16185db85Sdougm /*
26185db85Sdougm  * CDDL HEADER START
36185db85Sdougm  *
46185db85Sdougm  * The contents of this file are subject to the terms of the
56185db85Sdougm  * Common Development and Distribution License (the "License").
66185db85Sdougm  * You may not use this file except in compliance with the License.
76185db85Sdougm  *
86185db85Sdougm  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
96185db85Sdougm  * or http://www.opensolaris.org/os/licensing.
106185db85Sdougm  * See the License for the specific language governing permissions
116185db85Sdougm  * and limitations under the License.
126185db85Sdougm  *
136185db85Sdougm  * When distributing Covered Code, include this CDDL HEADER in each
146185db85Sdougm  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
156185db85Sdougm  * If applicable, add the following below this CDDL HEADER, with the
166185db85Sdougm  * fields enclosed by brackets "[]" replaced with your own identifying
176185db85Sdougm  * information: Portions Copyright [yyyy] [name of copyright owner]
186185db85Sdougm  *
196185db85Sdougm  * CDDL HEADER END
206185db85Sdougm  */
216185db85Sdougm 
226185db85Sdougm /*
23dc20a302Sas  * Copyright 2008 Sun Microsystems, Inc.  All rights reserved.
246185db85Sdougm  * Use is subject to license terms.
256185db85Sdougm  */
266185db85Sdougm 
276185db85Sdougm #pragma ident	"%Z%%M%	%I%	%E% SMI"
286185db85Sdougm 
296185db85Sdougm /*
306185db85Sdougm  * Share control API
316185db85Sdougm  */
326185db85Sdougm #include <stdio.h>
336185db85Sdougm #include <string.h>
346185db85Sdougm #include <ctype.h>
356185db85Sdougm #include <sys/types.h>
366185db85Sdougm #include <sys/stat.h>
37a99982a7Sdougm #include <fcntl.h>
386185db85Sdougm #include <unistd.h>
396185db85Sdougm #include <libxml/parser.h>
406185db85Sdougm #include <libxml/tree.h>
416185db85Sdougm #include "libshare.h"
426185db85Sdougm #include "libshare_impl.h"
436185db85Sdougm #include <libscf.h>
446185db85Sdougm #include "scfutil.h"
456185db85Sdougm #include <ctype.h>
466185db85Sdougm #include <libintl.h>
47549ec3ffSdougm #include <thread.h>
48549ec3ffSdougm #include <synch.h>
496185db85Sdougm 
50a99982a7Sdougm #define	DFS_LOCK_FILE	"/etc/dfs/fstypes"
5157b448deSdougm #define	SA_STRSIZE	256	/* max string size for names */
52a99982a7Sdougm 
53da6c28aaSamw /*
54da6c28aaSamw  * internal object type values returned by sa_get_object_type()
55da6c28aaSamw  */
56da6c28aaSamw #define	SA_TYPE_UNKNOWN		0
57da6c28aaSamw #define	SA_TYPE_GROUP		1
58da6c28aaSamw #define	SA_TYPE_SHARE		2
59da6c28aaSamw #define	SA_TYPE_RESOURCE	3
60da6c28aaSamw #define	SA_TYPE_OPTIONSET	4
61da6c28aaSamw #define	SA_TYPE_ALTSPACE	5
62da6c28aaSamw 
636185db85Sdougm /*
646185db85Sdougm  * internal data structures
656185db85Sdougm  */
666185db85Sdougm 
676185db85Sdougm extern struct sa_proto_plugin *sap_proto_list;
686185db85Sdougm 
696185db85Sdougm /* current SMF/SVC repository handle */
70549ec3ffSdougm extern void getlegacyconfig(sa_handle_t, char *, xmlNodePtr *);
71549ec3ffSdougm extern int gettransients(sa_handle_impl_t, xmlNodePtr *);
726185db85Sdougm extern int sa_valid_property(void *, char *, sa_property_t);
736185db85Sdougm extern char *sa_fstype(char *);
746185db85Sdougm extern int sa_is_share(void *);
75da6c28aaSamw extern int sa_is_resource(void *);
766185db85Sdougm extern ssize_t scf_max_name_len; /* defined in scfutil during initialization */
776185db85Sdougm extern int sa_group_is_zfs(sa_group_t);
786185db85Sdougm extern int sa_path_is_zfs(char *);
796185db85Sdougm extern int sa_zfs_set_sharenfs(sa_group_t, char *, int);
80da6c28aaSamw extern int sa_zfs_set_sharesmb(sa_group_t, char *, int);
81549ec3ffSdougm extern void update_legacy_config(sa_handle_t);
826185db85Sdougm extern int issubdir(char *, char *);
8357b448deSdougm extern int sa_zfs_init(sa_handle_impl_t);
84549ec3ffSdougm extern void sa_zfs_fini(sa_handle_impl_t);
85a99982a7Sdougm extern void sablocksigs(sigset_t *);
86a99982a7Sdougm extern void saunblocksigs(sigset_t *);
87da6c28aaSamw static sa_group_t sa_get_optionset_parent(sa_optionset_t);
88da6c28aaSamw static char *get_node_attr(void *, char *);
89*5b6e0c46Sdougm extern void sa_update_sharetab_ts(sa_handle_t);
906185db85Sdougm 
91549ec3ffSdougm /*
92549ec3ffSdougm  * Data structures for finding/managing the document root to access
93549ec3ffSdougm  * handle mapping. The list isn't expected to grow very large so a
94549ec3ffSdougm  * simple list is acceptable. The purpose is to provide a way to start
95549ec3ffSdougm  * with a group or share and find the library handle needed for
96549ec3ffSdougm  * various operations.
97549ec3ffSdougm  */
98549ec3ffSdougm mutex_t sa_global_lock;
99549ec3ffSdougm struct doc2handle {
100549ec3ffSdougm 	struct doc2handle	*next;
101549ec3ffSdougm 	xmlNodePtr		root;
102549ec3ffSdougm 	sa_handle_impl_t	handle;
103549ec3ffSdougm };
104549ec3ffSdougm 
10557b448deSdougm /* definitions used in a couple of property functions */
10657b448deSdougm #define	SA_PROP_OP_REMOVE	1
10757b448deSdougm #define	SA_PROP_OP_ADD		2
10857b448deSdougm #define	SA_PROP_OP_UPDATE	3
10957b448deSdougm 
110549ec3ffSdougm static struct doc2handle *sa_global_handles = NULL;
1116185db85Sdougm 
1126185db85Sdougm /* helper functions */
1136185db85Sdougm 
114549ec3ffSdougm /*
115549ec3ffSdougm  * sa_errorstr(err)
116549ec3ffSdougm  *
117549ec3ffSdougm  * convert an error value to an error string
118549ec3ffSdougm  */
119549ec3ffSdougm 
1206185db85Sdougm char *
1216185db85Sdougm sa_errorstr(int err)
1226185db85Sdougm {
1236185db85Sdougm 	static char errstr[32];
1246185db85Sdougm 	char *ret = NULL;
1256185db85Sdougm 
1266185db85Sdougm 	switch (err) {
1276185db85Sdougm 	case SA_OK:
12857b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "ok");
12957b448deSdougm 		break;
1306185db85Sdougm 	case SA_NO_SUCH_PATH:
13157b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "path doesn't exist");
13257b448deSdougm 		break;
1336185db85Sdougm 	case SA_NO_MEMORY:
13457b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "no memory");
13557b448deSdougm 		break;
1366185db85Sdougm 	case SA_DUPLICATE_NAME:
13757b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "name in use");
13857b448deSdougm 		break;
1396185db85Sdougm 	case SA_BAD_PATH:
14057b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "bad path");
14157b448deSdougm 		break;
1426185db85Sdougm 	case SA_NO_SUCH_GROUP:
14357b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "no such group");
14457b448deSdougm 		break;
1456185db85Sdougm 	case SA_CONFIG_ERR:
14657b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "configuration error");
14757b448deSdougm 		break;
1486185db85Sdougm 	case SA_SYSTEM_ERR:
14957b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "system error");
15057b448deSdougm 		break;
1516185db85Sdougm 	case SA_SYNTAX_ERR:
15257b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "syntax error");
15357b448deSdougm 		break;
1546185db85Sdougm 	case SA_NO_PERMISSION:
15557b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "no permission");
15657b448deSdougm 		break;
1576185db85Sdougm 	case SA_BUSY:
15857b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "busy");
15957b448deSdougm 		break;
1606185db85Sdougm 	case SA_NO_SUCH_PROP:
16157b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "no such property");
16257b448deSdougm 		break;
1636185db85Sdougm 	case SA_INVALID_NAME:
16457b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "invalid name");
16557b448deSdougm 		break;
1666185db85Sdougm 	case SA_INVALID_PROTOCOL:
16757b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "invalid protocol");
16857b448deSdougm 		break;
1696185db85Sdougm 	case SA_NOT_ALLOWED:
17057b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "operation not allowed");
17157b448deSdougm 		break;
1726185db85Sdougm 	case SA_BAD_VALUE:
17357b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "bad property value");
17457b448deSdougm 		break;
1756185db85Sdougm 	case SA_INVALID_SECURITY:
17657b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "invalid security type");
17757b448deSdougm 		break;
1786185db85Sdougm 	case SA_NO_SUCH_SECURITY:
17957b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "security type not found");
18057b448deSdougm 		break;
1816185db85Sdougm 	case SA_VALUE_CONFLICT:
18257b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "property value conflict");
18357b448deSdougm 		break;
1846185db85Sdougm 	case SA_NOT_IMPLEMENTED:
18557b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "not implemented");
18657b448deSdougm 		break;
1876185db85Sdougm 	case SA_INVALID_PATH:
18857b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "invalid path");
18957b448deSdougm 		break;
1906185db85Sdougm 	case SA_NOT_SUPPORTED:
19157b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "operation not supported");
19257b448deSdougm 		break;
1936185db85Sdougm 	case SA_PROP_SHARE_ONLY:
19457b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "property not valid for group");
19557b448deSdougm 		break;
1966185db85Sdougm 	case SA_NOT_SHARED:
19757b448deSdougm 		ret = dgettext(TEXT_DOMAIN, "not shared");
19857b448deSdougm 		break;
199da6c28aaSamw 	case SA_NO_SUCH_RESOURCE:
200da6c28aaSamw 		ret = dgettext(TEXT_DOMAIN, "no such resource");
201da6c28aaSamw 		break;
202da6c28aaSamw 	case SA_RESOURCE_REQUIRED:
203da6c28aaSamw 		ret = dgettext(TEXT_DOMAIN, "resource name required");
204da6c28aaSamw 		break;
205da6c28aaSamw 	case SA_MULTIPLE_ERROR:
206da6c28aaSamw 		ret = dgettext(TEXT_DOMAIN, "errors from multiple protocols");
207da6c28aaSamw 		break;
208da6c28aaSamw 	case SA_PATH_IS_SUBDIR:
209da6c28aaSamw 		ret = dgettext(TEXT_DOMAIN, "path is a subpath of share");
210da6c28aaSamw 		break;
211da6c28aaSamw 	case SA_PATH_IS_PARENTDIR:
212da6c28aaSamw 		ret = dgettext(TEXT_DOMAIN, "path is parent of a share");
213da6c28aaSamw 		break;
2146185db85Sdougm 	default:
21557b448deSdougm 		(void) snprintf(errstr, sizeof (errstr),
21657b448deSdougm 		    dgettext(TEXT_DOMAIN, "unknown %d"), err);
21757b448deSdougm 		ret = errstr;
2186185db85Sdougm 	}
2196185db85Sdougm 	return (ret);
2206185db85Sdougm }
2216185db85Sdougm 
222549ec3ffSdougm /*
223549ec3ffSdougm  * Document root to active handle mapping functions.  These are only
224549ec3ffSdougm  * used internally. A mutex is used to prevent access while the list
225549ec3ffSdougm  * is changing. In general, the list will be relatively short - one
226549ec3ffSdougm  * item per thread that has called sa_init().
