 2286 2287 2288 2289 2290 2291 2292 2293

	cifs_buf_release(pSMB);

	if (rc == -EAGAIN)
		goto renameRetry;

	return rc;
}

2294
int CIFSSMBRenameOpenFile(const int xid, struct cifs_tcon *pTcon,
2295
		int netfid, const char *target_name,
2296
		const struct nls_table *nls_codepage, int remap)
L
Linus Torvalds 已提交
2297 2298 2299
{
	struct smb_com_transaction2_sfi_req *pSMB  = NULL;
	struct smb_com_transaction2_sfi_rsp *pSMBr = NULL;
2300
	struct set_file_rename *rename_info;
L
Linus Torvalds 已提交
2301 2302 2303 2304 2305 2306 2307
	char *data_offset;
	char dummy_string[30];
	int rc = 0;
	int bytes_returned = 0;
	int len_of_str;
	__u16 params, param_offset, offset, count, byte_count;

2308
	cFYI(1, "Rename to File by handle");
L
Linus Torvalds 已提交
2309 2310 2311 2312 2313 2314 2315 2316 2317 2318 2319 2320 2321 2322 2323 2324 2325
	rc = smb_init(SMB_COM_TRANSACTION2, 15, pTcon, (void **) &pSMB,
			(void **) &pSMBr);
	if (rc)
		return rc;

	params = 6;
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	param_offset = offsetof(struct smb_com_transaction2_sfi_req, Fid) - 4;
	offset = param_offset + params;

	data_offset = (char *) (&pSMB->hdr.Protocol) + offset;
	rename_info = (struct set_file_rename *) data_offset;
	pSMB->MaxParameterCount = cpu_to_le16(2);
S
Steve French 已提交
2326
	pSMB->MaxDataCount = cpu_to_le16(1000); /* BB find max SMB from sess */
L
Linus Torvalds 已提交
2327 2328 2329 2330 2331 2332 2333 2334 2335 2336 2337 2338
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_SET_FILE_INFORMATION);
	byte_count = 3 /* pad */  + params;
	pSMB->ParameterCount = cpu_to_le16(params);
	pSMB->TotalParameterCount = pSMB->ParameterCount;
	pSMB->ParameterOffset = cpu_to_le16(param_offset);
	pSMB->DataOffset = cpu_to_le16(offset);
	/* construct random name ".cifs_tmp<inodenum><mid>" */
	rename_info->overwrite = cpu_to_le32(1);
	rename_info->root_fid  = 0;
	/* unicode only call */
S
Steve French 已提交
2339
	if (target_name == NULL) {
2340 2341
		sprintf(dummy_string, "cifs%x", pSMB->hdr.Mid);
		len_of_str = cifsConvertToUCS((__le16 *)rename_info->target_name,
2342
					dummy_string, 24, nls_codepage, remap);
L
Linus Torvalds 已提交
2343
	} else {
2344
		len_of_str = cifsConvertToUCS((__le16 *)rename_info->target_name,
2345 2346
					target_name, PATH_MAX, nls_codepage,
					remap);
L
Linus Torvalds 已提交
2347 2348
	}
	rename_info->target_name_len = cpu_to_le32(2 * len_of_str);
2349
	count = 12 /* sizeof(struct set_file_rename) */ + (2 * len_of_str);
L
Linus Torvalds 已提交
2350 2351 2352 2353 2354 2355 2356
	byte_count += count;
	pSMB->DataCount = cpu_to_le16(count);
	pSMB->TotalDataCount = pSMB->DataCount;
	pSMB->Fid = netfid;
	pSMB->InformationLevel =
		cpu_to_le16(SMB_SET_FILE_RENAME_INFORMATION);
	pSMB->Reserved4 = 0;
2357
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
2358 2359
	pSMB->ByteCount = cpu_to_le16(byte_count);
	rc = SendReceive(xid, pTcon->ses, (struct smb_hdr *) pSMB,
2360
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
2361
	cifs_stats_inc(&pTcon->num_t2renames);
S
Steve French 已提交
2362
	if (rc)
2363
		cFYI(1, "Send error in Rename (by file handle) = %d", rc);
2364

L
Linus Torvalds 已提交
2365 2366 2367 2368 2369 2370 2371 2372 2373
	cifs_buf_release(pSMB);

	/* Note: On -EAGAIN error only caller can retry on handle based calls
		since file handle passed in no longer valid */

	return rc;
}

int
2374
CIFSSMBCopy(const int xid, struct cifs_tcon *tcon, const char *fromName,
2375 2376
	    const __u16 target_tid, const char *toName, const int flags,
	    const struct nls_table *nls_codepage, int remap)
L
Linus Torvalds 已提交
2377 2378 2379 2380 2381 2382 2383 2384
{
	int rc = 0;
	COPY_REQ *pSMB = NULL;
	COPY_RSP *pSMBr = NULL;
	int bytes_returned;
	int name_len, name_len2;
	__u16 count;

2385
	cFYI(1, "In CIFSSMBCopy");
L
Linus Torvalds 已提交
2386 2387 2388 2389 2390 2391 2392 2393 2394 2395 2396 2397
copyRetry:
	rc = smb_init(SMB_COM_COPY, 1, tcon, (void **) &pSMB,
			(void **) &pSMBr);
	if (rc)
		return rc;

	pSMB->BufferFormat = 0x04;
	pSMB->Tid2 = target_tid;

	pSMB->Flags = cpu_to_le16(flags & COPY_TREE);

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
2398
		name_len = cifsConvertToUCS((__le16 *) pSMB->OldFileName,
2399 2400
					    fromName, PATH_MAX, nls_codepage,
					    remap);
L
Linus Torvalds 已提交
2401 2402 2403 2404 2405
		name_len++;     /* trailing null */
		name_len *= 2;
		pSMB->OldFileName[name_len] = 0x04;     /* pad */
		/* protocol requires ASCII signature byte on Unicode string */
		pSMB->OldFileName[name_len + 1] = 0x00;
2406 2407
		name_len2 =
		    cifsConvertToUCS((__le16 *)&pSMB->OldFileName[name_len + 2],
2408
				toName, PATH_MAX, nls_codepage, remap);
L
Linus Torvalds 已提交
2409 2410
		name_len2 += 1 /* trailing null */  + 1 /* Signature word */ ;
		name_len2 *= 2; /* convert to bytes */
2411
	} else { 	/* BB improve the check for buffer overruns BB */
L
Linus Torvalds 已提交
2412 2413 2414 2415 2416 2417 2418 2419 2420 2421 2422 2423
		name_len = strnlen(fromName, PATH_MAX);
		name_len++;     /* trailing null */
		strncpy(pSMB->OldFileName, fromName, name_len);
		name_len2 = strnlen(toName, PATH_MAX);
		name_len2++;    /* trailing null */
		pSMB->OldFileName[name_len] = 0x04;  /* 2nd buffer format */
		strncpy(&pSMB->OldFileName[name_len + 1], toName, name_len2);
		name_len2++;    /* trailing null */
		name_len2++;    /* signature byte */
	}

	count = 1 /* 1st signature byte */  + name_len + name_len2;
2424
	inc_rfc1001_len(pSMB, count);
L
Linus Torvalds 已提交
2425 2426 2427 2428 2429
	pSMB->ByteCount = cpu_to_le16(count);

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
		(struct smb_hdr *) pSMBr, &bytes_returned, 0);
	if (rc) {
2430 2431
		cFYI(1, "Send error in copy = %d with %d files copied",
			rc, le16_to_cpu(pSMBr->CopyCount));
L
Linus Torvalds 已提交
2432
	}
2433
	cifs_buf_release(pSMB);
L
Linus Torvalds 已提交
2434 2435 2436 2437 2438 2439 2440 2441

	if (rc == -EAGAIN)
		goto copyRetry;

	return rc;
}

int
2442
CIFSUnixCreateSymLink(const int xid, struct cifs_tcon *tcon,
L
Linus Torvalds 已提交
2443 2444 2445 2446 2447 2448 2449 2450 2451 2452 2453 2454
		      const char *fromName, const char *toName,
		      const struct nls_table *nls_codepage)
{
	TRANSACTION2_SPI_REQ *pSMB = NULL;
	TRANSACTION2_SPI_RSP *pSMBr = NULL;
	char *data_offset;
	int name_len;
	int name_len_target;
	int rc = 0;
	int bytes_returned = 0;
	__u16 params, param_offset, offset, byte_count;

2455
	cFYI(1, "In Symlink Unix style");
L
Linus Torvalds 已提交
2456 2457 2458 2459 2460 2461 2462 2463
createSymLinkRetry:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		name_len =
2464
		    cifs_strtoUCS((__le16 *) pSMB->FileName, fromName, PATH_MAX
L
Linus Torvalds 已提交
2465 2466 2467 2468 2469
				  /* find define for this maxpathcomponent */
				  , nls_codepage);
		name_len++;	/* trailing null */
		name_len *= 2;

2470
	} else {	/* BB improve the check for buffer overruns BB */
L
Linus Torvalds 已提交
2471 2472 2473 2474 2475 2476 2477 2478 2479 2480 2481
		name_len = strnlen(fromName, PATH_MAX);
		name_len++;	/* trailing null */
		strncpy(pSMB->FileName, fromName, name_len);
	}
	params = 6 + name_len;
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	param_offset = offsetof(struct smb_com_transaction2_spi_req,
2482
				InformationLevel) - 4;
L
Linus Torvalds 已提交
2483 2484 2485 2486 2487
	offset = param_offset + params;

	data_offset = (char *) (&pSMB->hdr.Protocol) + offset;
	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		name_len_target =
2488
		    cifs_strtoUCS((__le16 *) data_offset, toName, PATH_MAX
L
Linus Torvalds 已提交
2489 2490 2491 2492
				  /* find define for this maxpathcomponent */
				  , nls_codepage);
		name_len_target++;	/* trailing null */
		name_len_target *= 2;
2493
	} else {	/* BB improve the check for buffer overruns BB */
L
Linus Torvalds 已提交
2494 2495 2496 2497 2498 2499 2500 2501 2502 2503 2504 2505 2506 2507 2508 2509 2510 2511 2512 2513
		name_len_target = strnlen(toName, PATH_MAX);
		name_len_target++;	/* trailing null */
		strncpy(data_offset, toName, name_len_target);
	}

	pSMB->MaxParameterCount = cpu_to_le16(2);
	/* BB find exact max on data count below from sess */
	pSMB->MaxDataCount = cpu_to_le16(1000);
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_SET_PATH_INFORMATION);
	byte_count = 3 /* pad */  + params + name_len_target;
	pSMB->DataCount = cpu_to_le16(name_len_target);
	pSMB->ParameterCount = cpu_to_le16(params);
	pSMB->TotalDataCount = pSMB->DataCount;
	pSMB->TotalParameterCount = pSMB->ParameterCount;
	pSMB->ParameterOffset = cpu_to_le16(param_offset);
	pSMB->DataOffset = cpu_to_le16(offset);
	pSMB->InformationLevel = cpu_to_le16(SMB_SET_FILE_UNIX_LINK);
	pSMB->Reserved4 = 0;
2514
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
2515 2516 2517
	pSMB->ByteCount = cpu_to_le16(byte_count);
	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
2518
	cifs_stats_inc(&tcon->num_symlinks);
S
Steve French 已提交
2519
	if (rc)
2520
		cFYI(1, "Send error in SetPathInfo create symlink = %d", rc);
L
Linus Torvalds 已提交
2521

2522
	cifs_buf_release(pSMB);
L
Linus Torvalds 已提交
2523 2524 2525 2526 2527 2528 2529 2530

	if (rc == -EAGAIN)
		goto createSymLinkRetry;

	return rc;
}

int
2531
CIFSUnixCreateHardLink(const int xid, struct cifs_tcon *tcon,
L
Linus Torvalds 已提交
2532
		       const char *fromName, const char *toName,
2533
		       const struct nls_table *nls_codepage, int remap)
L
Linus Torvalds 已提交
2534 2535 2536 2537 2538 2539 2540 2541 2542 2543
{
	TRANSACTION2_SPI_REQ *pSMB = NULL;
	TRANSACTION2_SPI_RSP *pSMBr = NULL;
	char *data_offset;
	int name_len;
	int name_len_target;
	int rc = 0;
	int bytes_returned = 0;
	__u16 params, param_offset, offset, byte_count;

2544
	cFYI(1, "In Create Hard link Unix style");
L
Linus Torvalds 已提交
2545 2546 2547 2548 2549 2550 2551
createHardLinkRetry:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
2552
		name_len = cifsConvertToUCS((__le16 *) pSMB->FileName, toName,
2553
					    PATH_MAX, nls_codepage, remap);
L
Linus Torvalds 已提交
2554 2555 2556
		name_len++;	/* trailing null */
		name_len *= 2;

2557
	} else {	/* BB improve the check for buffer overruns BB */
L
Linus Torvalds 已提交
2558 2559 2560 2561 2562 2563 2564 2565 2566 2567 2568
		name_len = strnlen(toName, PATH_MAX);
		name_len++;	/* trailing null */
		strncpy(pSMB->FileName, toName, name_len);
	}
	params = 6 + name_len;
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	param_offset = offsetof(struct smb_com_transaction2_spi_req,
2569
				InformationLevel) - 4;
L
Linus Torvalds 已提交
2570 2571 2572 2573 2574
	offset = param_offset + params;

	data_offset = (char *) (&pSMB->hdr.Protocol) + offset;
	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		name_len_target =
2575
		    cifsConvertToUCS((__le16 *) data_offset, fromName, PATH_MAX,
2576
				     nls_codepage, remap);
L
Linus Torvalds 已提交
2577 2578
		name_len_target++;	/* trailing null */
		name_len_target *= 2;
2579
	} else {	/* BB improve the check for buffer overruns BB */
L
Linus Torvalds 已提交
2580 2581 2582 2583 2584 2585 2586 2587 2588 2589 2590 2591 2592 2593 2594 2595 2596 2597 2598 2599
		name_len_target = strnlen(fromName, PATH_MAX);
		name_len_target++;	/* trailing null */
		strncpy(data_offset, fromName, name_len_target);
	}

	pSMB->MaxParameterCount = cpu_to_le16(2);
	/* BB find exact max on data count below from sess*/
	pSMB->MaxDataCount = cpu_to_le16(1000);
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_SET_PATH_INFORMATION);
	byte_count = 3 /* pad */  + params + name_len_target;
	pSMB->ParameterCount = cpu_to_le16(params);
	pSMB->TotalParameterCount = pSMB->ParameterCount;
	pSMB->DataCount = cpu_to_le16(name_len_target);
	pSMB->TotalDataCount = pSMB->DataCount;
	pSMB->ParameterOffset = cpu_to_le16(param_offset);
	pSMB->DataOffset = cpu_to_le16(offset);
	pSMB->InformationLevel = cpu_to_le16(SMB_SET_FILE_UNIX_HLINK);
	pSMB->Reserved4 = 0;
2600
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
2601 2602 2603
	pSMB->ByteCount = cpu_to_le16(byte_count);
	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
2604
	cifs_stats_inc(&tcon->num_hardlinks);
S
Steve French 已提交
2605
	if (rc)
2606
		cFYI(1, "Send error in SetPathInfo (hard link) = %d", rc);
L
Linus Torvalds 已提交
2607 2608 2609 2610 2611 2612 2613 2614 2615

	cifs_buf_release(pSMB);
	if (rc == -EAGAIN)
		goto createHardLinkRetry;

	return rc;
}

int
2616
CIFSCreateHardLink(const int xid, struct cifs_tcon *tcon,
L
Linus Torvalds 已提交
2617
		   const char *fromName, const char *toName,
2618
		   const struct nls_table *nls_codepage, int remap)
L
Linus Torvalds 已提交
2619 2620 2621 2622 2623 2624 2625 2626
{
	int rc = 0;
	NT_RENAME_REQ *pSMB = NULL;
	RENAME_RSP *pSMBr = NULL;
	int bytes_returned;
	int name_len, name_len2;
	__u16 count;

2627
	cFYI(1, "In CIFSCreateHardLink");
L
Linus Torvalds 已提交
2628 2629 2630 2631 2632 2633 2634 2635 2636 2637 2638 2639 2640 2641 2642 2643 2644
winCreateHardLinkRetry:

	rc = smb_init(SMB_COM_NT_RENAME, 4, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	pSMB->SearchAttributes =
	    cpu_to_le16(ATTR_READONLY | ATTR_HIDDEN | ATTR_SYSTEM |
			ATTR_DIRECTORY);
	pSMB->Flags = cpu_to_le16(CREATE_HARD_LINK);
	pSMB->ClusterCount = 0;

	pSMB->BufferFormat = 0x04;

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		name_len =
2645
		    cifsConvertToUCS((__le16 *) pSMB->OldFileName, fromName,
2646
				     PATH_MAX, nls_codepage, remap);
L
Linus Torvalds 已提交
2647 2648
		name_len++;	/* trailing null */
		name_len *= 2;
2649 2650 2651 2652

		/* protocol specifies ASCII buffer format (0x04) for unicode */
		pSMB->OldFileName[name_len] = 0x04;
		pSMB->OldFileName[name_len + 1] = 0x00; /* pad */
L
Linus Torvalds 已提交
2653
		name_len2 =
2654
		    cifsConvertToUCS((__le16 *)&pSMB->OldFileName[name_len + 2],
2655
				     toName, PATH_MAX, nls_codepage, remap);
L
Linus Torvalds 已提交
2656 2657
		name_len2 += 1 /* trailing null */  + 1 /* Signature word */ ;
		name_len2 *= 2;	/* convert to bytes */
2658
	} else {	/* BB improve the check for buffer overruns BB */
L
Linus Torvalds 已提交
2659 2660 2661 2662 2663 2664 2665 2666 2667 2668 2669 2670
		name_len = strnlen(fromName, PATH_MAX);
		name_len++;	/* trailing null */
		strncpy(pSMB->OldFileName, fromName, name_len);
		name_len2 = strnlen(toName, PATH_MAX);
		name_len2++;	/* trailing null */
		pSMB->OldFileName[name_len] = 0x04;	/* 2nd buffer format */
		strncpy(&pSMB->OldFileName[name_len + 1], toName, name_len2);
		name_len2++;	/* trailing null */
		name_len2++;	/* signature byte */
	}

	count = 1 /* string type byte */  + name_len + name_len2;
2671
	inc_rfc1001_len(pSMB, count);
L
Linus Torvalds 已提交
2672 2673 2674 2675
	pSMB->ByteCount = cpu_to_le16(count);

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
2676
	cifs_stats_inc(&tcon->num_hardlinks);
S
Steve French 已提交
2677
	if (rc)
2678
		cFYI(1, "Send error in hard link (NT rename) = %d", rc);
S
Steve French 已提交
2679

L
Linus Torvalds 已提交
2680 2681 2682 2683 2684 2685 2686 2687
	cifs_buf_release(pSMB);
	if (rc == -EAGAIN)
		goto winCreateHardLinkRetry;

	return rc;
}

int
2688
CIFSSMBUnixQuerySymLink(const int xid, struct cifs_tcon *tcon,
2689
			const unsigned char *searchName, char **symlinkinfo,
L
Linus Torvalds 已提交
2690 2691 2692 2693 2694 2695 2696 2697 2698
			const struct nls_table *nls_codepage)
{
/* SMB_QUERY_FILE_UNIX_LINK */
	TRANSACTION2_QPI_REQ *pSMB = NULL;
	TRANSACTION2_QPI_RSP *pSMBr = NULL;
	int rc = 0;
	int bytes_returned;
	int name_len;
	__u16 params, byte_count;
2699
	char *data_start;
L
Linus Torvalds 已提交
2700

2701
	cFYI(1, "In QPathSymLinkInfo (Unix) for path %s", searchName);
L
Linus Torvalds 已提交
2702 2703 2704 2705 2706 2707 2708 2709 2710

querySymLinkRetry:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		name_len =
2711 2712
		    cifs_strtoUCS((__le16 *) pSMB->FileName, searchName,
				  PATH_MAX, nls_codepage);
L
Linus Torvalds 已提交
2713 2714
		name_len++;	/* trailing null */
		name_len *= 2;
2715
	} else {	/* BB improve the check for buffer overruns BB */
L
Linus Torvalds 已提交
2716 2717 2718 2719 2720 2721 2722 2723
		name_len = strnlen(searchName, PATH_MAX);
		name_len++;	/* trailing null */
		strncpy(pSMB->FileName, searchName, name_len);
	}

	params = 2 /* level */  + 4 /* rsrvd */  + name_len /* incl null */ ;
	pSMB->TotalDataCount = 0;
	pSMB->MaxParameterCount = cpu_to_le16(2);
2724
	pSMB->MaxDataCount = cpu_to_le16(CIFSMaxBufSize);
L
Linus Torvalds 已提交
2725 2726 2727 2728 2729 2730
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	pSMB->ParameterOffset = cpu_to_le16(offsetof(
2731
	struct smb_com_transaction2_qpi_req, InformationLevel) - 4);
L
Linus Torvalds 已提交
2732 2733 2734 2735 2736 2737 2738 2739 2740 2741
	pSMB->DataCount = 0;
	pSMB->DataOffset = 0;
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_QUERY_PATH_INFORMATION);
	byte_count = params + 1 /* pad */ ;
	pSMB->TotalParameterCount = cpu_to_le16(params);
	pSMB->ParameterCount = pSMB->TotalParameterCount;
	pSMB->InformationLevel = cpu_to_le16(SMB_QUERY_FILE_UNIX_LINK);
	pSMB->Reserved4 = 0;
2742
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
2743 2744 2745 2746 2747
	pSMB->ByteCount = cpu_to_le16(byte_count);

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
	if (rc) {
2748
		cFYI(1, "Send error in QuerySymLinkInfo = %d", rc);
L
Linus Torvalds 已提交
2749 2750 2751 2752 2753
	} else {
		/* decode response */

		rc = validate_t2((struct smb_t2_rsp *)pSMBr);
		/* BB also check enough total bytes returned */
2754
		if (rc || get_bcc(&pSMBr->hdr) < 2)
2755
			rc = -EIO;
L
Linus Torvalds 已提交
2756
		else {
2757
			bool is_unicode;
2758 2759 2760 2761
			u16 count = le16_to_cpu(pSMBr->t2.DataCount);

			data_start = ((char *) &pSMBr->hdr.Protocol) +
					   le16_to_cpu(pSMBr->t2.DataOffset);
L
Linus Torvalds 已提交
2762

2763 2764 2765 2766 2767
			if (pSMBr->hdr.Flags2 & SMBFLG2_UNICODE)
				is_unicode = true;
			else
				is_unicode = false;

2768
			/* BB FIXME investigate remapping reserved chars here */
2769
			*symlinkinfo = cifs_strndup_from_ucs(data_start, count,
2770
						    is_unicode, nls_codepage);
2771
			if (!*symlinkinfo)
2772
				rc = -ENOMEM;
L
Linus Torvalds 已提交
2773 2774 2775 2776 2777 2778 2779 2780
		}
	}
	cifs_buf_release(pSMB);
	if (rc == -EAGAIN)
		goto querySymLinkRetry;
	return rc;
}

