2019-07-20 10:26:52 +00:00
|
|
|
package sftpd
|
|
|
|
|
|
|
|
import (
|
|
|
|
"io"
|
|
|
|
"net"
|
|
|
|
"os"
|
2020-01-05 10:41:25 +00:00
|
|
|
"path"
|
2019-07-20 10:26:52 +00:00
|
|
|
"sync"
|
|
|
|
"time"
|
|
|
|
|
2020-05-06 17:36:34 +00:00
|
|
|
"github.com/pkg/sftp"
|
2019-09-11 14:29:56 +00:00
|
|
|
"golang.org/x/crypto/ssh"
|
2019-07-20 10:26:52 +00:00
|
|
|
|
|
|
|
"github.com/drakkan/sftpgo/dataprovider"
|
|
|
|
"github.com/drakkan/sftpgo/logger"
|
2020-05-06 17:36:34 +00:00
|
|
|
"github.com/drakkan/sftpgo/vfs"
|
2019-07-20 10:26:52 +00:00
|
|
|
)
|
|
|
|
|
|
|
|
// Connection details for an authenticated user
|
|
|
|
type Connection struct {
|
2019-07-30 18:51:29 +00:00
|
|
|
// Unique identifier for the connection
|
|
|
|
ID string
|
|
|
|
// logged in user's details
|
|
|
|
User dataprovider.User
|
|
|
|
// client's version string
|
2019-07-20 10:26:52 +00:00
|
|
|
ClientVersion string
|
2019-07-30 18:51:29 +00:00
|
|
|
// Remote address for this connection
|
|
|
|
RemoteAddr net.Addr
|
|
|
|
// start time for this connection
|
|
|
|
StartTime time.Time
|
|
|
|
// last activity for this connection
|
|
|
|
lastActivity time.Time
|
2019-08-24 12:41:15 +00:00
|
|
|
protocol string
|
2019-09-11 07:41:46 +00:00
|
|
|
netConn net.Conn
|
2019-09-11 14:29:56 +00:00
|
|
|
channel ssh.Channel
|
2019-11-18 22:30:37 +00:00
|
|
|
command string
|
2020-01-19 06:41:05 +00:00
|
|
|
fs vfs.Fs
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
|
|
|
|
2019-09-06 09:23:06 +00:00
|
|
|
// Log outputs a log entry to the configured logger
|
2019-09-06 13:19:01 +00:00
|
|
|
func (c Connection) Log(level logger.LogLevel, sender string, format string, v ...interface{}) {
|
|
|
|
logger.Log(level, sender, c.ID, format, v...)
|
2019-09-06 09:23:06 +00:00
|
|
|
}
|
|
|
|
|
2019-07-20 10:26:52 +00:00
|
|
|
// Fileread creates a reader for a file on the system and returns the reader back.
|
|
|
|
func (c Connection) Fileread(request *sftp.Request) (io.ReaderAt, error) {
|
|
|
|
updateConnectionActivity(c.ID)
|
|
|
|
|
2020-01-05 10:41:25 +00:00
|
|
|
if !c.User.HasPerm(dataprovider.PermDownload, path.Dir(request.Filepath)) {
|
|
|
|
return nil, sftp.ErrSSHFxPermissionDenied
|
|
|
|
}
|
|
|
|
|
2020-03-01 21:10:29 +00:00
|
|
|
if !c.User.IsFileAllowed(request.Filepath) {
|
|
|
|
c.Log(logger.LevelWarn, logSender, "reading file %#v is not allowed", request.Filepath)
|
|
|
|
return nil, sftp.ErrSSHFxPermissionDenied
|
|
|
|
}
|
|
|
|
|
2020-01-19 12:58:55 +00:00
|
|
|
p, err := c.fs.ResolvePath(request.Filepath)
|
2019-07-20 10:26:52 +00:00
|
|
|
if err != nil {
|
2020-01-19 06:41:05 +00:00
|
|
|
return nil, vfs.GetSFTPError(c.fs, err)
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
|
|
|
|
2020-01-19 06:41:05 +00:00
|
|
|
file, r, cancelFn, err := c.fs.Open(p)
|
2019-07-20 10:26:52 +00:00
|
|
|
if err != nil {
|
2020-02-13 07:26:45 +00:00
|
|
|
c.Log(logger.LevelWarn, logSender, "could not open file %#v for reading: %+v", p, err)
|
2020-01-19 06:41:05 +00:00
|
|
|
return nil, vfs.GetSFTPError(c.fs, err)
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
|
|
|
|
2019-09-06 13:19:01 +00:00
|
|
|
c.Log(logger.LevelDebug, logSender, "fileread requested for path: %#v", p)
|
2019-07-20 10:26:52 +00:00
|
|
|
|
|
|
|
transfer := Transfer{
|
2020-06-07 21:30:18 +00:00
|
|
|
file: file,
|
|
|
|
readerAt: r,
|
|
|
|
writerAt: nil,
|
|
|
|
cancelFn: cancelFn,
|
|
|
|
path: p,
|
|
|
|
start: time.Now(),
|
|
|
|
bytesSent: 0,
|
|
|
|
bytesReceived: 0,
|
|
|
|
user: c.User,
|
|
|
|
connectionID: c.ID,
|
|
|
|
transferType: transferDownload,
|
|
|
|
lastActivity: time.Now(),
|
|
|
|
isNewFile: false,
|
|
|
|
protocol: c.protocol,
|
|
|
|
transferError: nil,
|
|
|
|
isFinished: false,
|
|
|
|
minWriteOffset: 0,
|
|
|
|
requestPath: request.Filepath,
|
|
|
|
lock: new(sync.Mutex),
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
|
|
|
addTransfer(&transfer)
|
|
|
|
return &transfer, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// Filewrite handles the write actions for a file on the system.
|
|
|
|
func (c Connection) Filewrite(request *sftp.Request) (io.WriterAt, error) {
|
|
|
|
updateConnectionActivity(c.ID)
|
2020-03-01 21:10:29 +00:00
|
|
|
|
|
|
|
if !c.User.IsFileAllowed(request.Filepath) {
|
|
|
|
c.Log(logger.LevelWarn, logSender, "writing file %#v is not allowed", request.Filepath)
|
|
|
|
return nil, sftp.ErrSSHFxPermissionDenied
|
|
|
|
}
|
|
|
|
|
2020-01-19 12:58:55 +00:00
|
|
|
p, err := c.fs.ResolvePath(request.Filepath)
|
2019-07-20 10:26:52 +00:00
|
|
|
if err != nil {
|
2020-01-19 06:41:05 +00:00
|
|
|
return nil, vfs.GetSFTPError(c.fs, err)
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
|
|
|
|
2019-08-04 07:37:58 +00:00
|
|
|
filePath := p
|
2020-01-19 06:41:05 +00:00
|
|
|
if isAtomicUploadEnabled() && c.fs.IsAtomicUploadSupported() {
|
|
|
|
filePath = c.fs.GetAtomicUploadPath(p)
|
2019-08-04 07:37:58 +00:00
|
|
|
}
|
|
|
|
|
2020-06-07 21:30:18 +00:00
|
|
|
stat, statErr := c.fs.Lstat(p)
|
|
|
|
if (statErr == nil && stat.Mode()&os.ModeSymlink == os.ModeSymlink) || c.fs.IsNotExist(statErr) {
|
2020-01-05 10:41:25 +00:00
|
|
|
if !c.User.HasPerm(dataprovider.PermUpload, path.Dir(request.Filepath)) {
|
2019-12-25 17:20:19 +00:00
|
|
|
return nil, sftp.ErrSSHFxPermissionDenied
|
|
|
|
}
|
2020-06-07 21:30:18 +00:00
|
|
|
return c.handleSFTPUploadToNewFile(p, filePath, request.Filepath)
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
if statErr != nil {
|
2020-02-13 07:26:45 +00:00
|
|
|
c.Log(logger.LevelError, logSender, "error performing file stat %#v: %+v", p, statErr)
|
2020-01-19 06:41:05 +00:00
|
|
|
return nil, vfs.GetSFTPError(c.fs, statErr)
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
|
|
|
|
2019-08-04 07:37:58 +00:00
|
|
|
// This happen if we upload a file that has the same name of an existing directory
|
2019-07-20 10:26:52 +00:00
|
|
|
if stat.IsDir() {
|
2019-09-06 13:19:01 +00:00
|
|
|
c.Log(logger.LevelWarn, logSender, "attempted to open a directory for writing to: %#v", p)
|
2019-10-14 20:44:57 +00:00
|
|
|
return nil, sftp.ErrSSHFxOpUnsupported
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
|
|
|
|
2020-01-05 10:41:25 +00:00
|
|
|
if !c.User.HasPerm(dataprovider.PermOverwrite, path.Dir(request.Filepath)) {
|
2019-10-14 20:44:57 +00:00
|
|
|
return nil, sftp.ErrSSHFxPermissionDenied
|
2019-09-17 06:53:45 +00:00
|
|
|
}
|
|
|
|
|
2020-06-07 21:30:18 +00:00
|
|
|
return c.handleSFTPUploadToExistingFile(request.Pflags(), p, filePath, stat.Size(), request.Filepath)
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// Filecmd hander for basic SFTP system calls related to files, but not anything to do with reading
|
|
|
|
// or writing to those files.