227549ec3ffSdougm  */
228549ec3ffSdougm 
229549ec3ffSdougm sa_handle_impl_t
230549ec3ffSdougm get_handle_for_root(xmlNodePtr root)
231549ec3ffSdougm {
232549ec3ffSdougm 	struct doc2handle *item;
233549ec3ffSdougm 
234549ec3ffSdougm 	(void) mutex_lock(&sa_global_lock);
235549ec3ffSdougm 	for (item = sa_global_handles; item != NULL; item = item->next) {
23657b448deSdougm 		if (item->root == root)
23757b448deSdougm 			break;
238549ec3ffSdougm 	}
239549ec3ffSdougm 	(void) mutex_unlock(&sa_global_lock);
240549ec3ffSdougm 	if (item != NULL)
24157b448deSdougm 		return (item->handle);
242549ec3ffSdougm 	return (NULL);
243549ec3ffSdougm }
244549ec3ffSdougm 
245549ec3ffSdougm static int
246549ec3ffSdougm add_handle_for_root(xmlNodePtr root, sa_handle_impl_t handle)
247549ec3ffSdougm {
248549ec3ffSdougm 	struct doc2handle *item;
249549ec3ffSdougm 	int ret = SA_NO_MEMORY;
250549ec3ffSdougm 
251549ec3ffSdougm 	item = (struct doc2handle *)calloc(sizeof (struct doc2handle), 1);
252549ec3ffSdougm 	if (item != NULL) {
25357b448deSdougm 		item->root = root;
25457b448deSdougm 		item->handle = handle;
25557b448deSdougm 		(void) mutex_lock(&sa_global_lock);
25657b448deSdougm 		item->next = sa_global_handles;
25757b448deSdougm 		sa_global_handles = item;
25857b448deSdougm 		(void) mutex_unlock(&sa_global_lock);
25957b448deSdougm 		ret = SA_OK;
260549ec3ffSdougm 	}
261549ec3ffSdougm 	return (ret);
262549ec3ffSdougm }
263549ec3ffSdougm 
264549ec3ffSdougm /*
265549ec3ffSdougm  * remove_handle_for_root(root)
266549ec3ffSdougm  *
267549ec3ffSdougm  * Walks the list of handles and removes the one for this "root" from
268549ec3ffSdougm  * the list. It is up to the caller to free the data.
269549ec3ffSdougm  */
270549ec3ffSdougm 
271549ec3ffSdougm static void
272549ec3ffSdougm remove_handle_for_root(xmlNodePtr root)
273549ec3ffSdougm {
274549ec3ffSdougm 	struct doc2handle *item, *prev;
275549ec3ffSdougm 
276549ec3ffSdougm 	(void) mutex_lock(&sa_global_lock);
277549ec3ffSdougm 	for (prev = NULL, item = sa_global_handles; item != NULL;
27857b448deSdougm 	    item = item->next) {
27957b448deSdougm 		if (item->root == root) {
28057b448deSdougm 			/* first in the list */
28157b448deSdougm 			if (prev == NULL)
28257b448deSdougm 				sa_global_handles = sa_global_handles->next;
28357b448deSdougm 			else
28457b448deSdougm 				prev->next = item->next;
28557b448deSdougm 			/* Item is out of the list so free the list structure */
28657b448deSdougm 			free(item);
28757b448deSdougm 			break;
288549ec3ffSdougm 		}
28957b448deSdougm 		prev = item;
290549ec3ffSdougm 	}
291549ec3ffSdougm 	(void) mutex_unlock(&sa_global_lock);
292549ec3ffSdougm }
293549ec3ffSdougm 
294549ec3ffSdougm /*
295549ec3ffSdougm  * sa_find_group_handle(sa_group_t group)
296549ec3ffSdougm  *
297549ec3ffSdougm  * Find the sa_handle_t for the configuration associated with this
298549ec3ffSdougm  * group.
299549ec3ffSdougm  */
300549ec3ffSdougm sa_handle_t
301549ec3ffSdougm sa_find_group_handle(sa_group_t group)
302549ec3ffSdougm {
303549ec3ffSdougm 	xmlNodePtr node = (xmlNodePtr)group;
304549ec3ffSdougm 	sa_handle_t handle;
305549ec3ffSdougm 
306549ec3ffSdougm 	while (node != NULL) {
30757b448deSdougm 		if (strcmp((char *)(node->name), "sharecfg") == 0) {
30857b448deSdougm 			/* have the root so get the handle */
30957b448deSdougm 			handle = (sa_handle_t)get_handle_for_root(node);
31057b448deSdougm 			return (handle);
31157b448deSdougm 		}
31257b448deSdougm 		node = node->parent;
313549ec3ffSdougm 	}
314549ec3ffSdougm 	return (NULL);
315549ec3ffSdougm }
316549ec3ffSdougm 
3176185db85Sdougm /*
3186185db85Sdougm  * set_legacy_timestamp(root, path, timevalue)
3196185db85Sdougm  *
3206185db85Sdougm  * add the current timestamp value to the configuration for use in
3216185db85Sdougm  * determining when to update the legacy files.  For SMF, this
3226185db85Sdougm  * property is kept in default/operation/legacy_timestamp
3236185db85Sdougm  */
3246185db85Sdougm 
3256185db85Sdougm static void
3266185db85Sdougm set_legacy_timestamp(xmlNodePtr root, char *path, uint64_t tval)
3276185db85Sdougm {
3286185db85Sdougm 	xmlNodePtr node;
3296185db85Sdougm 	xmlChar *lpath = NULL;
330549ec3ffSdougm 	sa_handle_impl_t handle;
331549ec3ffSdougm 
332549ec3ffSdougm 	/* Have to have a handle or else we weren't initialized. */
333549ec3ffSdougm 	handle = get_handle_for_root(root);
334549ec3ffSdougm 	if (handle == NULL)
33557b448deSdougm 		return;
3366185db85Sdougm 
3376185db85Sdougm 	for (node = root->xmlChildrenNode; node != NULL;
33857b448deSdougm 	    node = node->next) {
33957b448deSdougm 		if (xmlStrcmp(node->name, (xmlChar *)"legacy") == 0) {
34057b448deSdougm 			/* a possible legacy node for this path */
34157b448deSdougm 			lpath = xmlGetProp(node, (xmlChar *)"path");
34257b448deSdougm 			if (lpath != NULL &&
34357b448deSdougm 			    xmlStrcmp(lpath, (xmlChar *)path) == 0) {
34457b448deSdougm 				xmlFree(lpath);
34557b448deSdougm 				break;
34657b448deSdougm 			}
34757b448deSdougm 			if (lpath != NULL)
34857b448deSdougm 				xmlFree(lpath);
3496185db85Sdougm 		}
3506185db85Sdougm 	}
3516185db85Sdougm 	if (node == NULL) {
35257b448deSdougm 		/* need to create the first legacy timestamp node */
35357b448deSdougm 		node = xmlNewChild(root, NULL, (xmlChar *)"legacy", NULL);
3546185db85Sdougm 	}
3556185db85Sdougm 	if (node != NULL) {
35657b448deSdougm 		char tstring[32];
35757b448deSdougm 		int ret;
35857b448deSdougm 
35957b448deSdougm 		(void) snprintf(tstring, sizeof (tstring), "%lld", tval);
36057b448deSdougm 		xmlSetProp(node, (xmlChar *)"timestamp", (xmlChar *)tstring);
36157b448deSdougm 		xmlSetProp(node, (xmlChar *)"path", (xmlChar *)path);
36257b448deSdougm 		/* now commit to SMF */
36357b448deSdougm 		ret = sa_get_instance(handle->scfhandle, "default");
3646185db85Sdougm 		if (ret == SA_OK) {
36557b448deSdougm 			ret = sa_start_transaction(handle->scfhandle,
36657b448deSdougm 			    "operation");
36757b448deSdougm 			if (ret == SA_OK) {
36857b448deSdougm 				ret = sa_set_property(handle->scfhandle,
36957b448deSdougm 				    "legacy-timestamp", tstring);
37057b448deSdougm 				if (ret == SA_OK) {
37157b448deSdougm 					(void) sa_end_transaction(
372*5b6e0c46Sdougm 					    handle->scfhandle, handle);
37357b448deSdougm 				} else {
37457b448deSdougm 					sa_abort_transaction(handle->scfhandle);
37557b448deSdougm 				}
37657b448deSdougm 			}
3776185db85Sdougm 		}
3786185db85Sdougm 	}
3796185db85Sdougm }
3806185db85Sdougm 
3816185db85Sdougm /*
3826185db85Sdougm  * is_shared(share)
3836185db85Sdougm  *
3846185db85Sdougm  * determine if the specified share is currently shared or not.
3856185db85Sdougm  */
3866185db85Sdougm static int
3876185db85Sdougm is_shared(sa_share_t share)
3886185db85Sdougm {
3896185db85Sdougm 	char *shared;
3906185db85Sdougm 	int result = 0; /* assume not */
3916185db85Sdougm 
3926185db85Sdougm 	shared = sa_get_share_attr(share, "shared");
3936185db85Sdougm 	if (shared != NULL) {
39457b448deSdougm 		if (strcmp(shared, "true") == 0)
39557b448deSdougm 			result = 1;
39657b448deSdougm 		sa_free_attr_string(shared);
3976185db85Sdougm 	}
3986185db85Sdougm 	return (result);
3996185db85Sdougm }
4006185db85Sdougm 
401da6c28aaSamw /*
402da6c28aaSamw  * excluded_protocol(share, proto)
403da6c28aaSamw  *
404da6c28aaSamw  * Returns B_TRUE if the specified protocol appears in the "exclude"
405da6c28aaSamw  * property. This is used to prevent sharing special case shares
406da6c28aaSamw  * (e.g. subdirs when SMB wants a subdir and NFS doesn't. B_FALSE is
407da6c28aaSamw  * returned if the protocol isn't in the list.
408da6c28aaSamw  */
409da6c28aaSamw static boolean_t
410da6c28aaSamw excluded_protocol(sa_share_t share, char *proto)
411da6c28aaSamw {
412da6c28aaSamw 	char *protolist;
413da6c28aaSamw 	char *str;
414da6c28aaSamw 	char *token;
415da6c28aaSamw 
416da6c28aaSamw 	protolist = sa_get_share_attr(share, "exclude");
417da6c28aaSamw 	if (protolist != NULL) {
418da6c28aaSamw 		str = protolist;
419da6c28aaSamw 		while ((token = strtok(str, ",")) != NULL) {
420da6c28aaSamw 			if (strcmp(token, proto) == 0) {
421da6c28aaSamw 				sa_free_attr_string(protolist);
422da6c28aaSamw 				return (B_TRUE);
423da6c28aaSamw 			}
424da6c28aaSamw 			str = NULL;
425da6c28aaSamw 		}
426da6c28aaSamw 		sa_free_attr_string(protolist);
427da6c28aaSamw 	}
428da6c28aaSamw 	return (B_FALSE);
429da6c28aaSamw }
430da6c28aaSamw 
4316185db85Sdougm /*
432a99982a7Sdougm  * checksubdirgroup(group, newpath, strictness)
433f345c0beSdougm  *
434a99982a7Sdougm  * check all the specified newpath against all the paths in the
435a99982a7Sdougm  * group. This is a helper function for checksubdir to make it easier
436a99982a7Sdougm  * to also check ZFS subgroups.
437a99982a7Sdougm  * The strictness values mean:
438f345c0beSdougm  * SA_CHECK_NORMAL == only check newpath against shares that are active
439f345c0beSdougm  * SA_CHECK_STRICT == check newpath against both active shares and those
440f345c0beSdougm  *		      stored in the repository
4416185db85Sdougm  */
4426185db85Sdougm static int
443a99982a7Sdougm checksubdirgroup(sa_group_t group, char *newpath, int strictness)
4446185db85Sdougm {
4456185db85Sdougm 	sa_share_t share;
446a99982a7Sdougm 	char *path;
447a99982a7Sdougm 	int issub = SA_OK;
448da6c28aaSamw 	int subdir;
449da6c28aaSamw 	int parent;
450da6c28aaSamw 
451da6c28aaSamw 	if (newpath == NULL)
452da6c28aaSamw 		return (SA_INVALID_PATH);
4536185db85Sdougm 
454a99982a7Sdougm 	for (share = sa_get_share(group, NULL); share != NULL;
455a99982a7Sdougm 	    share = sa_get_next_share(share)) {
4566185db85Sdougm 		/*
4576185db85Sdougm 		 * The original behavior of share never checked
4586185db85Sdougm 		 * against the permanent configuration
4596185db85Sdougm 		 * (/etc/dfs/dfstab).  PIT has a number of cases where
4606185db85Sdougm 		 * it depends on this older behavior even though it
4616185db85Sdougm 		 * could be considered incorrect.  We may tighten this
4626185db85Sdougm 		 * up in the future.