2781 2782 2783 2784 2785 2786 2787 2788 2789 2790 2791
#ifdef CONFIG_CIFS_SYMLINK_EXPERIMENTAL
/*
 *	Recent Windows versions now create symlinks more frequently
 *	and they use the "reparse point" mechanism below.  We can of course
 *	do symlinks nicely to Samba and other servers which support the
 *	CIFS Unix Extensions and we can also do SFU symlinks and "client only"
 *	"MF" symlinks optionally, but for recent Windows we really need to
 *	reenable the code below and fix the cifs_symlink callers to handle this.
 *	In the interim this code has been moved to its own config option so
 *	it is not compiled in by default until callers fixed up and more tested.
 */
L
Linus Torvalds 已提交
2792
int
2793
CIFSSMBQueryReparseLinkInfo(const int xid, struct cifs_tcon *tcon,
L
Linus Torvalds 已提交
2794
			const unsigned char *searchName,
2795
			char *symlinkinfo, const int buflen, __u16 fid,
L
Linus Torvalds 已提交
2796 2797 2798 2799
			const struct nls_table *nls_codepage)
{
	int rc = 0;
	int bytes_returned;
2800 2801
	struct smb_com_transaction_ioctl_req *pSMB;
	struct smb_com_transaction_ioctl_rsp *pSMBr;
L
Linus Torvalds 已提交
2802

2803
	cFYI(1, "In Windows reparse style QueryLink for path %s", searchName);
L
Linus Torvalds 已提交
2804 2805 2806 2807 2808 2809 2810 2811 2812
	rc = smb_init(SMB_COM_NT_TRANSACT, 23, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	pSMB->TotalParameterCount = 0 ;
	pSMB->TotalDataCount = 0;
	pSMB->MaxParameterCount = cpu_to_le32(2);
	/* BB find exact data count max from sess structure BB */
2813
	pSMB->MaxDataCount = cpu_to_le32(CIFSMaxBufSize & 0xFFFFFF00);
L
Linus Torvalds 已提交
2814 2815 2816 2817 2818 2819 2820 2821 2822 2823 2824 2825 2826 2827 2828 2829 2830
	pSMB->MaxSetupCount = 4;
	pSMB->Reserved = 0;
	pSMB->ParameterOffset = 0;
	pSMB->DataCount = 0;
	pSMB->DataOffset = 0;
	pSMB->SetupCount = 4;
	pSMB->SubCommand = cpu_to_le16(NT_TRANSACT_IOCTL);
	pSMB->ParameterCount = pSMB->TotalParameterCount;
	pSMB->FunctionCode = cpu_to_le32(FSCTL_GET_REPARSE_POINT);
	pSMB->IsFsctl = 1; /* FSCTL */
	pSMB->IsRootFlag = 0;
	pSMB->Fid = fid; /* file handle always le */
	pSMB->ByteCount = 0;

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
	if (rc) {
2831
		cFYI(1, "Send error in QueryReparseLinkInfo = %d", rc);
L
Linus Torvalds 已提交
2832 2833 2834
	} else {		/* decode response */
		__u32 data_offset = le32_to_cpu(pSMBr->DataOffset);
		__u32 data_count = le32_to_cpu(pSMBr->DataCount);
2835 2836
		if (get_bcc(&pSMBr->hdr) < 2 || data_offset > 512) {
			/* BB also check enough total bytes returned */
L
Linus Torvalds 已提交
2837
			rc = -EIO;	/* bad smb */
2838 2839 2840 2841
			goto qreparse_out;
		}
		if (data_count && (data_count < 2048)) {
			char *end_of_smb = 2 /* sizeof byte count */ +
2842
			       get_bcc(&pSMBr->hdr) + (char *)&pSMBr->ByteCount;
L
Linus Torvalds 已提交
2843

2844
			struct reparse_data *reparse_buf =
2845 2846 2847
						(struct reparse_data *)
						((char *)&pSMBr->hdr.Protocol
								 + data_offset);
2848 2849 2850 2851 2852 2853 2854
			if ((char *)reparse_buf >= end_of_smb) {
				rc = -EIO;
				goto qreparse_out;
			}
			if ((reparse_buf->LinkNamesBuf +
				reparse_buf->TargetNameOffset +
				reparse_buf->TargetNameLen) > end_of_smb) {
2855
				cFYI(1, "reparse buf beyond SMB");
2856 2857 2858
				rc = -EIO;
				goto qreparse_out;
			}
2859

2860 2861
			if (pSMBr->hdr.Flags2 & SMBFLG2_UNICODE) {
				cifs_from_ucs2(symlinkinfo, (__le16 *)
2862 2863
						(reparse_buf->LinkNamesBuf +
						reparse_buf->TargetNameOffset),
2864 2865 2866 2867 2868 2869 2870 2871 2872
						buflen,
						reparse_buf->TargetNameLen,
						nls_codepage, 0);
			} else { /* ASCII names */
				strncpy(symlinkinfo,
					reparse_buf->LinkNamesBuf +
					reparse_buf->TargetNameOffset,
					min_t(const int, buflen,
					   reparse_buf->TargetNameLen));
L
Linus Torvalds 已提交
2873
			}
2874 2875
		} else {
			rc = -EIO;
2876 2877
			cFYI(1, "Invalid return data count on "
				 "get reparse info ioctl");
L
Linus Torvalds 已提交
2878
		}
2879 2880
		symlinkinfo[buflen] = 0; /* just in case so the caller
					does not go off the end of the buffer */
2881
		cFYI(1, "readlink result - %s", symlinkinfo);
L
Linus Torvalds 已提交
2882
	}
S
Steve French 已提交
2883

L
Linus Torvalds 已提交
2884
qreparse_out:
2885
	cifs_buf_release(pSMB);
L
Linus Torvalds 已提交
2886 2887 2888 2889 2890 2891

	/* Note: On -EAGAIN error only caller can retry on handle based calls
		since file handle passed in no longer valid */

	return rc;
}
2892
#endif /* CIFS_SYMLINK_EXPERIMENTAL */ /* BB temporarily unused */
L
Linus Torvalds 已提交
2893 2894 2895 2896

#ifdef CONFIG_CIFS_POSIX

/*Convert an Access Control Entry from wire format to local POSIX xattr format*/
2897 2898
static void cifs_convert_ace(posix_acl_xattr_entry *ace,
			     struct cifs_posix_ace *cifs_ace)
L
Linus Torvalds 已提交
2899 2900
{
	/* u8 cifs fields do not need le conversion */
2901 2902 2903
	ace->e_perm = cpu_to_le16(cifs_ace->cifs_e_perm);
	ace->e_tag  = cpu_to_le16(cifs_ace->cifs_e_tag);
	ace->e_id   = cpu_to_le32(le64_to_cpu(cifs_ace->cifs_uid));
2904
	/* cFYI(1, "perm %d tag %d id %d",ace->e_perm,ace->e_tag,ace->e_id); */
L
Linus Torvalds 已提交
2905 2906 2907 2908 2909

	return;
}

/* Convert ACL from CIFS POSIX wire format to local Linux POSIX ACL xattr */
2910 2911
static int cifs_copy_posix_acl(char *trgt, char *src, const int buflen,
			       const int acl_type, const int size_of_data_area)
L
Linus Torvalds 已提交
2912 2913 2914 2915
{
	int size =  0;
	int i;
	__u16 count;
2916 2917 2918
	struct cifs_posix_ace *pACE;
	struct cifs_posix_acl *cifs_acl = (struct cifs_posix_acl *)src;
	posix_acl_xattr_header *local_acl = (posix_acl_xattr_header *)trgt;
L
Linus Torvalds 已提交
2919 2920 2921 2922

	if (le16_to_cpu(cifs_acl->version) != CIFS_ACL_VERSION)
		return -EOPNOTSUPP;

S
Steve French 已提交
2923
	if (acl_type & ACL_TYPE_ACCESS) {
L
Linus Torvalds 已提交
2924 2925 2926 2927 2928
		count = le16_to_cpu(cifs_acl->access_entry_count);
		pACE = &cifs_acl->ace_array[0];
		size = sizeof(struct cifs_posix_acl);
		size += sizeof(struct cifs_posix_ace) * count;
		/* check if we would go beyond end of SMB */
S
Steve French 已提交
2929
		if (size_of_data_area < size) {
2930 2931
			cFYI(1, "bad CIFS POSIX ACL size %d vs. %d",
				size_of_data_area, size);
L
Linus Torvalds 已提交
2932 2933
			return -EINVAL;
		}
S
Steve French 已提交
2934
	} else if (acl_type & ACL_TYPE_DEFAULT) {
L
Linus Torvalds 已提交
2935 2936 2937 2938 2939 2940 2941 2942
		count = le16_to_cpu(cifs_acl->access_entry_count);
		size = sizeof(struct cifs_posix_acl);
		size += sizeof(struct cifs_posix_ace) * count;
/* skip past access ACEs to get to default ACEs */
		pACE = &cifs_acl->ace_array[count];
		count = le16_to_cpu(cifs_acl->default_entry_count);
		size += sizeof(struct cifs_posix_ace) * count;
		/* check if we would go beyond end of SMB */
S
Steve French 已提交
2943
		if (size_of_data_area < size)
L
Linus Torvalds 已提交
2944 2945 2946 2947 2948 2949 2950
			return -EINVAL;
	} else {
		/* illegal type */
		return -EINVAL;
	}

	size = posix_acl_xattr_size(count);
S
Steve French 已提交
2951
	if ((buflen == 0) || (local_acl == NULL)) {
2952
		/* used to query ACL EA size */
S
Steve French 已提交
2953
	} else if (size > buflen) {
L
Linus Torvalds 已提交
2954 2955
		return -ERANGE;
	} else /* buffer big enough */ {
2956
		local_acl->a_version = cpu_to_le32(POSIX_ACL_XATTR_VERSION);
2957 2958 2959
		for (i = 0; i < count ; i++) {
			cifs_convert_ace(&local_acl->a_entries[i], pACE);
			pACE++;
L
Linus Torvalds 已提交
2960 2961 2962 2963 2964
		}
	}
	return size;
}

2965 2966
static __u16 convert_ace_to_cifs_ace(struct cifs_posix_ace *cifs_ace,
				     const posix_acl_xattr_entry *local_ace)
L
Linus Torvalds 已提交
2967 2968 2969
{
	__u16 rc = 0; /* 0 = ACL converted ok */

2970 2971
	cifs_ace->cifs_e_perm = le16_to_cpu(local_ace->e_perm);
	cifs_ace->cifs_e_tag =  le16_to_cpu(local_ace->e_tag);
L
Linus Torvalds 已提交
2972
	/* BB is there a better way to handle the large uid? */
S
Steve French 已提交
2973
	if (local_ace->e_id == cpu_to_le32(-1)) {
L
Linus Torvalds 已提交
2974 2975
	/* Probably no need to le convert -1 on any arch but can not hurt */
		cifs_ace->cifs_uid = cpu_to_le64(-1);
2976
	} else
2977
		cifs_ace->cifs_uid = cpu_to_le64(le32_to_cpu(local_ace->e_id));
2978
	/*cFYI(1, "perm %d tag %d id %d",ace->e_perm,ace->e_tag,ace->e_id);*/
L
Linus Torvalds 已提交
2979 2980 2981 2982
	return rc;
}

/* Convert ACL from local Linux POSIX xattr to CIFS POSIX ACL wire format */
2983 2984
static __u16 ACL_to_cifs_posix(char *parm_data, const char *pACL,
			       const int buflen, const int acl_type)
L
Linus Torvalds 已提交
2985 2986
{
	__u16 rc = 0;
2987 2988
	struct cifs_posix_acl *cifs_acl = (struct cifs_posix_acl *)parm_data;
	posix_acl_xattr_header *local_acl = (posix_acl_xattr_header *)pACL;
L
Linus Torvalds 已提交
2989 2990 2991
	int count;
	int i;

S
Steve French 已提交
2992
	if ((buflen == 0) || (pACL == NULL) || (cifs_acl == NULL))
L
Linus Torvalds 已提交
2993 2994 2995
		return 0;

	count = posix_acl_xattr_count((size_t)buflen);
2996
	cFYI(1, "setting acl with %d entries from buf of length %d and "
2997
		"version of %d",
2998
		count, buflen, le32_to_cpu(local_acl->a_version));
S
Steve French 已提交
2999
	if (le32_to_cpu(local_acl->a_version) != 2) {
3000 3001
		cFYI(1, "unknown POSIX ACL version %d",
		     le32_to_cpu(local_acl->a_version));
L
Linus Torvalds 已提交
3002 3003 3004
		return 0;
	}
	cifs_acl->version = cpu_to_le16(1);
S
Steve French 已提交
3005
	if (acl_type == ACL_TYPE_ACCESS)
3006
		cifs_acl->access_entry_count = cpu_to_le16(count);
S
Steve French 已提交
3007
	else if (acl_type == ACL_TYPE_DEFAULT)
3008
		cifs_acl->default_entry_count = cpu_to_le16(count);
L
Linus Torvalds 已提交
3009
	else {
3010
		cFYI(1, "unknown ACL type %d", acl_type);
L
Linus Torvalds 已提交
3011 3012
		return 0;
	}
3013
	for (i = 0; i < count; i++) {
L
Linus Torvalds 已提交
3014 3015
		rc = convert_ace_to_cifs_ace(&cifs_acl->ace_array[i],
					&local_acl->a_entries[i]);
S
Steve French 已提交
3016
		if (rc != 0) {
L
Linus Torvalds 已提交
3017 3018 3019 3020
			/* ACE not converted */
			break;
		}
	}
S
Steve French 已提交
3021
	if (rc == 0) {
L
Linus Torvalds 已提交
3022 3023 3024 3025 3026 3027 3028 3029
		rc = (__u16)(count * sizeof(struct cifs_posix_ace));
		rc += sizeof(struct cifs_posix_acl);
		/* BB add check to make sure ACL does not overflow SMB */
	}
	return rc;
}

int
3030
CIFSSMBGetPosixACL(const int xid, struct cifs_tcon *tcon,
3031 3032 3033
		   const unsigned char *searchName,
		   char *acl_inf, const int buflen, const int acl_type,
		   const struct nls_table *nls_codepage, int remap)
L
Linus Torvalds 已提交
3034 3035 3036 3037 3038 3039 3040 3041
{
/* SMB_QUERY_POSIX_ACL */
	TRANSACTION2_QPI_REQ *pSMB = NULL;
	TRANSACTION2_QPI_RSP *pSMBr = NULL;
	int rc = 0;
	int bytes_returned;
	int name_len;
	__u16 params, byte_count;
3042

3043
	cFYI(1, "In GetPosixACL (Unix) for path %s", searchName);
L
Linus Torvalds 已提交
3044 3045 3046 3047 3048 3049

queryAclRetry:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
		(void **) &pSMBr);
	if (rc)
		return rc;
3050

L
Linus Torvalds 已提交
3051 3052
	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		name_len =
3053
			cifsConvertToUCS((__le16 *) pSMB->FileName, searchName,
3054
					 PATH_MAX, nls_codepage, remap);
L
Linus Torvalds 已提交
3055 3056 3057 3058
		name_len++;     /* trailing null */
		name_len *= 2;
		pSMB->FileName[name_len] = 0;
		pSMB->FileName[name_len+1] = 0;
3059
	} else {	/* BB improve the check for buffer overruns BB */
L
Linus Torvalds 已提交
3060 3061 3062 3063 3064 3065 3066 3067
		name_len = strnlen(searchName, PATH_MAX);
		name_len++;     /* trailing null */
		strncpy(pSMB->FileName, searchName, name_len);
	}

	params = 2 /* level */  + 4 /* rsrvd */  + name_len /* incl null */ ;
	pSMB->TotalDataCount = 0;
	pSMB->MaxParameterCount = cpu_to_le16(2);
3068
	/* BB find exact max data count below from sess structure BB */
L
Linus Torvalds 已提交
3069 3070 3071 3072 3073 3074 3075
	pSMB->MaxDataCount = cpu_to_le16(4000);
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	pSMB->ParameterOffset = cpu_to_le16(
3076 3077
		offsetof(struct smb_com_transaction2_qpi_req,
			 InformationLevel) - 4);
L
Linus Torvalds 已提交
3078 3079 3080 3081 3082 3083 3084 3085 3086 3087
	pSMB->DataCount = 0;
	pSMB->DataOffset = 0;
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_QUERY_PATH_INFORMATION);
	byte_count = params + 1 /* pad */ ;
	pSMB->TotalParameterCount = cpu_to_le16(params);
	pSMB->ParameterCount = pSMB->TotalParameterCount;
	pSMB->InformationLevel = cpu_to_le16(SMB_QUERY_POSIX_ACL);
	pSMB->Reserved4 = 0;
3088
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
3089 3090 3091 3092
	pSMB->ByteCount = cpu_to_le16(byte_count);

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
		(struct smb_hdr *) pSMBr, &bytes_returned, 0);
3093
	cifs_stats_inc(&tcon->num_acl_get);
L
Linus Torvalds 已提交
3094
	if (rc) {
3095
		cFYI(1, "Send error in Query POSIX ACL = %d", rc);
L
Linus Torvalds 已提交
3096 3097
	} else {
		/* decode response */
3098

L
Linus Torvalds 已提交
3099 3100
		rc = validate_t2((struct smb_t2_rsp *)pSMBr);
		/* BB also check enough total bytes returned */
3101
		if (rc || get_bcc(&pSMBr->hdr) < 2)
L
Linus Torvalds 已提交
3102 3103 3104 3105 3106 3107
			rc = -EIO;      /* bad smb */
		else {
			__u16 data_offset = le16_to_cpu(pSMBr->t2.DataOffset);
			__u16 count = le16_to_cpu(pSMBr->t2.DataCount);
			rc = cifs_copy_posix_acl(acl_inf,
				(char *)&pSMBr->hdr.Protocol+data_offset,
3108
				buflen, acl_type, count);
L
Linus Torvalds 已提交
3109 3110 3111 3112 3113 3114 3115 3116 3117
		}
	}
	cifs_buf_release(pSMB);
	if (rc == -EAGAIN)
		goto queryAclRetry;
	return rc;
}

int
3118
CIFSSMBSetPosixACL(const int xid, struct cifs_tcon *tcon,
3119 3120 3121 3122
		   const unsigned char *fileName,
		   const char *local_acl, const int buflen,
		   const int acl_type,
		   const struct nls_table *nls_codepage, int remap)
L
Linus Torvalds 已提交
3123 3124 3125 3126 3127 3128 3129 3130 3131
{
	struct smb_com_transaction2_spi_req *pSMB = NULL;
	struct smb_com_transaction2_spi_rsp *pSMBr = NULL;
	char *parm_data;
	int name_len;
	int rc = 0;
	int bytes_returned = 0;
	__u16 params, byte_count, data_count, param_offset, offset;

3132
	cFYI(1, "In SetPosixACL (Unix) for path %s", fileName);
L
Linus Torvalds 已提交
3133 3134
setAclRetry:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
3135
		      (void **) &pSMBr);
L
Linus Torvalds 已提交
3136 3137 3138 3139
	if (rc)
		return rc;
	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		name_len =
3140
			cifsConvertToUCS((__le16 *) pSMB->FileName, fileName,
3141
				      PATH_MAX, nls_codepage, remap);
L
Linus Torvalds 已提交
3142 3143
		name_len++;     /* trailing null */
		name_len *= 2;
3144
	} else {	/* BB improve the check for buffer overruns BB */
L
Linus Torvalds 已提交
3145 3146 3147 3148 3149 3150
		name_len = strnlen(fileName, PATH_MAX);
		name_len++;     /* trailing null */
		strncpy(pSMB->FileName, fileName, name_len);
	}
	params = 6 + name_len;
	pSMB->MaxParameterCount = cpu_to_le16(2);
3151 3152
	/* BB find max SMB size from sess */
	pSMB->MaxDataCount = cpu_to_le16(1000);
L
Linus Torvalds 已提交
3153 3154 3155 3156 3157 3158
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	param_offset = offsetof(struct smb_com_transaction2_spi_req,
3159
				InformationLevel) - 4;
L
Linus Torvalds 已提交
3160 3161 3162 3163 3164
	offset = param_offset + params;
	parm_data = ((char *) &pSMB->hdr.Protocol) + offset;
	pSMB->ParameterOffset = cpu_to_le16(param_offset);

	/* convert to on the wire format for POSIX ACL */
3165
	data_count = ACL_to_cifs_posix(parm_data, local_acl, buflen, acl_type);
L
Linus Torvalds 已提交
3166

S
Steve French 已提交
3167
	if (data_count == 0) {
L
Linus Torvalds 已提交
3168 3169 3170 3171 3172 3173 3174 3175 3176 3177 3178 3179 3180 3181
		rc = -EOPNOTSUPP;
		goto setACLerrorExit;
	}
	pSMB->DataOffset = cpu_to_le16(offset);
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_SET_PATH_INFORMATION);
	pSMB->InformationLevel = cpu_to_le16(SMB_SET_POSIX_ACL);
	byte_count = 3 /* pad */  + params + data_count;
	pSMB->DataCount = cpu_to_le16(data_count);
	pSMB->TotalDataCount = pSMB->DataCount;
	pSMB->ParameterCount = cpu_to_le16(params);
	pSMB->TotalParameterCount = pSMB->ParameterCount;
	pSMB->Reserved4 = 0;
3182
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
3183 3184
	pSMB->ByteCount = cpu_to_le16(byte_count);
	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
3185
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
S
Steve French 已提交
3186
	if (rc)
3187
		cFYI(1, "Set POSIX ACL returned %d", rc);
L
Linus Torvalds 已提交
3188 3189 3190 3191 3192 3193 3194 3195

setACLerrorExit:
	cifs_buf_release(pSMB);
	if (rc == -EAGAIN)
		goto setAclRetry;
	return rc;
}

3196 3197
/* BB fix tabs in this function FIXME BB */
int
3198
CIFSGetExtAttr(const int xid, struct cifs_tcon *tcon,
S
Steve French 已提交
3199
	       const int netfid, __u64 *pExtAttrBits, __u64 *pMask)
3200
{
3201 3202 3203 3204 3205
	int rc = 0;
	struct smb_t2_qfi_req *pSMB = NULL;
	struct smb_t2_qfi_rsp *pSMBr = NULL;
	int bytes_returned;
	__u16 params, byte_count;
3206

3207
	cFYI(1, "In GetExtAttr");
S
Steve French 已提交
3208 3209
	if (tcon == NULL)
		return -ENODEV;
3210 3211

GetExtAttrRetry:
S
Steve French 已提交
3212 3213 3214 3215
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
			(void **) &pSMBr);
	if (rc)
		return rc;
3216