|
|
|
|
func (c Connection) Filecmd(request *sftp.Request) error {
|
|
|
|
updateConnectionActivity(c.ID)
|
|
|
|
|
2020-01-19 12:58:55 +00:00
|
|
|
p, err := c.fs.ResolvePath(request.Filepath)
|
2019-07-20 10:26:52 +00:00
|
|
|
if err != nil {
|
2020-01-19 06:41:05 +00:00
|
|
|
return vfs.GetSFTPError(c.fs, err)
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
2019-07-20 22:19:17 +00:00
|
|
|
target, err := c.getSFTPCmdTargetPath(request.Target)
|
|
|
|
if err != nil {
|
2019-11-15 11:15:07 +00:00
|
|
|
return err
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
|
|
|
|
2019-09-06 13:19:01 +00:00
|
|
|
c.Log(logger.LevelDebug, logSender, "new cmd, method: %v, sourcePath: %#v, targetPath: %#v", request.Method,
|
2019-07-20 22:19:17 +00:00
|
|
|
p, target)
|
2019-07-20 10:26:52 +00:00
|
|
|
|
|
|
|
switch request.Method {
|
|
|
|
case "Setstat":
|
2019-11-15 11:15:07 +00:00
|
|
|
return c.handleSFTPSetstat(p, request)
|
2019-07-20 10:26:52 +00:00
|
|
|
case "Rename":
|
2020-01-05 10:41:25 +00:00
|
|
|
if err = c.handleSFTPRename(p, target, request); err != nil {
|
2019-07-20 22:19:17 +00:00
|
|
|
return err
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
|
|
|
case "Rmdir":
|
2020-01-05 10:41:25 +00:00
|
|
|
return c.handleSFTPRmdir(p, request)
|
2019-07-20 10:26:52 +00:00
|
|
|
case "Mkdir":
|
2020-01-05 10:41:25 +00:00
|
|
|
err = c.handleSFTPMkdir(p, request)
|
2019-07-20 10:26:52 +00:00
|
|
|
if err != nil {
|
2019-07-20 22:19:17 +00:00
|
|
|
return err
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
|
|
|
case "Symlink":
|
2020-01-05 10:41:25 +00:00
|
|
|
if err = c.handleSFTPSymlink(p, target, request); err != nil {
|
2019-07-20 22:19:17 +00:00
|
|
|
return err
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
|
|
|
case "Remove":
|
2020-01-05 10:41:25 +00:00
|
|
|
return c.handleSFTPRemove(p, request)
|
2019-07-20 10:26:52 +00:00
|
|
|
default:
|
2019-10-14 20:44:57 +00:00
|
|
|
return sftp.ErrSSHFxOpUnsupported
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
var fileLocation = p
|
|
|
|
if target != "" {
|
|
|
|
fileLocation = target
|
|
|
|
}
|
|
|
|
|
2019-07-20 22:19:17 +00:00
|
|
|
// we return if we remove a file or a dir so source path or target path always exists here
|
2020-01-19 06:41:05 +00:00
|
|
|
vfs.SetPathPermissions(c.fs, fileLocation, c.User.GetUID(), c.User.GetGID())
|
2019-07-20 10:26:52 +00:00
|
|
|
|
2019-10-14 20:44:57 +00:00
|
|
|
return sftp.ErrSSHFxOk
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// Filelist is the handler for SFTP filesystem list calls. This will handle calls to list the contents of
|
|
|
|
// a directory as well as perform file/folder stat calls.
|
|
|
|
func (c Connection) Filelist(request *sftp.Request) (sftp.ListerAt, error) {
|
|
|
|
updateConnectionActivity(c.ID)
|
2020-01-19 12:58:55 +00:00
|
|
|
p, err := c.fs.ResolvePath(request.Filepath)
|
2019-07-20 10:26:52 +00:00
|
|
|
if err != nil {
|
2020-01-19 06:41:05 +00:00
|
|
|
return nil, vfs.GetSFTPError(c.fs, err)
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
switch request.Method {
|
|
|
|
case "List":
|
2020-01-05 10:41:25 +00:00
|
|
|
if !c.User.HasPerm(dataprovider.PermListItems, request.Filepath) {
|
2019-10-14 20:44:57 +00:00
|
|
|
return nil, sftp.ErrSSHFxPermissionDenied
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
|
|
|
|
2019-09-06 13:19:01 +00:00
|
|
|
c.Log(logger.LevelDebug, logSender, "requested list file for dir: %#v", p)
|
2020-01-19 06:41:05 +00:00
|
|
|
files, err := c.fs.ReadDir(p)
|
2019-11-15 11:15:07 +00:00
|
|
|
if err != nil {
|
2020-02-13 07:26:45 +00:00
|
|
|
c.Log(logger.LevelWarn, logSender, "error listing directory: %+v", err)
|
2020-01-19 06:41:05 +00:00
|
|
|
return nil, vfs.GetSFTPError(c.fs, err)
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
|
|
|
|
2020-02-23 10:30:26 +00:00
|
|
|
return listerAt(c.User.AddVirtualDirs(files, request.Filepath)), nil
|
2019-07-20 10:26:52 +00:00
|
|
|
case "Stat":
|
2020-01-05 10:41:25 +00:00
|
|
|
if !c.User.HasPerm(dataprovider.PermListItems, path.Dir(request.Filepath)) {
|
2019-10-14 20:44:57 +00:00
|
|
|
return nil, sftp.ErrSSHFxPermissionDenied
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
|
|
|
|
2019-11-16 09:23:41 +00:00
|
|
|
c.Log(logger.LevelDebug, logSender, "requested stat for path: %#v", p)
|
2020-01-19 06:41:05 +00:00
|
|
|
s, err := c.fs.Stat(p)
|
2019-11-15 11:15:07 +00:00
|
|
|
if err != nil {
|
2020-02-13 07:26:45 +00:00
|
|
|
c.Log(logger.LevelWarn, logSender, "error running stat on path: %+v", err)
|
2020-01-19 06:41:05 +00:00
|
|
|
return nil, vfs.GetSFTPError(c.fs, err)
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
|
|
|
|
2019-07-30 18:51:29 +00:00
|
|
|
return listerAt([]os.FileInfo{s}), nil
|
2019-07-20 10:26:52 +00:00
|
|
|
default:
|
2019-10-14 20:44:57 +00:00
|
|
|
return nil, sftp.ErrSSHFxOpUnsupported
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2019-07-20 22:19:17 +00:00
|
|
|
func (c Connection) getSFTPCmdTargetPath(requestTarget string) (string, error) {
|
|
|
|
var target string
|
|
|
|
// If a target is provided in this request validate that it is going to the correct
|
2019-11-15 11:15:07 +00:00
|
|
|
// location for the server. If it is not, return an error
|
|
|
|
if len(requestTarget) > 0 {
|
2019-07-20 22:19:17 +00:00
|
|
|
var err error
|
2020-01-19 12:58:55 +00:00
|
|
|
target, err = c.fs.ResolvePath(requestTarget)
|
2019-07-20 22:19:17 +00:00
|
|
|
if err != nil {
|
2020-01-19 06:41:05 +00:00
|
|
|
return target, vfs.GetSFTPError(c.fs, err)
|
2019-07-20 22:19:17 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