4636185db85Sdougm 		 */
46457b448deSdougm 		if (strictness == SA_CHECK_NORMAL && !is_shared(share))
46557b448deSdougm 			continue;
4666185db85Sdougm 
46757b448deSdougm 		path = sa_get_share_attr(share, "path");
468f345c0beSdougm 		/*
469f345c0beSdougm 		 * If path is NULL, then a share is in the process of
470f345c0beSdougm 		 * construction or someone has modified the property
471a99982a7Sdougm 		 * group inappropriately. It should be
472a99982a7Sdougm 		 * ignored. issubdir() comes from the original share
473a99982a7Sdougm 		 * implementation and does the difficult part of
474a99982a7Sdougm 		 * checking subdirectories.
475f345c0beSdougm 		 */
47657b448deSdougm 		if (path == NULL)
47757b448deSdougm 			continue;
478da6c28aaSamw 
479da6c28aaSamw 		if (strcmp(path, newpath) == 0) {
48057b448deSdougm 			issub = SA_INVALID_PATH;
481da6c28aaSamw 		} else {
482da6c28aaSamw 			subdir = issubdir(newpath, path);
483da6c28aaSamw 			parent = issubdir(path, newpath);
484da6c28aaSamw 			if (subdir || parent) {
485da6c28aaSamw 				sa_free_attr_string(path);
486da6c28aaSamw 				path = NULL;
487da6c28aaSamw 				return (subdir ?
488da6c28aaSamw 				    SA_PATH_IS_SUBDIR : SA_PATH_IS_PARENTDIR);
489da6c28aaSamw 			}
49057b448deSdougm 		}
4916185db85Sdougm 		sa_free_attr_string(path);
4926185db85Sdougm 		path = NULL;
493a99982a7Sdougm 	}
494a99982a7Sdougm 	return (issub);
495a99982a7Sdougm }
496a99982a7Sdougm 
497a99982a7Sdougm /*
498a99982a7Sdougm  * checksubdir(newpath, strictness)
499a99982a7Sdougm  *
500a99982a7Sdougm  * checksubdir determines if the specified path (newpath) is a
501a99982a7Sdougm  * subdirectory of another share. It calls checksubdirgroup() to do
502a99982a7Sdougm  * the complicated work. The strictness parameter determines how
503a99982a7Sdougm  * strict a check to make against the path. The strictness values
504a99982a7Sdougm  * mean: SA_CHECK_NORMAL == only check newpath against shares that are
505a99982a7Sdougm  * active SA_CHECK_STRICT == check newpath against both active shares
506a99982a7Sdougm  * and those * stored in the repository
507a99982a7Sdougm  */
508a99982a7Sdougm static int
509549ec3ffSdougm checksubdir(sa_handle_t handle, char *newpath, int strictness)
510a99982a7Sdougm {
511a99982a7Sdougm 	sa_group_t group;
512da6c28aaSamw 	int issub = SA_OK;
513a99982a7Sdougm 	char *path = NULL;
514a99982a7Sdougm 
515da6c28aaSamw 	for (group = sa_get_group(handle, NULL);
516da6c28aaSamw 	    group != NULL && issub == SA_OK;
517da6c28aaSamw 	    group = sa_get_next_group(group)) {
51857b448deSdougm 		if (sa_group_is_zfs(group)) {
51957b448deSdougm 			sa_group_t subgroup;
52057b448deSdougm 			for (subgroup = sa_get_sub_group(group);
521da6c28aaSamw 			    subgroup != NULL && issub == SA_OK;
52257b448deSdougm 			    subgroup = sa_get_next_group(subgroup))
52357b448deSdougm 				issub = checksubdirgroup(subgroup, newpath,
52457b448deSdougm 				    strictness);
52557b448deSdougm 		} else {
52657b448deSdougm 			issub = checksubdirgroup(group, newpath, strictness);
52757b448deSdougm 		}
5286185db85Sdougm 	}
5296185db85Sdougm 	if (path != NULL)
53057b448deSdougm 		sa_free_attr_string(path);
5316185db85Sdougm 	return (issub);
5326185db85Sdougm }
5336185db85Sdougm 
5346185db85Sdougm /*
535f345c0beSdougm  * validpath(path, strictness)
5366185db85Sdougm  * determine if the provided path is valid for a share. It shouldn't
5376185db85Sdougm  * be a sub-dir of an already shared path or the parent directory of a
5386185db85Sdougm  * share path.
5396185db85Sdougm  */
5406185db85Sdougm static int
541549ec3ffSdougm validpath(sa_handle_t handle, char *path, int strictness)
5426185db85Sdougm {
5436185db85Sdougm 	int error = SA_OK;
5446185db85Sdougm 	struct stat st;
5456185db85Sdougm 	sa_share_t share;
5466185db85Sdougm 	char *fstype;
5476185db85Sdougm 
54857b448deSdougm 	if (*path != '/')
54957b448deSdougm 		return (SA_BAD_PATH);
55057b448deSdougm 
5516185db85Sdougm 	if (stat(path, &st) < 0) {
55257b448deSdougm 		error = SA_NO_SUCH_PATH;
5536185db85Sdougm 	} else {
55457b448deSdougm 		share = sa_find_share(handle, path);
55557b448deSdougm 		if (share != NULL)
55657b448deSdougm 			error = SA_DUPLICATE_NAME;
55757b448deSdougm 
55857b448deSdougm 		if (error == SA_OK) {
55957b448deSdougm 			/*
56057b448deSdougm 			 * check for special case with file system
56157b448deSdougm 			 * that might have restrictions.  For now, ZFS
56257b448deSdougm 			 * is the only case since it has its own idea
56357b448deSdougm 			 * of how to configure shares. We do this
56457b448deSdougm 			 * before subdir checking since things like
56557b448deSdougm 			 * ZFS will do that for us. This should also
56657b448deSdougm 			 * be done via plugin interface.
56757b448deSdougm 			 */
56857b448deSdougm 			fstype = sa_fstype(path);
56957b448deSdougm 			if (fstype != NULL && strcmp(fstype, "zfs") == 0) {
57057b448deSdougm 				if (sa_zfs_is_shared(handle, path))
57157b448deSdougm 					error = SA_INVALID_NAME;
57257b448deSdougm 			}
57357b448deSdougm 			if (fstype != NULL)
57457b448deSdougm 				sa_free_fstype(fstype);
5756185db85Sdougm 		}
57657b448deSdougm 		if (error == SA_OK)
57757b448deSdougm 			error = checksubdir(handle, path, strictness);
5786185db85Sdougm 	}
5796185db85Sdougm 	return (error);
5806185db85Sdougm }
5816185db85Sdougm 
5826185db85Sdougm /*
5836185db85Sdougm  * check to see if group/share is persistent.
584da6c28aaSamw  *
585da6c28aaSamw  * "group" can be either an sa_group_t or an sa_share_t. (void *)
586da6c28aaSamw  * works since both thse types are also void *.
5876185db85Sdougm  */
588da6c28aaSamw int
589da6c28aaSamw sa_is_persistent(void *group)
5906185db85Sdougm {
5916185db85Sdougm 	char *type;
5926185db85Sdougm 	int persist = 1;
5936185db85Sdougm 
594da6c28aaSamw 	type = sa_get_group_attr((sa_group_t)group, "type");
5956185db85Sdougm 	if (type != NULL && strcmp(type, "transient") == 0)
59657b448deSdougm 		persist = 0;
5976185db85Sdougm 	if (type != NULL)
59857b448deSdougm 		sa_free_attr_string(type);
5996185db85Sdougm 	return (persist);
6006185db85Sdougm }
6016185db85Sdougm 
6026185db85Sdougm /*
6036185db85Sdougm  * sa_valid_group_name(name)
6046185db85Sdougm  *
6056185db85Sdougm  * check that the "name" contains only valid characters and otherwise
6066185db85Sdougm  * fits the required naming conventions. Valid names must start with
6076185db85Sdougm  * an alphabetic and the remainder may consist of only alphanumeric
6086185db85Sdougm  * plus the '-' and '_' characters. This name limitation comes from
6096185db85Sdougm  * inherent limitations in SMF.
6106185db85Sdougm  */
6116185db85Sdougm 
6126185db85Sdougm int
6136185db85Sdougm sa_valid_group_name(char *name)
6146185db85Sdougm {
6156185db85Sdougm 	int ret = 1;
6166185db85Sdougm 	ssize_t len;
6176185db85Sdougm 
6186185db85Sdougm 	if (name != NULL && isalpha(*name)) {
61957b448deSdougm 		char c;
62057b448deSdougm 		len = strlen(name);
62157b448deSdougm 		if (len < (scf_max_name_len - sizeof ("group:"))) {
62257b448deSdougm 			for (c = *name++; c != '\0' && ret != 0; c = *name++) {
62357b448deSdougm 				if (!isalnum(c) && c != '-' && c != '_')
62457b448deSdougm 					ret = 0;
62557b448deSdougm 			}
62657b448deSdougm 		} else {
6276185db85Sdougm 			ret = 0;
6286185db85Sdougm 		}
6296185db85Sdougm 	} else {
63057b448deSdougm 		ret = 0;
6316185db85Sdougm 	}
6326185db85Sdougm 	return (ret);
6336185db85Sdougm }
6346185db85Sdougm 
6356185db85Sdougm 
6366185db85Sdougm /*
6376185db85Sdougm  * is_zfs_group(group)
6386185db85Sdougm  *	Determine if the specified group is a ZFS sharenfs group
6396185db85Sdougm  */
6406185db85Sdougm static int
6416185db85Sdougm is_zfs_group(sa_group_t group)
6426185db85Sdougm {
6436185db85Sdougm 	int ret = 0;
6446185db85Sdougm 	xmlNodePtr parent;
6456185db85Sdougm 	xmlChar *zfs;
6466185db85Sdougm 
64757b448deSdougm 	if (strcmp((char *)((xmlNodePtr)group)->name, "share") == 0)
64857b448deSdougm 		parent = (xmlNodePtr)sa_get_parent_group(group);
64957b448deSdougm 	else
65057b448deSdougm 		parent = (xmlNodePtr)group;
6516185db85Sdougm 	zfs = xmlGetProp(parent, (xmlChar *)"zfs");
6526185db85Sdougm 	if (zfs != NULL) {
65357b448deSdougm 		xmlFree(zfs);
65457b448deSdougm 		ret = 1;
6556185db85Sdougm 	}
6566185db85Sdougm 	return (ret);
6576185db85Sdougm }
6586185db85Sdougm 
659da6c28aaSamw /*
660da6c28aaSamw  * sa_get_object_type(object)
661da6c28aaSamw  *
662da6c28aaSamw  * This function returns a numeric value representing the object
663da6c28aaSamw  * type. This allows using simpler checks when doing type specific
664da6c28aaSamw  * operations.
665da6c28aaSamw  */
666da6c28aaSamw 
667da6c28aaSamw static int
668da6c28aaSamw sa_get_object_type(void *object)
669da6c28aaSamw {
670da6c28aaSamw 	xmlNodePtr node = (xmlNodePtr)object;
671da6c28aaSamw 	int type;
672da6c28aaSamw 
673da6c28aaSamw 	if (xmlStrcmp(node->name, (xmlChar *)"group") == 0)
674da6c28aaSamw 		type = SA_TYPE_GROUP;
675da6c28aaSamw 	else if (xmlStrcmp(node->name, (xmlChar *)"share") == 0)
676da6c28aaSamw 		type = SA_TYPE_SHARE;
677da6c28aaSamw 	else if (xmlStrcmp(node->name, (xmlChar *)"resource") == 0)
678da6c28aaSamw 		type = SA_TYPE_RESOURCE;
679da6c28aaSamw 	else if (xmlStrcmp(node->name, (xmlChar *)"optionset") == 0)
680da6c28aaSamw 		type = SA_TYPE_OPTIONSET;
681da6c28aaSamw 	else if (xmlStrcmp(node->name, (xmlChar *)"security") == 0)
682da6c28aaSamw 		type = SA_TYPE_ALTSPACE;
683da6c28aaSamw 	else
684da6c28aaSamw 		assert(0);
685da6c28aaSamw 	return (type);
686da6c28aaSamw }
687da6c28aaSamw 
6886185db85Sdougm /*
6896185db85Sdougm  * sa_optionset_name(optionset, oname, len, id)
6906185db85Sdougm  *	return the SMF name for the optionset. If id is not NULL, it
6916185db85Sdougm  *	will have the GUID value for a share and should be used
6926185db85Sdougm  *	instead of the keyword "optionset" which is used for
6936185db85Sdougm  *	groups. If the optionset doesn't have a protocol type
6946185db85Sdougm  *	associated with it, "default" is used. This shouldn't happen
6956185db85Sdougm  *	at this point but may be desirable in the future if there are
6966185db85Sdougm  *	protocol independent properties added. The name is returned in
6976185db85Sdougm  *	oname.