S
Steve French 已提交
3217
	params = 2 /* level */ + 2 /* fid */;
S
Steve French 已提交
3218 3219 3220 3221 3222 3223 3224 3225 3226 3227 3228 3229 3230 3231 3232 3233 3234 3235 3236 3237 3238
	pSMB->t2.TotalDataCount = 0;
	pSMB->t2.MaxParameterCount = cpu_to_le16(4);
	/* BB find exact max data count below from sess structure BB */
	pSMB->t2.MaxDataCount = cpu_to_le16(4000);
	pSMB->t2.MaxSetupCount = 0;
	pSMB->t2.Reserved = 0;
	pSMB->t2.Flags = 0;
	pSMB->t2.Timeout = 0;
	pSMB->t2.Reserved2 = 0;
	pSMB->t2.ParameterOffset = cpu_to_le16(offsetof(struct smb_t2_qfi_req,
					       Fid) - 4);
	pSMB->t2.DataCount = 0;
	pSMB->t2.DataOffset = 0;
	pSMB->t2.SetupCount = 1;
	pSMB->t2.Reserved3 = 0;
	pSMB->t2.SubCommand = cpu_to_le16(TRANS2_QUERY_FILE_INFORMATION);
	byte_count = params + 1 /* pad */ ;
	pSMB->t2.TotalParameterCount = cpu_to_le16(params);
	pSMB->t2.ParameterCount = pSMB->t2.TotalParameterCount;
	pSMB->InformationLevel = cpu_to_le16(SMB_QUERY_ATTR_FLAGS);
	pSMB->Pad = 0;
3239
	pSMB->Fid = netfid;
3240
	inc_rfc1001_len(pSMB, byte_count);
S
Steve French 已提交
3241 3242 3243 3244 3245
	pSMB->t2.ByteCount = cpu_to_le16(byte_count);

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
	if (rc) {
3246
		cFYI(1, "error %d in GetExtAttr", rc);
S
Steve French 已提交
3247 3248 3249 3250
	} else {
		/* decode response */
		rc = validate_t2((struct smb_t2_rsp *)pSMBr);
		/* BB also check enough total bytes returned */
3251
		if (rc || get_bcc(&pSMBr->hdr) < 2)
S
Steve French 已提交
3252 3253 3254 3255 3256 3257 3258 3259 3260
			/* If rc should we check for EOPNOSUPP and
			   disable the srvino flag? or in caller? */
			rc = -EIO;      /* bad smb */
		else {
			__u16 data_offset = le16_to_cpu(pSMBr->t2.DataOffset);
			__u16 count = le16_to_cpu(pSMBr->t2.DataCount);
			struct file_chattr_info *pfinfo;
			/* BB Do we need a cast or hash here ? */
			if (count != 16) {
3261
				cFYI(1, "Illegal size ret in GetExtAttr");
S
Steve French 已提交
3262 3263 3264 3265 3266 3267
				rc = -EIO;
				goto GetExtAttrOut;
			}
			pfinfo = (struct file_chattr_info *)
				 (data_offset + (char *) &pSMBr->hdr.Protocol);
			*pExtAttrBits = le64_to_cpu(pfinfo->mode);
3268
			*pMask = le64_to_cpu(pfinfo->mask);
S
Steve French 已提交
3269 3270
		}
	}
3271
GetExtAttrOut:
S
Steve French 已提交
3272 3273 3274 3275
	cifs_buf_release(pSMB);
	if (rc == -EAGAIN)
		goto GetExtAttrRetry;
	return rc;
3276 3277 3278
}

#endif /* CONFIG_POSIX */
L
Linus Torvalds 已提交
3279

J
Jeff Layton 已提交
3280 3281 3282 3283 3284 3285 3286 3287 3288 3289 3290
#ifdef CONFIG_CIFS_ACL
/*
 * Initialize NT TRANSACT SMB into small smb request buffer.  This assumes that
 * all NT TRANSACTS that we init here have total parm and data under about 400
 * bytes (to fit in small cifs buffer size), which is the case so far, it
 * easily fits. NB: Setup words themselves and ByteCount MaxSetupCount (size of
 * returned setup area) and MaxParameterCount (returned parms size) must be set
 * by caller
 */
static int
smb_init_nttransact(const __u16 sub_command, const int setup_count,
3291
		   const int parm_len, struct cifs_tcon *tcon,
J
Jeff Layton 已提交
3292 3293 3294 3295 3296 3297 3298 3299 3300 3301 3302 3303 3304 3305
		   void **ret_buf)
{
	int rc;
	__u32 temp_offset;
	struct smb_com_ntransact_req *pSMB;

	rc = small_smb_init(SMB_COM_NT_TRANSACT, 19 + setup_count, tcon,
				(void **)&pSMB);
	if (rc)
		return rc;
	*ret_buf = (void *)pSMB;
	pSMB->Reserved = 0;
	pSMB->TotalParameterCount = cpu_to_le32(parm_len);
	pSMB->TotalDataCount  = 0;
3306
	pSMB->MaxDataCount = cpu_to_le32(CIFSMaxBufSize & 0xFFFFFF00);
J
Jeff Layton 已提交
3307 3308 3309 3310 3311 3312 3313 3314 3315 3316 3317 3318 3319 3320 3321 3322 3323 3324
	pSMB->ParameterCount = pSMB->TotalParameterCount;
	pSMB->DataCount  = pSMB->TotalDataCount;
	temp_offset = offsetof(struct smb_com_ntransact_req, Parms) +
			(setup_count * 2) - 4 /* for rfc1001 length itself */;
	pSMB->ParameterOffset = cpu_to_le32(temp_offset);
	pSMB->DataOffset = cpu_to_le32(temp_offset + parm_len);
	pSMB->SetupCount = setup_count; /* no need to le convert byte fields */
	pSMB->SubCommand = cpu_to_le16(sub_command);
	return 0;
}

static int
validate_ntransact(char *buf, char **ppparm, char **ppdata,
		   __u32 *pparmlen, __u32 *pdatalen)
{
	char *end_of_smb;
	__u32 data_count, data_offset, parm_count, parm_offset;
	struct smb_com_ntransact_rsp *pSMBr;
3325
	u16 bcc;
J
Jeff Layton 已提交
3326 3327 3328 3329 3330 3331 3332 3333 3334

	*pdatalen = 0;
	*pparmlen = 0;

	if (buf == NULL)
		return -EINVAL;

	pSMBr = (struct smb_com_ntransact_rsp *)buf;

3335 3336
	bcc = get_bcc(&pSMBr->hdr);
	end_of_smb = 2 /* sizeof byte count */ + bcc +
J
Jeff Layton 已提交
3337 3338 3339 3340 3341 3342 3343 3344 3345 3346 3347 3348 3349 3350 3351 3352 3353 3354 3355 3356 3357 3358 3359 3360 3361
			(char *)&pSMBr->ByteCount;

	data_offset = le32_to_cpu(pSMBr->DataOffset);
	data_count = le32_to_cpu(pSMBr->DataCount);
	parm_offset = le32_to_cpu(pSMBr->ParameterOffset);
	parm_count = le32_to_cpu(pSMBr->ParameterCount);

	*ppparm = (char *)&pSMBr->hdr.Protocol + parm_offset;
	*ppdata = (char *)&pSMBr->hdr.Protocol + data_offset;

	/* should we also check that parm and data areas do not overlap? */
	if (*ppparm > end_of_smb) {
		cFYI(1, "parms start after end of smb");
		return -EINVAL;
	} else if (parm_count + *ppparm > end_of_smb) {
		cFYI(1, "parm end after end of smb");
		return -EINVAL;
	} else if (*ppdata > end_of_smb) {
		cFYI(1, "data starts after end of smb");
		return -EINVAL;
	} else if (data_count + *ppdata > end_of_smb) {
		cFYI(1, "data %p + count %d (%p) past smb end %p start %p",
			*ppdata, data_count, (data_count + *ppdata),
			end_of_smb, pSMBr);
		return -EINVAL;
3362
	} else if (parm_count + data_count > bcc) {
J
Jeff Layton 已提交
3363 3364 3365 3366 3367 3368 3369 3370
		cFYI(1, "parm count and data count larger than SMB");
		return -EINVAL;
	}
	*pdatalen = data_count;
	*pparmlen = parm_count;
	return 0;
}

3371 3372
/* Get Security Descriptor (by handle) from remote server for a file or dir */
int
3373
CIFSSMBGetCIFSACL(const int xid, struct cifs_tcon *tcon, __u16 fid,
S
Steve French 已提交
3374
		  struct cifs_ntsd **acl_inf, __u32 *pbuflen)
3375 3376 3377
{
	int rc = 0;
	int buf_type = 0;
S
Steve French 已提交
3378
	QUERY_SEC_DESC_REQ *pSMB;
3379 3380
	struct kvec iov[1];

3381
	cFYI(1, "GetCifsACL");
3382

S
Steve French 已提交
3383 3384 3385
	*pbuflen = 0;
	*acl_inf = NULL;

S
Steve French 已提交
3386
	rc = smb_init_nttransact(NT_TRANSACT_QUERY_SECURITY_DESC, 0,
3387 3388 3389 3390 3391 3392 3393 3394 3395 3396 3397
			8 /* parm len */, tcon, (void **) &pSMB);
	if (rc)
		return rc;

	pSMB->MaxParameterCount = cpu_to_le32(4);
	/* BB TEST with big acls that might need to be e.g. larger than 16K */
	pSMB->MaxSetupCount = 0;
	pSMB->Fid = fid; /* file handle always le */
	pSMB->AclFlags = cpu_to_le32(CIFS_ACL_OWNER | CIFS_ACL_GROUP |
				     CIFS_ACL_DACL);
	pSMB->ByteCount = cpu_to_le16(11); /* 3 bytes pad + 8 bytes parm */
3398
	inc_rfc1001_len(pSMB, 11);
3399
	iov[0].iov_base = (char *)pSMB;
3400
	iov[0].iov_len = be32_to_cpu(pSMB->hdr.smb_buf_length) + 4;
3401

3402
	rc = SendReceive2(xid, tcon->ses, iov, 1 /* num iovec */, &buf_type,
3403
			 0);
3404 3405
	cifs_stats_inc(&tcon->num_acl_get);
	if (rc) {
3406
		cFYI(1, "Send error in QuerySecDesc = %d", rc);
3407
	} else {                /* decode response */
S
Steve French 已提交
3408
		__le32 *parm;
S
Steve French 已提交
3409 3410
		__u32 parm_len;
		__u32 acl_len;
3411
		struct smb_com_ntransact_rsp *pSMBr;
S
Steve French 已提交
3412
		char *pdata;
3413 3414

/* validate_nttransact */
3415
		rc = validate_ntransact(iov[0].iov_base, (char **)&parm,
S
Steve French 已提交
3416
					&pdata, &parm_len, pbuflen);
S
Steve French 已提交
3417
		if (rc)
3418 3419 3420
			goto qsec_out;
		pSMBr = (struct smb_com_ntransact_rsp *)iov[0].iov_base;

3421
		cFYI(1, "smb %p parm %p data %p", pSMBr, parm, *acl_inf);
3422 3423 3424

		if (le32_to_cpu(pSMBr->ParameterCount) != 4) {
			rc = -EIO;      /* bad smb */
S
Steve French 已提交
3425
			*pbuflen = 0;
3426 3427 3428 3429 3430
			goto qsec_out;
		}

/* BB check that data area is minimum length and as big as acl_len */

3431
		acl_len = le32_to_cpu(*parm);
S
Steve French 已提交
3432
		if (acl_len != *pbuflen) {
3433 3434
			cERROR(1, "acl length %d does not match %d",
				   acl_len, *pbuflen);
S
Steve French 已提交
3435 3436 3437
			if (*pbuflen > acl_len)
				*pbuflen = acl_len;
		}
3438

S
Steve French 已提交
3439 3440 3441 3442
		/* check if buffer is big enough for the acl
		   header followed by the smallest SID */
		if ((*pbuflen < sizeof(struct cifs_ntsd) + 8) ||
		    (*pbuflen >= 64 * 1024)) {
3443
			cERROR(1, "bad acl length %d", *pbuflen);
S
Steve French 已提交
3444 3445 3446 3447 3448 3449 3450 3451 3452 3453
			rc = -EINVAL;
			*pbuflen = 0;
		} else {
			*acl_inf = kmalloc(*pbuflen, GFP_KERNEL);
			if (*acl_inf == NULL) {
				*pbuflen = 0;
				rc = -ENOMEM;
			}
			memcpy(*acl_inf, pdata, *pbuflen);
		}
3454 3455
	}
qsec_out:
S
Steve French 已提交
3456
	if (buf_type == CIFS_SMALL_BUFFER)
3457
		cifs_small_buf_release(iov[0].iov_base);
S
Steve French 已提交
3458
	else if (buf_type == CIFS_LARGE_BUFFER)
3459
		cifs_buf_release(iov[0].iov_base);
3460
/*	cifs_small_buf_release(pSMB); */ /* Freed earlier now in SendReceive2 */
3461 3462
	return rc;
}
3463 3464

int
3465
CIFSSMBSetCIFSACL(const int xid, struct cifs_tcon *tcon, __u16 fid,
3466 3467 3468 3469 3470 3471 3472 3473 3474 3475 3476 3477 3478 3479 3480 3481 3482 3483 3484 3485 3486 3487 3488 3489 3490 3491 3492 3493 3494 3495 3496 3497 3498 3499 3500 3501 3502 3503 3504 3505 3506 3507 3508
			struct cifs_ntsd *pntsd, __u32 acllen)
{
	__u16 byte_count, param_count, data_count, param_offset, data_offset;
	int rc = 0;
	int bytes_returned = 0;
	SET_SEC_DESC_REQ *pSMB = NULL;
	NTRANSACT_RSP *pSMBr = NULL;

setCifsAclRetry:
	rc = smb_init(SMB_COM_NT_TRANSACT, 19, tcon, (void **) &pSMB,
			(void **) &pSMBr);
	if (rc)
			return (rc);

	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;

	param_count = 8;
	param_offset = offsetof(struct smb_com_transaction_ssec_req, Fid) - 4;
	data_count = acllen;
	data_offset = param_offset + param_count;
	byte_count = 3 /* pad */  + param_count;

	pSMB->DataCount = cpu_to_le32(data_count);
	pSMB->TotalDataCount = pSMB->DataCount;
	pSMB->MaxParameterCount = cpu_to_le32(4);
	pSMB->MaxDataCount = cpu_to_le32(16384);
	pSMB->ParameterCount = cpu_to_le32(param_count);
	pSMB->ParameterOffset = cpu_to_le32(param_offset);
	pSMB->TotalParameterCount = pSMB->ParameterCount;
	pSMB->DataOffset = cpu_to_le32(data_offset);
	pSMB->SetupCount = 0;
	pSMB->SubCommand = cpu_to_le16(NT_TRANSACT_SET_SECURITY_DESC);
	pSMB->ByteCount = cpu_to_le16(byte_count+data_count);

	pSMB->Fid = fid; /* file handle always le */
	pSMB->Reserved2 = 0;
	pSMB->AclFlags = cpu_to_le32(CIFS_ACL_DACL);

	if (pntsd && acllen) {
		memcpy((char *) &pSMBr->hdr.Protocol + data_offset,
			(char *) pntsd,
			acllen);
3509
		inc_rfc1001_len(pSMB, byte_count + data_count);
3510
	} else
3511
		inc_rfc1001_len(pSMB, byte_count);
3512 3513 3514 3515

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
		(struct smb_hdr *) pSMBr, &bytes_returned, 0);

3516
	cFYI(1, "SetCIFSACL bytes_returned: %d, rc: %d", bytes_returned, rc);
3517
	if (rc)
3518
		cFYI(1, "Set CIFS ACL returned %d", rc);
3519 3520 3521 3522 3523 3524 3525 3526
	cifs_buf_release(pSMB);

	if (rc == -EAGAIN)
		goto setCifsAclRetry;

	return (rc);
}

J
Jeff Layton 已提交
3527
#endif /* CONFIG_CIFS_ACL */
3528

3529 3530
/* Legacy Query Path Information call for lookup to old servers such
   as Win9x/WinME */
3531
int SMBQueryInformation(const int xid, struct cifs_tcon *tcon,
3532 3533 3534
			const unsigned char *searchName,
			FILE_ALL_INFO *pFinfo,
			const struct nls_table *nls_codepage, int remap)
3535
{
S
Steve French 已提交
3536 3537
	QUERY_INFORMATION_REQ *pSMB;
	QUERY_INFORMATION_RSP *pSMBr;
3538 3539 3540 3541
	int rc = 0;
	int bytes_returned;
	int name_len;

3542
	cFYI(1, "In SMBQPath path %s", searchName);
3543 3544
QInfRetry:
	rc = smb_init(SMB_COM_QUERY_INFORMATION, 0, tcon, (void **) &pSMB,
3545
		      (void **) &pSMBr);
3546 3547 3548 3549 3550
	if (rc)
		return rc;

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		name_len =
3551 3552
			cifsConvertToUCS((__le16 *) pSMB->FileName, searchName,
					PATH_MAX, nls_codepage, remap);
3553 3554
		name_len++;     /* trailing null */
		name_len *= 2;
3555
	} else {
3556 3557 3558 3559 3560
		name_len = strnlen(searchName, PATH_MAX);
		name_len++;     /* trailing null */
		strncpy(pSMB->FileName, searchName, name_len);
	}
	pSMB->BufferFormat = 0x04;
3561
	name_len++; /* account for buffer type byte */
3562
	inc_rfc1001_len(pSMB, (__u16)name_len);
3563 3564 3565
	pSMB->ByteCount = cpu_to_le16(name_len);

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
3566
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
3567
	if (rc) {
3568
		cFYI(1, "Send error in QueryInfo = %d", rc);
S
Steve French 已提交
3569
	} else if (pFinfo) {
3570 3571
		struct timespec ts;
		__u32 time = le32_to_cpu(pSMBr->last_write_time);
S
Steve French 已提交
3572 3573

		/* decode response */
3574
		/* BB FIXME - add time zone adjustment BB */
3575
		memset(pFinfo, 0, sizeof(FILE_ALL_INFO));
3576 3577 3578
		ts.tv_nsec = 0;
		ts.tv_sec = time;
		/* decode time fields */
A
Al Viro 已提交
3579
		pFinfo->ChangeTime = cpu_to_le64(cifs_UnixTimeToNT(ts));
3580 3581
		pFinfo->LastWriteTime = pFinfo->ChangeTime;
		pFinfo->LastAccessTime = 0;
3582 3583 3584 3585 3586
		pFinfo->AllocationSize =
			cpu_to_le64(le32_to_cpu(pSMBr->size));
		pFinfo->EndOfFile = pFinfo->AllocationSize;
		pFinfo->Attributes =
			cpu_to_le32(le16_to_cpu(pSMBr->attr));
3587 3588 3589 3590 3591 3592 3593 3594 3595 3596 3597
	} else
		rc = -EIO; /* bad buffer passed in */

	cifs_buf_release(pSMB);

	if (rc == -EAGAIN)
		goto QInfRetry;

	return rc;
}

3598
int
3599
CIFSSMBQFileInfo(const int xid, struct cifs_tcon *tcon,
3600 3601 3602 3603 3604 3605 3606 3607 3608 3609 3610 3611 3612 3613 3614 3615 3616 3617 3618 3619 3620 3621 3622 3623 3624 3625 3626 3627 3628 3629 3630 3631 3632 3633 3634 3635 3636
		 u16 netfid, FILE_ALL_INFO *pFindData)
{
	struct smb_t2_qfi_req *pSMB = NULL;
	struct smb_t2_qfi_rsp *pSMBr = NULL;
	int rc = 0;
	int bytes_returned;
	__u16 params, byte_count;

QFileInfoRetry:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	params = 2 /* level */ + 2 /* fid */;
	pSMB->t2.TotalDataCount = 0;
	pSMB->t2.MaxParameterCount = cpu_to_le16(4);
	/* BB find exact max data count below from sess structure BB */
	pSMB->t2.MaxDataCount = cpu_to_le16(CIFSMaxBufSize);
	pSMB->t2.MaxSetupCount = 0;
	pSMB->t2.Reserved = 0;
	pSMB->t2.Flags = 0;
	pSMB->t2.Timeout = 0;
	pSMB->t2.Reserved2 = 0;
	pSMB->t2.ParameterOffset = cpu_to_le16(offsetof(struct smb_t2_qfi_req,
					       Fid) - 4);
	pSMB->t2.DataCount = 0;
	pSMB->t2.DataOffset = 0;
	pSMB->t2.SetupCount = 1;
	pSMB->t2.Reserved3 = 0;
	pSMB->t2.SubCommand = cpu_to_le16(TRANS2_QUERY_FILE_INFORMATION);
	byte_count = params + 1 /* pad */ ;
	pSMB->t2.TotalParameterCount = cpu_to_le16(params);
	pSMB->t2.ParameterCount = pSMB->t2.TotalParameterCount;
	pSMB->InformationLevel = cpu_to_le16(SMB_QUERY_FILE_ALL_INFO);
	pSMB->Pad = 0;
	pSMB->Fid = netfid;
3637
	inc_rfc1001_len(pSMB, byte_count);
3638

3639 3640 3641
	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
	if (rc) {
3642
		cFYI(1, "Send error in QPathInfo = %d", rc);
3643 3644
	} else {		/* decode response */
		rc = validate_t2((struct smb_t2_rsp *)pSMBr);
3645

3646 3647
		if (rc) /* BB add auto retry on EOPNOTSUPP? */
			rc = -EIO;
3648
		else if (get_bcc(&pSMBr->hdr) < 40)
3649 3650 3651 3652 3653 3654 3655 3656 3657 3658 3659 3660
			rc = -EIO;	/* bad smb */
		else if (pFindData) {
			__u16 data_offset = le16_to_cpu(pSMBr->t2.DataOffset);
			memcpy((char *) pFindData,
			       (char *) &pSMBr->hdr.Protocol +
			       data_offset, sizeof(FILE_ALL_INFO));
		} else
		    rc = -ENOMEM;
	}
	cifs_buf_release(pSMB);
	if (rc == -EAGAIN)
		goto QFileInfoRetry;
3661

3662 3663
	return rc;
}
3664

L
Linus Torvalds 已提交
3665
int
3666
CIFSSMBQPathInfo(const int xid, struct cifs_tcon *tcon,
L
Linus Torvalds 已提交
3667
		 const unsigned char *searchName,
S
Steve French 已提交
3668
		 FILE_ALL_INFO *pFindData,
3669
		 int legacy /* old style infolevel */,
3670
		 const struct nls_table *nls_codepage, int remap)
L
Linus Torvalds 已提交
3671 3672 3673 3674 3675 3676 3677 3678 3679
{
/* level 263 SMB_QUERY_FILE_ALL_INFO */
	TRANSACTION2_QPI_REQ *pSMB = NULL;
	TRANSACTION2_QPI_RSP *pSMBr = NULL;
	int rc = 0;
	int bytes_returned;
	int name_len;
	__u16 params, byte_count;