return target, nil
|
|
|
|
}
|
|
|
|
|
2020-01-05 10:41:25 +00:00
|
|
|
func (c Connection) handleSFTPSetstat(filePath string, request *sftp.Request) error {
|
2019-11-15 11:15:07 +00:00
|
|
|
if setstatMode == 1 {
|
|
|
|
return nil
|
|
|
|
}
|
2020-01-05 10:41:25 +00:00
|
|
|
pathForPerms := request.Filepath
|
2020-01-19 06:41:05 +00:00
|
|
|
if fi, err := c.fs.Lstat(filePath); err == nil {
|
2019-12-25 17:20:19 +00:00
|
|
|
if fi.IsDir() {
|
2020-01-05 10:41:25 +00:00
|
|
|
pathForPerms = path.Dir(request.Filepath)
|
2019-12-25 17:20:19 +00:00
|
|
|
}
|
|
|
|
}
|
2019-11-15 11:15:07 +00:00
|
|
|
attrFlags := request.AttrFlags()
|
|
|
|
if attrFlags.Permissions {
|
2019-12-25 17:20:19 +00:00
|
|
|
if !c.User.HasPerm(dataprovider.PermChmod, pathForPerms) {
|
2019-11-15 11:15:07 +00:00
|
|
|
return sftp.ErrSSHFxPermissionDenied
|
|
|
|
}
|
|
|
|
fileMode := request.Attributes().FileMode()
|
2020-01-19 06:41:05 +00:00
|
|
|
if err := c.fs.Chmod(filePath, fileMode); err != nil {
|
2020-02-13 07:26:45 +00:00
|
|
|
c.Log(logger.LevelWarn, logSender, "failed to chmod path %#v, mode: %v, err: %+v", filePath, fileMode.String(), err)
|
2020-01-19 06:41:05 +00:00
|
|
|
return vfs.GetSFTPError(c.fs, err)
|
2019-11-15 11:15:07 +00:00
|
|
|
}
|
2020-01-05 10:41:25 +00:00
|
|
|
logger.CommandLog(chmodLogSender, filePath, "", c.User.Username, fileMode.String(), c.ID, c.protocol, -1, -1, "", "", "")
|
2019-11-15 11:15:07 +00:00
|
|
|
return nil
|
|
|
|
} else if attrFlags.UidGid {
|
2019-12-25 17:20:19 +00:00
|
|
|
if !c.User.HasPerm(dataprovider.PermChown, pathForPerms) {
|
2019-11-15 11:15:07 +00:00
|
|
|
return sftp.ErrSSHFxPermissionDenied
|
|
|
|
}
|
|
|
|
uid := int(request.Attributes().UID)
|
|
|
|
gid := int(request.Attributes().GID)
|
2020-01-19 06:41:05 +00:00
|
|
|
if err := c.fs.Chown(filePath, uid, gid); err != nil {
|
2020-02-13 07:26:45 +00:00
|
|
|
c.Log(logger.LevelWarn, logSender, "failed to chown path %#v, uid: %v, gid: %v, err: %+v", filePath, uid, gid, err)
|
2020-01-19 06:41:05 +00:00
|
|
|
return vfs.GetSFTPError(c.fs, err)
|
2019-11-15 11:15:07 +00:00
|
|
|
}
|
2020-01-05 10:41:25 +00:00
|
|
|
logger.CommandLog(chownLogSender, filePath, "", c.User.Username, "", c.ID, c.protocol, uid, gid, "", "", "")
|
2019-11-16 09:23:41 +00:00
|
|
|
return nil
|
|
|
|
} else if attrFlags.Acmodtime {
|
2019-12-25 17:20:19 +00:00
|
|
|
if !c.User.HasPerm(dataprovider.PermChtimes, pathForPerms) {
|
2019-11-16 09:23:41 +00:00
|
|
|
return sftp.ErrSSHFxPermissionDenied
|
|
|
|
}
|
|
|
|
dateFormat := "2006-01-02T15:04:05" // YYYY-MM-DDTHH:MM:SS
|
|
|
|
accessTime := time.Unix(int64(request.Attributes().Atime), 0)
|
|
|
|
modificationTime := time.Unix(int64(request.Attributes().Mtime), 0)
|
|
|
|
accessTimeString := accessTime.Format(dateFormat)
|
|
|
|
modificationTimeString := modificationTime.Format(dateFormat)
|
2020-01-19 06:41:05 +00:00
|
|
|
if err := c.fs.Chtimes(filePath, accessTime, modificationTime); err != nil {
|
2020-02-13 07:26:45 +00:00
|
|
|
c.Log(logger.LevelWarn, logSender, "failed to chtimes for path %#v, access time: %v, modification time: %v, err: %+v",
|
2020-01-05 10:41:25 +00:00
|
|
|
filePath, accessTime, modificationTime, err)
|
2020-01-19 06:41:05 +00:00
|
|
|
return vfs.GetSFTPError(c.fs, err)
|
2019-11-16 09:23:41 +00:00
|
|
|
}
|
2020-01-05 10:41:25 +00:00
|
|
|
logger.CommandLog(chtimesLogSender, filePath, "", c.User.Username, "", c.ID, c.protocol, -1, -1, accessTimeString,
|
2019-11-19 10:38:39 +00:00
|
|
|
modificationTimeString, "")
|
2019-11-15 11:15:07 +00:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2020-06-07 21:30:18 +00:00
|
|
|
func (c Connection) handleSFTPRename(sourcePath, targetPath string, request *sftp.Request) error {
|
|
|
|
if !c.isRenamePermitted(sourcePath, request) {
|
2019-12-29 06:43:59 +00:00
|
|
|
return sftp.ErrSSHFxPermissionDenied
|
|
|
|
}
|
2020-06-10 07:11:32 +00:00
|
|
|
if c.User.IsMappedPath(sourcePath) {
|
|
|
|
c.Log(logger.LevelWarn, logSender, "renaming a directory mapped as virtual folder is not allowed: %#v", sourcePath)
|
|
|
|
return sftp.ErrSSHFxPermissionDenied
|
|
|
|
}
|
|
|
|
if c.User.IsMappedPath(targetPath) {
|
|
|
|
c.Log(logger.LevelWarn, logSender, "renaming to a directory mapped as virtual folder is not allowed: %#v", targetPath)
|
|
|
|
return sftp.ErrSSHFxPermissionDenied
|
|
|
|
}
|
2020-06-07 21:30:18 +00:00
|
|
|
if c.User.HasVirtualFoldersInside(request.Filepath) {
|
|
|
|
if fi, err := c.fs.Stat(sourcePath); err == nil {
|
|
|
|
if fi.IsDir() {
|
|
|
|
c.Log(logger.LevelDebug, logSender, "renaming the folder %#v is not supported: it has virtual folders inside it",
|
|
|
|
request.Filepath)
|
|
|
|
return sftp.ErrSSHFxOpUnsupported
|
|
|
|
}
|
|
|
|
}
|
2020-02-23 10:30:26 +00:00
|
|
|
}
|
2020-06-07 21:30:18 +00:00
|
|
|
initialSize := int64(-1)
|
|
|
|
if fi, err := c.fs.Lstat(targetPath); err == nil {
|
|
|
|
if fi.IsDir() {
|
|
|
|
c.Log(logger.LevelWarn, logSender, "attempted to rename %#v overwriting an existing directory %#v", sourcePath, targetPath)
|
|
|
|
return sftp.ErrSSHFxOpUnsupported
|
|
|
|
}
|
|
|
|
// we are overwriting an existing file/symlink
|
|
|
|
if fi.Mode().IsRegular() {
|
|
|
|
initialSize = fi.Size()
|
|
|
|
}
|
|
|
|
if !c.User.HasPerm(dataprovider.PermOverwrite, path.Dir(request.Target)) {
|
|
|
|
c.Log(logger.LevelDebug, logSender, "renaming is not allowed, source: %#v target: %#v. "+
|
|
|
|
"Target exists but the user has no overwrite permission", request.Filepath, request.Target)
|
2020-03-01 21:10:29 +00:00
|
|
|
return sftp.ErrSSHFxPermissionDenied
|
|
|
