Line data Source code
1 : /*
2 : Unix SMB/CIFS implementation.
3 : change notify handling
4 : Copyright (C) Andrew Tridgell 2000
5 : Copyright (C) Jeremy Allison 1994-1998
6 : Copyright (C) Volker Lendecke 2007
7 :
8 : This program is free software; you can redistribute it and/or modify
9 : it under the terms of the GNU General Public License as published by
10 : the Free Software Foundation; either version 3 of the License, or
11 : (at your option) any later version.
12 :
13 : This program is distributed in the hope that it will be useful,
14 : but WITHOUT ANY WARRANTY; without even the implied warranty of
15 : MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 : GNU General Public License for more details.
17 :
18 : You should have received a copy of the GNU General Public License
19 : along with this program. If not, see <http://www.gnu.org/licenses/>.
20 : */
21 :
22 : #include "includes.h"
23 : #include "smbd/smbd.h"
24 : #include "smbd/globals.h"
25 : #include "../librpc/gen_ndr/ndr_notify.h"
26 : #include "librpc/gen_ndr/ndr_file_id.h"
27 : #include "libcli/security/privileges.h"
28 : #include "libcli/security/security.h"
29 :
30 : struct notify_change_event {
31 : struct timespec when;
32 : uint32_t action;
33 : const char *name;
34 : };
35 :
36 : struct notify_change_buf {
37 : /*
38 : * Filters for reinitializing after notifyd has been restarted
39 : */
40 : uint32_t filter;
41 : uint32_t subdir_filter;
42 :
43 : /*
44 : * If no requests are pending, changes are queued here. Simple array,
45 : * we only append.
46 : */
47 :
48 : uint32_t max_buffer_size;
49 :
50 : /*
51 : * num_changes == -1 means that we have got a catch-all change, when
52 : * asked we just return NT_STATUS_OK without specific changes.
53 : */
54 : int num_changes;
55 : struct notify_change_event *changes;
56 :
57 : /*
58 : * If no changes are around requests are queued here. Using a linked
59 : * list, because we have to append at the end and delete from the top.
60 : */
61 : struct notify_change_request *requests;
62 : };
63 :
64 : struct notify_change_request {
65 : struct notify_change_request *prev, *next;
66 : struct files_struct *fsp; /* backpointer for cancel by mid */
67 : struct smb_request *req;
68 : uint32_t filter;
69 : uint32_t max_param;
70 : void (*reply_fn)(struct smb_request *req,
71 : NTSTATUS error_code,
72 : uint8_t *buf, size_t len);
73 : struct notify_mid_map *mid_map;
74 : void *backend_data;
75 : };
76 :
77 : static void notify_fsp(files_struct *fsp, struct timespec when,
78 : uint32_t action, const char *name);
79 :
80 2780 : bool change_notify_fsp_has_changes(struct files_struct *fsp)
81 : {
82 2780 : if (fsp == NULL) {
83 0 : return false;
84 : }
85 :
86 2780 : if (fsp->notify == NULL) {
87 0 : return false;
88 : }
89 :
90 2780 : if (fsp->notify->num_changes == 0) {
91 2672 : return false;
92 : }
93 :
94 108 : return true;
95 : }
96 :
97 : /*
98 : * For NTCancel, we need to find the notify_change_request indexed by
99 : * mid. Separate list here.
100 : */
101 :
102 : struct notify_mid_map {
103 : struct notify_mid_map *prev, *next;
104 : struct notify_change_request *req;
105 : uint64_t mid;
106 : };
107 :
108 1080 : static bool notify_change_record_identical(struct notify_change_event *c1,
109 : struct notify_change_event *c2)
110 : {
111 : /* Note this is deliberately case sensitive. */
112 1080 : if (c1->action == c2->action &&
113 300 : strcmp(c1->name, c2->name) == 0) {
114 0 : return True;
115 : }
116 1080 : return False;
117 : }
118 :
119 3290 : static int compare_notify_change_events(const void *p1, const void *p2)
120 : {
121 3290 : const struct notify_change_event *e1 = p1;
122 3290 : const struct notify_change_event *e2 = p2;
123 :
124 3290 : return timespec_compare(&e1->when, &e2->when);
125 : }
126 :
127 242 : static bool notify_marshall_changes(int num_changes,
128 : uint32_t max_offset,
129 : struct notify_change_event *changes,
130 : DATA_BLOB *final_blob)
131 : {
132 0 : int i;
133 :
134 242 : if (num_changes == -1) {
135 0 : return false;
136 : }
137 :
138 : /*
139 : * Sort the notifies by timestamp when the event happened to avoid
140 : * coalescing and thus dropping events.