3680
/* cFYI(1, "In QPathInfo path %s", searchName); */
L
Linus Torvalds 已提交
3681 3682 3683 3684 3685 3686 3687 3688
QPathInfoRetry:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		name_len =
3689
		    cifsConvertToUCS((__le16 *) pSMB->FileName, searchName,
3690
				     PATH_MAX, nls_codepage, remap);
L
Linus Torvalds 已提交
3691 3692
		name_len++;	/* trailing null */
		name_len *= 2;
3693
	} else {	/* BB improve the check for buffer overruns BB */
L
Linus Torvalds 已提交
3694 3695 3696 3697 3698
		name_len = strnlen(searchName, PATH_MAX);
		name_len++;	/* trailing null */
		strncpy(pSMB->FileName, searchName, name_len);
	}

3699
	params = 2 /* level */ + 4 /* reserved */ + name_len /* includes NUL */;
L
Linus Torvalds 已提交
3700 3701
	pSMB->TotalDataCount = 0;
	pSMB->MaxParameterCount = cpu_to_le16(2);
3702 3703
	/* BB find exact max SMB PDU from sess structure BB */
	pSMB->MaxDataCount = cpu_to_le16(4000);
L
Linus Torvalds 已提交
3704 3705 3706 3707 3708 3709
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	pSMB->ParameterOffset = cpu_to_le16(offsetof(
3710
	struct smb_com_transaction2_qpi_req, InformationLevel) - 4);
L
Linus Torvalds 已提交
3711 3712 3713 3714 3715 3716 3717 3718
	pSMB->DataCount = 0;
	pSMB->DataOffset = 0;
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_QUERY_PATH_INFORMATION);
	byte_count = params + 1 /* pad */ ;
	pSMB->TotalParameterCount = cpu_to_le16(params);
	pSMB->ParameterCount = pSMB->TotalParameterCount;
S
Steve French 已提交
3719
	if (legacy)
3720 3721 3722
		pSMB->InformationLevel = cpu_to_le16(SMB_INFO_STANDARD);
	else
		pSMB->InformationLevel = cpu_to_le16(SMB_QUERY_FILE_ALL_INFO);
L
Linus Torvalds 已提交
3723
	pSMB->Reserved4 = 0;
3724
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
3725 3726 3727 3728 3729
	pSMB->ByteCount = cpu_to_le16(byte_count);

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
	if (rc) {
3730
		cFYI(1, "Send error in QPathInfo = %d", rc);
L
Linus Torvalds 已提交
3731 3732 3733
	} else {		/* decode response */
		rc = validate_t2((struct smb_t2_rsp *)pSMBr);

3734 3735
		if (rc) /* BB add auto retry on EOPNOTSUPP? */
			rc = -EIO;
3736
		else if (!legacy && get_bcc(&pSMBr->hdr) < 40)
L
Linus Torvalds 已提交
3737
			rc = -EIO;	/* bad smb */
3738
		else if (legacy && get_bcc(&pSMBr->hdr) < 24)
3739 3740 3741
			rc = -EIO;  /* 24 or 26 expected but we do not read
					last field */
		else if (pFindData) {
3742
			int size;
L
Linus Torvalds 已提交
3743
			__u16 data_offset = le16_to_cpu(pSMBr->t2.DataOffset);
S
Steve French 已提交
3744 3745 3746 3747 3748 3749

			/* On legacy responses we do not read the last field,
			EAsize, fortunately since it varies by subdialect and
			also note it differs on Set vs. Get, ie two bytes or 4
			bytes depending but we don't care here */
			if (legacy)
3750 3751 3752
				size = sizeof(FILE_INFO_STANDARD);
			else
				size = sizeof(FILE_ALL_INFO);
L
Linus Torvalds 已提交
3753 3754
			memcpy((char *) pFindData,
			       (char *) &pSMBr->hdr.Protocol +
3755
			       data_offset, size);
L
Linus Torvalds 已提交
3756 3757 3758 3759 3760 3761 3762 3763 3764 3765
		} else
		    rc = -ENOMEM;
	}
	cifs_buf_release(pSMB);
	if (rc == -EAGAIN)
		goto QPathInfoRetry;

	return rc;
}

3766
int
3767
CIFSSMBUnixQFileInfo(const int xid, struct cifs_tcon *tcon,
3768 3769 3770 3771 3772 3773 3774 3775 3776 3777 3778 3779 3780 3781 3782 3783 3784 3785 3786 3787 3788 3789 3790 3791 3792 3793 3794 3795 3796 3797 3798 3799 3800 3801 3802 3803 3804
		 u16 netfid, FILE_UNIX_BASIC_INFO *pFindData)
{
	struct smb_t2_qfi_req *pSMB = NULL;
	struct smb_t2_qfi_rsp *pSMBr = NULL;
	int rc = 0;
	int bytes_returned;
	__u16 params, byte_count;

UnixQFileInfoRetry:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	params = 2 /* level */ + 2 /* fid */;
	pSMB->t2.TotalDataCount = 0;
	pSMB->t2.MaxParameterCount = cpu_to_le16(4);
	/* BB find exact max data count below from sess structure BB */
	pSMB->t2.MaxDataCount = cpu_to_le16(CIFSMaxBufSize);
	pSMB->t2.MaxSetupCount = 0;
	pSMB->t2.Reserved = 0;
	pSMB->t2.Flags = 0;
	pSMB->t2.Timeout = 0;
	pSMB->t2.Reserved2 = 0;
	pSMB->t2.ParameterOffset = cpu_to_le16(offsetof(struct smb_t2_qfi_req,
					       Fid) - 4);
	pSMB->t2.DataCount = 0;
	pSMB->t2.DataOffset = 0;
	pSMB->t2.SetupCount = 1;
	pSMB->t2.Reserved3 = 0;
	pSMB->t2.SubCommand = cpu_to_le16(TRANS2_QUERY_FILE_INFORMATION);
	byte_count = params + 1 /* pad */ ;
	pSMB->t2.TotalParameterCount = cpu_to_le16(params);
	pSMB->t2.ParameterCount = pSMB->t2.TotalParameterCount;
	pSMB->InformationLevel = cpu_to_le16(SMB_QUERY_FILE_UNIX_BASIC);
	pSMB->Pad = 0;
	pSMB->Fid = netfid;
3805
	inc_rfc1001_len(pSMB, byte_count);
3806 3807 3808 3809

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
	if (rc) {
3810
		cFYI(1, "Send error in QPathInfo = %d", rc);
3811 3812 3813
	} else {		/* decode response */
		rc = validate_t2((struct smb_t2_rsp *)pSMBr);

3814
		if (rc || get_bcc(&pSMBr->hdr) < sizeof(FILE_UNIX_BASIC_INFO)) {
3815
			cERROR(1, "Malformed FILE_UNIX_BASIC_INFO response.\n"
3816
				   "Unix Extensions can be disabled on mount "
3817
				   "by specifying the nosfu mount option.");
3818 3819 3820 3821 3822 3823 3824 3825 3826 3827 3828 3829 3830 3831 3832 3833 3834
			rc = -EIO;	/* bad smb */
		} else {
			__u16 data_offset = le16_to_cpu(pSMBr->t2.DataOffset);
			memcpy((char *) pFindData,
			       (char *) &pSMBr->hdr.Protocol +
			       data_offset,
			       sizeof(FILE_UNIX_BASIC_INFO));
		}
	}

	cifs_buf_release(pSMB);
	if (rc == -EAGAIN)
		goto UnixQFileInfoRetry;

	return rc;
}

L
Linus Torvalds 已提交
3835
int
3836
CIFSSMBUnixQPathInfo(const int xid, struct cifs_tcon *tcon,
L
Linus Torvalds 已提交
3837
		     const unsigned char *searchName,
3838
		     FILE_UNIX_BASIC_INFO *pFindData,
3839
		     const struct nls_table *nls_codepage, int remap)
L
Linus Torvalds 已提交
3840 3841 3842 3843 3844 3845 3846 3847 3848
{
/* SMB_QUERY_FILE_UNIX_BASIC */
	TRANSACTION2_QPI_REQ *pSMB = NULL;
	TRANSACTION2_QPI_RSP *pSMBr = NULL;
	int rc = 0;
	int bytes_returned = 0;
	int name_len;
	__u16 params, byte_count;

3849
	cFYI(1, "In QPathInfo (Unix) the path %s", searchName);
L
Linus Torvalds 已提交
3850 3851 3852 3853 3854 3855 3856 3857
UnixQPathInfoRetry:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		name_len =
3858
		    cifsConvertToUCS((__le16 *) pSMB->FileName, searchName,
3859
				  PATH_MAX, nls_codepage, remap);
L
Linus Torvalds 已提交
3860 3861
		name_len++;	/* trailing null */
		name_len *= 2;
3862
	} else {	/* BB improve the check for buffer overruns BB */
L
Linus Torvalds 已提交
3863 3864 3865 3866 3867
		name_len = strnlen(searchName, PATH_MAX);
		name_len++;	/* trailing null */
		strncpy(pSMB->FileName, searchName, name_len);
	}

3868
	params = 2 /* level */ + 4 /* reserved */ + name_len /* includes NUL */;
L
Linus Torvalds 已提交
3869 3870 3871
	pSMB->TotalDataCount = 0;
	pSMB->MaxParameterCount = cpu_to_le16(2);
	/* BB find exact max SMB PDU from sess structure BB */
3872
	pSMB->MaxDataCount = cpu_to_le16(4000);
L
Linus Torvalds 已提交
3873 3874 3875 3876 3877 3878
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	pSMB->ParameterOffset = cpu_to_le16(offsetof(
3879
	struct smb_com_transaction2_qpi_req, InformationLevel) - 4);
L
Linus Torvalds 已提交
3880 3881 3882 3883 3884 3885 3886 3887 3888 3889
	pSMB->DataCount = 0;
	pSMB->DataOffset = 0;
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_QUERY_PATH_INFORMATION);
	byte_count = params + 1 /* pad */ ;
	pSMB->TotalParameterCount = cpu_to_le16(params);
	pSMB->ParameterCount = pSMB->TotalParameterCount;
	pSMB->InformationLevel = cpu_to_le16(SMB_QUERY_FILE_UNIX_BASIC);
	pSMB->Reserved4 = 0;
3890
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
3891 3892 3893 3894 3895
	pSMB->ByteCount = cpu_to_le16(byte_count);

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
	if (rc) {
3896
		cFYI(1, "Send error in QPathInfo = %d", rc);
L
Linus Torvalds 已提交
3897 3898 3899
	} else {		/* decode response */
		rc = validate_t2((struct smb_t2_rsp *)pSMBr);

3900
		if (rc || get_bcc(&pSMBr->hdr) < sizeof(FILE_UNIX_BASIC_INFO)) {
3901
			cERROR(1, "Malformed FILE_UNIX_BASIC_INFO response.\n"
3902
				   "Unix Extensions can be disabled on mount "
3903
				   "by specifying the nosfu mount option.");
L
Linus Torvalds 已提交
3904 3905 3906 3907 3908 3909
			rc = -EIO;	/* bad smb */
		} else {
			__u16 data_offset = le16_to_cpu(pSMBr->t2.DataOffset);
			memcpy((char *) pFindData,
			       (char *) &pSMBr->hdr.Protocol +
			       data_offset,
S
Steve French 已提交
3910
			       sizeof(FILE_UNIX_BASIC_INFO));
L
Linus Torvalds 已提交
3911 3912 3913 3914 3915 3916 3917 3918 3919 3920 3921
		}
	}
	cifs_buf_release(pSMB);
	if (rc == -EAGAIN)
		goto UnixQPathInfoRetry;

	return rc;
}

/* xid, tcon, searchName and codepage are input parms, rest are returned */
int
3922
CIFSFindFirst(const int xid, struct cifs_tcon *tcon,
3923
	      const char *searchName,
L
Linus Torvalds 已提交
3924
	      const struct nls_table *nls_codepage,
3925 3926
	      __u16 *pnetfid,
	      struct cifs_search_info *psrch_inf, int remap, const char dirsep)
L
Linus Torvalds 已提交
3927 3928 3929 3930
{
/* level 257 SMB_ */
	TRANSACTION2_FFIRST_REQ *pSMB = NULL;
	TRANSACTION2_FFIRST_RSP *pSMBr = NULL;
S
Steve French 已提交
3931
	T2_FFIRST_RSP_PARMS *parms;
L
Linus Torvalds 已提交
3932 3933 3934 3935 3936
	int rc = 0;
	int bytes_returned = 0;
	int name_len;
	__u16 params, byte_count;

3937
	cFYI(1, "In FindFirst for %s", searchName);
L
Linus Torvalds 已提交
3938 3939 3940 3941 3942 3943 3944 3945 3946

findFirstRetry:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		name_len =
3947
		    cifsConvertToUCS((__le16 *) pSMB->FileName, searchName,
3948 3949 3950 3951
				 PATH_MAX, nls_codepage, remap);
		/* We can not add the asterik earlier in case
		it got remapped to 0xF03A as if it were part of the
		directory name instead of a wildcard */
L
Linus Torvalds 已提交
3952
		name_len *= 2;
3953
		pSMB->FileName[name_len] = dirsep;
3954 3955 3956 3957
		pSMB->FileName[name_len+1] = 0;
		pSMB->FileName[name_len+2] = '*';
		pSMB->FileName[name_len+3] = 0;
		name_len += 4; /* now the trailing null */
L
Linus Torvalds 已提交
3958 3959
		pSMB->FileName[name_len] = 0; /* null terminate just in case */
		pSMB->FileName[name_len+1] = 0;
3960
		name_len += 2;
L
Linus Torvalds 已提交
3961 3962 3963
	} else {	/* BB add check for overrun of SMB buf BB */
		name_len = strnlen(searchName, PATH_MAX);
/* BB fix here and in unicode clause above ie
S
Steve French 已提交
3964
		if (name_len > buffersize-header)
L
Linus Torvalds 已提交
3965 3966
			free buffer exit; BB */
		strncpy(pSMB->FileName, searchName, name_len);
3967
		pSMB->FileName[name_len] = dirsep;
3968 3969 3970
		pSMB->FileName[name_len+1] = '*';
		pSMB->FileName[name_len+2] = 0;
		name_len += 3;
L
Linus Torvalds 已提交
3971 3972 3973 3974 3975
	}

	params = 12 + name_len /* includes null */ ;
	pSMB->TotalDataCount = 0;	/* no EAs */
	pSMB->MaxParameterCount = cpu_to_le16(10);
3976
	pSMB->MaxDataCount = cpu_to_le16(CIFSMaxBufSize & 0xFFFFFF00);
L
Linus Torvalds 已提交
3977 3978 3979 3980 3981 3982 3983 3984 3985
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	byte_count = params + 1 /* pad */ ;
	pSMB->TotalParameterCount = cpu_to_le16(params);
	pSMB->ParameterCount = pSMB->TotalParameterCount;
	pSMB->ParameterOffset = cpu_to_le16(
3986 3987
	      offsetof(struct smb_com_transaction2_ffirst_req, SearchAttributes)
		- 4);
L
Linus Torvalds 已提交
3988 3989 3990 3991 3992 3993 3994 3995
	pSMB->DataCount = 0;
	pSMB->DataOffset = 0;
	pSMB->SetupCount = 1;	/* one byte, no need to make endian neutral */
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_FIND_FIRST);
	pSMB->SearchAttributes =
	    cpu_to_le16(ATTR_READONLY | ATTR_HIDDEN | ATTR_SYSTEM |
			ATTR_DIRECTORY);
3996 3997
	pSMB->SearchCount = cpu_to_le16(CIFSMaxBufSize/sizeof(FILE_UNIX_INFO));
	pSMB->SearchFlags = cpu_to_le16(CIFS_SEARCH_CLOSE_AT_END |
L
Linus Torvalds 已提交
3998 3999 4000 4001 4002
		CIFS_SEARCH_RETURN_RESUME);
	pSMB->InformationLevel = cpu_to_le16(psrch_inf->info_level);

	/* BB what should we set StorageType to? Does it matter? BB */
	pSMB->SearchStorageType = 0;
4003
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
4004 4005 4006 4007
	pSMB->ByteCount = cpu_to_le16(byte_count);

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
4008
	cifs_stats_inc(&tcon->num_ffirst);
L
Linus Torvalds 已提交
4009

4010 4011
	if (rc) {/* BB add logic to retry regular search if Unix search
			rejected unexpectedly by server */
L
Linus Torvalds 已提交
4012
		/* BB Add code to handle unsupported level rc */
4013
		cFYI(1, "Error in FindFirst = %d", rc);
4014

4015
		cifs_buf_release(pSMB);
L
Linus Torvalds 已提交
4016 4017 4018 4019 4020 4021 4022 4023

		/* BB eventually could optimize out free and realloc of buf */
		/*    for this case */
		if (rc == -EAGAIN)
			goto findFirstRetry;
	} else { /* decode response */
		/* BB remember to free buffer if error BB */
		rc = validate_t2((struct smb_t2_rsp *)pSMBr);
S
Steve French 已提交
4024
		if (rc == 0) {
4025 4026
			unsigned int lnoff;

L
Linus Torvalds 已提交
4027
			if (pSMBr->hdr.Flags2 & SMBFLG2_UNICODE)
4028
				psrch_inf->unicode = true;
L
Linus Torvalds 已提交
4029
			else
4030
				psrch_inf->unicode = false;
L
Linus Torvalds 已提交
4031 4032

			psrch_inf->ntwrk_buf_start = (char *)pSMBr;
4033
			psrch_inf->smallBuf = 0;
4034 4035
			psrch_inf->srch_entries_start =
				(char *) &pSMBr->hdr.Protocol +
L
Linus Torvalds 已提交
4036 4037 4038 4039
					le16_to_cpu(pSMBr->t2.DataOffset);
			parms = (T2_FFIRST_RSP_PARMS *)((char *) &pSMBr->hdr.Protocol +
			       le16_to_cpu(pSMBr->t2.ParameterOffset));

S
Steve French 已提交
4040
			if (parms->EndofSearch)
4041
				psrch_inf->endOfSearch = true;
L
Linus Torvalds 已提交
4042
			else
4043
				psrch_inf->endOfSearch = false;
L
Linus Torvalds 已提交
4044

4045 4046
			psrch_inf->entries_in_buffer =
					le16_to_cpu(parms->SearchCount);
4047
			psrch_inf->index_of_last_entry = 2 /* skip . and .. */ +
L
Linus Torvalds 已提交
4048
				psrch_inf->entries_in_buffer;
4049
			lnoff = le16_to_cpu(parms->LastNameOffset);
4050
			if (CIFSMaxBufSize < lnoff) {
4051
				cERROR(1, "ignoring corrupt resume name");
4052 4053 4054 4055
				psrch_inf->last_entry = NULL;
				return rc;
			}

4056
			psrch_inf->last_entry = psrch_inf->srch_entries_start +
4057 4058
							lnoff;

L
Linus Torvalds 已提交
4059 4060 4061 4062 4063 4064 4065 4066 4067
			*pnetfid = parms->SearchHandle;
		} else {
			cifs_buf_release(pSMB);
		}
	}

	return rc;
}

4068
int CIFSFindNext(const int xid, struct cifs_tcon *tcon,
4069
		 __u16 searchHandle, struct cifs_search_info *psrch_inf)
L
Linus Torvalds 已提交
4070 4071 4072
{
	TRANSACTION2_FNEXT_REQ *pSMB = NULL;
	TRANSACTION2_FNEXT_RSP *pSMBr = NULL;
S
Steve French 已提交
4073
	T2_FNEXT_RSP_PARMS *parms;
L
Linus Torvalds 已提交
4074 4075
	char *response_data;
	int rc = 0;
4076 4077
	int bytes_returned;
	unsigned int name_len;
L
Linus Torvalds 已提交
4078 4079
	__u16 params, byte_count;

4080
	cFYI(1, "In FindNext");
L
Linus Torvalds 已提交
4081

4082
	if (psrch_inf->endOfSearch)
L
Linus Torvalds 已提交
4083 4084 4085 4086 4087 4088 4089
		return -ENOENT;

	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
		(void **) &pSMBr);
	if (rc)
		return rc;

4090
	params = 14; /* includes 2 bytes of null string, converted to LE below*/
L
Linus Torvalds 已提交
4091 4092 4093
	byte_count = 0;
	pSMB->TotalDataCount = 0;       /* no EAs */
	pSMB->MaxParameterCount = cpu_to_le16(8);
4094
	pSMB->MaxDataCount = cpu_to_le16(CIFSMaxBufSize & 0xFFFFFF00);
L
Linus Torvalds 已提交
4095 4096 4097 4098 4099 4100 4101 4102 4103 4104 4105 4106 4107 4108
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	pSMB->ParameterOffset =  cpu_to_le16(
	      offsetof(struct smb_com_transaction2_fnext_req,SearchHandle) - 4);
	pSMB->DataCount = 0;
	pSMB->DataOffset = 0;
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_FIND_NEXT);
	pSMB->SearchHandle = searchHandle;      /* always kept as le */
	pSMB->SearchCount =
S
Steve French 已提交
4109
		cpu_to_le16(CIFSMaxBufSize / sizeof(FILE_UNIX_INFO));
L
Linus Torvalds 已提交
4110 4111 4112 4113 4114 4115 4116
	pSMB->InformationLevel = cpu_to_le16(psrch_inf->info_level);
	pSMB->ResumeKey = psrch_inf->resume_key;
	pSMB->SearchFlags =
	      cpu_to_le16(CIFS_SEARCH_CLOSE_AT_END | CIFS_SEARCH_RETURN_RESUME);

	name_len = psrch_inf->resume_name_len;
	params += name_len;
S
Steve French 已提交
4117
	if (name_len < PATH_MAX) {
L
Linus Torvalds 已提交
4118 4119
		memcpy(pSMB->ResumeFileName, psrch_inf->presume_name, name_len);
		byte_count += name_len;
4120 4121 4122
		/* 14 byte parm len above enough for 2 byte null terminator */
		pSMB->ResumeFileName[name_len] = 0;
		pSMB->ResumeFileName[name_len+1] = 0;
L
Linus Torvalds 已提交
4123 4124 4125 4126 4127 4128 4129
	} else {
		rc = -EINVAL;
		goto FNext2_err_exit;
	}
	byte_count = params + 1 /* pad */ ;
	pSMB->TotalParameterCount = cpu_to_le16(params);
	pSMB->ParameterCount = pSMB->TotalParameterCount;
4130
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
4131
	pSMB->ByteCount = cpu_to_le16(byte_count);
4132

L
Linus Torvalds 已提交
4133 4134
	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			(struct smb_hdr *) pSMBr, &bytes_returned, 0);
4135
	cifs_stats_inc(&tcon->num_fnext);
L
Linus Torvalds 已提交
4136 4137
	if (rc) {
		if (rc == -EBADF) {
4138
			psrch_inf->endOfSearch = true;
J
Jeff Layton 已提交
4139
			cifs_buf_release(pSMB);
4140
			rc = 0; /* search probably was closed at end of search*/
L
Linus Torvalds 已提交
4141
		} else
4142
			cFYI(1, "FindNext returned = %d", rc);
L
Linus Torvalds 已提交
4143 4144
	} else {                /* decode response */
		rc = validate_t2((struct smb_t2_rsp *)pSMBr);
4145