|
}
|
|
|
|
}
|
2020-06-07 21:30:18 +00:00
|
|
|
if !c.hasSpaceForRename(request, initialSize, sourcePath) {
|
|
|
|
c.Log(logger.LevelInfo, logSender, "denying cross rename due to space limit")
|
|
|
|
return sftp.ErrSSHFxFailure
|
2019-07-20 22:19:17 +00:00
|
|
|
}
|
2020-01-19 06:41:05 +00:00
|
|
|
if err := c.fs.Rename(sourcePath, targetPath); err != nil {
|
2020-06-07 21:30:18 +00:00
|
|
|
c.Log(logger.LevelWarn, logSender, "failed to rename %#v -> %#v: %+v", sourcePath, targetPath, err)
|
2020-01-19 06:41:05 +00:00
|
|
|
return vfs.GetSFTPError(c.fs, err)
|
2019-07-20 22:19:17 +00:00
|
|
|
}
|
2020-06-07 21:30:18 +00:00
|
|
|
if dataprovider.GetQuotaTracking() > 0 {
|
|
|
|
c.updateQuotaAfterRename(request, targetPath, initialSize) //nolint:errcheck
|
|
|
|
}
|
2019-11-19 10:38:39 +00:00
|
|
|
logger.CommandLog(renameLogSender, sourcePath, targetPath, c.User.Username, "", c.ID, c.protocol, -1, -1, "", "", "")
|
2020-04-30 12:23:55 +00:00
|
|
|
// the returned error is used in test cases only, we already log the error inside executeAction
|
|
|
|
go executeAction(newActionNotification(c.User, operationRename, sourcePath, targetPath, "", 0, nil)) //nolint:errcheck
|
2019-07-20 22:19:17 +00:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2020-01-05 10:41:25 +00:00
|
|
|
func (c Connection) handleSFTPRmdir(dirPath string, request *sftp.Request) error {
|
2020-01-19 22:23:09 +00:00
|
|
|
if c.fs.GetRelativePath(dirPath) == "/" {
|
2019-12-29 06:43:59 +00:00
|
|
|
c.Log(logger.LevelWarn, logSender, "removing root dir is not allowed")
|
|
|
|
return sftp.ErrSSHFxPermissionDenied
|
|
|
|
}
|
2020-02-23 10:30:26 +00:00
|
|
|
if c.User.IsVirtualFolder(request.Filepath) {
|
|
|
|
c.Log(logger.LevelWarn, logSender, "removing a virtual folder is not allowed: %#v", request.Filepath)
|
|
|
|
return sftp.ErrSSHFxPermissionDenied
|
|
|
|
}
|
2020-06-07 21:30:18 +00:00
|
|
|
if c.User.HasVirtualFoldersInside(request.Filepath) {
|
|
|
|
c.Log(logger.LevelWarn, logSender, "removing a directory with a virtual folder inside is not allowed: %#v", request.Filepath)
|
|
|
|
return sftp.ErrSSHFxOpUnsupported
|
|
|
|
}
|
2020-06-10 07:11:32 +00:00
|
|
|
if c.User.IsMappedPath(dirPath) {
|
|
|
|
c.Log(logger.LevelWarn, logSender, "removing a directory mapped as virtual folder is not allowed: %#v", dirPath)
|
|
|
|
return sftp.ErrSSHFxPermissionDenied
|
|
|
|
}
|
2020-01-05 10:41:25 +00:00
|
|
|
if !c.User.HasPerm(dataprovider.PermDelete, path.Dir(request.Filepath)) {
|
2019-10-14 20:44:57 +00:00
|
|
|
return sftp.ErrSSHFxPermissionDenied
|
2019-07-20 22:19:17 +00:00
|
|
|
}
|
|
|
|
|
2019-10-16 05:48:22 +00:00
|
|
|
var fi os.FileInfo
|
|
|
|
var err error
|
2020-01-19 06:41:05 +00:00
|
|
|
if fi, err = c.fs.Lstat(dirPath); err != nil {
|
2020-02-13 07:26:45 +00:00
|
|
|
c.Log(logger.LevelWarn, logSender, "failed to remove a dir %#v: stat error: %+v", dirPath, err)
|
2020-01-19 06:41:05 +00:00
|
|
|
return vfs.GetSFTPError(c.fs, err)
|
2019-07-20 22:19:17 +00:00
|
|
|
}
|
2019-10-16 05:48:22 +00:00
|
|
|
if !fi.IsDir() || fi.Mode()&os.ModeSymlink == os.ModeSymlink {
|
2020-01-05 10:41:25 +00:00
|
|
|
c.Log(logger.LevelDebug, logSender, "cannot remove %#v is not a directory", dirPath)
|
2019-10-16 05:48:22 +00:00
|
|
|
return sftp.ErrSSHFxFailure
|
|
|
|
}
|
|
|
|
|
2020-01-19 06:41:05 +00:00
|
|
|
if err = c.fs.Remove(dirPath, true); err != nil {
|
2020-02-13 07:26:45 +00:00
|
|
|
c.Log(logger.LevelWarn, logSender, "failed to remove directory %#v: %+v", dirPath, err)
|
2020-01-19 06:41:05 +00:00
|
|
|
return vfs.GetSFTPError(c.fs, err)
|
2019-07-20 22:19:17 +00:00
|
|
|
}
|
|
|
|
|
2020-01-05 10:41:25 +00:00
|
|
|
logger.CommandLog(rmdirLogSender, dirPath, "", c.User.Username, "", c.ID, c.protocol, -1, -1, "", "", "")
|
2019-10-14 20:44:57 +00:00
|
|
|
return sftp.ErrSSHFxOk
|
2019-07-20 22:19:17 +00:00
|
|
|
}
|
|
|
|
|
2020-01-05 10:41:25 +00:00
|
|
|
func (c Connection) handleSFTPSymlink(sourcePath string, targetPath string, request *sftp.Request) error {
|
2020-01-19 22:23:09 +00:00
|
|
|
if c.fs.GetRelativePath(sourcePath) == "/" {
|
2019-12-29 06:43:59 +00:00
|
|
|
c.Log(logger.LevelWarn, logSender, "symlinking root dir is not allowed")
|
|
|
|
return sftp.ErrSSHFxPermissionDenied
|
|
|
|
}
|
2020-02-23 10:30:26 +00:00
|
|
|
if c.User.IsVirtualFolder(request.Target) {
|
|
|
|
c.Log(logger.LevelWarn, logSender, "symlinking a virtual folder is not allowed")
|
|
|
|
return sftp.ErrSSHFxPermissionDenied
|
|
|
|
}
|
2020-01-05 10:41:25 +00:00
|
|
|
if !c.User.HasPerm(dataprovider.PermCreateSymlinks, path.Dir(request.Target)) {
|
2019-10-14 20:44:57 +00:00
|
|
|
return sftp.ErrSSHFxPermissionDenied
|
2019-07-20 22:19:17 +00:00
|
|
|
}
|
2020-06-07 21:30:18 +00:00
|
|
|
if c.isCrossFoldersRequest(request) {
|
|
|
|
c.Log(logger.LevelWarn, logSender, "cross folder symlink is not supported, src: %v dst: %v", request.Filepath, request.Target)
|
|
|
|
return sftp.ErrSSHFxFailure
|
|
|
|
}
|
2020-06-10 07:11:32 +00:00
|
|
|
if c.User.IsMappedPath(sourcePath) {
|
|
|
|
c.Log(logger.LevelWarn, logSender, "symlinking a directory mapped as virtual folder is not allowed: %#v", sourcePath)
|
|
|
|
return sftp.ErrSSHFxPermissionDenied
|
|
|
|
}
|
|
|
|
if c.User.IsMappedPath(targetPath) {
|
|
|
|
c.Log(logger.LevelWarn, logSender, "symlinking to a directory mapped as virtual folder is not allowed: %#v", targetPath)
|
|
|
|
return sftp.ErrSSHFxPermissionDenied
|
|
|
|
}
|
2020-01-19 06:41:05 +00:00
|
|
|
if err := c.fs.Symlink(sourcePath, targetPath); err != nil {
|
2020-02-13 07:26:45 +00:00
|
|
|