141 : */
142 :
143 242 : qsort(changes, num_changes,
144 : sizeof(*changes), compare_notify_change_events);
145 :
146 1554 : for (i=0; i<num_changes; i++) {
147 0 : enum ndr_err_code ndr_err;
148 0 : struct notify_change_event *c;
149 0 : struct FILE_NOTIFY_INFORMATION m;
150 0 : DATA_BLOB blob;
151 1318 : uint16_t pad = 0;
152 :
153 : /* Coalesce any identical records. */
154 2398 : while (i+1 < num_changes &&
155 1080 : notify_change_record_identical(&changes[i],
156 1080 : &changes[i+1])) {
157 0 : i++;
158 : }
159 :
160 1318 : c = &changes[i];
161 :
162 1318 : m.FileName1 = c->name;
163 1318 : m.FileNameLength = strlen_m(c->name)*2;
164 1318 : m.Action = c->action;
165 :
166 1318 : m._pad = data_blob_null;
167 :
168 : /*
169 : * Offset to next entry, only if there is one
170 : */
171 :
172 1318 : if (i == (num_changes-1)) {
173 238 : m.NextEntryOffset = 0;
174 : } else {
175 1080 : if ((m.FileNameLength % 4) == 2) {
176 456 : m._pad = data_blob_const(&pad, 2);
177 : }
178 1080 : m.NextEntryOffset =
179 1080 : ndr_size_FILE_NOTIFY_INFORMATION(&m, 0);
180 : }
181 :
182 1318 : ndr_err = ndr_push_struct_blob(&blob, talloc_tos(), &m,
183 : (ndr_push_flags_fn_t)ndr_push_FILE_NOTIFY_INFORMATION);
184 1318 : if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err)) {
185 6 : return false;
186 : }
187 :
188 1318 : if (DEBUGLEVEL >= 10) {
189 0 : NDR_PRINT_DEBUG(FILE_NOTIFY_INFORMATION, &m);
190 : }
191 :
192 1318 : if (!data_blob_append(talloc_tos(), final_blob,
193 1318 : blob.data, blob.length)) {
194 0 : data_blob_free(&blob);
195 0 : return false;
196 : }
197 :
198 1318 : data_blob_free(&blob);
199 :
200 1318 : if (final_blob->length > max_offset) {
201 : /* Too much data for client. */
202 6 : DEBUG(10, ("Client only wanted %d bytes, trying to "
203 : "marshall %d bytes\n", (int)max_offset,
204 : (int)final_blob->length));
205 6 : return False;
206 : }
207 : }
208 :
209 236 : return True;
210 : }
211 :
212 : /****************************************************************************
213 : Setup the common parts of the return packet and send it.
214 : *****************************************************************************/
215 :
216 2780 : void change_notify_reply(struct smb_request *req,
217 : NTSTATUS error_code,
218 : uint32_t max_param,
219 : struct notify_change_buf *notify_buf,
220 : void (*reply_fn)(struct smb_request *req,
221 : NTSTATUS error_code,
222 : uint8_t *buf, size_t len))
223 : {
224 2780 : DATA_BLOB blob = data_blob_null;
225 :
226 2780 : if (!NT_STATUS_IS_OK(error_code)) {
227 2528 : reply_fn(req, error_code, NULL, 0);
228 2554 : return;
229 : }
230 :
231 252 : if (notify_buf == NULL) {
232 10 : reply_fn(req, NT_STATUS_OK, NULL, 0);
233 10 : return;
234 : }
235 :
236 242 : max_param = MIN(max_param, notify_buf->max_buffer_size);
237 :
238 242 : if (!notify_marshall_changes(notify_buf->num_changes, max_param,
239 : notify_buf->changes, &blob)) {
240 : /*
241 : * We exceed what the client is willing to accept. Send
242 : * nothing.