6986185db85Sdougm  */
6996185db85Sdougm 
7006185db85Sdougm static int
7016185db85Sdougm sa_optionset_name(sa_optionset_t optionset, char *oname, size_t len, char *id)
7026185db85Sdougm {
7036185db85Sdougm 	char *proto;
704da6c28aaSamw 	void *parent;
705da6c28aaSamw 	int ptype;
7066185db85Sdougm 
7076185db85Sdougm 	if (id == NULL)
70857b448deSdougm 		id = "optionset";
7096185db85Sdougm 
710da6c28aaSamw 	parent = sa_get_optionset_parent(optionset);
711da6c28aaSamw 	if (parent != NULL) {
712da6c28aaSamw 		ptype = sa_get_object_type(parent);
713da6c28aaSamw 		proto = sa_get_optionset_attr(optionset, "type");
714da6c28aaSamw 		if (ptype != SA_TYPE_RESOURCE) {
715da6c28aaSamw 			len = snprintf(oname, len, "%s_%s", id,
716da6c28aaSamw 			    proto ? proto : "default");
717da6c28aaSamw 		} else {
718da6c28aaSamw 			char *index;
719da6c28aaSamw 			index = get_node_attr((void *)parent, "id");
720da6c28aaSamw 			if (index != NULL)
721da6c28aaSamw 				len = snprintf(oname, len, "%s_%s_%s", id,
722da6c28aaSamw 				    proto ? proto : "default", index);
723da6c28aaSamw 			else
724da6c28aaSamw 				len = 0;
725da6c28aaSamw 		}
7266185db85Sdougm 
727da6c28aaSamw 		if (proto != NULL)
728da6c28aaSamw 			sa_free_attr_string(proto);
729da6c28aaSamw 	} else {
730da6c28aaSamw 		len = 0;
731da6c28aaSamw 	}
7326185db85Sdougm 	return (len);
7336185db85Sdougm }
7346185db85Sdougm 
7356185db85Sdougm /*
7366185db85Sdougm  * sa_security_name(optionset, oname, len, id)
7376185db85Sdougm  *
7386185db85Sdougm  * return the SMF name for the security. If id is not NULL, it will
7396185db85Sdougm  * have the GUID value for a share and should be used instead of the
7406185db85Sdougm  * keyword "optionset" which is used for groups. If the optionset
7416185db85Sdougm  * doesn't have a protocol type associated with it, "default" is
7426185db85Sdougm  * used. This shouldn't happen at this point but may be desirable in
7436185db85Sdougm  * the future if there are protocol independent properties added. The
7446185db85Sdougm  * name is returned in oname. The security type is also encoded into
7456185db85Sdougm  * the name. In the future, this wil *be handled a bit differently.
7466185db85Sdougm  */
7476185db85Sdougm 
7486185db85Sdougm static int
7496185db85Sdougm sa_security_name(sa_security_t security, char *oname, size_t len, char *id)
7506185db85Sdougm {
7516185db85Sdougm 	char *proto;
7526185db85Sdougm 	char *sectype;
7536185db85Sdougm 
7546185db85Sdougm 	if (id == NULL)
75557b448deSdougm 		id = "optionset";
7566185db85Sdougm 
7576185db85Sdougm 	proto = sa_get_security_attr(security, "type");
7586185db85Sdougm 	sectype = sa_get_security_attr(security, "sectype");
75957b448deSdougm 	len = snprintf(oname, len, "%s_%s_%s", id, proto ? proto : "default",
76057b448deSdougm 	    sectype ? sectype : "default");
7616185db85Sdougm 	if (proto != NULL)
76257b448deSdougm 		sa_free_attr_string(proto);
7636185db85Sdougm 	if (sectype != NULL)
76457b448deSdougm 		sa_free_attr_string(sectype);
7656185db85Sdougm 	return (len);
7666185db85Sdougm }
7676185db85Sdougm 
76857b448deSdougm /*
76957b448deSdougm  * verifydefgroupopts(handle)
77057b448deSdougm  *
77157b448deSdougm  * Make sure a "default" group exists and has default protocols enabled.
77257b448deSdougm  */
77357b448deSdougm static void
77457b448deSdougm verifydefgroupopts(sa_handle_t handle)
77557b448deSdougm {
77657b448deSdougm 	sa_group_t defgrp;
77757b448deSdougm 	sa_optionset_t opt;
778da6c28aaSamw 
77957b448deSdougm 	defgrp = sa_get_group(handle, "default");
78057b448deSdougm 	if (defgrp != NULL) {
78157b448deSdougm 		opt = sa_get_optionset(defgrp, NULL);
78257b448deSdougm 		/*
78357b448deSdougm 		 * NFS is the default for default group
78457b448deSdougm 		 */
78557b448deSdougm 		if (opt == NULL)
78657b448deSdougm 			opt = sa_create_optionset(defgrp, "nfs");
78757b448deSdougm 	}
78857b448deSdougm }
78957b448deSdougm 
7906185db85Sdougm /*
791f345c0beSdougm  * sa_init(init_service)
7926185db85Sdougm  *	Initialize the API
7936185db85Sdougm  *	find all the shared objects
7946185db85Sdougm  *	init the tables with all objects
7956185db85Sdougm  *	read in the current configuration
7966185db85Sdougm  */
7976185db85Sdougm 
79857b448deSdougm #define	GETPROP(prop)	scf_simple_prop_next_astring(prop)
79957b448deSdougm #define	CHECKTSTAMP(st, tval)	stat(SA_LEGACY_DFSTAB, &st) >= 0 && \
80057b448deSdougm 	tval != TSTAMP(st.st_ctim)
80157b448deSdougm 
802549ec3ffSdougm sa_handle_t
8036185db85Sdougm sa_init(int init_service)
8046185db85Sdougm {
8056185db85Sdougm 	struct stat st;
8066185db85Sdougm 	int legacy = 0;
8076185db85Sdougm 	uint64_t tval = 0;
808a99982a7Sdougm 	int lockfd;
809a99982a7Sdougm 	sigset_t old;
810a99982a7Sdougm 	int updatelegacy = B_FALSE;
811a99982a7Sdougm 	scf_simple_prop_t *prop;
812549ec3ffSdougm 	sa_handle_impl_t handle;
813549ec3ffSdougm 	int err;
814549ec3ffSdougm 
815549ec3ffSdougm 	handle = calloc(sizeof (struct sa_handle_impl), 1);
8166185db85Sdougm 
817549ec3ffSdougm 	if (handle != NULL) {
81857b448deSdougm 		/* get protocol specific structures */
81957b448deSdougm 		(void) proto_plugin_init();
82057b448deSdougm 		if (init_service & SA_INIT_SHARE_API) {
821a99982a7Sdougm 			/*
82257b448deSdougm 			 * initialize access into libzfs. We use this
82357b448deSdougm 			 * when collecting info about ZFS datasets and
82457b448deSdougm 			 * shares.
825a99982a7Sdougm 			 */
82657b448deSdougm 			if (sa_zfs_init(handle) == B_FALSE) {
82757b448deSdougm 				free(handle);
82857b448deSdougm 				(void) proto_plugin_fini();
82957b448deSdougm 				return (NULL);
83057b448deSdougm 			}
831a99982a7Sdougm 			/*
83257b448deSdougm 			 * since we want to use SMF, initialize an svc handle
83357b448deSdougm 			 * and find out what is there.
834a99982a7Sdougm 			 */
83557b448deSdougm 			handle->scfhandle = sa_scf_init(handle);
83657b448deSdougm 			if (handle->scfhandle != NULL) {
83757b448deSdougm 				/*
83857b448deSdougm 				 * Need to lock the extraction of the
83957b448deSdougm 				 * configuration if the dfstab file has
84057b448deSdougm 				 * changed. Lock everything now and release if
84157b448deSdougm 				 * not needed.  Use a file that isn't being
84257b448deSdougm 				 * manipulated by other parts of the system in
84357b448deSdougm 				 * order to not interfere with locking. Using
84457b448deSdougm 				 * dfstab doesn't work.
84557b448deSdougm 				 */
84657b448deSdougm 				sablocksigs(&old);
84757b448deSdougm 				lockfd = open(DFS_LOCK_FILE, O_RDWR);
84857b448deSdougm 				if (lockfd >= 0) {
84957b448deSdougm 					extern int errno;
85057b448deSdougm 					errno = 0;
85157b448deSdougm 					(void) lockf(lockfd, F_LOCK, 0);
85257b448deSdougm 					/*
85357b448deSdougm 					 * Check whether we are going to need
85457b448deSdougm 					 * to merge any dfstab changes. This
85557b448deSdougm 					 * is done by comparing the value of
85657b448deSdougm 					 * legacy-timestamp with the current
85757b448deSdougm 					 * st_ctim of the file. If they are
85857b448deSdougm 					 * different, an update is needed and
85957b448deSdougm 					 * the file must remain locked until
86057b448deSdougm 					 * the merge is done in order to
86157b448deSdougm 					 * prevent multiple startups from
86257b448deSdougm 					 * changing the SMF repository at the
86357b448deSdougm 					 * same time.  The first to get the
86457b448deSdougm 					 * lock will make any changes before
86557b448deSdougm 					 * the others can read the repository.
86657b448deSdougm 					 */
86757b448deSdougm 					prop = scf_simple_prop_get
86857b448deSdougm 					    (handle->scfhandle->handle,
86957b448deSdougm 					    (const char *)SA_SVC_FMRI_BASE
87057b448deSdougm 					    ":default", "operation",
87157b448deSdougm 					    "legacy-timestamp");
87257b448deSdougm 					if (prop != NULL) {
87357b448deSdougm 						char *i64;
87457b448deSdougm 						i64 = GETPROP(prop);
87557b448deSdougm 						if (i64 != NULL)
87657b448deSdougm 							tval = strtoull(i64,
87757b448deSdougm 							    NULL, 0);
87857b448deSdougm 						if (CHECKTSTAMP(st, tval))
87957b448deSdougm 							updatelegacy = B_TRUE;
88057b448deSdougm 						scf_simple_prop_free(prop);
88157b448deSdougm 					} else {
88257b448deSdougm 						/*
88357b448deSdougm 						 * We haven't set the
88457b448deSdougm 						 * timestamp before so do it.
88557b448deSdougm 						 */
88657b448deSdougm 						updatelegacy = B_TRUE;
88757b448deSdougm 					}
88857b448deSdougm 				}
88957b448deSdougm 				if (updatelegacy == B_FALSE) {
89057b448deSdougm 					/* Don't need the lock anymore */
89157b448deSdougm 					(void) lockf(lockfd, F_ULOCK, 0);
89257b448deSdougm 					(void) close(lockfd);
89357b448deSdougm 				}
8941d1813a7Sdougm 
89557b448deSdougm 				/*
89657b448deSdougm 				 * It is essential that the document tree and
89757b448deSdougm 				 * the internal list of roots to handles be
89857b448deSdougm 				 * setup before anything that might try to
89957b448deSdougm 				 * create a new object is called. The document
90057b448deSdougm 				 * tree is the combination of handle->doc and
90157b448deSdougm 				 * handle->tree. This allows searches,
90257b448deSdougm 				 * etc. when all you have is an object in the
90357b448deSdougm 				 * tree.