c.Log(logger.LevelWarn, logSender, "failed to create symlink %#v -> %#v: %+v", sourcePath, targetPath, err)
|
2020-01-19 06:41:05 +00:00
|
|
|
return vfs.GetSFTPError(c.fs, err)
|
2019-07-20 22:19:17 +00:00
|
|
|
}
|
2019-11-19 10:38:39 +00:00
|
|
|
logger.CommandLog(symlinkLogSender, sourcePath, targetPath, c.User.Username, "", c.ID, c.protocol, -1, -1, "", "", "")
|
2019-07-20 22:19:17 +00:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2020-01-05 10:41:25 +00:00
|
|
|
func (c Connection) handleSFTPMkdir(dirPath string, request *sftp.Request) error {
|
|
|
|
if !c.User.HasPerm(dataprovider.PermCreateDirs, path.Dir(request.Filepath)) {
|
2019-10-14 20:44:57 +00:00
|
|
|
return sftp.ErrSSHFxPermissionDenied
|
2019-07-20 22:19:17 +00:00
|
|
|
}
|
2020-02-23 10:30:26 +00:00
|
|
|
if c.User.IsVirtualFolder(request.Filepath) {
|
|
|
|
c.Log(logger.LevelWarn, logSender, "mkdir not allowed %#v is virtual folder is not allowed", request.Filepath)
|
|
|
|
return sftp.ErrSSHFxPermissionDenied
|
|
|
|
}
|
2020-01-19 06:41:05 +00:00
|
|
|
if err := c.fs.Mkdir(dirPath); err != nil {
|
2020-02-13 07:26:45 +00:00
|
|
|
c.Log(logger.LevelWarn, logSender, "error creating missing dir: %#v error: %+v", dirPath, err)
|
2020-01-19 06:41:05 +00:00
|
|
|
return vfs.GetSFTPError(c.fs, err)
|
2019-07-20 22:19:17 +00:00
|
|
|
}
|
2020-01-19 06:41:05 +00:00
|
|
|
vfs.SetPathPermissions(c.fs, dirPath, c.User.GetUID(), c.User.GetGID())
|
2019-10-16 05:48:22 +00:00
|
|
|
|
2020-01-05 10:41:25 +00:00
|
|
|
logger.CommandLog(mkdirLogSender, dirPath, "", c.User.Username, "", c.ID, c.protocol, -1, -1, "", "", "")
|
2019-07-20 22:19:17 +00:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2020-01-05 10:41:25 +00:00
|
|
|
func (c Connection) handleSFTPRemove(filePath string, request *sftp.Request) error {
|
|
|
|
if !c.User.HasPerm(dataprovider.PermDelete, path.Dir(request.Filepath)) {
|
2019-10-14 20:44:57 +00:00
|
|
|
return sftp.ErrSSHFxPermissionDenied
|
2019-07-20 22:19:17 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
var size int64
|
|
|
|
var fi os.FileInfo
|
|
|
|
var err error
|
2020-01-19 06:41:05 +00:00
|
|
|
if fi, err = c.fs.Lstat(filePath); err != nil {
|
2020-02-13 07:26:45 +00:00
|
|
|
c.Log(logger.LevelWarn, logSender, "failed to remove a file %#v: stat error: %+v", filePath, err)
|
2020-01-19 06:41:05 +00:00
|
|
|
return vfs.GetSFTPError(c.fs, err)
|
2019-07-20 22:19:17 +00:00
|
|
|
}
|
2019-10-16 05:48:22 +00:00
|
|
|
if fi.IsDir() && fi.Mode()&os.ModeSymlink != os.ModeSymlink {
|
2020-01-05 10:41:25 +00:00
|
|
|
c.Log(logger.LevelDebug, logSender, "cannot remove %#v is not a file/symlink", filePath)
|
2019-10-16 05:48:22 +00:00
|
|
|
return sftp.ErrSSHFxFailure
|
|
|
|
}
|
2020-03-01 21:10:29 +00:00
|
|
|
|
|
|
|
if !c.User.IsFileAllowed(request.Filepath) {
|
|
|
|
c.Log(logger.LevelDebug, logSender, "removing file %#v is not allowed", filePath)
|
|
|
|
return sftp.ErrSSHFxPermissionDenied
|
|
|
|
}
|
|
|
|
|
2019-07-20 22:19:17 +00:00
|
|
|
size = fi.Size()
|
2020-05-24 21:31:14 +00:00
|
|
|
actionErr := executeAction(newActionNotification(c.User, operationPreDelete, filePath, "", "", fi.Size(), nil))
|
|
|
|
if actionErr == nil {
|
|
|
|
c.Log(logger.LevelDebug, logSender, "remove for path %#v handled by pre-delete action", filePath)
|
|
|
|
} else {
|
|
|
|
if err := c.fs.Remove(filePath, false); err != nil {
|
|
|
|
c.Log(logger.LevelWarn, logSender, "failed to remove a file/symlink %#v: %+v", filePath, err)
|
|
|
|
return vfs.GetSFTPError(c.fs, err)
|
|
|
|
}
|
2019-07-20 22:19:17 +00:00
|
|
|
}
|
|
|
|
|
2020-01-05 10:41:25 +00:00
|
|
|
logger.CommandLog(removeLogSender, filePath, "", c.User.Username, "", c.ID, c.protocol, -1, -1, "", "", "")
|
2019-07-20 22:19:17 +00:00
|
|
|
if fi.Mode()&os.ModeSymlink != os.ModeSymlink {
|
2020-06-07 21:30:18 +00:00
|
|
|
vfolder, err := c.User.GetVirtualFolderForPath(request.Filepath)
|
|
|
|
if err == nil {
|
|
|
|
dataprovider.UpdateVirtualFolderQuota(dataProvider, vfolder.BaseVirtualFolder, -1, -size, false) //nolint:errcheck
|
|
|
|
if vfolder.IsIncludedInUserQuota() {
|
|
|
|
dataprovider.UpdateUserQuota(dataProvider, c.User, -1, -size, false) //nolint:errcheck
|
|
|
|
}
|
|
|
|
} else {
|
2020-05-01 13:27:53 +00:00
|
|
|
dataprovider.UpdateUserQuota(dataProvider, c.User, -1, -size, false) //nolint:errcheck
|
|
|
|
}
|
2019-07-20 22:19:17 +00:00
|
|
|
}
|
2020-05-24 21:31:14 +00:00
|
|
|
if actionErr != nil {
|
|
|
|
go executeAction(newActionNotification(c.User, operationDelete, filePath, "", "", fi.Size(), nil)) //nolint:errcheck
|
|
|
|
}
|
2019-07-20 22:19:17 +00:00
|
|
|
|
2019-10-14 20:44:57 +00:00
|
|
|
return sftp.ErrSSHFxOk
|
2019-07-20 22:19:17 +00:00
|
|
|
}
|
|
|
|
|
2020-06-07 21:30:18 +00:00
|
|
|
func (c Connection) handleSFTPUploadToNewFile(resolvedPath, filePath, requestPath string) (io.WriterAt, error) {
|
|
|
|
if !c.hasSpace(true, requestPath) {
|
|
|
|
c.Log(logger.LevelInfo, logSender, "denying file write due to quota limits")
|
2019-10-14 20:44:57 +00:00
|
|
|
return nil, sftp.ErrSSHFxFailure
|
2019-08-04 07:37:58 +00:00
|
|
|
}
|
|
|
|
|
2020-01-19 06:41:05 +00:00
|
|
|
file, w, cancelFn, err := c.fs.Create(filePath, 0)
|
2019-08-04 07:37:58 +00:00
|
|
|
if err != nil {
|
2020-06-07 21:30:18 +00:00
|
|
|
c.Log(logger.LevelWarn, logSender, "error creating file %#v: %+v", resolvedPath, err)
|
2020-01-19 06:41:05 +00:00
|
|
|
return nil, vfs.GetSFTPError(c.fs, err)
|
2019-08-04 07:37:58 +00:00
|
|
|
}
|
|
|
|
|
2020-01-19 06:41:05 +00:00
|
|
|
vfs.SetPathPermissions(c.fs, filePath, c.User.GetUID(), c.User.GetGID())
|
2019-08-04 07:37:58 +00:00
|
|
|
|
|
|