243 : */
244 6 : data_blob_free(&blob);
245 : }
246 :
247 242 : reply_fn(req, NT_STATUS_OK, blob.data, blob.length);
248 :
249 242 : data_blob_free(&blob);
250 :
251 242 : TALLOC_FREE(notify_buf->changes);
252 242 : notify_buf->num_changes = 0;
253 : }
254 :
255 : struct notify_fsp_state {
256 : struct files_struct *notified_fsp;
257 : struct timespec when;
258 : const struct notify_event *e;
259 : };
260 :
261 9410 : static struct files_struct *notify_fsp_cb(struct files_struct *fsp,
262 : void *private_data)
263 : {
264 9410 : struct notify_fsp_state *state = private_data;
265 :
266 9410 : if (fsp == state->notified_fsp) {
267 1968 : DBG_DEBUG("notify_callback called for %s\n", fsp_str_dbg(fsp));
268 1968 : notify_fsp(fsp, state->when, state->e->action, state->e->path);
269 1968 : return fsp;
270 : }
271 :
272 7442 : return NULL;
273 : }
274 :
275 1971 : void notify_callback(struct smbd_server_connection *sconn,
276 : void *private_data, struct timespec when,
277 : const struct notify_event *e)
278 : {
279 1971 : struct notify_fsp_state state = {
280 : .notified_fsp = private_data, .when = when, .e = e
281 : };
282 1971 : files_forall(sconn, notify_fsp_cb, &state);
283 1971 : }
284 :
285 1868 : NTSTATUS change_notify_create(struct files_struct *fsp,
286 : uint32_t max_buffer_size,
287 : uint32_t filter,
288 : bool recursive)
289 1868 : {
290 1868 : size_t len = fsp_fullbasepath(fsp, NULL, 0);
291 1868 : char fullpath[len+1];
292 1868 : NTSTATUS status = NT_STATUS_NOT_IMPLEMENTED;
293 :
294 : /*
295 : * Setting a changenotify needs READ/LIST access
296 : * on the directory handle.
297 : */
298 1868 : status = check_any_access_fsp(fsp, SEC_DIR_LIST);
299 1868 : if (!NT_STATUS_IS_OK(status)) {
300 2 : return status;
301 : }
302 :
303 1866 : if (fsp->notify != NULL) {
304 0 : DEBUG(1, ("change_notify_create: fsp->notify != NULL, "
305 : "fname = %s\n", fsp->fsp_name->base_name));
306 0 : return NT_STATUS_INVALID_PARAMETER;
307 : }
308 :
309 1866 : if (!(fsp->notify = talloc_zero(NULL, struct notify_change_buf))) {
310 0 : DEBUG(0, ("talloc failed\n"));
311 0 : return NT_STATUS_NO_MEMORY;
312 : }
313 1866 : fsp->notify->filter = filter;
314 1866 : fsp->notify->subdir_filter = recursive ? filter : 0;
315 1866 : fsp->notify->max_buffer_size = max_buffer_size;
316 :
317 1866 : fsp_fullbasepath(fsp, fullpath, sizeof(fullpath));
318 :
319 : /*
320 : * Avoid /. at the end of the path name. notify can't deal with it.
321 : */
322 1866 : if (len > 1 && fullpath[len-1] == '.' && fullpath[len-2] == '/') {
323 96 : fullpath[len-2] = '\0';
324 : }
325 :
326 1866 : if ((fsp->notify->filter != 0) ||
327 0 : (fsp->notify->subdir_filter != 0)) {
328 1866 : status = notify_add(fsp->conn->sconn->notify_ctx,
329 1850 : fullpath, fsp->notify->filter,
330 1850 : fsp->notify->subdir_filter, fsp);
331 : }
332 :
333 1866 : return status;
334 : }
335 :
336 2672 : NTSTATUS change_notify_add_request(struct smb_request *req,
337 : uint32_t max_param,
338 : uint32_t filter, bool recursive,
339 : struct files_struct *fsp,
340 : void (*reply_fn)(struct smb_request *req,
341 : NTSTATUS error_code,
342 : uint8_t *buf, size_t len))
343 : {
344 2672 : struct notify_change_request *request = NULL;
345 2672 : struct notify_mid_map *map = NULL;
346 2672 : struct smbd_server_connection *sconn = req->sconn;
347 :
348 2672 : DEBUG(10, ("change_notify_add_request: Adding request for %s: "
349 : "max_param = %d\n", fsp_str_dbg(fsp), (int)max_param));
350 :
351 2672 : if (!(request = talloc(NULL, struct notify_change_request))
352 2672 : || !(map = talloc(request, struct notify_mid_map))) {
353 0 : TALLOC_FREE(request);
354 0 : return NT_STATUS_NO_MEMORY;
355 : }
356 :
357 2672 : request->mid_map = map;
358 2672 : map->req = request;
359 :
360 2672 : request->req = talloc_move(request, &req);
361 2672 : request->max_param = max_param;
362 2672 : request->filter = filter;
363 2672 : request->fsp = fsp;
364 2672 : request->reply_fn = reply_fn;
365 2672 : request->backend_data = NULL;
366 :
367 2672 : DLIST_ADD_END(fsp->notify->requests, request);