S
Steve French 已提交
4146
		if (rc == 0) {
4147 4148
			unsigned int lnoff;

L
Linus Torvalds 已提交
4149 4150
			/* BB fixme add lock for file (srch_info) struct here */
			if (pSMBr->hdr.Flags2 & SMBFLG2_UNICODE)
4151
				psrch_inf->unicode = true;
L
Linus Torvalds 已提交
4152
			else
4153
				psrch_inf->unicode = false;
L
Linus Torvalds 已提交
4154 4155 4156 4157 4158
			response_data = (char *) &pSMBr->hdr.Protocol +
			       le16_to_cpu(pSMBr->t2.ParameterOffset);
			parms = (T2_FNEXT_RSP_PARMS *)response_data;
			response_data = (char *)&pSMBr->hdr.Protocol +
				le16_to_cpu(pSMBr->t2.DataOffset);
S
Steve French 已提交
4159
			if (psrch_inf->smallBuf)
4160 4161 4162 4163
				cifs_small_buf_release(
					psrch_inf->ntwrk_buf_start);
			else
				cifs_buf_release(psrch_inf->ntwrk_buf_start);
L
Linus Torvalds 已提交
4164 4165
			psrch_inf->srch_entries_start = response_data;
			psrch_inf->ntwrk_buf_start = (char *)pSMB;
4166
			psrch_inf->smallBuf = 0;
S
Steve French 已提交
4167
			if (parms->EndofSearch)
4168
				psrch_inf->endOfSearch = true;
L
Linus Torvalds 已提交
4169
			else
4170
				psrch_inf->endOfSearch = false;
4171 4172
			psrch_inf->entries_in_buffer =
						le16_to_cpu(parms->SearchCount);
L
Linus Torvalds 已提交
4173 4174
			psrch_inf->index_of_last_entry +=
				psrch_inf->entries_in_buffer;
4175
			lnoff = le16_to_cpu(parms->LastNameOffset);
4176
			if (CIFSMaxBufSize < lnoff) {
4177
				cERROR(1, "ignoring corrupt resume name");
4178 4179 4180 4181 4182 4183
				psrch_inf->last_entry = NULL;
				return rc;
			} else
				psrch_inf->last_entry =
					psrch_inf->srch_entries_start + lnoff;

4184 4185
/*  cFYI(1, "fnxt2 entries in buf %d index_of_last %d",
	    psrch_inf->entries_in_buffer, psrch_inf->index_of_last_entry); */
L
Linus Torvalds 已提交
4186 4187 4188 4189 4190 4191 4192 4193 4194 4195 4196 4197 4198 4199 4200 4201 4202 4203

			/* BB fixme add unlock here */
		}

	}

	/* BB On error, should we leave previous search buf (and count and
	last entry fields) intact or free the previous one? */

	/* Note: On -EAGAIN error only caller can retry on handle based calls
	since file handle passed in no longer valid */
FNext2_err_exit:
	if (rc != 0)
		cifs_buf_release(pSMB);
	return rc;
}

int
4204
CIFSFindClose(const int xid, struct cifs_tcon *tcon,
4205
	      const __u16 searchHandle)
L
Linus Torvalds 已提交
4206 4207 4208 4209
{
	int rc = 0;
	FINDCLOSE_REQ *pSMB = NULL;

4210
	cFYI(1, "In CIFSSMBFindClose");
L
Linus Torvalds 已提交
4211 4212 4213 4214
	rc = small_smb_init(SMB_COM_FIND_CLOSE2, 1, tcon, (void **)&pSMB);

	/* no sense returning error if session restarted
		as file handle has been closed */
S
Steve French 已提交
4215
	if (rc == -EAGAIN)
L
Linus Torvalds 已提交
4216 4217 4218 4219 4220 4221
		return 0;
	if (rc)
		return rc;

	pSMB->FileID = searchHandle;
	pSMB->ByteCount = 0;
4222
	rc = SendReceiveNoRsp(xid, tcon->ses, (struct smb_hdr *) pSMB, 0);
S
Steve French 已提交
4223
	if (rc)
4224
		cERROR(1, "Send error in FindClose = %d", rc);
S
Steve French 已提交
4225

4226
	cifs_stats_inc(&tcon->num_fclose);
L
Linus Torvalds 已提交
4227 4228 4229 4230 4231 4232 4233 4234 4235

	/* Since session is dead, search handle closed on server already */
	if (rc == -EAGAIN)
		rc = 0;

	return rc;
}

int
4236
CIFSGetSrvInodeNumber(const int xid, struct cifs_tcon *tcon,
4237
		      const unsigned char *searchName,
S
Steve French 已提交
4238
		      __u64 *inode_number,
4239
		      const struct nls_table *nls_codepage, int remap)
L
Linus Torvalds 已提交
4240 4241 4242 4243 4244 4245 4246
{
	int rc = 0;
	TRANSACTION2_QPI_REQ *pSMB = NULL;
	TRANSACTION2_QPI_RSP *pSMBr = NULL;
	int name_len, bytes_returned;
	__u16 params, byte_count;

4247
	cFYI(1, "In GetSrvInodeNum for %s", searchName);
S
Steve French 已提交
4248
	if (tcon == NULL)
4249
		return -ENODEV;
L
Linus Torvalds 已提交
4250 4251 4252

GetInodeNumberRetry:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
4253
		      (void **) &pSMBr);
L
Linus Torvalds 已提交
4254 4255 4256 4257 4258
	if (rc)
		return rc;

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		name_len =
4259
			cifsConvertToUCS((__le16 *) pSMB->FileName, searchName,
4260
					 PATH_MAX, nls_codepage, remap);
L
Linus Torvalds 已提交
4261 4262
		name_len++;     /* trailing null */
		name_len *= 2;
4263
	} else {	/* BB improve the check for buffer overruns BB */
L
Linus Torvalds 已提交
4264 4265 4266 4267 4268 4269 4270 4271 4272 4273 4274 4275 4276 4277 4278 4279
		name_len = strnlen(searchName, PATH_MAX);
		name_len++;     /* trailing null */
		strncpy(pSMB->FileName, searchName, name_len);
	}

	params = 2 /* level */  + 4 /* rsrvd */  + name_len /* incl null */ ;
	pSMB->TotalDataCount = 0;
	pSMB->MaxParameterCount = cpu_to_le16(2);
	/* BB find exact max data count below from sess structure BB */
	pSMB->MaxDataCount = cpu_to_le16(4000);
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	pSMB->ParameterOffset = cpu_to_le16(offsetof(
4280
		struct smb_com_transaction2_qpi_req, InformationLevel) - 4);
L
Linus Torvalds 已提交
4281 4282 4283 4284 4285 4286 4287 4288 4289 4290
	pSMB->DataCount = 0;
	pSMB->DataOffset = 0;
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_QUERY_PATH_INFORMATION);
	byte_count = params + 1 /* pad */ ;
	pSMB->TotalParameterCount = cpu_to_le16(params);
	pSMB->ParameterCount = pSMB->TotalParameterCount;
	pSMB->InformationLevel = cpu_to_le16(SMB_QUERY_FILE_INTERNAL_INFO);
	pSMB->Reserved4 = 0;
4291
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
4292 4293 4294 4295 4296
	pSMB->ByteCount = cpu_to_le16(byte_count);

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
		(struct smb_hdr *) pSMBr, &bytes_returned, 0);
	if (rc) {
4297
		cFYI(1, "error %d in QueryInternalInfo", rc);
L
Linus Torvalds 已提交
4298 4299 4300 4301
	} else {
		/* decode response */
		rc = validate_t2((struct smb_t2_rsp *)pSMBr);
		/* BB also check enough total bytes returned */
4302
		if (rc || get_bcc(&pSMBr->hdr) < 2)
L
Linus Torvalds 已提交
4303 4304 4305
			/* If rc should we check for EOPNOSUPP and
			disable the srvino flag? or in caller? */
			rc = -EIO;      /* bad smb */
4306
		else {
L
Linus Torvalds 已提交
4307 4308
			__u16 data_offset = le16_to_cpu(pSMBr->t2.DataOffset);
			__u16 count = le16_to_cpu(pSMBr->t2.DataCount);
4309
			struct file_internal_info *pfinfo;
L
Linus Torvalds 已提交
4310
			/* BB Do we need a cast or hash here ? */
S
Steve French 已提交
4311
			if (count < 8) {
4312
				cFYI(1, "Illegal size ret in QryIntrnlInf");
L
Linus Torvalds 已提交
4313 4314 4315 4316 4317
				rc = -EIO;
				goto GetInodeNumOut;
			}
			pfinfo = (struct file_internal_info *)
				(data_offset + (char *) &pSMBr->hdr.Protocol);
4318
			*inode_number = le64_to_cpu(pfinfo->UniqueId);
L
Linus Torvalds 已提交
4319 4320 4321 4322 4323 4324 4325 4326 4327
		}
	}
GetInodeNumOut:
	cifs_buf_release(pSMB);
	if (rc == -EAGAIN)
		goto GetInodeNumberRetry;
	return rc;
}

4328 4329 4330 4331 4332 4333 4334
/* parses DFS refferal V3 structure
 * caller is responsible for freeing target_nodes
 * returns:
 * 	on success - 0
 *	on failure - errno
 */
static int
4335
parse_DFS_referrals(TRANSACTION2_GET_DFS_REFER_RSP *pSMBr,
4336 4337
		unsigned int *num_of_nodes,
		struct dfs_info3_param **target_nodes,
4338 4339
		const struct nls_table *nls_codepage, int remap,
		const char *searchName)
4340 4341 4342 4343 4344 4345
{
	int i, rc = 0;
	char *data_end;
	bool is_unicode;
	struct dfs_referral_level_3 *ref;

4346 4347 4348 4349
	if (pSMBr->hdr.Flags2 & SMBFLG2_UNICODE)
		is_unicode = true;
	else
		is_unicode = false;
4350 4351 4352
	*num_of_nodes = le16_to_cpu(pSMBr->NumberOfReferrals);

	if (*num_of_nodes < 1) {
4353 4354
		cERROR(1, "num_referrals: must be at least > 0,"
			"but we get num_referrals = %d\n", *num_of_nodes);
4355
		rc = -EINVAL;
4356
		goto parse_DFS_referrals_exit;
4357 4358 4359
	}

	ref = (struct dfs_referral_level_3 *) &(pSMBr->referrals);
A
Al Viro 已提交
4360
	if (ref->VersionNumber != cpu_to_le16(3)) {
4361 4362
		cERROR(1, "Referrals of V%d version are not supported,"
			"should be V3", le16_to_cpu(ref->VersionNumber));
4363
		rc = -EINVAL;
4364
		goto parse_DFS_referrals_exit;
4365 4366 4367 4368 4369 4370
	}

	/* get the upper boundary of the resp buffer */
	data_end = (char *)(&(pSMBr->PathConsumed)) +
				le16_to_cpu(pSMBr->t2.DataCount);

4371
	cFYI(1, "num_referrals: %d dfs flags: 0x%x ...\n",
4372
			*num_of_nodes,
4373
			le32_to_cpu(pSMBr->DFSFlags));
4374 4375 4376 4377

	*target_nodes = kzalloc(sizeof(struct dfs_info3_param) *
			*num_of_nodes, GFP_KERNEL);
	if (*target_nodes == NULL) {
4378
		cERROR(1, "Failed to allocate buffer for target_nodes\n");
4379
		rc = -ENOMEM;
4380
		goto parse_DFS_referrals_exit;
4381 4382
	}

D
Daniel Mack 已提交
4383
	/* collect necessary data from referrals */
4384 4385 4386 4387 4388
	for (i = 0; i < *num_of_nodes; i++) {
		char *temp;
		int max_len;
		struct dfs_info3_param *node = (*target_nodes)+i;

4389
		node->flags = le32_to_cpu(pSMBr->DFSFlags);
4390
		if (is_unicode) {
4391 4392
			__le16 *tmp = kmalloc(strlen(searchName)*2 + 2,
						GFP_KERNEL);
4393 4394 4395 4396
			if (tmp == NULL) {
				rc = -ENOMEM;
				goto parse_DFS_referrals_exit;
			}
4397 4398
			cifsConvertToUCS((__le16 *) tmp, searchName,
					PATH_MAX, nls_codepage, remap);
4399 4400
			node->path_consumed = cifs_ucs2_bytes(tmp,
					le16_to_cpu(pSMBr->PathConsumed),
4401 4402 4403 4404 4405
					nls_codepage);
			kfree(tmp);
		} else
			node->path_consumed = le16_to_cpu(pSMBr->PathConsumed);

4406 4407 4408 4409 4410 4411
		node->server_type = le16_to_cpu(ref->ServerType);
		node->ref_flag = le16_to_cpu(ref->ReferralEntryFlags);

		/* copy DfsPath */
		temp = (char *)ref + le16_to_cpu(ref->DfsPathOffset);
		max_len = data_end - temp;
4412 4413
		node->path_name = cifs_strndup_from_ucs(temp, max_len,
						      is_unicode, nls_codepage);
4414 4415
		if (!node->path_name) {
			rc = -ENOMEM;
4416
			goto parse_DFS_referrals_exit;
4417
		}
4418 4419 4420 4421

		/* copy link target UNC */
		temp = (char *)ref + le16_to_cpu(ref->NetworkAddressOffset);
		max_len = data_end - temp;
4422 4423
		node->node_name = cifs_strndup_from_ucs(temp, max_len,
						      is_unicode, nls_codepage);
4424 4425
		if (!node->node_name)
			rc = -ENOMEM;
4426 4427
	}

4428
parse_DFS_referrals_exit:
4429 4430 4431 4432 4433 4434 4435 4436
	if (rc) {
		free_dfs_info_array(*target_nodes, *num_of_nodes);
		*target_nodes = NULL;
		*num_of_nodes = 0;
	}
	return rc;
}

L
Linus Torvalds 已提交
4437
int
4438
CIFSGetDFSRefer(const int xid, struct cifs_ses *ses,
L
Linus Torvalds 已提交
4439
		const unsigned char *searchName,
S
Steve French 已提交
4440 4441
		struct dfs_info3_param **target_nodes,
		unsigned int *num_of_nodes,
4442
		const struct nls_table *nls_codepage, int remap)
L
Linus Torvalds 已提交
4443 4444 4445 4446 4447 4448 4449 4450
{
/* TRANS2_GET_DFS_REFERRAL */
	TRANSACTION2_GET_DFS_REFER_REQ *pSMB = NULL;
	TRANSACTION2_GET_DFS_REFER_RSP *pSMBr = NULL;
	int rc = 0;
	int bytes_returned;
	int name_len;
	__u16 params, byte_count;
S
Steve French 已提交
4451 4452
	*num_of_nodes = 0;
	*target_nodes = NULL;
L
Linus Torvalds 已提交
4453

4454
	cFYI(1, "In GetDFSRefer the path %s", searchName);
L
Linus Torvalds 已提交
4455 4456 4457 4458 4459 4460 4461
	if (ses == NULL)
		return -ENODEV;
getDFSRetry:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, NULL, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;
4462 4463

	/* server pointer checked in called function,
4464 4465
	but should never be null here anyway */
	pSMB->hdr.Mid = GetNextMid(ses->server);
L
Linus Torvalds 已提交
4466 4467
	pSMB->hdr.Tid = ses->ipc_tid;
	pSMB->hdr.Uid = ses->Suid;
4468
	if (ses->capabilities & CAP_STATUS32)
L
Linus Torvalds 已提交
4469
		pSMB->hdr.Flags2 |= SMBFLG2_ERR_STATUS;
4470
	if (ses->capabilities & CAP_DFS)
L
Linus Torvalds 已提交
4471 4472 4473 4474 4475
		pSMB->hdr.Flags2 |= SMBFLG2_DFS;

	if (ses->capabilities & CAP_UNICODE) {
		pSMB->hdr.Flags2 |= SMBFLG2_UNICODE;
		name_len =
4476
		    cifsConvertToUCS((__le16 *) pSMB->RequestFileName,
4477
				     searchName, PATH_MAX, nls_codepage, remap);
L
Linus Torvalds 已提交
4478 4479
		name_len++;	/* trailing null */
		name_len *= 2;
4480
	} else {	/* BB improve the check for buffer overruns BB */
L
Linus Torvalds 已提交
4481 4482 4483 4484 4485
		name_len = strnlen(searchName, PATH_MAX);
		name_len++;	/* trailing null */
		strncpy(pSMB->RequestFileName, searchName, name_len);
	}

S
Steve French 已提交
4486
	if (ses->server) {
4487
		if (ses->server->sec_mode &
S
Steve French 已提交
4488 4489 4490 4491
		   (SECMODE_SIGN_REQUIRED | SECMODE_SIGN_ENABLED))
			pSMB->hdr.Flags2 |= SMBFLG2_SECURITY_SIGNATURE;
	}

4492
	pSMB->hdr.Uid = ses->Suid;
S
Steve French 已提交
4493

L
Linus Torvalds 已提交
4494 4495 4496 4497 4498
	params = 2 /* level */  + name_len /*includes null */ ;
	pSMB->TotalDataCount = 0;
	pSMB->DataCount = 0;
	pSMB->DataOffset = 0;
	pSMB->MaxParameterCount = 0;
4499 4500
	/* BB find exact max SMB PDU from sess structure BB */
	pSMB->MaxDataCount = cpu_to_le16(4000);
L
Linus Torvalds 已提交
4501 4502 4503 4504 4505 4506
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	pSMB->ParameterOffset = cpu_to_le16(offsetof(
4507
	  struct smb_com_transaction2_get_dfs_refer_req, MaxReferralLevel) - 4);
L
Linus Torvalds 已提交
4508 4509 4510 4511 4512 4513 4514
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_GET_DFS_REFERRAL);
	byte_count = params + 3 /* pad */ ;
	pSMB->ParameterCount = cpu_to_le16(params);
	pSMB->TotalParameterCount = pSMB->ParameterCount;
	pSMB->MaxReferralLevel = cpu_to_le16(3);
4515
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
4516 4517 4518 4519 4520
	pSMB->ByteCount = cpu_to_le16(byte_count);

	rc = SendReceive(xid, ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
	if (rc) {
4521
		cFYI(1, "Send error in GetDFSRefer = %d", rc);
S
Steve French 已提交
4522 4523 4524
		goto GetDFSRefExit;
	}
	rc = validate_t2((struct smb_t2_rsp *)pSMBr);
L
Linus Torvalds 已提交
4525

S
Steve French 已提交
4526
	/* BB Also check if enough total bytes returned? */
4527
	if (rc || get_bcc(&pSMBr->hdr) < 17) {
S
Steve French 已提交
4528
		rc = -EIO;      /* bad smb */
4529 4530
		goto GetDFSRefExit;
	}
S
Steve French 已提交
4531

4532
	cFYI(1, "Decoding GetDFSRefer response BCC: %d  Offset %d",
4533
				get_bcc(&pSMBr->hdr),
4534
				le16_to_cpu(pSMBr->t2.DataOffset));
L
Linus Torvalds 已提交
4535

4536
	/* parse returned result into more usable form */
4537
	rc = parse_DFS_referrals(pSMBr, num_of_nodes,
4538 4539
				 target_nodes, nls_codepage, remap,
				 searchName);
S
Steve French 已提交
4540

L
Linus Torvalds 已提交
4541
GetDFSRefExit:
4542
	cifs_buf_release(pSMB);
L
Linus Torvalds 已提交
4543 4544 4545 4546 4547 4548 4549

	if (rc == -EAGAIN)
		goto getDFSRetry;

	return rc;
}

4550 4551
/* Query File System Info such as free space to old servers such as Win 9x */
int
4552
SMBOldQFSInfo(const int xid, struct cifs_tcon *tcon, struct kstatfs *FSData)
4553 4554 4555 4556 4557 4558 4559 4560 4561
{
/* level 0x01 SMB_QUERY_FILE_SYSTEM_INFO */
	TRANSACTION2_QFSI_REQ *pSMB = NULL;
	TRANSACTION2_QFSI_RSP *pSMBr = NULL;
	FILE_SYSTEM_ALLOC_INFO *response_data;
	int rc = 0;
	int bytes_returned = 0;
	__u16 params, byte_count;

4562
	cFYI(1, "OldQFSInfo");
4563 4564 4565 4566 4567 4568 4569 4570 4571 4572 4573 4574 4575 4576 4577 4578 4579 4580 4581 4582 4583 4584 4585 4586 4587 4588
oldQFSInfoRetry:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
		(void **) &pSMBr);
	if (rc)
		return rc;

	params = 2;     /* level */
	pSMB->TotalDataCount = 0;
	pSMB->MaxParameterCount = cpu_to_le16(2);
	pSMB->MaxDataCount = cpu_to_le16(1000);
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	byte_count = params + 1 /* pad */ ;
	pSMB->TotalParameterCount = cpu_to_le16(params);
	pSMB->ParameterCount = pSMB->TotalParameterCount;
	pSMB->ParameterOffset = cpu_to_le16(offsetof(
	struct smb_com_transaction2_qfsi_req, InformationLevel) - 4);
	pSMB->DataCount = 0;
	pSMB->DataOffset = 0;
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_QUERY_FS_INFORMATION);
	pSMB->InformationLevel = cpu_to_le16(SMB_INFO_ALLOCATION);
4589
	inc_rfc1001_len(pSMB, byte_count);
4590 4591 4592 4593 4594
	pSMB->ByteCount = cpu_to_le16(byte_count);

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
		(struct smb_hdr *) pSMBr, &bytes_returned, 0);
	if (rc) {
4595
		cFYI(1, "Send error in QFSInfo = %d", rc);
4596 4597 4598
	} else {                /* decode response */
		rc = validate_t2((struct smb_t2_rsp *)pSMBr);

4599
		if (rc || get_bcc(&pSMBr->hdr) < 18)
4600 4601 4602
			rc = -EIO;      /* bad smb */
		else {
			__u16 data_offset = le16_to_cpu(pSMBr->t2.DataOffset);
4603
			cFYI(1, "qfsinf resp BCC: %d  Offset %d",
4604
				 get_bcc(&pSMBr->hdr), data_offset);
4605