|
transfer := Transfer{
|
2020-06-07 21:30:18 +00:00
|
|
|
file: file,
|
|
|
|
writerAt: w,
|
|
|
|
readerAt: nil,
|
|
|
|
cancelFn: cancelFn,
|
|
|
|
path: resolvedPath,
|
|
|
|
start: time.Now(),
|
|
|
|
bytesSent: 0,
|
|
|
|
bytesReceived: 0,
|
|
|
|
user: c.User,
|
|
|
|
connectionID: c.ID,
|
|
|
|
transferType: transferUpload,
|
|
|
|
lastActivity: time.Now(),
|
|
|
|
isNewFile: true,
|
|
|
|
protocol: c.protocol,
|
|
|
|
transferError: nil,
|
|
|
|
isFinished: false,
|
|
|
|
minWriteOffset: 0,
|
|
|
|
requestPath: requestPath,
|
|
|
|
lock: new(sync.Mutex),
|
2019-08-04 07:37:58 +00:00
|
|
|
}
|
|
|
|
addTransfer(&transfer)
|
|
|
|
return &transfer, nil
|
|
|
|
}
|
|
|
|
|
2020-06-07 21:30:18 +00:00
|
|
|
func (c Connection) handleSFTPUploadToExistingFile(pflags sftp.FileOpenFlags, resolvedPath, filePath string,
|
|
|
|
fileSize int64, requestPath string) (io.WriterAt, error) {
|
2019-08-04 07:37:58 +00:00
|
|
|
var err error
|
2020-06-07 21:30:18 +00:00
|
|
|
if !c.hasSpace(false, requestPath) {
|
|
|
|
c.Log(logger.LevelInfo, logSender, "denying file write due to quota limits")
|
2019-10-14 20:44:57 +00:00
|
|
|
return nil, sftp.ErrSSHFxFailure
|
2019-08-04 07:37:58 +00:00
|
|
|
}
|
|
|
|
|
2019-10-09 15:33:30 +00:00
|
|
|
minWriteOffset := int64(0)
|
2019-08-04 09:02:38 +00:00
|
|
|
osFlags := getOSOpenFlags(pflags)
|
2019-08-04 07:37:58 +00:00
|
|
|
|
2020-01-19 06:41:05 +00:00
|
|
|
if pflags.Append && osFlags&os.O_TRUNC == 0 && !c.fs.IsUploadResumeSupported() {
|
2020-06-07 21:30:18 +00:00
|
|
|
c.Log(logger.LevelInfo, logSender, "upload resume requested for path: %#v but not supported in fs implementation", resolvedPath)
|
2020-01-19 06:41:05 +00:00
|
|
|
return nil, sftp.ErrSSHFxOpUnsupported
|
|
|
|
}
|
|
|
|
|
|
|
|
if isAtomicUploadEnabled() && c.fs.IsAtomicUploadSupported() {
|
2020-06-07 21:30:18 +00:00
|
|
|
err = c.fs.Rename(resolvedPath, filePath)
|
2019-08-04 07:37:58 +00:00
|
|
|
if err != nil {
|
2020-02-13 07:26:45 +00:00
|
|
|
c.Log(logger.LevelWarn, logSender, "error renaming existing file for atomic upload, source: %#v, dest: %#v, err: %+v",
|
2020-06-07 21:30:18 +00:00
|
|
|
resolvedPath, filePath, err)
|
2020-01-19 06:41:05 +00:00
|
|
|
return nil, vfs.GetSFTPError(c.fs, err)
|
2019-08-04 07:37:58 +00:00
|
|
|
}
|
|
|
|
}
|
2020-01-19 06:41:05 +00:00
|
|
|
|
|
|
|
file, w, cancelFn, err := c.fs.Create(filePath, osFlags)
|
2019-08-04 07:37:58 +00:00
|
|
|
if err != nil {
|
2020-02-13 07:26:45 +00:00
|
|
|
c.Log(logger.LevelWarn, logSender, "error opening existing file, flags: %v, source: %#v, err: %+v", pflags, filePath, err)
|
2020-01-19 06:41:05 +00:00
|
|
|
return nil, vfs.GetSFTPError(c.fs, err)
|
2019-08-04 07:37:58 +00:00
|
|
|
}
|
|
|
|
|
2020-01-23 09:19:56 +00:00
|
|
|
initialSize := int64(0)
|
2019-10-09 15:33:30 +00:00
|
|
|
if pflags.Append && osFlags&os.O_TRUNC == 0 {
|
|
|
|
c.Log(logger.LevelDebug, logSender, "upload resume requested, file path: %#v initial size: %v", filePath, fileSize)
|
|
|
|
minWriteOffset = fileSize
|
|
|
|
} else {
|
2020-01-23 09:19:56 +00:00
|
|
|
if vfs.IsLocalOsFs(c.fs) {
|
2020-06-07 21:30:18 +00:00
|
|
|
vfolder, err := c.User.GetVirtualFolderForPath(requestPath)
|
|
|
|
if err == nil {
|
|
|
|
dataprovider.UpdateVirtualFolderQuota(dataProvider, vfolder.BaseVirtualFolder, 0, -fileSize, false) //nolint:errcheck
|
|
|
|
if vfolder.IsIncludedInUserQuota() {
|
|
|
|
dataprovider.UpdateUserQuota(dataProvider, c.User, 0, -fileSize, false) //nolint:errcheck
|
|
|
|
}
|
|
|
|
} else {
|
2020-05-01 13:27:53 +00:00
|
|
|
dataprovider.UpdateUserQuota(dataProvider, c.User, 0, -fileSize, false) //nolint:errcheck
|
|
|
|
}
|
2020-01-23 09:19:56 +00:00
|
|
|
} else {
|
|
|
|
initialSize = fileSize
|
|
|
|
}
|
2019-10-09 15:33:30 +00:00
|
|
|
}
|
2019-08-04 07:37:58 +00:00
|
|
|
|
2020-01-19 06:41:05 +00:00
|
|
|
vfs.SetPathPermissions(c.fs, filePath, c.User.GetUID(), c.User.GetGID())
|
2019-08-04 07:37:58 +00:00
|
|
|
|
|
|
|
transfer := Transfer{
|
2020-06-07 21:30:18 +00:00
|
|
|
file: file,
|
|
|
|
writerAt: w,
|
|
|
|
readerAt: nil,
|
|
|
|
cancelFn: cancelFn,
|
|
|
|
path: resolvedPath,
|
|
|
|
start: time.Now(),
|
|
|
|
bytesSent: 0,
|
|
|
|
bytesReceived: 0,
|
|
|
|
user: c.User,
|
|
|
|
connectionID: c.ID,
|
|
|
|
transferType: transferUpload,
|
|
|
|
lastActivity: time.Now(),
|
|
|
|
isNewFile: false,
|
|
|
|
protocol: c.protocol,
|
|
|
|
transferError: nil,
|
|
|
|
isFinished: false,
|
|
|
|
minWriteOffset: minWriteOffset,
|
|
|
|
initialSize: initialSize,
|
|
|
|
requestPath: requestPath,
|
|
|
|
lock: new(sync.Mutex),
|
2019-08-04 07:37:58 +00:00
|
|
|
}
|
|
|
|
addTransfer(&transfer)
|
|
|
|
return &transfer, nil
|
|
|
|
}
|
|
|
|
|
2020-06-07 21:30:18 +00:00
|
|
|
func (c Connection) hasSpaceForRename(request *sftp.Request, initialSize int64, sourcePath string) bool {
|
|
|
|
if dataprovider.GetQuotaTracking() == 0 {
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
sourceFolder, errSrc := c.User.GetVirtualFolderForPath(request.Filepath)
|
|
|
|
dstFolder, errDst := c.User.GetVirtualFolderForPath(request.Target)
|
|
|
|
if errSrc != nil && errDst != nil {
|
|
|
|
// rename inside the user home dir
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
if errSrc == nil && errDst == nil {
|
|
|
|
// rename between virtual folders
|
|
|
|
if sourceFolder.MappedPath == dstFolder.MappedPath {
|
|
|
|
// rename inside the same virtual folder
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if errSrc != nil && dstFolder.IsIncludedInUserQuota() {
|
|
|
|
// rename between user root dir and a virtual folder included in user quota