368 :
369 2672 : map->mid = request->req->mid;
370 2672 : DLIST_ADD(sconn->notify_mid_maps, map);
371 :
372 2672 : return NT_STATUS_OK;
373 : }
374 :
375 2672 : static void change_notify_remove_request(struct smbd_server_connection *sconn,
376 : struct notify_change_request *remove_req)
377 : {
378 16 : files_struct *fsp;
379 16 : struct notify_change_request *req;
380 :
381 : /*
382 : * Paranoia checks, the fsp referenced must must have the request in
383 : * its list of pending requests
384 : */
385 :
386 2672 : fsp = remove_req->fsp;
387 2672 : SMB_ASSERT(fsp->notify != NULL);
388 :
389 2672 : for (req = fsp->notify->requests; req; req = req->next) {
390 2672 : if (req == remove_req) {
391 2656 : break;
392 : }
393 : }
394 :
395 2672 : if (req == NULL) {
396 0 : smb_panic("notify_req not found in fsp's requests");
397 : }
398 :
399 2672 : DLIST_REMOVE(fsp->notify->requests, req);
400 2672 : DLIST_REMOVE(sconn->notify_mid_maps, req->mid_map);
401 2672 : TALLOC_FREE(req);
402 2672 : }
403 :
404 2500 : static void smbd_notify_cancel_by_map(struct notify_mid_map *map)
405 : {
406 2500 : struct smb_request *smbreq = map->req->req;
407 2500 : struct smbd_server_connection *sconn = smbreq->sconn;
408 2500 : struct smbd_smb2_request *smb2req = smbreq->smb2req;
409 2500 : NTSTATUS notify_status = NT_STATUS_CANCELLED;
410 :
411 2500 : if (smb2req != NULL) {
412 16 : NTSTATUS sstatus;
413 :
414 1578 : if (smb2req->session == NULL) {
415 0 : sstatus = NT_STATUS_USER_SESSION_DELETED;
416 : } else {
417 1578 : sstatus = smb2req->session->status;
418 : }
419 :
420 1578 : if (NT_STATUS_EQUAL(sstatus, NT_STATUS_NETWORK_SESSION_EXPIRED)) {
421 10 : sstatus = NT_STATUS_OK;
422 : }
423 :
424 1578 : if (!NT_STATUS_IS_OK(sstatus)) {
425 6 : notify_status = NT_STATUS_NOTIFY_CLEANUP;
426 1572 : } else if (smb2req->tcon == NULL) {
427 0 : notify_status = NT_STATUS_NOTIFY_CLEANUP;
428 1572 : } else if (!NT_STATUS_IS_OK(smb2req->tcon->status)) {
429 2 : notify_status = NT_STATUS_NOTIFY_CLEANUP;
430 : }
431 : }
432 :
433 2500 : change_notify_reply(smbreq, notify_status,
434 2484 : 0, NULL, map->req->reply_fn);
435 2500 : change_notify_remove_request(sconn, map->req);
436 2500 : }
437 :
438 : /****************************************************************************
439 : Delete entries by mid from the change notify pending queue. Always send reply.
440 : *****************************************************************************/
441 :
442 989 : bool remove_pending_change_notify_requests_by_mid(
443 : struct smbd_server_connection *sconn, uint64_t mid)
444 : {
445 0 : struct notify_mid_map *map;
446 :
447 993 : for (map = sconn->notify_mid_maps; map; map = map->next) {
448 926 : if (map->mid == mid) {
449 922 : break;
450 : }
451 : }
452 :
453 989 : if (map == NULL) {
454 67 : return false;
455 : }
456 :
457 922 : smbd_notify_cancel_by_map(map);
458 922 : return true;
459 : }
460 :
461 1578 : void smbd_notify_cancel_by_smbreq(const struct smb_request *smbreq)
462 : {
463 1578 : struct smbd_server_connection *sconn = smbreq->sconn;
464 16 : struct notify_mid_map *map;
465 :
466 1578 : for (map = sconn->notify_mid_maps; map; map = map->next) {
467 1578 : if (map->req->req == smbreq) {
468 1562 : break;
469 : }
470 : }
471 :
472 1578 : if (map == NULL) {
473 0 : return;
474 : }
475 :
476 1578 : smbd_notify_cancel_by_map(map);
477 : }
478 :
479 212156 : static struct files_struct *smbd_notify_cancel_deleted_fn(
480 : struct files_struct *fsp, void *private_data)
481 : {
482 212156 : struct file_id *fid = talloc_get_type_abort(
483 : private_data, struct file_id);
484 :
485 212156 : if (file_id_equal(&fsp->file_id, fid)) {
486 4024 : remove_pending_change_notify_requests_by_fid(
487 4024 : fsp, NT_STATUS_DELETE_PENDING);
488 : }
489 212156 : return NULL;
490 : }
491 :
492 150450 : void smbd_notify_cancel_deleted(struct messaging_context *msg,
493 : void *private_data, uint32_t msg_type,
494 : struct server_id server_id, DATA_BLOB *data)
495 : {
496 150450 : struct smbd_server_connection *sconn = talloc_get_type_abort(