90457b448deSdougm 				 */
90557b448deSdougm 				handle->doc = xmlNewDoc((xmlChar *)"1.0");
90657b448deSdougm 				handle->tree = xmlNewNode(NULL,
90757b448deSdougm 				    (xmlChar *)"sharecfg");
90857b448deSdougm 				if (handle->doc != NULL &&
90957b448deSdougm 				    handle->tree != NULL) {
91057b448deSdougm 					xmlDocSetRootElement(handle->doc,
91157b448deSdougm 					    handle->tree);
91257b448deSdougm 					err = add_handle_for_root(handle->tree,
91357b448deSdougm 					    handle);
91457b448deSdougm 					if (err == SA_OK)
91557b448deSdougm 						err = sa_get_config(
91657b448deSdougm 						    handle->scfhandle,
9171d1813a7Sdougm 						    handle->tree, handle);
91857b448deSdougm 				} else {
91957b448deSdougm 					if (handle->doc != NULL)
92057b448deSdougm 						xmlFreeDoc(handle->doc);
92157b448deSdougm 					if (handle->tree != NULL)
92257b448deSdougm 						xmlFreeNode(handle->tree);
92357b448deSdougm 					err = SA_NO_MEMORY;
92457b448deSdougm 				}
92557b448deSdougm 
92657b448deSdougm 				saunblocksigs(&old);
92757b448deSdougm 
92857b448deSdougm 				if (err != SA_OK) {
92957b448deSdougm 					/*
93057b448deSdougm 					 * If we couldn't add the tree handle
93157b448deSdougm 					 * to the list, then things are going
93257b448deSdougm 					 * to fail badly. Might as well undo
93357b448deSdougm 					 * everything now and fail the
93457b448deSdougm 					 * sa_init().
93557b448deSdougm 					 */
93657b448deSdougm 					sa_fini(handle);
93757b448deSdougm 					return (NULL);
93857b448deSdougm 				}
9391d1813a7Sdougm 
94057b448deSdougm 				if (tval == 0) {
94157b448deSdougm 					/*
94257b448deSdougm 					 * first time so make sure
94357b448deSdougm 					 * default is setup
94457b448deSdougm 					 */
94557b448deSdougm 					verifydefgroupopts(handle);
94657b448deSdougm 				}
947549ec3ffSdougm 
948546405c3Sdougm 				if (updatelegacy == B_TRUE) {
949546405c3Sdougm 					sablocksigs(&old);
950546405c3Sdougm 					getlegacyconfig((sa_handle_t)handle,
951546405c3Sdougm 					    SA_LEGACY_DFSTAB, &handle->tree);
952546405c3Sdougm 					if (stat(SA_LEGACY_DFSTAB, &st) >= 0)
953546405c3Sdougm 						set_legacy_timestamp(
954546405c3Sdougm 						    handle->tree,
955546405c3Sdougm 						    SA_LEGACY_DFSTAB,
956546405c3Sdougm 						    TSTAMP(st.st_ctim));
957546405c3Sdougm 					saunblocksigs(&old);
958546405c3Sdougm 					/*
959546405c3Sdougm 					 * Safe to unlock now to allow
960546405c3Sdougm 					 * others to run
961546405c3Sdougm 					 */
962546405c3Sdougm 					(void) lockf(lockfd, F_ULOCK, 0);
963546405c3Sdougm 					(void) close(lockfd);
964546405c3Sdougm 				}
965*5b6e0c46Sdougm 				/* Get sharetab timestamp */
966*5b6e0c46Sdougm 				sa_update_sharetab_ts((sa_handle_t)handle);
967*5b6e0c46Sdougm 
968*5b6e0c46Sdougm 				/* Get lastupdate (transaction) timestamp */
969*5b6e0c46Sdougm 				prop = scf_simple_prop_get(
970*5b6e0c46Sdougm 				    handle->scfhandle->handle,
971*5b6e0c46Sdougm 				    (const char *)SA_SVC_FMRI_BASE ":default",
972*5b6e0c46Sdougm 				    "state", "lastupdate");
973*5b6e0c46Sdougm 				if (prop != NULL) {
974*5b6e0c46Sdougm 					char *str;
975*5b6e0c46Sdougm 					str =
976*5b6e0c46Sdougm 					    scf_simple_prop_next_astring(prop);
977*5b6e0c46Sdougm 					if (str != NULL)
978*5b6e0c46Sdougm 						handle->tstrans =
979*5b6e0c46Sdougm 						    strtoull(str, NULL, 0);
980*5b6e0c46Sdougm 					else
981*5b6e0c46Sdougm 						handle->tstrans = 0;
982*5b6e0c46Sdougm 					scf_simple_prop_free(prop);
983*5b6e0c46Sdougm 				}
984546405c3Sdougm 				legacy |= sa_get_zfs_shares(handle, "zfs");
985546405c3Sdougm 				legacy |= gettransients(handle, &handle->tree);
9866185db85Sdougm 			}
9876185db85Sdougm 		}
9886185db85Sdougm 	}
989549ec3ffSdougm 	return ((sa_handle_t)handle);
9906185db85Sdougm }
9916185db85Sdougm 
9926185db85Sdougm /*
993549ec3ffSdougm  * sa_fini(handle)
9946185db85Sdougm  *	Uninitialize the API structures including the configuration
9951cea05afSdougm  *	data structures and ZFS related data.
9966185db85Sdougm  */
9976185db85Sdougm 
9986185db85Sdougm void
999549ec3ffSdougm sa_fini(sa_handle_t handle)
10006185db85Sdougm {
1001549ec3ffSdougm 	sa_handle_impl_t impl_handle = (sa_handle_impl_t)handle;
1002549ec3ffSdougm 
1003549ec3ffSdougm 	if (impl_handle != NULL) {
1004549ec3ffSdougm 		/*
1005549ec3ffSdougm 		 * Free the config trees and any other data structures
1006549ec3ffSdougm 		 * used in the handle.
1007549ec3ffSdougm 		 */
1008549ec3ffSdougm 		if (impl_handle->doc != NULL)
1009549ec3ffSdougm 			xmlFreeDoc(impl_handle->doc);
1010549ec3ffSdougm 		sa_scf_fini(impl_handle->scfhandle);
1011549ec3ffSdougm 		sa_zfs_fini(impl_handle);
1012549ec3ffSdougm 
1013549ec3ffSdougm 		/* Remove and free the entry in the global list. */
1014549ec3ffSdougm 		remove_handle_for_root(impl_handle->tree);
1015549ec3ffSdougm 
1016549ec3ffSdougm 		/* Make sure we free the handle */
1017549ec3ffSdougm 		free(impl_handle);
1018549ec3ffSdougm 
1019549ec3ffSdougm 		/*
1020549ec3ffSdougm 		 * If this was the last handle to release, unload the
1021549ec3ffSdougm 		 * plugins that were loaded.
1022549ec3ffSdougm 		 */
1023549ec3ffSdougm 		if (sa_global_handles == NULL)
102457b448deSdougm 			(void) proto_plugin_fini();
1025549ec3ffSdougm 
10266185db85Sdougm 	}
10276185db85Sdougm }
10286185db85Sdougm 
10296185db85Sdougm /*
10306185db85Sdougm  * sa_get_protocols(char **protocol)
10316185db85Sdougm  *	Get array of protocols that are supported
10326185db85Sdougm  *	Returns pointer to an allocated and NULL terminated
10336185db85Sdougm  *	array of strings.  Caller must free.
10346185db85Sdougm  *	This really should be determined dynamically.
10356185db85Sdougm  *	If there aren't any defined, return -1.
10366185db85Sdougm  *	Use free() to return memory.
10376185db85Sdougm  */
10386185db85Sdougm 
10396185db85Sdougm int
10406185db85Sdougm sa_get_protocols(char ***protocols)
10416185db85Sdougm {
10426185db85Sdougm 	int numproto = -1;
10436185db85Sdougm 
10446185db85Sdougm 	if (protocols != NULL) {
104557b448deSdougm 		struct sa_proto_plugin *plug;
104657b448deSdougm 		for (numproto = 0, plug = sap_proto_list; plug != NULL;
10476185db85Sdougm 		    plug = plug->plugin_next) {
104857b448deSdougm 			numproto++;
104957b448deSdougm 		}
105057b448deSdougm 
105157b448deSdougm 		*protocols = calloc(numproto + 1,  sizeof (char *));
105257b448deSdougm 		if (*protocols != NULL) {
105357b448deSdougm 			int ret = 0;
105457b448deSdougm 			for (plug = sap_proto_list; plug != NULL;
105557b448deSdougm 			    plug = plug->plugin_next) {
105657b448deSdougm 				/* faking for now */
105757b448deSdougm 				(*protocols)[ret++] =
105857b448deSdougm 				    plug->plugin_ops->sa_protocol;
105957b448deSdougm 			}
106057b448deSdougm 		} else {
106157b448deSdougm 			numproto = -1;
10626185db85Sdougm 		}
10636185db85Sdougm 	}
10646185db85Sdougm 	return (numproto);
10656185db85Sdougm }
10666185db85Sdougm 
10676185db85Sdougm /*
10686185db85Sdougm  * find_group_by_name(node, group)
10696185db85Sdougm  *
10706185db85Sdougm  * search the XML document subtree specified by node to find the group
10716185db85Sdougm  * specified by group. Searching subtree allows subgroups to be
10726185db85Sdougm  * searched for.
10736185db85Sdougm  */
10746185db85Sdougm 
10756185db85Sdougm static xmlNodePtr
10766185db85Sdougm find_group_by_name(xmlNodePtr node, xmlChar *group)
10776185db85Sdougm {
10786185db85Sdougm 	xmlChar *name = NULL;
10796185db85Sdougm 
10806185db85Sdougm 	for (node = node->xmlChildrenNode; node != NULL;
10816185db85Sdougm 	    node = node->next) {
108257b448deSdougm 		if (xmlStrcmp(node->name, (xmlChar *)"group") == 0) {
108357b448deSdougm 			/* if no groupname, return the first found */
108457b448deSdougm 			if (group == NULL)
108557b448deSdougm 				break;
108657b448deSdougm 			name = xmlGetProp(node, (xmlChar *)"name");
108757b448deSdougm 			if (name != NULL && xmlStrcmp(name, group) == 0)
108857b448deSdougm 				break;
108957b448deSdougm 			if (name != NULL) {
109057b448deSdougm 				xmlFree(name);
109157b448deSdougm 				name = NULL;
109257b448deSdougm 			}
10936185db85Sdougm 		}
10946185db85Sdougm 	}
10956185db85Sdougm 	if (name != NULL)
109657b448deSdougm 		xmlFree(name);
10976185db85Sdougm 	return (node);
10986185db85Sdougm }
10996185db85Sdougm 
11006185db85Sdougm /*
11016185db85Sdougm  * sa_get_group(groupname)
11026185db85Sdougm  *	Return the "group" specified.  If groupname is NULL,
11036185db85Sdougm  *	return the first group of the list of groups.
11046185db85Sdougm  */
11056185db85Sdougm sa_group_t
1106549ec3ffSdougm sa_get_group(sa_handle_t handle, char *groupname)
11076185db85Sdougm {
11086185db85Sdougm 	xmlNodePtr node = NULL;
11096185db85Sdougm 	char *subgroup = NULL;
11106185db85Sdougm 	char *group = NULL;
1111549ec3ffSdougm 	sa_handle_impl_t impl_handle = (sa_handle_impl_t)handle;
11126185db85Sdougm 
1113549ec3ffSdougm 	if (impl_handle != NULL && impl_handle->tree != NULL) {
111457b448deSdougm 		if (groupname != NULL) {
111557b448deSdougm 			group = strdup(groupname);
1116a3351425Sdougm 			if (group != NULL) {
1117a3351425Sdougm 				subgroup = strchr(group, '/');
1118a3351425Sdougm 				if (subgroup != NULL)
1119a3351425Sdougm 					*subgroup++ = '\0';
1120a3351425Sdougm 			}
112157b448deSdougm 		}
1122a3351425Sdougm 		/*
1123a3351425Sdougm 		 * We want to find the, possibly, named group. If
1124a3351425Sdougm 		 * group is not NULL, then lookup the name. If it is
1125a3351425Sdougm 		 * NULL, we only do the find if groupname is also
1126a3351425Sdougm 		 * NULL. This allows lookup of the "first" group in
1127a3351425Sdougm 		 * the internal list.