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
if !c.hasSpace(true, request.Target) {
|
|
|
|
if initialSize != -1 {
|
|
|
|
// we are overquota but we are overwriting a file so we check the quota size
|
|
|
|
if c.hasSpace(false, request.Target) {
|
|
|
|
// we have enough quota size
|
2019-07-20 10:26:52 +00:00
|
|
|
return true
|
|
|
|
}
|
2020-06-07 21:30:18 +00:00
|
|
|
if fi, err := c.fs.Lstat(sourcePath); err == nil {
|
|
|
|
if fi.Mode().IsRegular() {
|
|
|
|
// we have space if we are overwriting a bigger file with a smaller one
|
|
|
|
return initialSize >= fi.Size()
|
|
|
|
}
|
|
|
|
}
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
2020-06-07 21:30:18 +00:00
|
|
|
return false
|
|
|
|
}
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c Connection) hasSpace(checkFiles bool, requestPath string) bool {
|
|
|
|
if dataprovider.GetQuotaTracking() == 0 {
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
var quotaSize, usedSize int64
|
|
|
|
var quotaFiles, numFiles int
|
|
|
|
var err error
|
|
|
|
var vfolder vfs.VirtualFolder
|
|
|
|
vfolder, err = c.User.GetVirtualFolderForPath(requestPath)
|
|
|
|
if err == nil && !vfolder.IsIncludedInUserQuota() {
|
|
|
|
if vfolder.HasNoQuotaRestrictions(checkFiles) {
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
quotaSize = vfolder.QuotaSize
|
|
|
|
quotaFiles = vfolder.QuotaFiles
|
|
|
|
numFiles, usedSize, err = dataprovider.GetUsedVirtualFolderQuota(dataProvider, vfolder.MappedPath)
|
|
|
|
} else {
|
|
|
|
if c.User.HasNoQuotaRestrictions(checkFiles) {
|
|
|
|
return true
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
2020-06-07 21:30:18 +00:00
|
|
|
quotaSize = c.User.QuotaSize
|
|
|
|
quotaFiles = c.User.QuotaFiles
|
|
|
|
numFiles, usedSize, err = dataprovider.GetUsedQuota(dataProvider, c.User.Username)
|
|
|
|
}
|
|
|
|
if err != nil {
|
|
|
|
c.Log(logger.LevelWarn, logSender, "error getting used quota for %#v request path %#v: %v", c.User.Username, requestPath, err)
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
if (checkFiles && quotaFiles > 0 && numFiles >= quotaFiles) ||
|
|
|
|
(quotaSize > 0 && usedSize >= quotaSize) {
|
|
|
|
c.Log(logger.LevelDebug, logSender, "quota exceed for user %#v, request path %#v, num files: %v/%v, size: %v/%v check files: %v",
|
|
|
|
c.User.Username, requestPath, numFiles, quotaFiles, usedSize, quotaSize, checkFiles)
|
|
|
|
return false
|
2019-07-20 10:26:52 +00:00
|
|
|
}
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
|
2019-09-11 10:46:21 +00:00
|
|
|
func (c Connection) close() error {
|
2019-09-11 14:29:56 +00:00
|
|
|
if c.channel != nil {
|
|
|
|
err := c.channel.Close()
|
|
|
|
c.Log(logger.LevelInfo, logSender, "channel close, err: %v", err)
|
|
|
|
}
|
2019-09-11 10:46:21 +00:00
|
|
|
return c.netConn.Close()
|
|
|
|
}
|
|
|
|
|
2019-08-04 09:02:38 +00:00
|
|
|
func getOSOpenFlags(requestFlags sftp.FileOpenFlags) (flags int) {
|
2019-07-20 22:19:17 +00:00
|
|
|
var osFlags int
|
|
|
|
if requestFlags.Read && requestFlags.Write {
|
|
|
|
osFlags |= os.O_RDWR
|
|
|
|
} else if requestFlags.Write {
|
|
|
|
osFlags |= os.O_WRONLY
|
|
|
|
}
|
2019-10-09 15:33:30 +00:00
|
|
|
// we ignore Append flag since pkg/sftp use WriteAt that cannot work with os.O_APPEND
|
|
|
|
/*if requestFlags.Append {
|
2019-07-20 22:19:17 +00:00
|
|
|
osFlags |= os.O_APPEND
|
2019-10-09 15:33:30 +00:00
|
|
|
}*/
|
2019-07-20 22:19:17 +00:00
|
|
|
if requestFlags.Creat {
|
|
|
|
osFlags |= os.O_CREATE
|
|
|
|
}
|
|
|
|
if requestFlags.Trunc {
|
|
|
|
osFlags |= os.O_TRUNC
|
|
|
|
}
|
|
|
|
if requestFlags.Excl {
|
|
|
|
osFlags |= os.O_EXCL
|
|
|
|
}
|
2019-08-04 09:02:38 +00:00
|
|
|
return osFlags
|
2019-07-20 22:19:17 +00:00
|
|
|
}
|
2020-06-07 21:30:18 +00:00
|
|
|
|
|
|
|
func (c Connection) isCrossFoldersRequest(request *sftp.Request) bool {
|
|
|
|
sourceFolder, errSrc := c.User.GetVirtualFolderForPath(request.Filepath)
|
|
|
|
dstFolder, errDst := c.User.GetVirtualFolderForPath(request.Target)
|
|
|
|
if errSrc != nil && errDst != nil {
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
if errSrc == nil && errDst == nil {
|
|
|
|
return sourceFolder.MappedPath != dstFolder.MappedPath
|
|
|
|
}
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c Connection) isRenamePermitted(sourcePath string, request *sftp.Request) bool {
|
|
|
|
if c.fs.GetRelativePath(sourcePath) == "/" {
|
|
|
|
c.Log(logger.LevelWarn, logSender, "renaming root dir is not allowed")
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
if c.User.IsVirtualFolder(request.Filepath) || c.User.IsVirtualFolder(request.Target) {
|
|
|
|
c.Log(logger.LevelWarn, logSender, "renaming a virtual folder is not allowed")
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
if !c.User.IsFileAllowed(request.Filepath) || !c.User.IsFileAllowed(request.Target) {
|
|
|
|
if fi, err := c.fs.Lstat(sourcePath); err == nil && fi.Mode().IsRegular() {
|
|
|
|
c.Log(logger.LevelDebug, logSender, "renaming file is not allowed, source: %#v target: %#v", request.Filepath,
|
|
|
|
request.Target)
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
}
|
2020-06-13 21:49:28 +00:00
|
|
|
if !c.User.HasPerm(dataprovider.PermRename, path.Dir(request.Target)) &&
|
|
|
|
(!c.User.HasPerm(dataprovider.PermDelete, path.Dir(request.Filepath)) ||
|
|
|
|
!c.User.HasPerm(dataprovider.PermUpload, path.Dir(request.Target))) {
|
2020-06-07 21:30:18 +00:00
|
|
|
return false
|
|
|
|
}
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c Connection) updateQuotaMoveBetweenVFolders(sourceFolder, dstFolder vfs.VirtualFolder, initialSize, filesSize int64, numFiles int) {