497 : private_data, struct smbd_server_connection);
498 355 : struct file_id *fid;
499 355 : enum ndr_err_code ndr_err;
500 :
501 150450 : fid = talloc(talloc_tos(), struct file_id);
502 150450 : if (fid == NULL) {
503 0 : DEBUG(1, ("talloc failed\n"));
504 0 : return;
505 : }
506 :
507 150450 : ndr_err = ndr_pull_struct_blob_all(
508 : data, fid, fid, (ndr_pull_flags_fn_t)ndr_pull_file_id);
509 150450 : if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err)) {
510 0 : DEBUG(10, ("%s: ndr_pull_file_id failed: %s\n", __func__,
511 : ndr_errstr(ndr_err)));
512 0 : goto done;
513 : }
514 :
515 150450 : files_forall(sconn, smbd_notify_cancel_deleted_fn, fid);
516 :
517 150450 : done:
518 150450 : TALLOC_FREE(fid);
519 : }
520 :
521 0 : static struct files_struct *smbd_notifyd_reregister(struct files_struct *fsp,
522 : void *private_data)
523 : {
524 0 : DBG_DEBUG("reregister %s\n", fsp->fsp_name->base_name);
525 :
526 0 : if ((fsp->conn->sconn->notify_ctx != NULL) &&
527 0 : (fsp->notify != NULL) &&
528 0 : ((fsp->notify->filter != 0) ||
529 0 : (fsp->notify->subdir_filter != 0))) {
530 0 : size_t len = fsp_fullbasepath(fsp, NULL, 0);
531 0 : char fullpath[len+1];
532 :
533 0 : NTSTATUS status;
534 :
535 0 : fsp_fullbasepath(fsp, fullpath, sizeof(fullpath));
536 0 : if (len > 1 && fullpath[len-1] == '.' &&
537 0 : fullpath[len-2] == '/') {
538 0 : fullpath[len-2] = '\0';
539 : }
540 :
541 0 : status = notify_add(fsp->conn->sconn->notify_ctx,
542 0 : fullpath, fsp->notify->filter,
543 0 : fsp->notify->subdir_filter, fsp);
544 0 : if (!NT_STATUS_IS_OK(status)) {
545 0 : DBG_DEBUG("notify_add failed: %s\n",
546 : nt_errstr(status));
547 : }
548 : }
549 0 : return NULL;
550 : }
551 :
552 0 : void smbd_notifyd_restarted(struct messaging_context *msg,
553 : void *private_data, uint32_t msg_type,
554 : struct server_id server_id, DATA_BLOB *data)
555 : {
556 0 : struct smbd_server_connection *sconn = talloc_get_type_abort(
557 : private_data, struct smbd_server_connection);
558 :
559 0 : TALLOC_FREE(sconn->notify_ctx);
560 :
561 0 : sconn->notify_ctx = notify_init(sconn, sconn->msg_ctx,
562 : sconn, notify_callback);
563 0 : if (sconn->notify_ctx == NULL) {
564 0 : DBG_DEBUG("notify_init failed\n");
565 0 : return;
566 : }
567 :
568 0 : files_forall(sconn, smbd_notifyd_reregister, sconn->notify_ctx);
569 : }
570 :
571 : /****************************************************************************
572 : Delete entries by fnum from the change notify pending queue.
573 : *****************************************************************************/
574 :
575 88288 : void remove_pending_change_notify_requests_by_fid(files_struct *fsp,
576 : NTSTATUS status)
577 : {
578 88288 : if (fsp->notify == NULL) {
579 86035 : return;
580 : }
581 :
582 1916 : while (fsp->notify->requests != NULL) {
583 38 : change_notify_reply(fsp->notify->requests->req,
584 : status, 0, NULL,
585 38 : fsp->notify->requests->reply_fn);
586 38 : change_notify_remove_request(fsp->conn->sconn,
587 38 : fsp->notify->requests);
588 : }
589 : }
590 :
591 359810 : void notify_fname(connection_struct *conn, uint32_t action, uint32_t filter,
592 : const char *path)
593 : {
594 359810 : struct notify_context *notify_ctx = conn->sconn->notify_ctx;
595 :
596 359810 : if (path[0] == '.' && path[1] == '/') {
597 0 : path += 2;
598 : }
599 :
600 359810 : notify_trigger(notify_ctx, action, filter, conn->connectpath, path);
601 359810 : }
602 :
603 12 : static bool user_can_stat_name_under_fsp(files_struct *fsp, const char *name)
604 : {
605 0 : uint32_t rights;
606 12 : struct smb_filename *fname = NULL;
607 12 : char *filepath = NULL;
608 0 : NTSTATUS status;
609 12 : char *p = NULL;
610 :
611 : /*
612 : * Assume we get filepath (relative to the share)
613 : * like this:
614 : *
615 : * 'dir1/dir2/dir3/file'
616 : *
617 : * We start with LIST and TRAVERSE on the
618 : * direct parent ('dir1/dir2/dir3')
619 : *
620 : * Then we switch to just TRAVERSE for
621 : * the rest: 'dir1/dir2', 'dir1', '.'