1128a3351425Sdougm 		 */
1129a3351425Sdougm 		if (group != NULL || groupname == NULL)
1130a3351425Sdougm 			node = find_group_by_name(impl_handle->tree,
1131a3351425Sdougm 			    (xmlChar *)group);
1132a3351425Sdougm 
113357b448deSdougm 		/* if a subgroup, find it before returning */
113457b448deSdougm 		if (subgroup != NULL && node != NULL)
113557b448deSdougm 			node = find_group_by_name(node, (xmlChar *)subgroup);
11366185db85Sdougm 	}
11376185db85Sdougm 	if (node != NULL && (char *)group != NULL)
113857b448deSdougm 		(void) sa_get_instance(impl_handle->scfhandle, (char *)group);
11396185db85Sdougm 	if (group != NULL)
114057b448deSdougm 		free(group);
11416185db85Sdougm 	return ((sa_group_t)(node));
11426185db85Sdougm }
11436185db85Sdougm 
11446185db85Sdougm /*
11456185db85Sdougm  * sa_get_next_group(group)
11466185db85Sdougm  *	Return the "next" group after the specified group from
11476185db85Sdougm  *	the internal group list.  NULL if there are no more.
11486185db85Sdougm  */
11496185db85Sdougm sa_group_t
11506185db85Sdougm sa_get_next_group(sa_group_t group)
11516185db85Sdougm {
11526185db85Sdougm 	xmlNodePtr ngroup = NULL;
11536185db85Sdougm 	if (group != NULL) {
115457b448deSdougm 		for (ngroup = ((xmlNodePtr)group)->next; ngroup != NULL;
11556185db85Sdougm 		    ngroup = ngroup->next) {
115657b448deSdougm 			if (xmlStrcmp(ngroup->name, (xmlChar *)"group") == 0)
115757b448deSdougm 				break;
115857b448deSdougm 		}
11596185db85Sdougm 	}
11606185db85Sdougm 	return ((sa_group_t)ngroup);
11616185db85Sdougm }
11626185db85Sdougm 
11636185db85Sdougm /*
11646185db85Sdougm  * sa_get_share(group, sharepath)
11656185db85Sdougm  *	Return the share object for the share specified. The share
11666185db85Sdougm  *	must be in the specified group.  Return NULL if not found.
11676185db85Sdougm  */
11686185db85Sdougm sa_share_t
11696185db85Sdougm sa_get_share(sa_group_t group, char *sharepath)
11706185db85Sdougm {
11716185db85Sdougm 	xmlNodePtr node = NULL;
11726185db85Sdougm 	xmlChar *path;
11736185db85Sdougm 
11746185db85Sdougm 	/*
11756185db85Sdougm 	 * For future scalability, this should end up building a cache
11766185db85Sdougm 	 * since it will get called regularly by the mountd and info
11776185db85Sdougm 	 * services.
11786185db85Sdougm 	 */
11796185db85Sdougm 	if (group != NULL) {
118057b448deSdougm 		for (node = ((xmlNodePtr)group)->children; node != NULL;
11816185db85Sdougm 		    node = node->next) {
118257b448deSdougm 			if (xmlStrcmp(node->name, (xmlChar *)"share") == 0) {
118357b448deSdougm 				if (sharepath == NULL) {
118457b448deSdougm 					break;
118557b448deSdougm 				} else {
118657b448deSdougm 					/* is it the correct share? */
118757b448deSdougm 					path = xmlGetProp(node,
118857b448deSdougm 					    (xmlChar *)"path");
118957b448deSdougm 					if (path != NULL &&
119057b448deSdougm 					    xmlStrcmp(path,
119157b448deSdougm 					    (xmlChar *)sharepath) == 0) {
119257b448deSdougm 						xmlFree(path);
119357b448deSdougm 						break;
119457b448deSdougm 					}
119557b448deSdougm 					xmlFree(path);
119657b448deSdougm 				}
11976185db85Sdougm 			}
11986185db85Sdougm 		}
11996185db85Sdougm 	}
12006185db85Sdougm 	return ((sa_share_t)node);
12016185db85Sdougm }
12026185db85Sdougm 
12036185db85Sdougm /*
12046185db85Sdougm  * sa_get_next_share(share)
12056185db85Sdougm  *	Return the next share following the specified share
12066185db85Sdougm  *	from the internal list of shares. Returns NULL if there
12076185db85Sdougm  *	are no more shares.  The list is relative to the same
12086185db85Sdougm  *	group.
12096185db85Sdougm  */
12106185db85Sdougm sa_share_t
12116185db85Sdougm sa_get_next_share(sa_share_t share)
12126185db85Sdougm {
12136185db85Sdougm 	xmlNodePtr node = NULL;
12146185db85Sdougm 
12156185db85Sdougm 	if (share != NULL) {
121657b448deSdougm 		for (node = ((xmlNodePtr)share)->next; node != NULL;
12176185db85Sdougm 		    node = node->next) {
121857b448deSdougm 			if (xmlStrcmp(node->name, (xmlChar *)"share") == 0) {
121957b448deSdougm 				break;
122057b448deSdougm 			}
12216185db85Sdougm 		}
12226185db85Sdougm 	}
12236185db85Sdougm 	return ((sa_share_t)node);
12246185db85Sdougm }
12256185db85Sdougm 
12266185db85Sdougm /*
12276185db85Sdougm  * _sa_get_child_node(node, type)
12286185db85Sdougm  *
12296185db85Sdougm  * find the child node of the specified node that has "type". This is
12306185db85Sdougm  * used to implement several internal functions.
12316185db85Sdougm  */
12326185db85Sdougm 
12336185db85Sdougm static xmlNodePtr
12346185db85Sdougm _sa_get_child_node(xmlNodePtr node, xmlChar *type)
12356185db85Sdougm {
12366185db85Sdougm 	xmlNodePtr child;
12376185db85Sdougm 	for (child = node->xmlChildrenNode; child != NULL;
12386185db85Sdougm 	    child = child->next)
123957b448deSdougm 		if (xmlStrcmp(child->name, type) == 0)
124057b448deSdougm 			return (child);
12416185db85Sdougm 	return ((xmlNodePtr)NULL);
12426185db85Sdougm }
12436185db85Sdougm 
12446185db85Sdougm /*
12456185db85Sdougm  *  find_share(group, path)
12466185db85Sdougm  *
12476185db85Sdougm  * Search all the shares in the specified group for one that has the
12486185db85Sdougm  * specified path.
12496185db85Sdougm  */
12506185db85Sdougm 
12516185db85Sdougm static sa_share_t
12526185db85Sdougm find_share(sa_group_t group, char *sharepath)
12536185db85Sdougm {
12546185db85Sdougm 	sa_share_t share;
12556185db85Sdougm 	char *path;
12566185db85Sdougm 
12576185db85Sdougm 	for (share = sa_get_share(group, NULL); share != NULL;
12586185db85Sdougm 	    share = sa_get_next_share(share)) {
125957b448deSdougm 		path = sa_get_share_attr(share, "path");
126057b448deSdougm 		if (path != NULL && strcmp(path, sharepath) == 0) {
126157b448deSdougm 			sa_free_attr_string(path);
126257b448deSdougm 			break;
126357b448deSdougm 		}
126457b448deSdougm 		if (path != NULL)
126557b448deSdougm 			sa_free_attr_string(path);
12666185db85Sdougm 	}
12676185db85Sdougm 	return (share);
12686185db85Sdougm }
12696185db85Sdougm 
12706185db85Sdougm /*
12716185db85Sdougm  * sa_get_sub_group(group)
12726185db85Sdougm  *
12736185db85Sdougm  * Get the first sub-group of group. The sa_get_next_group() function
12746185db85Sdougm  * can be used to get the rest. This is currently only used for ZFS
12756185db85Sdougm  * sub-groups but could be used to implement a more general mechanism.
12766185db85Sdougm  */
12776185db85Sdougm 
12786185db85Sdougm sa_group_t
12796185db85Sdougm sa_get_sub_group(sa_group_t group)
12806185db85Sdougm {
12816185db85Sdougm 	return ((sa_group_t)_sa_get_child_node((xmlNodePtr)group,
128257b448deSdougm 	    (xmlChar *)"group"));
12836185db85Sdougm }
12846185db85Sdougm 
12856185db85Sdougm /*
12866185db85Sdougm  * sa_find_share(sharepath)
12876185db85Sdougm  *	Finds a share regardless of group.  In the future, this
12886185db85Sdougm  *	function should utilize a cache and hash table of some kind.
12896185db85Sdougm  *	The current assumption is that a path will only be shared
12906185db85Sdougm  *	once.  In the future, this may change as implementation of
12916185db85Sdougm  *	resource names comes into being.
12926185db85Sdougm  */
12936185db85Sdougm sa_share_t
1294549ec3ffSdougm sa_find_share(sa_handle_t handle, char *sharepath)
12956185db85Sdougm {
12966185db85Sdougm 	sa_group_t group;
12976185db85Sdougm 	sa_group_t zgroup;
12986185db85Sdougm 	sa_share_t share = NULL;
12996185db85Sdougm 	int done = 0;
13006185db85Sdougm 
1301549ec3ffSdougm 	for (group = sa_get_group(handle, NULL); group != NULL && !done;
130257b448deSdougm 	    group = sa_get_next_group(group)) {
130357b448deSdougm 		if (is_zfs_group(group)) {
130457b448deSdougm 			for (zgroup =
130557b448deSdougm 			    (sa_group_t)_sa_get_child_node((xmlNodePtr)group,
130657b448deSdougm 			    (xmlChar *)"group");
130757b448deSdougm 			    zgroup != NULL;
130857b448deSdougm 			    zgroup = sa_get_next_group(zgroup)) {
130957b448deSdougm 				share = find_share(zgroup, sharepath);
131057b448deSdougm 				if (share != NULL)
131157b448deSdougm 					break;
131257b448deSdougm 			}
131357b448deSdougm 		} else {
131457b448deSdougm 			share = find_share(group, sharepath);
13156185db85Sdougm 		}
131657b448deSdougm 		if (share != NULL)
131757b448deSdougm 			break;
13186185db85Sdougm 	}
13196185db85Sdougm 	return (share);
13206185db85Sdougm }
13216185db85Sdougm 
13226185db85Sdougm /*
1323f345c0beSdougm  *  sa_check_path(group, path, strictness)
13246185db85Sdougm  *
1325da6c28aaSamw  * Check that path is a valid path relative to the group.  Currently,
13266185db85Sdougm  * we are ignoring the group and checking only the NFS rules. Later,
13276185db85Sdougm  * we may want to use the group to then check against the protocols
1328f345c0beSdougm  * enabled on the group. The strictness values mean:
1329f345c0beSdougm  * SA_CHECK_NORMAL == only check newpath against shares that are active
1330f345c0beSdougm  * SA_CHECK_STRICT == check newpath against both active shares and those
1331f345c0beSdougm  *		      stored in the repository
13326185db85Sdougm  */
13336185db85Sdougm 
13346185db85Sdougm int
1335f345c0beSdougm sa_check_path(sa_group_t group, char *path, int strictness)
13366185db85Sdougm {
1337549ec3ffSdougm 	sa_handle_t handle;
1338549ec3ffSdougm 
1339549ec3ffSdougm 	handle = sa_find_group_handle(group);
1340549ec3ffSdougm 	return (validpath(handle, path, strictness));
13416185db85Sdougm }
13426185db85Sdougm 
13436185db85Sdougm /*
1344da6c28aaSamw  * mark_excluded_protos(group, share, flags)
1345da6c28aaSamw  *
1346da6c28aaSamw  * Walk through all the protocols enabled for the group and check to
1347da6c28aaSamw  * see if the share has any of them should be in the exclude list
1348da6c28aaSamw  * based on the featureset of the protocol. If there are any, add the
1349da6c28aaSamw  * "exclude" property to the share.
