summaryrefslogtreecommitdiffstats
path: root/source3/modules
Commit message (Collapse)AuthorAgeFilesLines
...
* Move to using 64-bit mid values in our internal open file database.Jeremy Allison2010-04-122-5/+7
| | | | | | | This will allow us to share logic much easier between SMB1 and SMB2 servers. Jeremy
* Plumb SMB2 stubs into all the places we defer SMB1 operations.Jeremy Allison2010-04-091-34/+34
| | | | | | | | Rename functions to be internally consistent. Next step is to cope queueing single (non-compounded) SMB2 requests to put some code inside the stubs. Jeremy.
* Fix related to bug #7326 - can't read/write any files with full_auditVolker Lendecke2010-04-051-2/+3
|
* s3: Use bitmap_talloc in vfs_full_audit.cVolker Lendecke2010-03-281-40/+20
| | | | This also simplifies the calling convention for init_bitmap() slightly
* s3: Fix some nonempty blank linesVolker Lendecke2010-03-281-20/+19
|
* s3: vfs_smb_traffic_analyzer.c: remove warnings from developer buildHolger Hetterich2010-03-251-14/+16
| | | | | | | | | | | This patch should remove all warnings coming up when compiling traffic analyzer with configure.developer. Re-activate the smb_traffic_analyzer_rmdir function by adding it's vfs_fn_pointer to vfs_smb_traffic_analyzer_fns. Copy the mode_t used in smb_traffic_analyzer_open to the corresponding data structure.
* Fix bug #7283 - vfs_acl_tdb does not work as expected.Jeremy Allison2010-03-241-34/+14
| | | | | | | both vfs_acl_common.c and vfs_acl_tdb.c were using the connection handle, thus conflicted. Fix this. Jeremy.
* s3: file_walk_table -> files_forallVolker Lendecke2010-03-221-1/+1
| | | | | This is more in line with the rest of the Samba code, like connections_forall etc.
* s3-vfs: fix some buildwarnings in traffic analyzer, there are many more.Günther Deschner2010-03-161-9/+11
| | | | | | Holger, please check. Guenther
* Update copyrightJim McDonough2010-03-161-1/+1
|
* s3: vfs_smb_traffic_analyzer.c: add VFS functions for file open and closeHolger Hetterich2010-03-162-2/+65
|
* smb_traffic_analyzer.c: optimize marshalling function and documentHolger Hetterich2010-03-162-34/+54
| | | | | | | | | Collect all data that is needed, and use only one talloc_asprintf operation to create the string of common data. This simplifies the code a bit and is most probably faster than the old method. Also, #define SMBTA_COMMON_DATA_COUNT as a complete string, speeding things up because we know the value at compile time.
* vfs_smb_traffic_analyzer.c: added functionHolger Hetterich2010-03-161-63/+58
| | | | | | | | | static char *smb_traffic_analyzer_anonymize This takes a lot of code out of the main functions, and makes it a bit simpler. Do the anonymization in a function. Since we already anonymized the username we don't need to do this a second time in the v2 marshalling function.
* Simplify the code a bit by creating the functions:Holger Hetterich2010-03-161-84/+123
| | | | | | | smb_traffic_analyzer_encrypt - doing the encryption of a data block, smb_traffic_analyzer_create_header - create the protocol header, smb_traffic_analyzer_write_data - actually write the data to the socket.
* Add the number of common data blocks to the protocol.Holger Hetterich2010-03-162-10/+33
| | | | | | | | | | | Always send the number of common data blocks first. This way, we can make the protocol backwards compatible. A receiver running with an older subprotocol can just ignore if a newer sender sends more common data. Add a few remarks to the marshalling function. Add two #define lines defining the protocol subrelease number and the number of common data blocks to the header file.
* Put all the protocol stuff into a separate header file.Holger Hetterich2010-03-162-114/+152
| | | | | | All the structures and the vfs function identifier list is required by the receiver. It's therefore very handy to have this in an extra header file.
* Add smbta-util to manage the encryption key.Holger Hetterich2010-03-161-0/+1
| | | | | | | This program allows the administrator to enable or disable AES encryption when using vfs_smb_traffic_analyzer. It also generates new keys, stores them to a file, so that the file can be reused on another client or server.