4606
			response_data = (FILE_SYSTEM_ALLOC_INFO *)
4607 4608 4609 4610 4611 4612
				(((char *) &pSMBr->hdr.Protocol) + data_offset);
			FSData->f_bsize =
				le16_to_cpu(response_data->BytesPerSector) *
				le32_to_cpu(response_data->
					SectorsPerAllocationUnit);
			FSData->f_blocks =
4613
			       le32_to_cpu(response_data->TotalAllocationUnits);
4614 4615
			FSData->f_bfree = FSData->f_bavail =
				le32_to_cpu(response_data->FreeAllocationUnits);
4616 4617 4618 4619
			cFYI(1, "Blocks: %lld  Free: %lld Block size %ld",
			     (unsigned long long)FSData->f_blocks,
			     (unsigned long long)FSData->f_bfree,
			     FSData->f_bsize);
4620 4621 4622 4623 4624 4625 4626 4627 4628 4629
		}
	}
	cifs_buf_release(pSMB);

	if (rc == -EAGAIN)
		goto oldQFSInfoRetry;

	return rc;
}

L
Linus Torvalds 已提交
4630
int
4631
CIFSSMBQFSInfo(const int xid, struct cifs_tcon *tcon, struct kstatfs *FSData)
L
Linus Torvalds 已提交
4632 4633 4634 4635 4636 4637 4638 4639 4640
{
/* level 0x103 SMB_QUERY_FILE_SYSTEM_INFO */
	TRANSACTION2_QFSI_REQ *pSMB = NULL;
	TRANSACTION2_QFSI_RSP *pSMBr = NULL;
	FILE_SYSTEM_INFO *response_data;
	int rc = 0;
	int bytes_returned = 0;
	__u16 params, byte_count;

4641
	cFYI(1, "In QFSInfo");
L
Linus Torvalds 已提交
4642 4643 4644 4645 4646 4647 4648 4649 4650
QFSInfoRetry:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	params = 2;	/* level */
	pSMB->TotalDataCount = 0;
	pSMB->MaxParameterCount = cpu_to_le16(2);
4651
	pSMB->MaxDataCount = cpu_to_le16(1000);
L
Linus Torvalds 已提交
4652 4653 4654 4655 4656 4657 4658 4659 4660
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	byte_count = params + 1 /* pad */ ;
	pSMB->TotalParameterCount = cpu_to_le16(params);
	pSMB->ParameterCount = pSMB->TotalParameterCount;
	pSMB->ParameterOffset = cpu_to_le16(offsetof(
4661
		struct smb_com_transaction2_qfsi_req, InformationLevel) - 4);
L
Linus Torvalds 已提交
4662 4663 4664 4665 4666 4667
	pSMB->DataCount = 0;
	pSMB->DataOffset = 0;
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_QUERY_FS_INFORMATION);
	pSMB->InformationLevel = cpu_to_le16(SMB_QUERY_FS_SIZE_INFO);
4668
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
4669 4670 4671 4672 4673
	pSMB->ByteCount = cpu_to_le16(byte_count);

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
	if (rc) {
4674
		cFYI(1, "Send error in QFSInfo = %d", rc);
L
Linus Torvalds 已提交
4675
	} else {		/* decode response */
4676
		rc = validate_t2((struct smb_t2_rsp *)pSMBr);
L
Linus Torvalds 已提交
4677

4678
		if (rc || get_bcc(&pSMBr->hdr) < 24)
L
Linus Torvalds 已提交
4679 4680 4681 4682 4683 4684 4685 4686 4687 4688 4689 4690 4691 4692 4693 4694
			rc = -EIO;	/* bad smb */
		else {
			__u16 data_offset = le16_to_cpu(pSMBr->t2.DataOffset);

			response_data =
			    (FILE_SYSTEM_INFO
			     *) (((char *) &pSMBr->hdr.Protocol) +
				 data_offset);
			FSData->f_bsize =
			    le32_to_cpu(response_data->BytesPerSector) *
			    le32_to_cpu(response_data->
					SectorsPerAllocationUnit);
			FSData->f_blocks =
			    le64_to_cpu(response_data->TotalAllocationUnits);
			FSData->f_bfree = FSData->f_bavail =
			    le64_to_cpu(response_data->FreeAllocationUnits);
4695 4696 4697 4698
			cFYI(1, "Blocks: %lld  Free: %lld Block size %ld",
			     (unsigned long long)FSData->f_blocks,
			     (unsigned long long)FSData->f_bfree,
			     FSData->f_bsize);
L
Linus Torvalds 已提交
4699 4700 4701 4702 4703 4704 4705 4706 4707 4708 4709
		}
	}
	cifs_buf_release(pSMB);

	if (rc == -EAGAIN)
		goto QFSInfoRetry;

	return rc;
}

int
4710
CIFSSMBQFSAttributeInfo(const int xid, struct cifs_tcon *tcon)
L
Linus Torvalds 已提交
4711 4712 4713 4714 4715 4716 4717 4718 4719
{
/* level 0x105  SMB_QUERY_FILE_SYSTEM_INFO */
	TRANSACTION2_QFSI_REQ *pSMB = NULL;
	TRANSACTION2_QFSI_RSP *pSMBr = NULL;
	FILE_SYSTEM_ATTRIBUTE_INFO *response_data;
	int rc = 0;
	int bytes_returned = 0;
	__u16 params, byte_count;

4720
	cFYI(1, "In QFSAttributeInfo");
L
Linus Torvalds 已提交
4721 4722 4723 4724 4725 4726 4727 4728 4729
QFSAttributeRetry:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	params = 2;	/* level */
	pSMB->TotalDataCount = 0;
	pSMB->MaxParameterCount = cpu_to_le16(2);
4730 4731
	/* BB find exact max SMB PDU from sess structure BB */
	pSMB->MaxDataCount = cpu_to_le16(1000);
L
Linus Torvalds 已提交
4732 4733 4734 4735 4736 4737 4738 4739 4740
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	byte_count = params + 1 /* pad */ ;
	pSMB->TotalParameterCount = cpu_to_le16(params);
	pSMB->ParameterCount = pSMB->TotalParameterCount;
	pSMB->ParameterOffset = cpu_to_le16(offsetof(
4741
		struct smb_com_transaction2_qfsi_req, InformationLevel) - 4);
L
Linus Torvalds 已提交
4742 4743 4744 4745 4746 4747
	pSMB->DataCount = 0;
	pSMB->DataOffset = 0;
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_QUERY_FS_INFORMATION);
	pSMB->InformationLevel = cpu_to_le16(SMB_QUERY_FS_ATTRIBUTE_INFO);
4748
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
4749 4750 4751 4752 4753
	pSMB->ByteCount = cpu_to_le16(byte_count);

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
	if (rc) {
4754
		cERROR(1, "Send error in QFSAttributeInfo = %d", rc);
L
Linus Torvalds 已提交
4755 4756 4757
	} else {		/* decode response */
		rc = validate_t2((struct smb_t2_rsp *)pSMBr);

4758
		if (rc || get_bcc(&pSMBr->hdr) < 13) {
4759
			/* BB also check if enough bytes returned */
L
Linus Torvalds 已提交
4760 4761 4762 4763 4764 4765 4766 4767
			rc = -EIO;	/* bad smb */
		} else {
			__u16 data_offset = le16_to_cpu(pSMBr->t2.DataOffset);
			response_data =
			    (FILE_SYSTEM_ATTRIBUTE_INFO
			     *) (((char *) &pSMBr->hdr.Protocol) +
				 data_offset);
			memcpy(&tcon->fsAttrInfo, response_data,
4768
			       sizeof(FILE_SYSTEM_ATTRIBUTE_INFO));
L
Linus Torvalds 已提交
4769 4770 4771 4772 4773 4774 4775 4776 4777 4778 4779
		}
	}
	cifs_buf_release(pSMB);

	if (rc == -EAGAIN)
		goto QFSAttributeRetry;

	return rc;
}

int
4780
CIFSSMBQFSDeviceInfo(const int xid, struct cifs_tcon *tcon)
L
Linus Torvalds 已提交
4781 4782 4783 4784 4785 4786 4787 4788 4789
{
/* level 0x104 SMB_QUERY_FILE_SYSTEM_INFO */
	TRANSACTION2_QFSI_REQ *pSMB = NULL;
	TRANSACTION2_QFSI_RSP *pSMBr = NULL;
	FILE_SYSTEM_DEVICE_INFO *response_data;
	int rc = 0;
	int bytes_returned = 0;
	__u16 params, byte_count;

4790
	cFYI(1, "In QFSDeviceInfo");
L
Linus Torvalds 已提交
4791 4792 4793 4794 4795 4796 4797 4798 4799
QFSDeviceRetry:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	params = 2;	/* level */
	pSMB->TotalDataCount = 0;
	pSMB->MaxParameterCount = cpu_to_le16(2);
4800 4801
	/* BB find exact max SMB PDU from sess structure BB */
	pSMB->MaxDataCount = cpu_to_le16(1000);
L
Linus Torvalds 已提交
4802 4803 4804 4805 4806 4807 4808 4809 4810
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	byte_count = params + 1 /* pad */ ;
	pSMB->TotalParameterCount = cpu_to_le16(params);
	pSMB->ParameterCount = pSMB->TotalParameterCount;
	pSMB->ParameterOffset = cpu_to_le16(offsetof(
4811
		struct smb_com_transaction2_qfsi_req, InformationLevel) - 4);
L
Linus Torvalds 已提交
4812 4813 4814 4815 4816 4817 4818

	pSMB->DataCount = 0;
	pSMB->DataOffset = 0;
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_QUERY_FS_INFORMATION);
	pSMB->InformationLevel = cpu_to_le16(SMB_QUERY_FS_DEVICE_INFO);
4819
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
4820 4821 4822 4823 4824
	pSMB->ByteCount = cpu_to_le16(byte_count);

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
	if (rc) {
4825
		cFYI(1, "Send error in QFSDeviceInfo = %d", rc);
L
Linus Torvalds 已提交
4826 4827 4828
	} else {		/* decode response */
		rc = validate_t2((struct smb_t2_rsp *)pSMBr);

4829 4830
		if (rc || get_bcc(&pSMBr->hdr) <
			  sizeof(FILE_SYSTEM_DEVICE_INFO))
L
Linus Torvalds 已提交
4831 4832 4833 4834
			rc = -EIO;	/* bad smb */
		else {
			__u16 data_offset = le16_to_cpu(pSMBr->t2.DataOffset);
			response_data =
4835 4836
			    (FILE_SYSTEM_DEVICE_INFO *)
				(((char *) &pSMBr->hdr.Protocol) +
L
Linus Torvalds 已提交
4837 4838
				 data_offset);
			memcpy(&tcon->fsDevInfo, response_data,
4839
			       sizeof(FILE_SYSTEM_DEVICE_INFO));
L
Linus Torvalds 已提交
4840 4841 4842 4843 4844 4845 4846 4847 4848 4849 4850
		}
	}
	cifs_buf_release(pSMB);

	if (rc == -EAGAIN)
		goto QFSDeviceRetry;

	return rc;
}

int
4851
CIFSSMBQFSUnixInfo(const int xid, struct cifs_tcon *tcon)
L
Linus Torvalds 已提交
4852 4853 4854 4855 4856 4857 4858 4859 4860
{
/* level 0x200  SMB_QUERY_CIFS_UNIX_INFO */
	TRANSACTION2_QFSI_REQ *pSMB = NULL;
	TRANSACTION2_QFSI_RSP *pSMBr = NULL;
	FILE_SYSTEM_UNIX_INFO *response_data;
	int rc = 0;
	int bytes_returned = 0;
	__u16 params, byte_count;

4861
	cFYI(1, "In QFSUnixInfo");
L
Linus Torvalds 已提交
4862
QFSUnixRetry:
4863 4864
	rc = smb_init_no_reconnect(SMB_COM_TRANSACTION2, 15, tcon,
				   (void **) &pSMB, (void **) &pSMBr);
L
Linus Torvalds 已提交
4865 4866 4867 4868 4869 4870 4871 4872
	if (rc)
		return rc;

	params = 2;	/* level */
	pSMB->TotalDataCount = 0;
	pSMB->DataCount = 0;
	pSMB->DataOffset = 0;
	pSMB->MaxParameterCount = cpu_to_le16(2);
4873 4874
	/* BB find exact max SMB PDU from sess structure BB */
	pSMB->MaxDataCount = cpu_to_le16(100);
L
Linus Torvalds 已提交
4875 4876 4877 4878 4879 4880 4881 4882
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	byte_count = params + 1 /* pad */ ;
	pSMB->ParameterCount = cpu_to_le16(params);
	pSMB->TotalParameterCount = pSMB->ParameterCount;
4883 4884
	pSMB->ParameterOffset = cpu_to_le16(offsetof(struct
			smb_com_transaction2_qfsi_req, InformationLevel) - 4);
L
Linus Torvalds 已提交
4885 4886 4887 4888
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_QUERY_FS_INFORMATION);
	pSMB->InformationLevel = cpu_to_le16(SMB_QUERY_CIFS_UNIX_INFO);
4889
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
4890 4891 4892 4893 4894
	pSMB->ByteCount = cpu_to_le16(byte_count);

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
	if (rc) {
4895
		cERROR(1, "Send error in QFSUnixInfo = %d", rc);
L
Linus Torvalds 已提交
4896 4897 4898
	} else {		/* decode response */
		rc = validate_t2((struct smb_t2_rsp *)pSMBr);

4899
		if (rc || get_bcc(&pSMBr->hdr) < 13) {
L
Linus Torvalds 已提交
4900 4901 4902 4903 4904 4905 4906 4907
			rc = -EIO;	/* bad smb */
		} else {
			__u16 data_offset = le16_to_cpu(pSMBr->t2.DataOffset);
			response_data =
			    (FILE_SYSTEM_UNIX_INFO
			     *) (((char *) &pSMBr->hdr.Protocol) +
				 data_offset);
			memcpy(&tcon->fsUnixInfo, response_data,
4908
			       sizeof(FILE_SYSTEM_UNIX_INFO));
L
Linus Torvalds 已提交
4909 4910 4911 4912 4913 4914 4915 4916 4917 4918 4919
		}
	}
	cifs_buf_release(pSMB);

	if (rc == -EAGAIN)
		goto QFSUnixRetry;


	return rc;
}

4920
int
4921
CIFSSMBSetFSUnixInfo(const int xid, struct cifs_tcon *tcon, __u64 cap)
4922 4923 4924 4925 4926 4927 4928 4929
{
/* level 0x200  SMB_SET_CIFS_UNIX_INFO */
	TRANSACTION2_SETFSI_REQ *pSMB = NULL;
	TRANSACTION2_SETFSI_RSP *pSMBr = NULL;
	int rc = 0;
	int bytes_returned = 0;
	__u16 params, param_offset, offset, byte_count;

4930
	cFYI(1, "In SETFSUnixInfo");
4931
SETFSUnixRetry:
4932
	/* BB switch to small buf init to save memory */
4933 4934
	rc = smb_init_no_reconnect(SMB_COM_TRANSACTION2, 15, tcon,
					(void **) &pSMB, (void **) &pSMBr);
4935 4936 4937 4938 4939 4940 4941 4942 4943
	if (rc)
		return rc;

	params = 4;	/* 2 bytes zero followed by info level. */
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
4944 4945
	param_offset = offsetof(struct smb_com_transaction2_setfsi_req, FileNum)
				- 4;
4946 4947 4948
	offset = param_offset + params;

	pSMB->MaxParameterCount = cpu_to_le16(4);
4949 4950
	/* BB find exact max SMB PDU from sess structure BB */
	pSMB->MaxDataCount = cpu_to_le16(100);
4951 4952 4953 4954 4955 4956 4957 4958 4959 4960 4961 4962 4963 4964 4965 4966 4967 4968 4969 4970 4971
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_SET_FS_INFORMATION);
	byte_count = 1 /* pad */ + params + 12;

	pSMB->DataCount = cpu_to_le16(12);
	pSMB->ParameterCount = cpu_to_le16(params);
	pSMB->TotalDataCount = pSMB->DataCount;
	pSMB->TotalParameterCount = pSMB->ParameterCount;
	pSMB->ParameterOffset = cpu_to_le16(param_offset);
	pSMB->DataOffset = cpu_to_le16(offset);

	/* Params. */
	pSMB->FileNum = 0;
	pSMB->InformationLevel = cpu_to_le16(SMB_SET_CIFS_UNIX_INFO);

	/* Data. */
	pSMB->ClientUnixMajor = cpu_to_le16(CIFS_UNIX_MAJOR_VERSION);
	pSMB->ClientUnixMinor = cpu_to_le16(CIFS_UNIX_MINOR_VERSION);
	pSMB->ClientUnixCap = cpu_to_le64(cap);

4972
	inc_rfc1001_len(pSMB, byte_count);
4973 4974 4975 4976 4977
	pSMB->ByteCount = cpu_to_le16(byte_count);

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
	if (rc) {
4978
		cERROR(1, "Send error in SETFSUnixInfo = %d", rc);
4979 4980
	} else {		/* decode response */
		rc = validate_t2((struct smb_t2_rsp *)pSMBr);
S
Steve French 已提交
4981
		if (rc)
4982 4983 4984 4985 4986 4987 4988 4989 4990 4991 4992
			rc = -EIO;	/* bad smb */
	}
	cifs_buf_release(pSMB);

	if (rc == -EAGAIN)
		goto SETFSUnixRetry;

	return rc;
}


L
Linus Torvalds 已提交
4993 4994

int
4995
CIFSSMBQFSPosixInfo(const int xid, struct cifs_tcon *tcon,
4996
		   struct kstatfs *FSData)
L
Linus Torvalds 已提交
4997 4998 4999 5000 5001 5002 5003 5004 5005
{
/* level 0x201  SMB_QUERY_CIFS_POSIX_INFO */
	TRANSACTION2_QFSI_REQ *pSMB = NULL;
	TRANSACTION2_QFSI_RSP *pSMBr = NULL;
	FILE_SYSTEM_POSIX_INFO *response_data;
	int rc = 0;
	int bytes_returned = 0;
	__u16 params, byte_count;

5006
	cFYI(1, "In QFSPosixInfo");
L
Linus Torvalds 已提交
5007 5008 5009 5010 5011 5012 5013 5014 5015 5016 5017
QFSPosixRetry:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	params = 2;	/* level */
	pSMB->TotalDataCount = 0;
	pSMB->DataCount = 0;
	pSMB->DataOffset = 0;
	pSMB->MaxParameterCount = cpu_to_le16(2);
5018 5019
	/* BB find exact max SMB PDU from sess structure BB */
	pSMB->MaxDataCount = cpu_to_le16(100);
L
Linus Torvalds 已提交
5020 5021 5022 5023 5024 5025 5026 5027
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	byte_count = params + 1 /* pad */ ;
	pSMB->ParameterCount = cpu_to_le16(params);
	pSMB->TotalParameterCount = pSMB->ParameterCount;
5028 5029
	pSMB->ParameterOffset = cpu_to_le16(offsetof(struct
			smb_com_transaction2_qfsi_req, InformationLevel) - 4);
L
Linus Torvalds 已提交
5030 5031 5032 5033
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_QUERY_FS_INFORMATION);
	pSMB->InformationLevel = cpu_to_le16(SMB_QUERY_POSIX_FS_INFO);
5034
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
5035 5036 5037 5038 5039
	pSMB->ByteCount = cpu_to_le16(byte_count);

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
	if (rc) {
5040
		cFYI(1, "Send error in QFSUnixInfo = %d", rc);
L
Linus Torvalds 已提交
5041 5042 5043
	} else {		/* decode response */
		rc = validate_t2((struct smb_t2_rsp *)pSMBr);

5044
		if (rc || get_bcc(&pSMBr->hdr) < 13) {
L
Linus Torvalds 已提交
5045 5046 5047 5048 5049 5050 5051 5052 5053 5054 5055 5056 5057
			rc = -EIO;	/* bad smb */
		} else {
			__u16 data_offset = le16_to_cpu(pSMBr->t2.DataOffset);
			response_data =
			    (FILE_SYSTEM_POSIX_INFO
			     *) (((char *) &pSMBr->hdr.Protocol) +
				 data_offset);
			FSData->f_bsize =
					le32_to_cpu(response_data->BlockSize);
			FSData->f_blocks =
					le64_to_cpu(response_data->TotalBlocks);
			FSData->f_bfree =
			    le64_to_cpu(response_data->BlocksAvail);
S
Steve French 已提交
5058
			if (response_data->UserBlocksAvail == cpu_to_le64(-1)) {
L
Linus Torvalds 已提交
5059 5060 5061
				FSData->f_bavail = FSData->f_bfree;
			} else {
				FSData->f_bavail =
5062
				    le64_to_cpu(response_data->UserBlocksAvail);
L
Linus Torvalds 已提交
5063
			}
S
Steve French 已提交
5064
			if (response_data->TotalFileNodes != cpu_to_le64(-1))
L
Linus Torvalds 已提交
5065
				FSData->f_files =
5066
				     le64_to_cpu(response_data->TotalFileNodes);
S
Steve French 已提交
5067
			if (response_data->FreeFileNodes != cpu_to_le64(-1))
L
Linus Torvalds 已提交
5068
				FSData->f_ffree =
5069
				      le64_to_cpu(response_data->FreeFileNodes);
L
Linus Torvalds 已提交
5070 5071 5072 5073 5074 5075 5076 5077 5078 5079 5080
		}
	}
	cifs_buf_release(pSMB);

	if (rc == -EAGAIN)
		goto QFSPosixRetry;

	return rc;
}


5081 5082 5083
/* We can not use write of zero bytes trick to
   set file size due to need for large file support.  Also note that
   this SetPathInfo is preferred to SetFileInfo based method in next
L
Linus Torvalds 已提交
5084 5085 5086 5087
   routine which is only needed to work around a sharing violation bug
   in Samba which this routine can run into */

int
5088
CIFSSMBSetEOF(const int xid, struct cifs_tcon *tcon, const char *fileName,
5089
	      __u64 size, bool SetAllocation,
5090
	      const struct nls_table *nls_codepage, int remap)
L
Linus Torvalds 已提交
5091 5092 5093 5094 5095 5096 5097 5098 5099
{
	struct smb_com_transaction2_spi_req *pSMB = NULL;
	struct smb_com_transaction2_spi_rsp *pSMBr = NULL;
	struct file_end_of_file_info *parm_data;
	int name_len;
	int rc = 0;
	int bytes_returned = 0;
	__u16 params, byte_count, data_count, param_offset, offset;