1350da6c28aaSamw  */
1351da6c28aaSamw static void
1352da6c28aaSamw mark_excluded_protos(sa_group_t group, xmlNodePtr share, uint64_t flags)
1353da6c28aaSamw {
1354da6c28aaSamw 	sa_optionset_t optionset;
1355da6c28aaSamw 	char exclude_list[SA_STRSIZE];
1356da6c28aaSamw 	char *sep = "";
1357da6c28aaSamw 
1358da6c28aaSamw 	exclude_list[0] = '\0';
1359da6c28aaSamw 	for (optionset = sa_get_optionset(group, NULL);
1360da6c28aaSamw 	    optionset != NULL;
1361da6c28aaSamw 	    optionset = sa_get_next_optionset(optionset)) {
1362da6c28aaSamw 		char *value;
1363da6c28aaSamw 		uint64_t features;
1364da6c28aaSamw 		value = sa_get_optionset_attr(optionset, "type");
1365da6c28aaSamw 		if (value == NULL)
1366da6c28aaSamw 			continue;
1367da6c28aaSamw 		features = sa_proto_get_featureset(value);
1368da6c28aaSamw 		sa_free_attr_string(value);
1369da6c28aaSamw 		if (!(features & flags)) {
1370da6c28aaSamw 			(void) strlcat(exclude_list, sep,
1371da6c28aaSamw 			    sizeof (exclude_list));
1372da6c28aaSamw 			(void) strlcat(exclude_list, value,
1373da6c28aaSamw 			    sizeof (exclude_list));
1374da6c28aaSamw 			sep = ",";
1375da6c28aaSamw 		}
1376da6c28aaSamw 	}
1377da6c28aaSamw 	if (exclude_list[0] != '\0')
1378da6c28aaSamw 		xmlSetProp(share, (xmlChar *)"exclude",
1379da6c28aaSamw 		    (xmlChar *)exclude_list);
1380da6c28aaSamw }
1381da6c28aaSamw 
1382da6c28aaSamw /*
1383da6c28aaSamw  * get_all_features(group)
1384da6c28aaSamw  *
1385da6c28aaSamw  * Walk through all the protocols on the group and collect all
1386da6c28aaSamw  * possible enabled features. This is the OR of all the featuresets.
1387da6c28aaSamw  */
1388da6c28aaSamw static uint64_t
1389da6c28aaSamw get_all_features(sa_group_t group)
1390da6c28aaSamw {
1391da6c28aaSamw 	sa_optionset_t optionset;
1392da6c28aaSamw 	uint64_t features = 0;
1393da6c28aaSamw 
1394da6c28aaSamw 	for (optionset = sa_get_optionset(group, NULL);
1395da6c28aaSamw 	    optionset != NULL;
1396da6c28aaSamw 	    optionset = sa_get_next_optionset(optionset)) {
1397da6c28aaSamw 		char *value;
1398da6c28aaSamw 		value = sa_get_optionset_attr(optionset, "type");
1399da6c28aaSamw 		if (value == NULL)
1400da6c28aaSamw 			continue;
1401da6c28aaSamw 		features |= sa_proto_get_featureset(value);
1402da6c28aaSamw 		sa_free_attr_string(value);
1403da6c28aaSamw 	}
1404da6c28aaSamw 	return (features);
1405da6c28aaSamw }
1406da6c28aaSamw 
1407da6c28aaSamw 
1408da6c28aaSamw /*
1409da6c28aaSamw  * _sa_add_share(group, sharepath, persist, *error, flags)
14106185db85Sdougm  *
1411da6c28aaSamw  * Common code for all types of add_share. sa_add_share() is the
14126185db85Sdougm  * public API, we also need to be able to do this when parsing legacy
14136185db85Sdougm  * files and construction of the internal configuration while
1414da6c28aaSamw  * extracting config info from SMF. "flags" indicates if some
1415da6c28aaSamw  * protocols need relaxed rules while other don't. These values are
1416da6c28aaSamw  * the featureset values defined in libshare.h.
14176185db85Sdougm  */
14186185db85Sdougm 
14196185db85Sdougm sa_share_t
1420da6c28aaSamw _sa_add_share(sa_group_t group, char *sharepath, int persist, int *error,
1421da6c28aaSamw     uint64_t flags)
14226185db85Sdougm {
14236185db85Sdougm 	xmlNodePtr node = NULL;
14246185db85Sdougm 	int err;
14256185db85Sdougm 
14266185db85Sdougm 	err  = SA_OK; /* assume success */
14276185db85Sdougm 
142857b448deSdougm 	node = xmlNewChild((xmlNodePtr)group, NULL, (xmlChar *)"share", NULL);
1429da6c28aaSamw 	if (node == NULL) {
1430da6c28aaSamw 		if (error != NULL)
1431da6c28aaSamw 			*error = SA_NO_MEMORY;
1432da6c28aaSamw 		return (node);
1433da6c28aaSamw 	}
1434da6c28aaSamw 
1435da6c28aaSamw 	xmlSetProp(node, (xmlChar *)"path", (xmlChar *)sharepath);
1436da6c28aaSamw 	xmlSetProp(node, (xmlChar *)"type",
1437da6c28aaSamw 	    persist ? (xmlChar *)"persist" : (xmlChar *)"transient");
1438da6c28aaSamw 	if (flags != 0)
1439da6c28aaSamw 		mark_excluded_protos(group, node, flags);
1440da6c28aaSamw 	if (persist != SA_SHARE_TRANSIENT) {
1441da6c28aaSamw 		/*
1442da6c28aaSamw 		 * persistent shares come in two flavors: SMF and
1443da6c28aaSamw 		 * ZFS. Sort this one out based on target group and
1444da6c28aaSamw 		 * path type. Both NFS and SMB are supported. First,
1445da6c28aaSamw 		 * check to see if the protocol is enabled on the
1446da6c28aaSamw 		 * subgroup and then setup the share appropriately.
1447da6c28aaSamw 		 */
1448da6c28aaSamw 		if (sa_group_is_zfs(group) &&
1449da6c28aaSamw 		    sa_path_is_zfs(sharepath)) {
1450da6c28aaSamw 			if (sa_get_optionset(group, "nfs") != NULL)
145157b448deSdougm 				err = sa_zfs_set_sharenfs(group, sharepath, 1);
1452da6c28aaSamw 			else if (sa_get_optionset(group, "smb") != NULL)
1453da6c28aaSamw 				err = sa_zfs_set_sharesmb(group, sharepath, 1);
1454da6c28aaSamw 		} else {
1455da6c28aaSamw 			sa_handle_impl_t impl_handle;
1456da6c28aaSamw 			impl_handle =
1457da6c28aaSamw 			    (sa_handle_impl_t)sa_find_group_handle(group);
1458da6c28aaSamw 			if (impl_handle != NULL) {
1459da6c28aaSamw 				err = sa_commit_share(impl_handle->scfhandle,
1460da6c28aaSamw 				    group, (sa_share_t)node);
146157b448deSdougm 			} else {
1462da6c28aaSamw 				err = SA_SYSTEM_ERR;
146357b448deSdougm 			}
146457b448deSdougm 		}
14656185db85Sdougm 	}
1466da6c28aaSamw 	if (err == SA_NO_PERMISSION && persist & SA_SHARE_PARSER)
1467da6c28aaSamw 		/* called by the dfstab parser so could be a show */
1468da6c28aaSamw 		err = SA_OK;
1469da6c28aaSamw 
1470da6c28aaSamw 	if (err != SA_OK) {
1471da6c28aaSamw 		/*
1472da6c28aaSamw 		 * we couldn't commit to the repository so undo
1473da6c28aaSamw 		 * our internal state to reflect reality.
1474da6c28aaSamw 		 */
1475da6c28aaSamw 		xmlUnlinkNode(node);
1476da6c28aaSamw 		xmlFreeNode(node);
1477da6c28aaSamw 		node = NULL;
1478da6c28aaSamw 	}
1479da6c28aaSamw 
14806185db85Sdougm 	if (error != NULL)
148157b448deSdougm 		*error = err;
1482da6c28aaSamw 
14836185db85Sdougm 	return (node);
14846185db85Sdougm }
14856185db85Sdougm 
14866185db85Sdougm /*
14876185db85Sdougm  * sa_add_share(group, sharepath, persist, *error)
14886185db85Sdougm  *
14896185db85Sdougm  *	Add a new share object to the specified group.  The share will
14906185db85Sdougm  *	have the specified sharepath and will only be constructed if
14916185db85Sdougm  *	it is a valid path to be shared.  NULL is returned on error
14926185db85Sdougm  *	and a detailed error value will be returned via the error
14936185db85Sdougm  *	pointer.
14946185db85Sdougm  */
14956185db85Sdougm sa_share_t
14966185db85Sdougm sa_add_share(sa_group_t group, char *sharepath, int persist, int *error)
14976185db85Sdougm {
14986185db85Sdougm 	xmlNodePtr node = NULL;
1499f345c0beSdougm 	int strictness = SA_CHECK_NORMAL;
1500549ec3ffSdougm 	sa_handle_t handle;
1501da6c28aaSamw 	uint64_t special = 0;
1502da6c28aaSamw 	uint64_t features;
1503f345c0beSdougm 
1504f345c0beSdougm 	/*
1505f345c0beSdougm 	 * If the share is to be permanent, use strict checking so a
1506f345c0beSdougm 	 * bad config doesn't get created. Transient shares only need
1507f345c0beSdougm 	 * to check against the currently active
1508f345c0beSdougm 	 * shares. SA_SHARE_PARSER is a modifier used internally to
1509f345c0beSdougm 	 * indicate that we are being called by the dfstab parser and
1510f345c0beSdougm 	 * that we need strict checking in all cases. Normally persist
1511f345c0beSdougm 	 * is in integer value but SA_SHARE_PARSER may be or'd into
1512f345c0beSdougm 	 * it as an override.
1513f345c0beSdougm 	 */
1514f345c0beSdougm 	if (persist & SA_SHARE_PARSER || persist == SA_SHARE_PERMANENT)
151557b448deSdougm 		strictness = SA_CHECK_STRICT;
15166185db85Sdougm 
1517549ec3ffSdougm 	handle = sa_find_group_handle(group);
1518549ec3ffSdougm 
1519da6c28aaSamw 	/*
1520da6c28aaSamw 	 * need to determine if the share is valid. The rules are:
1521da6c28aaSamw 	 *	- The path must not already exist
1522da6c28aaSamw 	 *	- The path must not be a subdir or parent dir of an
1523da6c28aaSamw 	 *	  existing path unless at least one protocol allows it.
1524da6c28aaSamw 	 * The sub/parent check is done in sa_check_path().
1525da6c28aaSamw 	 */
1526da6c28aaSamw 
1527da6c28aaSamw 	if (sa_find_share(handle, sharepath) == NULL) {
1528da6c28aaSamw 		*error = sa_check_path(group, sharepath, strictness);
1529da6c28aaSamw 		features = get_all_features(group);
1530da6c28aaSamw 		switch (*error) {
1531da6c28aaSamw 		case SA_PATH_IS_SUBDIR:
1532da6c28aaSamw 			if (features & SA_FEATURE_ALLOWSUBDIRS)
1533da6c28aaSamw 				special |= SA_FEATURE_ALLOWSUBDIRS;
1534da6c28aaSamw 			break;
1535da6c28aaSamw 		case SA_PATH_IS_PARENTDIR:
1536da6c28aaSamw 			if (features & SA_FEATURE_ALLOWPARDIRS)
1537da6c28aaSamw 				special |= SA_FEATURE_ALLOWPARDIRS;
1538da6c28aaSamw 			break;
1539da6c28aaSamw 		}
1540da6c28aaSamw 		if (*error == SA_OK || special != SA_FEATURE_NONE)
1541da6c28aaSamw 			node = _sa_add_share(group, sharepath, persist,
1542da6c28aaSamw 			    error, special);
1543da6c28aaSamw 	} else {
154457b448deSdougm 		*error = SA_DUPLICATE_NAME;
1545da6c28aaSamw 	}
15466185db85Sdougm 
15476185db85Sdougm 	return ((sa_share_t)node);
15486185db85Sdougm }
15496185db85Sdougm 
15506185db85Sdougm /*
15516185db85Sdougm  * sa_enable_share(share, protocol)
15526185db85Sdougm  *	Enable the specified share to the specified protocol.
15536185db85Sdougm  *	If protocol is NULL, then all protocols.