* Implement AES encryption of the data block.Holger Hetterich2010-03-161-13/+33
| | | | | | | | | | | | First try. This runs on 16 bytes long AES block size, and enlarges the data block with 16 bytes, to make sure all bytes are in. The added bytes are filled with '.'. It then creates a header featuring the new length to be send, and finally sends the data block, then returns. This code is untested, as creating the receiver will be my next step. To simplify traffic_analyzer's code, this code should run as a function. It's on the do-to-list.
* Implement anonymization for protocol v2.Holger Hetterich2010-03-161-14/+53
| | | | | | | | | Since we need to care for the SID too, do the anonymization in the marshalling function and anonymize both the username and the SID. Remove the 'A' status flag from the header definition. A listener could see from the unencrypted header if the module is anonymizing or not, which is certainly not wanted.
* Make all remarks compatible to the linux kernel coding styleguide.Holger Hetterich2010-03-161-27/+33
|
* Added an exact description of the V2 protocol.Holger Hetterich2010-03-161-0/+62
| | | | | I don't think it should have it's place the man page, because this is developer information.
* Move the creation of the header.Holger Hetterich2010-03-161-11/+37
| | | | | | | | | | | | | | | | | | | | Since the header block of the protocol contains the number of bytes to come, we always send the header itself unmodified. If we compress or crypt the data we are about to send, the length of the data to send may change. Therefore, we no longer create the header in smb_traffic_analyzer_create_string, but shortly before we send the data. For both cases, encryption and normal, we create our own header, and send it before the actual data. In case of protocol v1, we don't need to create an extra header. Just send the data, and return from the function. Change a debug message to say that the header for crypted data has been created. Add a status flags consisting of 6 bytes to the header. Their function will be descriped in one of the next patches, which is descriping the header in a longer comment. When anonymization and/or encryption is used, set the flags accordingly.
* Fetch the SID of the user we are running as and send with the commonHolger Hetterich2010-03-161-2/+5
| | | | data.
* Additionally send the vfs function id with the protocol.Holger Hetterich2010-03-161-7/+11
|
* According to the linux kernel coding styleguide, it's better toHolger Hetterich2010-03-161-46/+46
| | | | | align the switch and it's case statements in the same column. This saves us one indentation level.
* Don't use typedefs on the VFS function data structures asHolger Hetterich2010-03-161-27/+27
| | | | | typedefs are evil according to the linux kernel coding styleguide.
* Add read,pread,write,pwrite support to the V2 protocol.Holger Hetterich2010-03-161-3/+14
|
* Enable AES encryption of the data if a key was found in secrets.tdb.Holger Hetterich2010-03-161-3/+22
|
* Add rmdir, chdir, and rename as supported VFS functionsHolger Hetterich2010-03-161-9/+87
|
* The format of data we are sending over the network will be flexible when ↵Holger Hetterich2010-03-161-4/+74
| | | | | | | sending over the network in protocol v2. To be able to do this, we create a new va-list function that is creating the buffer to send. Also it makes it easier for the receiver to parse the data; it sends an initial header containing the full length of the buffer to be send. For the individual strings, it sends sub headers containing the length of the upcoming substring to be send. With the header-data-header-data [..] structure we don't need to quote the sub strings finally enabling having all possible character sets in filenames etc.. In the sending function, implement mkdir to actually send it's data for testing.
* Create structs carrying the data of individual VFS functions, and hand those ↵Holger Hetterich2010-03-161-33/+47
| | | | over to the send function, which then casts the void pointer to the struct required by looking at the id. This allows us to return different result data depending on the VFS function that is running. Make the protocol v1 sender compatible to this. Adapt the existing VFS functions to use the new data structures. Make use of the new functionality and extend the mkdir VFS logger function to return the creation mode additionally.
* Introduce smb_traffic_analyzer protocol v2.Holger Hetterich2010-03-161-7/+62
| | | | | | | From Holger: Make smb_traffic_analyzer differ the protocol versions to enable the development of version 2 of the protocol. To do this, a new parameter "protocol_version" has been introduced, which can be set to "V1", "V2", or nothing. If protocol_version is not set, V1 will be chosen automatically. Created an enum for identifying VFS functions in the upcoming protocol v2. Converted the existing VFS functions to use the identifier, and set the read/write bool used in protocol v1 accordingly, also ignore any other VFS functions except read/write/pread/pwrite in v1. Added a first new VFS function for mkdir, which I use for testing and implementing both the sender and receiver for v2.