622 : *
623 : * For a file in the share root, we'll have
624 : * 'file'
625 : * and would just check '.' with LIST and TRAVERSE.
626 : *
627 : * It's important to always check '.' as the last step,
628 : * which means we check the permissions of the share root
629 : * directory.
630 : */
631 :
632 12 : if (ISDOT(fsp->fsp_name->base_name)) {
633 6 : filepath = talloc_strdup(talloc_tos(), name);
634 : } else {
635 6 : filepath = talloc_asprintf(talloc_tos(),
636 : "%s/%s",
637 6 : fsp->fsp_name->base_name,
638 : name);
639 : }
640 12 : if (filepath == NULL) {
641 0 : DBG_ERR("Memory allocation failed\n");
642 0 : return false;
643 : }
644 :
645 12 : rights = SEC_DIR_LIST|SEC_DIR_TRAVERSE;
646 12 : p = strrchr_m(filepath, '/');
647 : /*
648 : * Check each path component, excluding the share root.
649 : *
650 : * We could check all components including root using
651 : * a do { .. } while() loop, but IMHO the logic is clearer
652 : * having the share root check separately afterwards.
653 : */
654 16 : while (p != NULL) {
655 12 : *p = '\0';
656 12 : status = synthetic_pathref(talloc_tos(),
657 12 : fsp->conn->cwd_fsp,
658 : filepath,
659 : NULL,
660 : NULL,
661 : 0,
662 : 0,
663 : &fname);
664 12 : if (!NT_STATUS_IS_OK(status)) {
665 0 : DBG_ERR("synthetic_pathref failed for %s, error %s\n",
666 : filepath,
667 : nt_errstr(status));
668 0 : TALLOC_FREE(fname);
669 0 : TALLOC_FREE(filepath);
670 0 : return false;
671 : }
672 :
673 12 : status = smbd_check_access_rights_fsp(fsp->conn->cwd_fsp,
674 12 : fname->fsp,
675 : false,
676 : rights);
677 12 : if (!NT_STATUS_IS_OK(status)) {
678 8 : DBG_DEBUG("Access rights for %s/%s: %s\n",
679 : fsp->conn->connectpath,
680 : filepath,
681 : nt_errstr(status));
682 8 : TALLOC_FREE(fname);
683 8 : TALLOC_FREE(filepath);
684 8 : return false;
685 : }
686 :
687 4 : TALLOC_FREE(fname);
688 4 : rights = SEC_DIR_TRAVERSE;
689 4 : p = strrchr_m(filepath, '/');
690 : }
691 :
692 4 : TALLOC_FREE(filepath);
693 :
694 : /* Finally check share root. */
695 4 : filepath = talloc_strdup(talloc_tos(), ".");
696 4 : if (filepath == NULL) {
697 0 : DBG_ERR("Memory allocation failed\n");
698 0 : return false;
699 : }
700 4 : status = synthetic_pathref(talloc_tos(),
701 4 : fsp->conn->cwd_fsp,
702 : filepath,
703 : NULL,
704 : NULL,
705 : 0,
706 : 0,
707 : &fname);
708 4 : if (!NT_STATUS_IS_OK(status)) {
709 0 : DBG_ERR("synthetic_pathref failed for %s, error %s\n",
710 : filepath,
711 : nt_errstr(status));
712 0 : TALLOC_FREE(fname);
713 0 : TALLOC_FREE(filepath);
714 0 : return false;
715 : }
716 4 : status = smbd_check_access_rights_fsp(fsp->conn->cwd_fsp,
717 4 : fname->fsp,
718 : false,
719 : rights);
720 4 : if (!NT_STATUS_IS_OK(status)) {
721 0 : DBG_DEBUG("TRAVERSE access rights for %s failed with %s\n",
722 : fsp->conn->connectpath,
723 : nt_errstr(status));
724 0 : TALLOC_FREE(fname);
725 0 : TALLOC_FREE(filepath);
726 0 : return false;
727 : }
728 4 : TALLOC_FREE(fname);
729 4 : TALLOC_FREE(filepath);
730 4 : return true;
731 : }
732 :
733 1968 : static void notify_fsp(files_struct *fsp, struct timespec when,
734 : uint32_t action, const char *name)
735 : {
736 14 : struct notify_change_event *change, *changes;
737 14 : char *tmp;
738 :
739 1968 : if (fsp->notify == NULL) {
740 : /*
741 : * Nobody is waiting, don't queue
742 : */
743 1834 : return;