|
|
|
|
if sourceFolder.MappedPath == dstFolder.MappedPath {
|
|
|
|
// both files are inside the same virtual folder
|
|
|
|
if initialSize != -1 {
|
|
|
|
dataprovider.UpdateVirtualFolderQuota(dataProvider, dstFolder.BaseVirtualFolder, -numFiles, -initialSize, false) //nolint:errcheck
|
|
|
|
if dstFolder.IsIncludedInUserQuota() {
|
|
|
|
dataprovider.UpdateUserQuota(dataProvider, c.User, -numFiles, -initialSize, false) //nolint:errcheck
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return
|
|
|
|
}
|
|
|
|
// files are inside different virtual folders
|
|
|
|
dataprovider.UpdateVirtualFolderQuota(dataProvider, sourceFolder.BaseVirtualFolder, -numFiles, -filesSize, false) //nolint:errcheck
|
|
|
|
if sourceFolder.IsIncludedInUserQuota() {
|
|
|
|
dataprovider.UpdateUserQuota(dataProvider, c.User, -numFiles, -filesSize, false) //nolint:errcheck
|
|
|
|
}
|
|
|
|
if initialSize == -1 {
|
|
|
|
dataprovider.UpdateVirtualFolderQuota(dataProvider, dstFolder.BaseVirtualFolder, numFiles, filesSize, false) //nolint:errcheck
|
|
|
|
if dstFolder.IsIncludedInUserQuota() {
|
|
|
|
dataprovider.UpdateUserQuota(dataProvider, c.User, numFiles, filesSize, false) //nolint:errcheck
|
|
|
|
}
|
|
|
|
} else {
|
|
|
|
// we cannot have a directory here, initialSize != -1 only for files
|
|
|
|
dataprovider.UpdateVirtualFolderQuota(dataProvider, dstFolder.BaseVirtualFolder, 0, filesSize-initialSize, false) //nolint:errcheck
|
|
|
|
if dstFolder.IsIncludedInUserQuota() {
|
|
|
|
dataprovider.UpdateUserQuota(dataProvider, c.User, 0, filesSize-initialSize, false) //nolint:errcheck
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c Connection) updateQuotaMoveFromVFolder(sourceFolder vfs.VirtualFolder, initialSize, filesSize int64, numFiles int) {
|
|
|
|
// move between a virtual folder and the user home dir
|
|
|
|
dataprovider.UpdateVirtualFolderQuota(dataProvider, sourceFolder.BaseVirtualFolder, -numFiles, -filesSize, false) //nolint:errcheck
|
|
|
|
if sourceFolder.IsIncludedInUserQuota() {
|
|
|
|
dataprovider.UpdateUserQuota(dataProvider, c.User, -numFiles, -filesSize, false) //nolint:errcheck
|
|
|
|
}
|
|
|
|
if initialSize == -1 {
|
|
|
|
dataprovider.UpdateUserQuota(dataProvider, c.User, numFiles, filesSize, false) //nolint:errcheck
|
|
|
|
} else {
|
|
|
|
// we cannot have a directory here, initialSize != -1 only for files
|
|
|
|
dataprovider.UpdateUserQuota(dataProvider, c.User, 0, filesSize-initialSize, false) //nolint:errcheck
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c Connection) updateQuotaMoveToVFolder(dstFolder vfs.VirtualFolder, initialSize, filesSize int64, numFiles int) {
|
|
|
|
// move between the user home dir and a virtual folder
|
|
|
|
dataprovider.UpdateUserQuota(dataProvider, c.User, -numFiles, -filesSize, false) //nolint:errcheck
|
|
|
|
if initialSize == -1 {
|
|
|
|
dataprovider.UpdateVirtualFolderQuota(dataProvider, dstFolder.BaseVirtualFolder, numFiles, filesSize, false) //nolint:errcheck
|
|
|
|
if dstFolder.IsIncludedInUserQuota() {
|
|
|
|
dataprovider.UpdateUserQuota(dataProvider, c.User, numFiles, filesSize, false) //nolint:errcheck
|
|
|
|
}
|
|
|
|
} else {
|
|
|
|
// we cannot have a directory here, initialSize != -1 only for files
|
|
|
|
dataprovider.UpdateVirtualFolderQuota(dataProvider, dstFolder.BaseVirtualFolder, 0, filesSize-initialSize, false) //nolint:errcheck
|
|
|
|
if dstFolder.IsIncludedInUserQuota() {
|
|
|
|
dataprovider.UpdateUserQuota(dataProvider, c.User, 0, filesSize-initialSize, false) //nolint:errcheck
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c Connection) updateQuotaAfterRename(request *sftp.Request, targetPath string, initialSize int64) error {
|
|
|
|
// we don't allow to overwrite an existing directory so targetPath can be:
|
|
|
|
// - a new file, a symlink is as a new file here
|
|
|
|
// - a file overwriting an existing one
|
|
|
|
// - a new directory
|
|
|
|
// initialSize != -1 only when overwriting files
|
|
|
|
sourceFolder, errSrc := c.User.GetVirtualFolderForPath(request.Filepath)
|
|
|
|
dstFolder, errDst := c.User.GetVirtualFolderForPath(request.Target)
|
|
|
|
if errSrc != nil && errDst != nil {
|
|
|
|
// both files are contained inside the user home dir
|
|
|
|
if initialSize != -1 {
|
|
|
|
// we cannot have a directory here
|
|
|
|
dataprovider.UpdateUserQuota(dataProvider, c.User, -1, -initialSize, false) //nolint:errcheck
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
filesSize := int64(0)
|
|
|
|
numFiles := 1
|
|
|
|
if fi, err := c.fs.Stat(targetPath); err == nil {
|
|
|
|
if fi.Mode().IsDir() {
|
|
|
|
numFiles, filesSize, err = c.fs.GetDirSize(targetPath)
|
|
|
|
if err != nil {
|
|
|
|
logger.Warn(logSender, "", "failed to update quota after rename, error scanning moved folder %#v: %v", targetPath, err)
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
} else {
|
|
|
|
filesSize = fi.Size()
|
|
|
|
}
|
|
|
|
} else {
|
|
|
|
c.Log(logger.LevelWarn, logSender, "failed to update quota after rename, file %#v stat error: %+v", targetPath, err)
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
if errSrc == nil && errDst == nil {
|
|
|
|
c.updateQuotaMoveBetweenVFolders(sourceFolder, dstFolder, initialSize, filesSize, numFiles)
|
|
|
|
}
|
|
|
|
if errSrc == nil && errDst != nil {
|
|
|
|
c.updateQuotaMoveFromVFolder(sourceFolder, initialSize, filesSize, numFiles)
|
|
|
|
}
|
|
|
|
if errSrc != nil && errDst == nil {
|
|
|
|
c.updateQuotaMoveToVFolder(dstFolder, initialSize, filesSize, numFiles)
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|