* Remove the bool admin_user from conn struct. We no longer look at this to ↵Jeremy Allison2010-03-151-1/+0
| | | | | | make access decisions. Jeremy.
* Pass "connection_struct *conn" into functions that currently use ↵Jeremy Allison2010-03-151-1/+1
| | | | | | | | "current_user.XXX" Will allow me to replace them with accessor functions. Jeremy.
* Rever e80ceb1d7355c8c46a2ed90d5721cf367640f4e8 "Remove more uses of "extern ↵Jeremy Allison2010-03-151-1/+1
| | | | | | | | struct current_user current_user;"." As requested by Volker, split this into smaller commits. Jeremy.
* Missed a couple more uses of conn->server_info->ptok that need to be ↵Jeremy Allison2010-03-121-7/+9
| | | | | | | | | get_current_nttok(conn) Centralize the root check into smb1_file_se_access_check() so this is used by modules/vfs_acl_common.c also. Jeremy.
* Remove more uses of "extern struct current_user current_user;".Jeremy Allison2010-03-121-1/+1
| | | | | | | | | | | | | Use accessor functions to get to this value. Tidies up much of the user context code. Volker, please look at the changes in smbd/uid.c to familiarize yourself with these changes as I think they make the logic in there cleaner. Cause smbd/posix_acls.c code to look at current user context, not stored context on the conn struct - allows correct use of these function calls under a become_root()/unbecome_root() pair. Jeremy.
* vfs_netatalk: Segfault if hide files or veto files has no ".AppleDouble"SATOH Fumiyasu2010-03-101-1/+1
|
* s3: add vfs_crossrenameBjörn Jacke2010-03-081-0/+200
| | | | | this module adds optional server-side support for limited rename operations beyond filesystem boundaries, which was the previously the default.
* s3: remove cross-device rename support from vfs_defaultBjörn Jacke2010-03-081-116/+0
| | | | | | | | | | | | | cross-device rename support has some major limitations: - on huge files clients will timeout or hang - ACLs and EA information is not retained Usually a client will have to handle this. A Windows Server with a reparse point will also just return NT_STATUS_NOT_SAME_DEVICE. We will now by default do the same. I will add a vfs module which will restore the old cross-device renames.
* Fix for bug #7189 - Open txt files with notepad on samba shares creates problem.Jeremy Allison2010-03-055-10/+24
| | | | | | | | | | Ensure we don't use any of the create_options for Samba private use. Add a new parameter to the VFS_CREATE call (private_flags) which is only used internally. Renumber NTCREATEX_OPTIONS_PRIVATE_DENY_DOS and NTCREATEX_OPTIONS_PRIVATE_DENY_FCB to match the S4 code). Rev. the VFS interface to version 28. Jeremy.
* s3:vfs_aixacl2: add missing semicolonBjörn Jacke2010-03-021-1/+1
| | | | fixes #7197. Thanks to William Jojo for the correction.
* s3: vfs_full_audit.c: implement negated vfs_ops in the success/failure listHolger Hetterich2010-02-281-24/+31
| | | | | | | Supports negated arguments in configuration like: full_audit:success = all !readdir !telldir !closedir Update the manpage accordingly. Part of BSO#4025
* s3-modules: fix get_acl_blob in the acl_tdb VFS module.Günther Deschner2010-02-181-1/+1
| | | | | | Shuttle-reviewed by jra :) Guenther
* s3-vfs: use TYPESAFE_QSORT() in s3 VFS modulesAndrew Tridgell2010-02-142-8/+6
|
* Fix bad use when freeing linked list. Todd Stecher (Original author) please ↵Jeremy Allison2010-02-101-6/+8
| | | | | | check ! Jeremy.
* s3-perfcount: update to use new DLIST macrosAndrew Tridgell2010-02-102-3/+2
| | | | (cherry picked from commit a13b507f2d8be7f90c8872094cd0732926a6fcbb)
* vfs_catia: fix return type warningsBjörn Jacke2010-02-091-2/+2
|
* Fix bug #6876 for acl_tdb module.Jeremy Allison2010-02-081-2/+1
| | | | | | | As pointed out by bj@sernet.de, the rmdir module initializer was duplicated. Fix this properly. Jeremy.
* s3: fix build issue on Tru64Björn Jacke2010-02-071-7/+7
| | | | | Thanks, Volker for the hint - acl_type is a macro on Tru64. Renamed it to acltype. This fixes #7103.