744 : }
745 :
746 1968 : if (lp_honor_change_notify_privilege(SNUM(fsp->conn))) {
747 0 : bool has_sec_change_notify_privilege;
748 38 : bool expose = false;
749 :
750 38 : has_sec_change_notify_privilege = security_token_has_privilege(
751 38 : fsp->conn->session_info->security_token,
752 : SEC_PRIV_CHANGE_NOTIFY);
753 :
754 38 : if (has_sec_change_notify_privilege) {
755 26 : expose = true;
756 : } else {
757 0 : bool ok;
758 :
759 12 : ok = become_user_without_service_by_fsp(fsp);
760 12 : if (ok) {
761 12 : expose = user_can_stat_name_under_fsp(fsp, name);
762 12 : unbecome_user_without_service();
763 : }
764 : }
765 38 : DBG_DEBUG("has_sec_change_notify_privilege=%s "
766 : "expose=%s for %s notify %s\n",
767 : has_sec_change_notify_privilege ? "true" : "false",
768 : expose ? "true" : "false",
769 : fsp->fsp_name->base_name, name);
770 38 : if (!expose) {
771 8 : return;
772 : }
773 : }
774 :
775 : /*
776 : * Someone has triggered a notify previously, queue the change for
777 : * later.
778 : */
779 :
780 1960 : if ((fsp->notify->num_changes > 1000) || (name == NULL)) {
781 : /*
782 : * The real number depends on the client buf, just provide a
783 : * guard against a DoS here. If name == NULL the CN backend is
784 : * alerting us to a problem. Possibly dropped events. Clear
785 : * queued changes and send the catch-all response to the client
786 : * if a request is pending.
787 : */
788 0 : TALLOC_FREE(fsp->notify->changes);
789 0 : fsp->notify->num_changes = -1;
790 0 : if (fsp->notify->requests != NULL) {
791 0 : change_notify_reply(fsp->notify->requests->req,
792 0 : NT_STATUS_OK,
793 0 : fsp->notify->requests->max_param,
794 : fsp->notify,
795 0 : fsp->notify->requests->reply_fn);
796 0 : change_notify_remove_request(fsp->conn->sconn,
797 0 : fsp->notify->requests);
798 : }
799 0 : return;
800 : }
801 :
802 : /* If we've exceeded the server side queue or received a NULL name
803 : * from the underlying CN implementation, don't queue up any more
804 : * requests until we can send a catch-all response to the client */
805 1960 : if (fsp->notify->num_changes == -1) {
806 0 : return;
807 : }
808 :
809 1960 : if (!(changes = talloc_realloc(
810 : fsp->notify, fsp->notify->changes,
811 : struct notify_change_event,
812 : fsp->notify->num_changes+1))) {
813 0 : DEBUG(0, ("talloc_realloc failed\n"));
814 0 : return;
815 : }
816 :
817 1960 : fsp->notify->changes = changes;
818 :
819 1960 : change = &(fsp->notify->changes[fsp->notify->num_changes]);
820 :
821 1960 : if (!(tmp = talloc_strdup(changes, name))) {
822 0 : DEBUG(0, ("talloc_strdup failed\n"));
823 0 : return;
824 : }
825 :
826 1960 : string_replace(tmp, '/', '\\');
827 1960 : change->name = tmp;
828 :
829 1960 : change->when = when;
830 1960 : change->action = action;
831 1960 : fsp->notify->num_changes += 1;
832 :
833 1960 : if (fsp->notify->requests == NULL) {
834 : /*
835 : * Nobody is waiting, so don't send anything. The ot
836 : */
837 1806 : return;
838 : }
839 :
840 140 : if (action == NOTIFY_ACTION_OLD_NAME) {
841 : /*
842 : * We have to send the two rename events in one reply. So hold
843 : * the first part back.
844 : */
845 6 : return;
846 : }
847 :
848 : /*
849 : * Someone is waiting for the change, trigger the reply immediately.
850 : *
851 : * TODO: do we have to walk the lists of requests pending?