5100
	cFYI(1, "In SetEOF");
L
Linus Torvalds 已提交
5101 5102 5103 5104 5105 5106 5107 5108
SetEOFRetry:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		name_len =
5109
		    cifsConvertToUCS((__le16 *) pSMB->FileName, fileName,
5110
				     PATH_MAX, nls_codepage, remap);
L
Linus Torvalds 已提交
5111 5112
		name_len++;	/* trailing null */
		name_len *= 2;
5113
	} else {	/* BB improve the check for buffer overruns BB */
L
Linus Torvalds 已提交
5114 5115 5116 5117 5118
		name_len = strnlen(fileName, PATH_MAX);
		name_len++;	/* trailing null */
		strncpy(pSMB->FileName, fileName, name_len);
	}
	params = 6 + name_len;
5119
	data_count = sizeof(struct file_end_of_file_info);
L
Linus Torvalds 已提交
5120
	pSMB->MaxParameterCount = cpu_to_le16(2);
5121
	pSMB->MaxDataCount = cpu_to_le16(4100);
L
Linus Torvalds 已提交
5122 5123 5124 5125 5126 5127
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	param_offset = offsetof(struct smb_com_transaction2_spi_req,
5128
				InformationLevel) - 4;
L
Linus Torvalds 已提交
5129
	offset = param_offset + params;
S
Steve French 已提交
5130
	if (SetAllocation) {
5131 5132 5133 5134 5135 5136 5137
		if (tcon->ses->capabilities & CAP_INFOLEVEL_PASSTHRU)
			pSMB->InformationLevel =
				cpu_to_le16(SMB_SET_FILE_ALLOCATION_INFO2);
		else
			pSMB->InformationLevel =
				cpu_to_le16(SMB_SET_FILE_ALLOCATION_INFO);
	} else /* Set File Size */  {
L
Linus Torvalds 已提交
5138 5139
	    if (tcon->ses->capabilities & CAP_INFOLEVEL_PASSTHRU)
		    pSMB->InformationLevel =
5140
				cpu_to_le16(SMB_SET_FILE_END_OF_FILE_INFO2);
L
Linus Torvalds 已提交
5141 5142
	    else
		    pSMB->InformationLevel =
5143
				cpu_to_le16(SMB_SET_FILE_END_OF_FILE_INFO);
L
Linus Torvalds 已提交
5144 5145 5146 5147 5148 5149 5150 5151 5152 5153 5154 5155 5156 5157 5158 5159
	}

	parm_data =
	    (struct file_end_of_file_info *) (((char *) &pSMB->hdr.Protocol) +
				       offset);
	pSMB->ParameterOffset = cpu_to_le16(param_offset);
	pSMB->DataOffset = cpu_to_le16(offset);
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_SET_PATH_INFORMATION);
	byte_count = 3 /* pad */  + params + data_count;
	pSMB->DataCount = cpu_to_le16(data_count);
	pSMB->TotalDataCount = pSMB->DataCount;
	pSMB->ParameterCount = cpu_to_le16(params);
	pSMB->TotalParameterCount = pSMB->ParameterCount;
	pSMB->Reserved4 = 0;
5160
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
5161 5162 5163 5164
	parm_data->FileSize = cpu_to_le64(size);
	pSMB->ByteCount = cpu_to_le16(byte_count);
	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
S
Steve French 已提交
5165
	if (rc)
5166
		cFYI(1, "SetPathInfo (file size) returned %d", rc);
L
Linus Torvalds 已提交
5167 5168 5169 5170 5171 5172 5173 5174 5175 5176

	cifs_buf_release(pSMB);

	if (rc == -EAGAIN)
		goto SetEOFRetry;

	return rc;
}

int
5177
CIFSSMBSetFileSize(const int xid, struct cifs_tcon *tcon, __u64 size,
5178
		   __u16 fid, __u32 pid_of_opener, bool SetAllocation)
L
Linus Torvalds 已提交
5179 5180 5181 5182 5183 5184
{
	struct smb_com_transaction2_sfi_req *pSMB  = NULL;
	struct file_end_of_file_info *parm_data;
	int rc = 0;
	__u16 params, param_offset, offset, byte_count, count;

5185 5186
	cFYI(1, "SetFileSize (via SetFileInfo) %lld",
			(long long)size);
5187 5188
	rc = small_smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB);

L
Linus Torvalds 已提交
5189 5190 5191 5192 5193
	if (rc)
		return rc;

	pSMB->hdr.Pid = cpu_to_le16((__u16)pid_of_opener);
	pSMB->hdr.PidHigh = cpu_to_le16((__u16)(pid_of_opener >> 16));
5194

L
Linus Torvalds 已提交
5195 5196 5197 5198 5199 5200 5201 5202 5203 5204 5205
	params = 6;
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	param_offset = offsetof(struct smb_com_transaction2_sfi_req, Fid) - 4;
	offset = param_offset + params;

	count = sizeof(struct file_end_of_file_info);
	pSMB->MaxParameterCount = cpu_to_le16(2);
5206 5207
	/* BB find exact max SMB PDU from sess structure BB */
	pSMB->MaxDataCount = cpu_to_le16(1000);
L
Linus Torvalds 已提交
5208 5209 5210 5211 5212 5213 5214 5215 5216 5217
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_SET_FILE_INFORMATION);
	byte_count = 3 /* pad */  + params + count;
	pSMB->DataCount = cpu_to_le16(count);
	pSMB->ParameterCount = cpu_to_le16(params);
	pSMB->TotalDataCount = pSMB->DataCount;
	pSMB->TotalParameterCount = pSMB->ParameterCount;
	pSMB->ParameterOffset = cpu_to_le16(param_offset);
	parm_data =
5218 5219
		(struct file_end_of_file_info *) (((char *) &pSMB->hdr.Protocol)
				+ offset);
L
Linus Torvalds 已提交
5220 5221 5222
	pSMB->DataOffset = cpu_to_le16(offset);
	parm_data->FileSize = cpu_to_le64(size);
	pSMB->Fid = fid;
S
Steve French 已提交
5223
	if (SetAllocation) {
L
Linus Torvalds 已提交
5224 5225 5226 5227 5228 5229
		if (tcon->ses->capabilities & CAP_INFOLEVEL_PASSTHRU)
			pSMB->InformationLevel =
				cpu_to_le16(SMB_SET_FILE_ALLOCATION_INFO2);
		else
			pSMB->InformationLevel =
				cpu_to_le16(SMB_SET_FILE_ALLOCATION_INFO);
5230
	} else /* Set File Size */  {
L
Linus Torvalds 已提交
5231 5232
	    if (tcon->ses->capabilities & CAP_INFOLEVEL_PASSTHRU)
		    pSMB->InformationLevel =
5233
				cpu_to_le16(SMB_SET_FILE_END_OF_FILE_INFO2);
L
Linus Torvalds 已提交
5234 5235
	    else
		    pSMB->InformationLevel =
5236
				cpu_to_le16(SMB_SET_FILE_END_OF_FILE_INFO);
L
Linus Torvalds 已提交
5237 5238
	}
	pSMB->Reserved4 = 0;
5239
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
5240
	pSMB->ByteCount = cpu_to_le16(byte_count);
5241
	rc = SendReceiveNoRsp(xid, tcon->ses, (struct smb_hdr *) pSMB, 0);
L
Linus Torvalds 已提交
5242
	if (rc) {
5243
		cFYI(1, "Send error in SetFileInfo (SetFileSize) = %d", rc);
L
Linus Torvalds 已提交
5244 5245
	}

5246
	/* Note: On -EAGAIN error only caller can retry on handle based calls
L
Linus Torvalds 已提交
5247 5248 5249 5250 5251
		since file handle passed in no longer valid */

	return rc;
}

5252
/* Some legacy servers such as NT4 require that the file times be set on
L
Linus Torvalds 已提交
5253 5254 5255 5256 5257 5258
   an open handle, rather than by pathname - this is awkward due to
   potential access conflicts on the open, but it is unavoidable for these
   old servers since the only other choice is to go from 100 nanosecond DCE
   time and resort to the original setpathinfo level which takes the ancient
   DOS time format with 2 second granularity */
int
5259
CIFSSMBSetFileInfo(const int xid, struct cifs_tcon *tcon,
5260
		    const FILE_BASIC_INFO *data, __u16 fid, __u32 pid_of_opener)
L
Linus Torvalds 已提交
5261 5262 5263 5264 5265 5266
{
	struct smb_com_transaction2_sfi_req *pSMB  = NULL;
	char *data_offset;
	int rc = 0;
	__u16 params, param_offset, offset, byte_count, count;

5267
	cFYI(1, "Set Times (via SetFileInfo)");
5268 5269
	rc = small_smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB);

L
Linus Torvalds 已提交
5270 5271 5272
	if (rc)
		return rc;

5273 5274
	pSMB->hdr.Pid = cpu_to_le16((__u16)pid_of_opener);
	pSMB->hdr.PidHigh = cpu_to_le16((__u16)(pid_of_opener >> 16));
5275

L
Linus Torvalds 已提交
5276 5277 5278 5279 5280 5281 5282 5283 5284
	params = 6;
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	param_offset = offsetof(struct smb_com_transaction2_sfi_req, Fid) - 4;
	offset = param_offset + params;

5285
	data_offset = (char *) (&pSMB->hdr.Protocol) + offset;
L
Linus Torvalds 已提交
5286

5287
	count = sizeof(FILE_BASIC_INFO);
L
Linus Torvalds 已提交
5288
	pSMB->MaxParameterCount = cpu_to_le16(2);
5289 5290
	/* BB find max SMB PDU from sess */
	pSMB->MaxDataCount = cpu_to_le16(1000);
L
Linus Torvalds 已提交
5291 5292 5293 5294 5295 5296 5297 5298 5299 5300 5301 5302 5303 5304 5305 5306
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_SET_FILE_INFORMATION);
	byte_count = 3 /* pad */  + params + count;
	pSMB->DataCount = cpu_to_le16(count);
	pSMB->ParameterCount = cpu_to_le16(params);
	pSMB->TotalDataCount = pSMB->DataCount;
	pSMB->TotalParameterCount = pSMB->ParameterCount;
	pSMB->ParameterOffset = cpu_to_le16(param_offset);
	pSMB->DataOffset = cpu_to_le16(offset);
	pSMB->Fid = fid;
	if (tcon->ses->capabilities & CAP_INFOLEVEL_PASSTHRU)
		pSMB->InformationLevel = cpu_to_le16(SMB_SET_FILE_BASIC_INFO2);
	else
		pSMB->InformationLevel = cpu_to_le16(SMB_SET_FILE_BASIC_INFO);
	pSMB->Reserved4 = 0;
5307
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
5308
	pSMB->ByteCount = cpu_to_le16(byte_count);
5309
	memcpy(data_offset, data, sizeof(FILE_BASIC_INFO));
5310
	rc = SendReceiveNoRsp(xid, tcon->ses, (struct smb_hdr *) pSMB, 0);
S
Steve French 已提交
5311
	if (rc)
5312
		cFYI(1, "Send error in Set Time (SetFileInfo) = %d", rc);
L
Linus Torvalds 已提交
5313

5314
	/* Note: On -EAGAIN error only caller can retry on handle based calls
L
Linus Torvalds 已提交
5315 5316 5317 5318 5319
		since file handle passed in no longer valid */

	return rc;
}

5320
int
5321
CIFSSMBSetFileDisposition(const int xid, struct cifs_tcon *tcon,
5322 5323 5324 5325 5326 5327 5328
			  bool delete_file, __u16 fid, __u32 pid_of_opener)
{
	struct smb_com_transaction2_sfi_req *pSMB  = NULL;
	char *data_offset;
	int rc = 0;
	__u16 params, param_offset, offset, byte_count, count;

5329
	cFYI(1, "Set File Disposition (via SetFileInfo)");
5330 5331 5332 5333 5334 5335 5336 5337 5338 5339 5340 5341 5342 5343 5344 5345 5346 5347 5348 5349 5350 5351 5352 5353 5354 5355 5356 5357 5358 5359 5360 5361 5362 5363 5364 5365
	rc = small_smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB);

	if (rc)
		return rc;

	pSMB->hdr.Pid = cpu_to_le16((__u16)pid_of_opener);
	pSMB->hdr.PidHigh = cpu_to_le16((__u16)(pid_of_opener >> 16));

	params = 6;
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	param_offset = offsetof(struct smb_com_transaction2_sfi_req, Fid) - 4;
	offset = param_offset + params;

	data_offset = (char *) (&pSMB->hdr.Protocol) + offset;

	count = 1;
	pSMB->MaxParameterCount = cpu_to_le16(2);
	/* BB find max SMB PDU from sess */
	pSMB->MaxDataCount = cpu_to_le16(1000);
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_SET_FILE_INFORMATION);
	byte_count = 3 /* pad */  + params + count;
	pSMB->DataCount = cpu_to_le16(count);
	pSMB->ParameterCount = cpu_to_le16(params);
	pSMB->TotalDataCount = pSMB->DataCount;
	pSMB->TotalParameterCount = pSMB->ParameterCount;
	pSMB->ParameterOffset = cpu_to_le16(param_offset);
	pSMB->DataOffset = cpu_to_le16(offset);
	pSMB->Fid = fid;
	pSMB->InformationLevel = cpu_to_le16(SMB_SET_FILE_DISPOSITION_INFO);
	pSMB->Reserved4 = 0;
5366
	inc_rfc1001_len(pSMB, byte_count);
5367 5368 5369 5370
	pSMB->ByteCount = cpu_to_le16(byte_count);
	*data_offset = delete_file ? 1 : 0;
	rc = SendReceiveNoRsp(xid, tcon->ses, (struct smb_hdr *) pSMB, 0);
	if (rc)
5371
		cFYI(1, "Send error in SetFileDisposition = %d", rc);
5372 5373 5374

	return rc;
}
L
Linus Torvalds 已提交
5375 5376

int
5377
CIFSSMBSetPathInfo(const int xid, struct cifs_tcon *tcon,
5378 5379
		   const char *fileName, const FILE_BASIC_INFO *data,
		   const struct nls_table *nls_codepage, int remap)
L
Linus Torvalds 已提交
5380 5381 5382 5383 5384 5385 5386 5387 5388
{
	TRANSACTION2_SPI_REQ *pSMB = NULL;
	TRANSACTION2_SPI_RSP *pSMBr = NULL;
	int name_len;
	int rc = 0;
	int bytes_returned = 0;
	char *data_offset;
	__u16 params, param_offset, offset, byte_count, count;

5389
	cFYI(1, "In SetTimes");
L
Linus Torvalds 已提交
5390 5391 5392 5393 5394 5395 5396 5397 5398

SetTimesRetry:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		name_len =
5399
		    cifsConvertToUCS((__le16 *) pSMB->FileName, fileName,
5400
				     PATH_MAX, nls_codepage, remap);
L
Linus Torvalds 已提交
5401 5402
		name_len++;	/* trailing null */
		name_len *= 2;
5403
	} else {	/* BB improve the check for buffer overruns BB */
L
Linus Torvalds 已提交
5404 5405 5406 5407 5408 5409
		name_len = strnlen(fileName, PATH_MAX);
		name_len++;	/* trailing null */
		strncpy(pSMB->FileName, fileName, name_len);
	}

	params = 6 + name_len;
5410
	count = sizeof(FILE_BASIC_INFO);
L
Linus Torvalds 已提交
5411
	pSMB->MaxParameterCount = cpu_to_le16(2);
5412 5413
	/* BB find max SMB PDU from sess structure BB */
	pSMB->MaxDataCount = cpu_to_le16(1000);
L
Linus Torvalds 已提交
5414 5415 5416 5417 5418 5419
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	param_offset = offsetof(struct smb_com_transaction2_spi_req,
5420
				InformationLevel) - 4;
L
Linus Torvalds 已提交
5421 5422 5423 5424 5425 5426 5427 5428 5429 5430 5431 5432 5433 5434 5435 5436 5437 5438
	offset = param_offset + params;
	data_offset = (char *) (&pSMB->hdr.Protocol) + offset;
	pSMB->ParameterOffset = cpu_to_le16(param_offset);
	pSMB->DataOffset = cpu_to_le16(offset);
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_SET_PATH_INFORMATION);
	byte_count = 3 /* pad */  + params + count;

	pSMB->DataCount = cpu_to_le16(count);
	pSMB->ParameterCount = cpu_to_le16(params);
	pSMB->TotalDataCount = pSMB->DataCount;
	pSMB->TotalParameterCount = pSMB->ParameterCount;
	if (tcon->ses->capabilities & CAP_INFOLEVEL_PASSTHRU)
		pSMB->InformationLevel = cpu_to_le16(SMB_SET_FILE_BASIC_INFO2);
	else
		pSMB->InformationLevel = cpu_to_le16(SMB_SET_FILE_BASIC_INFO);
	pSMB->Reserved4 = 0;
5439
	inc_rfc1001_len(pSMB, byte_count);
5440
	memcpy(data_offset, data, sizeof(FILE_BASIC_INFO));
L
Linus Torvalds 已提交
5441 5442 5443
	pSMB->ByteCount = cpu_to_le16(byte_count);
	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
S
Steve French 已提交
5444
	if (rc)
5445
		cFYI(1, "SetPathInfo (times) returned %d", rc);
L
Linus Torvalds 已提交
5446 5447 5448 5449 5450 5451 5452 5453 5454 5455 5456 5457 5458 5459 5460

	cifs_buf_release(pSMB);

	if (rc == -EAGAIN)
		goto SetTimesRetry;

	return rc;
}

/* Can not be used to set time stamps yet (due to old DOS time format) */
/* Can be used to set attributes */
#if 0  /* Possibly not needed - since it turns out that strangely NT4 has a bug
	  handling it anyway and NT4 was what we thought it would be needed for
	  Do not delete it until we prove whether needed for Win9x though */
int
5461
CIFSSMBSetAttrLegacy(int xid, struct cifs_tcon *tcon, char *fileName,
L
Linus Torvalds 已提交
5462 5463 5464 5465 5466 5467 5468 5469
		__u16 dos_attrs, const struct nls_table *nls_codepage)
{
	SETATTR_REQ *pSMB = NULL;
	SETATTR_RSP *pSMBr = NULL;
	int rc = 0;
	int bytes_returned;
	int name_len;

5470
	cFYI(1, "In SetAttrLegacy");
L
Linus Torvalds 已提交
5471 5472 5473 5474 5475 5476 5477 5478 5479

SetAttrLgcyRetry:
	rc = smb_init(SMB_COM_SETATTR, 8, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		name_len =
5480
			ConvertToUCS((__le16 *) pSMB->fileName, fileName,
L
Linus Torvalds 已提交
5481 5482 5483
				PATH_MAX, nls_codepage);
		name_len++;     /* trailing null */
		name_len *= 2;
5484
	} else {	/* BB improve the check for buffer overruns BB */
L
Linus Torvalds 已提交
5485 5486 5487 5488 5489 5490
		name_len = strnlen(fileName, PATH_MAX);
		name_len++;     /* trailing null */
		strncpy(pSMB->fileName, fileName, name_len);
	}
	pSMB->attr = cpu_to_le16(dos_attrs);
	pSMB->BufferFormat = 0x04;
5491
	inc_rfc1001_len(pSMB, name_len + 1);
L
Linus Torvalds 已提交
5492 5493 5494
	pSMB->ByteCount = cpu_to_le16(name_len + 1);
	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
S
Steve French 已提交
5495
	if (rc)
5496
		cFYI(1, "Error in LegacySetAttr = %d", rc);
L
Linus Torvalds 已提交
5497 5498 5499 5500 5501 5502 5503 5504 5505 5506

	cifs_buf_release(pSMB);

	if (rc == -EAGAIN)
		goto SetAttrLgcyRetry;

	return rc;
}
#endif /* temporarily unneeded SetAttr legacy function */

5507 5508 5509 5510 5511 5512 5513 5514 5515 5516
static void
cifs_fill_unix_set_info(FILE_UNIX_BASIC_INFO *data_offset,
			const struct cifs_unix_set_info_args *args)
{
	u64 mode = args->mode;

	/*
	 * Samba server ignores set of file size to zero due to bugs in some
	 * older clients, but we should be precise - we use SetFileSize to
	 * set file size and do not want to truncate file size to zero
L
Lucas De Marchi 已提交
5517
	 * accidentally as happened on one Samba server beta by putting
5518 5519 5520 5521 5522 5523 5524 5525 5526 5527 5528 5529 5530 5531 5532 5533 5534 5535 5536 5537 5538 5539 5540 5541 5542 5543 5544 5545 5546 5547
	 * zero instead of -1 here
	 */
	data_offset->EndOfFile = cpu_to_le64(NO_CHANGE_64);
	data_offset->NumOfBytes = cpu_to_le64(NO_CHANGE_64);
	data_offset->LastStatusChange = cpu_to_le64(args->ctime);
	data_offset->LastAccessTime = cpu_to_le64(args->atime);
	data_offset->LastModificationTime = cpu_to_le64(args->mtime);
	data_offset->Uid = cpu_to_le64(args->uid);
	data_offset->Gid = cpu_to_le64(args->gid);
	/* better to leave device as zero when it is  */
	data_offset->DevMajor = cpu_to_le64(MAJOR(args->device));
	data_offset->DevMinor = cpu_to_le64(MINOR(args->device));
	data_offset->Permissions = cpu_to_le64(mode);

	if (S_ISREG(mode))
		data_offset->Type = cpu_to_le32(UNIX_FILE);
	else if (S_ISDIR(mode))
		data_offset->Type = cpu_to_le32(UNIX_DIR);
	else if (S_ISLNK(mode))
		data_offset->Type = cpu_to_le32(UNIX_SYMLINK);
	else if (S_ISCHR(mode))
		data_offset->Type = cpu_to_le32(UNIX_CHARDEV);
	else if (S_ISBLK(mode))
		data_offset->Type = cpu_to_le32(UNIX_BLOCKDEV);
	else if (S_ISFIFO(mode))
		data_offset->Type = cpu_to_le32(UNIX_FIFO);
	else if (S_ISSOCK(mode))
		data_offset->Type = cpu_to_le32(UNIX_SOCKET);
}

5548
int
5549
CIFSSMBUnixSetFileInfo(const int xid, struct cifs_tcon *tcon,
5550 5551 5552 5553 5554 5555 5556 5557
		       const struct cifs_unix_set_info_args *args,
		       u16 fid, u32 pid_of_opener)
{
	struct smb_com_transaction2_sfi_req *pSMB  = NULL;
	FILE_UNIX_BASIC_INFO *data_offset;
	int rc = 0;
	u16 params, param_offset, offset, byte_count, count;

5558
	cFYI(1, "Set Unix Info (via SetFileInfo)");
5559 5560 5561 5562 5563 5564 5565 5566 5567 5568 5569 5570 5571 5572 5573 5574 5575 5576 5577 5578 5579 5580 5581 5582 5583 5584 5585 5586 5587 5588 5589 5590 5591 5592 5593 5594 5595
	rc = small_smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB);

	if (rc)
		return rc;

	pSMB->hdr.Pid = cpu_to_le16((__u16)pid_of_opener);
	pSMB->hdr.PidHigh = cpu_to_le16((__u16)(pid_of_opener >> 16));

	params = 6;
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	param_offset = offsetof(struct smb_com_transaction2_sfi_req, Fid) - 4;
	offset = param_offset + params;

	data_offset = (FILE_UNIX_BASIC_INFO *)
				((char *)(&pSMB->hdr.Protocol) + offset);
	count = sizeof(FILE_UNIX_BASIC_INFO);

	pSMB->MaxParameterCount = cpu_to_le16(2);
	/* BB find max SMB PDU from sess */
	pSMB->MaxDataCount = cpu_to_le16(1000);
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_SET_FILE_INFORMATION);
	byte_count = 3 /* pad */  + params + count;
	pSMB->DataCount = cpu_to_le16(count);
	pSMB->ParameterCount = cpu_to_le16(params);
	pSMB->TotalDataCount = pSMB->DataCount;
	pSMB->TotalParameterCount = pSMB->ParameterCount;
	pSMB->ParameterOffset = cpu_to_le16(param_offset);
	pSMB->DataOffset = cpu_to_le16(offset);
	pSMB->Fid = fid;
	pSMB->InformationLevel = cpu_to_le16(SMB_SET_FILE_UNIX_BASIC);
	pSMB->Reserved4 = 0;
5596
	inc_rfc1001_len(pSMB, byte_count);
5597 5598 5599 5600 5601 5602
	pSMB->ByteCount = cpu_to_le16(byte_count);

	cifs_fill_unix_set_info(data_offset, args);

	rc = SendReceiveNoRsp(xid, tcon->ses, (struct smb_hdr *) pSMB, 0);
	if (rc)
5603
		cFYI(1, "Send error in Set Time (SetFileInfo) = %d", rc);
5604 5605 5606 5607 5608 5609 5610