852 : */
853 :
854 134 : change_notify_reply(fsp->notify->requests->req,
855 134 : NT_STATUS_OK,
856 134 : fsp->notify->requests->max_param,
857 : fsp->notify,
858 134 : fsp->notify->requests->reply_fn);
859 :
860 134 : change_notify_remove_request(fsp->conn->sconn, fsp->notify->requests);
861 : }
862 :
863 1050 : char *notify_filter_string(TALLOC_CTX *mem_ctx, uint32_t filter)
864 : {
865 1050 : char *result = NULL;
866 :
867 1050 : result = talloc_strdup(mem_ctx, "");
868 1050 : if (result == NULL) {
869 0 : return NULL;
870 : }
871 :
872 1050 : if (filter & FILE_NOTIFY_CHANGE_FILE_NAME) {
873 168 : result = talloc_asprintf_append(result, "FILE_NAME|");
874 168 : if (result == NULL) {
875 0 : return NULL;
876 : }
877 : }
878 1050 : if (filter & FILE_NOTIFY_CHANGE_DIR_NAME) {
879 160 : result = talloc_asprintf_append(result, "DIR_NAME|");
880 160 : if (result == NULL) {
881 0 : return NULL;
882 : }
883 : }
884 1050 : if (filter & FILE_NOTIFY_CHANGE_ATTRIBUTES) {
885 44 : result = talloc_asprintf_append(result, "ATTRIBUTES|");
886 44 : if (result == NULL) {
887 0 : return NULL;
888 : }
889 : }
890 1050 : if (filter & FILE_NOTIFY_CHANGE_SIZE) {
891 28 : result = talloc_asprintf_append(result, "SIZE|");
892 28 : if (result == NULL) {
893 0 : return NULL;
894 : }
895 : }
896 1050 : if (filter & FILE_NOTIFY_CHANGE_LAST_WRITE) {
897 28 : result = talloc_asprintf_append(result, "LAST_WRITE|");
898 28 : if (result == NULL) {
899 0 : return NULL;
900 : }
901 : }
902 1050 : if (filter & FILE_NOTIFY_CHANGE_LAST_ACCESS) {
903 28 : result = talloc_asprintf_append(result, "LAST_ACCESS|");
904 28 : if (result == NULL) {
905 0 : return NULL;
906 : }
907 : }
908 1050 : if (filter & FILE_NOTIFY_CHANGE_CREATION) {
909 36 : result = talloc_asprintf_append(result, "CREATION|");
910 36 : if (result == NULL) {
911 0 : return NULL;
912 : }
913 : }
914 1050 : if (filter & FILE_NOTIFY_CHANGE_EA) {
915 28 : result = talloc_asprintf_append(result, "EA|");
916 28 : if (result == NULL) {
917 0 : return NULL;
918 : }
919 : }
920 1050 : if (filter & FILE_NOTIFY_CHANGE_SECURITY) {
921 28 : result = talloc_asprintf_append(result, "SECURITY|");
922 28 : if (result == NULL) {
923 0 : return NULL;
924 : }
925 : }
926 1050 : if (filter & FILE_NOTIFY_CHANGE_STREAM_NAME) {
927 30 : result = talloc_asprintf_append(result, "STREAM_NAME|");
928 30 : if (result == NULL) {
929 0 : return NULL;
930 : }
931 : }
932 1050 : if (filter & FILE_NOTIFY_CHANGE_STREAM_SIZE) {
933 28 : result = talloc_asprintf_append(result, "STREAM_SIZE|");
934 28 : if (result == NULL) {
935 0 : return NULL;
936 : }
937 : }
938 1050 : if (filter & FILE_NOTIFY_CHANGE_STREAM_WRITE) {
939 28 : result = talloc_asprintf_append(result, "STREAM_WRITE|");
940 28 : if (result == NULL) {
941 0 : return NULL;
942 : }
943 : }
944 :
945 1050 : if (*result == '\0') return result;
946 :
947 486 : result[strlen(result)-1] = '\0';
948 486 : return result;
949 : }
950 :
951 0 : struct sys_notify_context *sys_notify_context_create(TALLOC_CTX *mem_ctx,
952 : struct tevent_context *ev)
953 : {
954 0 : struct sys_notify_context *ctx;
955 :
956 0 : if (!(ctx = talloc(mem_ctx, struct sys_notify_context))) {
957 0 : DEBUG(0, ("talloc failed\n"));
958 0 : return NULL;
959 : }
960 :
961 0 : ctx->ev = ev;
962 0 : ctx->private_data = NULL;
963 0 : return ctx;
964 : }
|