	/* Note: On -EAGAIN error only caller can retry on handle based calls
		since file handle passed in no longer valid */

	return rc;
}

L
Linus Torvalds 已提交
5611
int
5612
CIFSSMBUnixSetPathInfo(const int xid, struct cifs_tcon *tcon, char *fileName,
5613 5614
		       const struct cifs_unix_set_info_args *args,
		       const struct nls_table *nls_codepage, int remap)
L
Linus Torvalds 已提交
5615 5616 5617 5618 5619 5620 5621 5622 5623
{
	TRANSACTION2_SPI_REQ *pSMB = NULL;
	TRANSACTION2_SPI_RSP *pSMBr = NULL;
	int name_len;
	int rc = 0;
	int bytes_returned = 0;
	FILE_UNIX_BASIC_INFO *data_offset;
	__u16 params, param_offset, offset, count, byte_count;

5624
	cFYI(1, "In SetUID/GID/Mode");
L
Linus Torvalds 已提交
5625 5626 5627 5628 5629 5630 5631 5632
setPermsRetry:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		name_len =
5633
		    cifsConvertToUCS((__le16 *) pSMB->FileName, fileName,
5634
				     PATH_MAX, nls_codepage, remap);
L
Linus Torvalds 已提交
5635 5636
		name_len++;	/* trailing null */
		name_len *= 2;
5637
	} else {	/* BB improve the check for buffer overruns BB */
L
Linus Torvalds 已提交
5638 5639 5640 5641 5642 5643
		name_len = strnlen(fileName, PATH_MAX);
		name_len++;	/* trailing null */
		strncpy(pSMB->FileName, fileName, name_len);
	}

	params = 6 + name_len;
5644
	count = sizeof(FILE_UNIX_BASIC_INFO);
L
Linus Torvalds 已提交
5645
	pSMB->MaxParameterCount = cpu_to_le16(2);
5646 5647
	/* BB find max SMB PDU from sess structure BB */
	pSMB->MaxDataCount = cpu_to_le16(1000);
L
Linus Torvalds 已提交
5648 5649 5650 5651 5652 5653
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	param_offset = offsetof(struct smb_com_transaction2_spi_req,
5654
				InformationLevel) - 4;
L
Linus Torvalds 已提交
5655 5656 5657 5658 5659 5660 5661 5662 5663 5664 5665 5666 5667 5668 5669 5670 5671
	offset = param_offset + params;
	data_offset =
	    (FILE_UNIX_BASIC_INFO *) ((char *) &pSMB->hdr.Protocol +
				      offset);
	memset(data_offset, 0, count);
	pSMB->DataOffset = cpu_to_le16(offset);
	pSMB->ParameterOffset = cpu_to_le16(param_offset);
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_SET_PATH_INFORMATION);
	byte_count = 3 /* pad */  + params + count;
	pSMB->ParameterCount = cpu_to_le16(params);
	pSMB->DataCount = cpu_to_le16(count);
	pSMB->TotalParameterCount = pSMB->ParameterCount;
	pSMB->TotalDataCount = pSMB->DataCount;
	pSMB->InformationLevel = cpu_to_le16(SMB_SET_FILE_UNIX_BASIC);
	pSMB->Reserved4 = 0;
5672
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
5673

5674
	cifs_fill_unix_set_info(data_offset, args);
L
Linus Torvalds 已提交
5675 5676 5677 5678

	pSMB->ByteCount = cpu_to_le16(byte_count);
	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
S
Steve French 已提交
5679
	if (rc)
5680
		cFYI(1, "SetPathInfo (perms) returned %d", rc);
L
Linus Torvalds 已提交
5681

5682
	cifs_buf_release(pSMB);
L
Linus Torvalds 已提交
5683 5684 5685 5686 5687 5688
	if (rc == -EAGAIN)
		goto setPermsRetry;
	return rc;
}

#ifdef CONFIG_CIFS_XATTR
5689 5690 5691 5692 5693 5694 5695 5696 5697
/*
 * Do a path-based QUERY_ALL_EAS call and parse the result. This is a common
 * function used by listxattr and getxattr type calls. When ea_name is set,
 * it looks for that attribute name and stuffs that value into the EAData
 * buffer. When ea_name is NULL, it stuffs a list of attribute names into the
 * buffer. In both cases, the return value is either the length of the
 * resulting data or a negative error code. If EAData is a NULL pointer then
 * the data isn't copied to it, but the length is returned.
 */
L
Linus Torvalds 已提交
5698
ssize_t
5699
CIFSSMBQAllEAs(const int xid, struct cifs_tcon *tcon,
5700 5701 5702
		const unsigned char *searchName, const unsigned char *ea_name,
		char *EAData, size_t buf_size,
		const struct nls_table *nls_codepage, int remap)
L
Linus Torvalds 已提交
5703 5704 5705 5706 5707 5708
{
		/* BB assumes one setup word */
	TRANSACTION2_QPI_REQ *pSMB = NULL;
	TRANSACTION2_QPI_RSP *pSMBr = NULL;
	int rc = 0;
	int bytes_returned;
5709
	int list_len;
5710
	struct fealist *ea_response_data;
5711 5712
	struct fea *temp_fea;
	char *temp_ptr;
5713
	char *end_of_smb;
5714
	__u16 params, byte_count, data_offset;
5715
	unsigned int ea_name_len = ea_name ? strlen(ea_name) : 0;
L
Linus Torvalds 已提交
5716

5717
	cFYI(1, "In Query All EAs path %s", searchName);
L
Linus Torvalds 已提交
5718 5719 5720 5721 5722 5723 5724
QAllEAsRetry:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
5725
		list_len =
5726
		    cifsConvertToUCS((__le16 *) pSMB->FileName, searchName,
5727
				     PATH_MAX, nls_codepage, remap);
5728 5729
		list_len++;	/* trailing null */
		list_len *= 2;
L
Linus Torvalds 已提交
5730
	} else {	/* BB improve the check for buffer overruns BB */
5731 5732 5733
		list_len = strnlen(searchName, PATH_MAX);
		list_len++;	/* trailing null */
		strncpy(pSMB->FileName, searchName, list_len);
L
Linus Torvalds 已提交
5734 5735
	}

5736
	params = 2 /* level */ + 4 /* reserved */ + list_len /* includes NUL */;
L
Linus Torvalds 已提交
5737 5738
	pSMB->TotalDataCount = 0;
	pSMB->MaxParameterCount = cpu_to_le16(2);
5739
	/* BB find exact max SMB PDU from sess structure BB */
5740
	pSMB->MaxDataCount = cpu_to_le16(CIFSMaxBufSize);
L
Linus Torvalds 已提交
5741 5742 5743 5744 5745 5746
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	pSMB->ParameterOffset = cpu_to_le16(offsetof(
5747
	struct smb_com_transaction2_qpi_req, InformationLevel) - 4);
L
Linus Torvalds 已提交
5748 5749 5750 5751 5752 5753 5754 5755 5756 5757
	pSMB->DataCount = 0;
	pSMB->DataOffset = 0;
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_QUERY_PATH_INFORMATION);
	byte_count = params + 1 /* pad */ ;
	pSMB->TotalParameterCount = cpu_to_le16(params);
	pSMB->ParameterCount = pSMB->TotalParameterCount;
	pSMB->InformationLevel = cpu_to_le16(SMB_INFO_QUERY_ALL_EAS);
	pSMB->Reserved4 = 0;
5758
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
5759 5760 5761 5762 5763
	pSMB->ByteCount = cpu_to_le16(byte_count);

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
	if (rc) {
5764
		cFYI(1, "Send error in QueryAllEAs = %d", rc);
5765 5766
		goto QAllEAsOut;
	}
L
Linus Torvalds 已提交
5767

5768 5769 5770 5771 5772 5773

	/* BB also check enough total bytes returned */
	/* BB we need to improve the validity checking
	of these trans2 responses */

	rc = validate_t2((struct smb_t2_rsp *)pSMBr);
5774
	if (rc || get_bcc(&pSMBr->hdr) < 4) {
5775 5776 5777 5778 5779 5780 5781 5782 5783 5784 5785 5786 5787 5788 5789 5790
		rc = -EIO;	/* bad smb */
		goto QAllEAsOut;
	}

	/* check that length of list is not more than bcc */
	/* check that each entry does not go beyond length
	   of list */
	/* check that each element of each entry does not
	   go beyond end of list */
	/* validate_trans2_offsets() */
	/* BB check if start of smb + data_offset > &bcc+ bcc */

	data_offset = le16_to_cpu(pSMBr->t2.DataOffset);
	ea_response_data = (struct fealist *)
				(((char *) &pSMBr->hdr.Protocol) + data_offset);

5791
	list_len = le32_to_cpu(ea_response_data->list_len);
5792
	cFYI(1, "ea length %d", list_len);
5793
	if (list_len <= 8) {
5794
		cFYI(1, "empty EA list returned from server");
5795 5796 5797
		goto QAllEAsOut;
	}

5798
	/* make sure list_len doesn't go past end of SMB */
5799
	end_of_smb = (char *)pByteArea(&pSMBr->hdr) + get_bcc(&pSMBr->hdr);
5800
	if ((char *)ea_response_data + list_len > end_of_smb) {
5801
		cFYI(1, "EA list appears to go beyond SMB");
5802 5803 5804 5805
		rc = -EIO;
		goto QAllEAsOut;
	}

5806
	/* account for ea list len */
5807
	list_len -= 4;
5808 5809
	temp_fea = ea_response_data->list;
	temp_ptr = (char *)temp_fea;
5810
	while (list_len > 0) {
5811
		unsigned int name_len;
5812
		__u16 value_len;
5813

5814
		list_len -= 4;
5815
		temp_ptr += 4;
5816 5817
		/* make sure we can read name_len and value_len */
		if (list_len < 0) {
5818
			cFYI(1, "EA entry goes beyond length of list");
5819 5820 5821 5822 5823 5824 5825 5826
			rc = -EIO;
			goto QAllEAsOut;
		}

		name_len = temp_fea->name_len;
		value_len = le16_to_cpu(temp_fea->value_len);
		list_len -= name_len + 1 + value_len;
		if (list_len < 0) {
5827
			cFYI(1, "EA entry goes beyond length of list");
5828 5829 5830 5831
			rc = -EIO;
			goto QAllEAsOut;
		}

5832
		if (ea_name) {
5833
			if (ea_name_len == name_len &&
5834
			    memcmp(ea_name, temp_ptr, name_len) == 0) {
5835 5836 5837 5838 5839 5840 5841 5842 5843 5844 5845
				temp_ptr += name_len + 1;
				rc = value_len;
				if (buf_size == 0)
					goto QAllEAsOut;
				if ((size_t)value_len > buf_size) {
					rc = -ERANGE;
					goto QAllEAsOut;
				}
				memcpy(EAData, temp_ptr, value_len);
				goto QAllEAsOut;
			}
5846
		} else {
5847 5848 5849 5850 5851 5852 5853 5854 5855 5856 5857 5858 5859 5860 5861 5862 5863
			/* account for prefix user. and trailing null */
			rc += (5 + 1 + name_len);
			if (rc < (int) buf_size) {
				memcpy(EAData, "user.", 5);
				EAData += 5;
				memcpy(EAData, temp_ptr, name_len);
				EAData += name_len;
				/* null terminate name */
				*EAData = 0;
				++EAData;
			} else if (buf_size == 0) {
				/* skip copy - calc size only */
			} else {
				/* stop before overrun buffer */
				rc = -ERANGE;
				break;
			}
L
Linus Torvalds 已提交
5864
		}
5865
		temp_ptr += name_len + 1 + value_len;
5866
		temp_fea = (struct fea *)temp_ptr;
L
Linus Torvalds 已提交
5867
	}
5868

5869 5870 5871 5872
	/* didn't find the named attribute */
	if (ea_name)
		rc = -ENODATA;

5873
QAllEAsOut:
5874
	cifs_buf_release(pSMB);
L
Linus Torvalds 已提交
5875 5876 5877 5878 5879 5880 5881
	if (rc == -EAGAIN)
		goto QAllEAsRetry;

	return (ssize_t)rc;
}

int
5882
CIFSSMBSetEA(const int xid, struct cifs_tcon *tcon, const char *fileName,
5883 5884 5885
	     const char *ea_name, const void *ea_value,
	     const __u16 ea_value_len, const struct nls_table *nls_codepage,
	     int remap)
L
Linus Torvalds 已提交
5886 5887 5888 5889 5890 5891 5892 5893 5894
{
	struct smb_com_transaction2_spi_req *pSMB = NULL;
	struct smb_com_transaction2_spi_rsp *pSMBr = NULL;
	struct fealist *parm_data;
	int name_len;
	int rc = 0;
	int bytes_returned = 0;
	__u16 params, param_offset, byte_count, offset, count;

5895
	cFYI(1, "In SetEA");
L
Linus Torvalds 已提交
5896 5897 5898 5899 5900 5901 5902 5903
SetEARetry:
	rc = smb_init(SMB_COM_TRANSACTION2, 15, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	if (pSMB->hdr.Flags2 & SMBFLG2_UNICODE) {
		name_len =
5904
		    cifsConvertToUCS((__le16 *) pSMB->FileName, fileName,
5905
				     PATH_MAX, nls_codepage, remap);
L
Linus Torvalds 已提交
5906 5907
		name_len++;	/* trailing null */
		name_len *= 2;
5908
	} else {	/* BB improve the check for buffer overruns BB */
L
Linus Torvalds 已提交
5909 5910 5911 5912 5913 5914 5915 5916 5917 5918
		name_len = strnlen(fileName, PATH_MAX);
		name_len++;	/* trailing null */
		strncpy(pSMB->FileName, fileName, name_len);
	}

	params = 6 + name_len;

	/* done calculating parms using name_len of file name,
	now use name_len to calculate length of ea name
	we are going to create in the inode xattrs */
S
Steve French 已提交
5919
	if (ea_name == NULL)
L
Linus Torvalds 已提交
5920 5921
		name_len = 0;
	else
5922
		name_len = strnlen(ea_name, 255);
L
Linus Torvalds 已提交
5923

5924
	count = sizeof(*parm_data) + ea_value_len + name_len;
L
Linus Torvalds 已提交
5925
	pSMB->MaxParameterCount = cpu_to_le16(2);
5926 5927
	/* BB find max SMB PDU from sess */
	pSMB->MaxDataCount = cpu_to_le16(1000);
L
Linus Torvalds 已提交
5928 5929 5930 5931 5932 5933
	pSMB->MaxSetupCount = 0;
	pSMB->Reserved = 0;
	pSMB->Flags = 0;
	pSMB->Timeout = 0;
	pSMB->Reserved2 = 0;
	param_offset = offsetof(struct smb_com_transaction2_spi_req,
5934
				InformationLevel) - 4;
L
Linus Torvalds 已提交
5935 5936 5937 5938 5939 5940 5941 5942 5943 5944 5945 5946 5947 5948 5949 5950 5951
	offset = param_offset + params;
	pSMB->InformationLevel =
		cpu_to_le16(SMB_SET_FILE_EA);

	parm_data =
		(struct fealist *) (((char *) &pSMB->hdr.Protocol) +
				       offset);
	pSMB->ParameterOffset = cpu_to_le16(param_offset);
	pSMB->DataOffset = cpu_to_le16(offset);
	pSMB->SetupCount = 1;
	pSMB->Reserved3 = 0;
	pSMB->SubCommand = cpu_to_le16(TRANS2_SET_PATH_INFORMATION);
	byte_count = 3 /* pad */  + params + count;
	pSMB->DataCount = cpu_to_le16(count);
	parm_data->list_len = cpu_to_le32(count);
	parm_data->list[0].EA_flags = 0;
	/* we checked above that name len is less than 255 */
A
Alexey Dobriyan 已提交
5952
	parm_data->list[0].name_len = (__u8)name_len;
L
Linus Torvalds 已提交
5953
	/* EA names are always ASCII */
S
Steve French 已提交
5954
	if (ea_name)
5955
		strncpy(parm_data->list[0].name, ea_name, name_len);
L
Linus Torvalds 已提交
5956 5957 5958 5959 5960
	parm_data->list[0].name[name_len] = 0;
	parm_data->list[0].value_len = cpu_to_le16(ea_value_len);
	/* caller ensures that ea_value_len is less than 64K but
	we need to ensure that it fits within the smb */

5961 5962
	/*BB add length check to see if it would fit in
	     negotiated SMB buffer size BB */
S
Steve French 已提交
5963 5964
	/* if (ea_value_len > buffer_size - 512 (enough for header)) */
	if (ea_value_len)
5965 5966
		memcpy(parm_data->list[0].name+name_len+1,
		       ea_value, ea_value_len);
L
Linus Torvalds 已提交
5967 5968 5969 5970 5971

	pSMB->TotalDataCount = pSMB->DataCount;
	pSMB->ParameterCount = cpu_to_le16(params);
	pSMB->TotalParameterCount = pSMB->ParameterCount;
	pSMB->Reserved4 = 0;
5972
	inc_rfc1001_len(pSMB, byte_count);
L
Linus Torvalds 已提交
5973 5974 5975
	pSMB->ByteCount = cpu_to_le16(byte_count);
	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *) pSMBr, &bytes_returned, 0);
S
Steve French 已提交
5976
	if (rc)
5977
		cFYI(1, "SetPathInfo (EA) returned %d", rc);
L
Linus Torvalds 已提交
5978 5979 5980 5981 5982 5983 5984 5985 5986

	cifs_buf_release(pSMB);

	if (rc == -EAGAIN)
		goto SetEARetry;

	return rc;
}
#endif
5987 5988 5989 5990 5991 5992 5993 5994 5995 5996 5997 5998 5999 6000 6001 6002 6003 6004 6005 6006 6007 6008

#ifdef CONFIG_CIFS_DNOTIFY_EXPERIMENTAL /* BB unused temporarily */
/*
 *	Years ago the kernel added a "dnotify" function for Samba server,
 *	to allow network clients (such as Windows) to display updated
 *	lists of files in directory listings automatically when
 *	files are added by one user when another user has the
 *	same directory open on their desktop.  The Linux cifs kernel
 *	client hooked into the kernel side of this interface for
 *	the same reason, but ironically when the VFS moved from
 *	"dnotify" to "inotify" it became harder to plug in Linux
 *	network file system clients (the most obvious use case
 *	for notify interfaces is when multiple users can update
 *	the contents of the same directory - exactly what network
 *	file systems can do) although the server (Samba) could
 *	still use it.  For the short term we leave the worker
 *	function ifdeffed out (below) until inotify is fixed
 *	in the VFS to make it easier to plug in network file
 *	system clients.  If inotify turns out to be permanently
 *	incompatible for network fs clients, we could instead simply
 *	expose this config flag by adding a future cifs (and smb2) notify ioctl.
 */
6009
int CIFSSMBNotify(const int xid, struct cifs_tcon *tcon,
6010 6011 6012 6013 6014 6015 6016 6017 6018 6019 6020 6021 6022 6023 6024 6025 6026 6027 6028
		  const int notify_subdirs, const __u16 netfid,
		  __u32 filter, struct file *pfile, int multishot,
		  const struct nls_table *nls_codepage)
{
	int rc = 0;
	struct smb_com_transaction_change_notify_req *pSMB = NULL;
	struct smb_com_ntransaction_change_notify_rsp *pSMBr = NULL;
	struct dir_notify_req *dnotify_req;
	int bytes_returned;

	cFYI(1, "In CIFSSMBNotify for file handle %d", (int)netfid);
	rc = smb_init(SMB_COM_NT_TRANSACT, 23, tcon, (void **) &pSMB,
		      (void **) &pSMBr);
	if (rc)
		return rc;

	pSMB->TotalParameterCount = 0 ;
	pSMB->TotalDataCount = 0;
	pSMB->MaxParameterCount = cpu_to_le32(2);
6029
	pSMB->MaxDataCount = cpu_to_le32(CIFSMaxBufSize & 0xFFFFFF00);
6030 6031 6032 6033 6034 6035 6036 6037 6038 6039 6040 6041 6042 6043 6044 6045 6046 6047 6048 6049 6050 6051 6052 6053 6054 6055 6056 6057 6058 6059 6060 6061 6062 6063 6064 6065 6066 6067 6068 6069 6070 6071 6072 6073 6074 6075 6076
	pSMB->MaxSetupCount = 4;
	pSMB->Reserved = 0;
	pSMB->ParameterOffset = 0;
	pSMB->DataCount = 0;
	pSMB->DataOffset = 0;
	pSMB->SetupCount = 4; /* single byte does not need le conversion */
	pSMB->SubCommand = cpu_to_le16(NT_TRANSACT_NOTIFY_CHANGE);
	pSMB->ParameterCount = pSMB->TotalParameterCount;
	if (notify_subdirs)
		pSMB->WatchTree = 1; /* one byte - no le conversion needed */
	pSMB->Reserved2 = 0;
	pSMB->CompletionFilter = cpu_to_le32(filter);
	pSMB->Fid = netfid; /* file handle always le */
	pSMB->ByteCount = 0;

	rc = SendReceive(xid, tcon->ses, (struct smb_hdr *) pSMB,
			 (struct smb_hdr *)pSMBr, &bytes_returned,
			 CIFS_ASYNC_OP);
	if (rc) {
		cFYI(1, "Error in Notify = %d", rc);
	} else {
		/* Add file to outstanding requests */
		/* BB change to kmem cache alloc */
		dnotify_req = kmalloc(
						sizeof(struct dir_notify_req),
						 GFP_KERNEL);
		if (dnotify_req) {
			dnotify_req->Pid = pSMB->hdr.Pid;
			dnotify_req->PidHigh = pSMB->hdr.PidHigh;
			dnotify_req->Mid = pSMB->hdr.Mid;
			dnotify_req->Tid = pSMB->hdr.Tid;
			dnotify_req->Uid = pSMB->hdr.Uid;
			dnotify_req->netfid = netfid;
			dnotify_req->pfile = pfile;
			dnotify_req->filter = filter;
			dnotify_req->multishot = multishot;
			spin_lock(&GlobalMid_Lock);
			list_add_tail(&dnotify_req->lhead,
					&GlobalDnotifyReqList);
			spin_unlock(&GlobalMid_Lock);
		} else
			rc = -ENOMEM;
	}
	cifs_buf_release(pSMB);
	return rc;
}
#endif /* was needed for dnotify, and will be needed for inotify when VFS fix */