15546185db85Sdougm  */
15556185db85Sdougm int
15566185db85Sdougm sa_enable_share(sa_share_t share, char *protocol)
15576185db85Sdougm {
15586185db85Sdougm 	char *sharepath;
15596185db85Sdougm 	struct stat st;
1560da6c28aaSamw 	int err = SA_OK;
1561da6c28aaSamw 	int ret;
15626185db85Sdougm 
15636185db85Sdougm 	sharepath = sa_get_share_attr(share, "path");
1564da6c28aaSamw 	if (sharepath == NULL)
1565da6c28aaSamw 		return (SA_NO_MEMORY);
15666185db85Sdougm 	if (stat(sharepath, &st) < 0) {
156757b448deSdougm 		err = SA_NO_SUCH_PATH;
15686185db85Sdougm 	} else {
156957b448deSdougm 		/* tell the server about the share */
157057b448deSdougm 		if (protocol != NULL) {
1571da6c28aaSamw 			if (excluded_protocol(share, protocol))
1572da6c28aaSamw 				goto done;
1573da6c28aaSamw 
157457b448deSdougm 			/* lookup protocol specific handler */
157557b448deSdougm 			err = sa_proto_share(protocol, share);
157657b448deSdougm 			if (err == SA_OK)
1577da6c28aaSamw 				(void) sa_set_share_attr(share,
1578da6c28aaSamw 				    "shared", "true");
157957b448deSdougm 		} else {
1580da6c28aaSamw 			/* Tell all protocols about the share */
1581da6c28aaSamw 			sa_group_t group;
1582da6c28aaSamw 			sa_optionset_t optionset;
1583da6c28aaSamw 
1584da6c28aaSamw 			group = sa_get_parent_group(share);
1585da6c28aaSamw 
1586da6c28aaSamw 			for (optionset = sa_get_optionset(group, NULL);
1587da6c28aaSamw 			    optionset != NULL;
1588da6c28aaSamw 			    optionset = sa_get_next_optionset(optionset)) {
1589da6c28aaSamw 				char *proto;
1590da6c28aaSamw 				proto = sa_get_optionset_attr(optionset,
1591da6c28aaSamw 				    "type");
1592da6c28aaSamw 				if (proto != NULL) {
1593da6c28aaSamw 					if (!excluded_protocol(share, proto)) {
1594da6c28aaSamw 						ret = sa_proto_share(proto,
1595da6c28aaSamw 						    share);
1596da6c28aaSamw 						if (ret != SA_OK)
1597da6c28aaSamw 							err = ret;
1598da6c28aaSamw 					}
1599da6c28aaSamw 					sa_free_attr_string(proto);
1600da6c28aaSamw 				}
1601da6c28aaSamw 			}
160257b448deSdougm 			(void) sa_set_share_attr(share, "shared", "true");
160357b448deSdougm 		}
16046185db85Sdougm 	}
1605da6c28aaSamw done:
16066185db85Sdougm 	if (sharepath != NULL)
160757b448deSdougm 		sa_free_attr_string(sharepath);
16086185db85Sdougm 	return (err);
16096185db85Sdougm }
16106185db85Sdougm 
16116185db85Sdougm /*
16126185db85Sdougm  * sa_disable_share(share, protocol)
1613da6c28aaSamw  *	Disable the specified share to the specified protocol.  If
1614da6c28aaSamw  *	protocol is NULL, then all protocols that are enabled for the
1615da6c28aaSamw  *	share should be disabled.
16166185db85Sdougm  */
16176185db85Sdougm int
16186185db85Sdougm sa_disable_share(sa_share_t share, char *protocol)
16196185db85Sdougm {
16206185db85Sdougm 	char *path;
1621da6c28aaSamw 	int err = SA_OK;
16226185db85Sdougm 	int ret = SA_OK;
16236185db85Sdougm 
16246185db85Sdougm 	path = sa_get_share_attr(share, "path");
16256185db85Sdougm 
16266185db85Sdougm 	if (protocol != NULL) {
1627ecd6cf80Smarks 		ret = sa_proto_unshare(share, protocol, path);
16286185db85Sdougm 	} else {
162957b448deSdougm 		/* need to do all protocols */
1630da6c28aaSamw 		sa_group_t group;
1631da6c28aaSamw 		sa_optionset_t optionset;
1632da6c28aaSamw 
1633da6c28aaSamw 		group = sa_get_parent_group(share);
1634da6c28aaSamw 
1635da6c28aaSamw 		/* Tell all protocols about the share */
1636da6c28aaSamw 		for (optionset = sa_get_optionset(group, NULL);
1637da6c28aaSamw 		    optionset != NULL;
1638da6c28aaSamw 		    optionset = sa_get_next_optionset(optionset)) {
1639da6c28aaSamw 			char *proto;
1640da6c28aaSamw 
1641da6c28aaSamw 			proto = sa_get_optionset_attr(optionset, "type");
1642da6c28aaSamw 			if (proto != NULL) {
1643da6c28aaSamw 				err = sa_proto_unshare(share, proto, path);
1644da6c28aaSamw 				if (err != SA_OK)
1645da6c28aaSamw 					ret = err;
1646da6c28aaSamw 				sa_free_attr_string(proto);
1647da6c28aaSamw 			}
1648da6c28aaSamw 		}
16496185db85Sdougm 	}
16506185db85Sdougm 	if (ret == SA_OK)
16516185db85Sdougm 		(void) sa_set_share_attr(share, "shared", NULL);
16526185db85Sdougm 	if (path != NULL)
165357b448deSdougm 		sa_free_attr_string(path);
16546185db85Sdougm 	return (ret);
16556185db85Sdougm }
16566185db85Sdougm 
16576185db85Sdougm /*
16586185db85Sdougm  * sa_remove_share(share)
16596185db85Sdougm  *
16606185db85Sdougm  * remove the specified share from its containing group.
16616185db85Sdougm  * Remove from the SMF or ZFS configuration space.
16626185db85Sdougm  */
16636185db85Sdougm 
16646185db85Sdougm int
16656185db85Sdougm sa_remove_share(sa_share_t share)
16666185db85Sdougm {
16676185db85Sdougm 	sa_group_t group;
16686185db85Sdougm 	int ret = SA_OK;
16696185db85Sdougm 	char *type;
16706185db85Sdougm 	int transient = 0;
16716185db85Sdougm 	char *groupname;
16726185db85Sdougm 	char *zfs;
16736185db85Sdougm 
16746185db85Sdougm 	type = sa_get_share_attr(share, "type");
16756185db85Sdougm 	group = sa_get_parent_group(share);
16766185db85Sdougm 	zfs = sa_get_group_attr(group, "zfs");
16776185db85Sdougm 	groupname = sa_get_group_attr(group, "name");
16786185db85Sdougm 	if (type != NULL && strcmp(type, "persist") != 0)
167957b448deSdougm 		transient = 1;
16806185db85Sdougm 	if (type != NULL)
168157b448deSdougm 		sa_free_attr_string(type);
16826185db85Sdougm 
16836185db85Sdougm 	/* remove the node from its group then free the memory */
16846185db85Sdougm 
16856185db85Sdougm 	/*
16866185db85Sdougm 	 * need to test if "busy"
16876185db85Sdougm 	 */
16886185db85Sdougm 	/* only do SMF action if permanent */
16896185db85Sdougm 	if (!transient || zfs != NULL) {
169057b448deSdougm 		/* remove from legacy dfstab as well as possible SMF */
1691da6c28aaSamw 		ret = sa_delete_legacy(share, NULL);
169257b448deSdougm 		if (ret == SA_OK) {
169357b448deSdougm 			if (!sa_group_is_zfs(group)) {
169457b448deSdougm 				sa_handle_impl_t impl_handle;
169557b448deSdougm 				impl_handle = (sa_handle_impl_t)
169657b448deSdougm 				    sa_find_group_handle(group);
169757b448deSdougm 				if (impl_handle != NULL) {
169857b448deSdougm 					ret = sa_delete_share(
169957b448deSdougm 					    impl_handle->scfhandle, group,
170057b448deSdougm 					    share);
170157b448deSdougm 				} else {
170257b448deSdougm 					ret = SA_SYSTEM_ERR;
170357b448deSdougm 				}
170457b448deSdougm 			} else {
170557b448deSdougm 				char *sharepath = sa_get_share_attr(share,
170657b448deSdougm 				    "path");
170757b448deSdougm 				if (sharepath != NULL) {
170857b448deSdougm 					ret = sa_zfs_set_sharenfs(group,
170957b448deSdougm 					    sharepath, 0);
171057b448deSdougm 					sa_free_attr_string(sharepath);
171157b448deSdougm 				}
171257b448deSdougm 			}
17136185db85Sdougm 		}
17146185db85Sdougm 	}
17156185db85Sdougm 	if (groupname != NULL)
171657b448deSdougm 		sa_free_attr_string(groupname);
17176185db85Sdougm 	if (zfs != NULL)
171857b448deSdougm 		sa_free_attr_string(zfs);
17196185db85Sdougm 
17206185db85Sdougm 	xmlUnlinkNode((xmlNodePtr)share);
17216185db85Sdougm 	xmlFreeNode((xmlNodePtr)share);
17226185db85Sdougm 	return (ret);
17236185db85Sdougm }
17246185db85Sdougm 
17256185db85Sdougm /*
17266185db85Sdougm  * sa_move_share(group, share)
17276185db85Sdougm  *
17286185db85Sdougm  * move the specified share to the specified group.  Update SMF
17296185db85Sdougm  * appropriately.
17306185db85Sdougm  */
17316185db85Sdougm 
17326185db85Sdougm int
17336185db85Sdougm sa_move_share(sa_group_t group, sa_share_t share)
17346185db85Sdougm {
17356185db85Sdougm 	sa_group_t oldgroup;
17366185db85Sdougm 	int ret = SA_OK;
17376185db85Sdougm 
17386185db85Sdougm 	/* remove the node from its group then free the memory */
17396185db85Sdougm 
17406185db85Sdougm 	oldgroup = sa_get_parent_group(share);
17416185db85Sdougm 	if (oldgroup != group) {
174257b448deSdougm 		sa_handle_impl_t impl_handle;
174357b448deSdougm 		xmlUnlinkNode((xmlNodePtr)share);
17446185db85Sdougm 		/*
174557b448deSdougm 		 * now that the share isn't in its old group, add to
174657b448deSdougm 		 * the new one
17476185db85Sdougm 		 */
174857b448deSdougm 		xmlAddChild((xmlNodePtr)group, (xmlNodePtr)share);
174957b448deSdougm 		/* need to deal with SMF */
175057b448deSdougm 		impl_handle = (sa_handle_impl_t)sa_find_group_handle(group);
175157b448deSdougm 		if (impl_handle != NULL) {
175257b448deSdougm 			/*
175357b448deSdougm 			 * need to remove from old group first and then add to
175457b448deSdougm 			 * new group. Ideally, we would do the other order but
175557b448deSdougm 			 * need to avoid having the share in two groups at the
175657b448deSdougm 			 * same time.
175757b448deSdougm 			 */
175857b448deSdougm 			ret = sa_delete_share(impl_handle->scfhandle, oldgroup,
175957b448deSdougm 			    share);
176057b448deSdougm 			if (ret == SA_OK)
176157b448deSdougm 				ret = sa_commit_share(impl_handle->scfhandle,
176257b448deSdougm 				    group, share);
176357b448deSdougm 		} else {
176457b448deSdougm 			ret = SA_SYSTEM_ERR;
176557b448deSdougm 		}
17666185db85Sdougm 	}
17676185db85Sdougm 	return (ret);
17686185db85Sdougm }
17696185db85Sdougm 
17706185db85Sdougm /*
17716185db85Sdougm  * sa_get_parent_group(share)
17726185db85Sdougm  *
1773da6c28aaSamw  * Return the containing group for the share. If a group was actually
17746185db85Sdougm  * passed in, we don't want a parent so return NULL.
17756185db85Sdougm  */
17766185db85Sdougm 
17776185db85Sdougm sa_group_t
17786185db85Sdougm sa_get_parent_group(sa_share_t share)
17796185db85Sdougm {
17806185db85Sdougm 	xmlNodePtr node = NULL;
17816185db85Sdougm 	if (share != NULL) {
178257b448deSdougm 		node = ((xmlNodePtr)share)->parent;
17836185db85Sdougm 		/*
17846185db85Sdougm 		 * make sure parent is a group and not sharecfg since
17856185db85Sdougm 		 * we may be cheating and passing in a group.
17866185db85Sdougm 		 * Eventually, groups of groups might come into being.
17876185db85Sdougm 		 */
178857b448deSdougm 		if (node == NULL ||
178957b448deSdougm 		    xmlStrcmp(node->name, (xmlChar *)"sharecfg") == 0)
179057b448deSdougm 			node = NULL;
17916185db85Sdougm 	}
17926185db85Sdougm 	return ((sa_group_t)node);
17936185db85Sdougm }
17946185db85Sdougm 
17956185db85Sdougm /*
1796549ec3ffSdougm  * _sa_create_group(impl_handle, groupname)
17976185db85Sdougm  *
17986185db85Sdougm  * Create a group in the document. The caller will need to deal with
17996185db85Sdougm  * configuration store and activation.
18006185db85Sdougm  */
18016185db85Sdougm 
18026185db85Sdougm sa_group_t
1803549ec3ffSdougm _sa_create_group(sa_handle_impl_t impl_handle, char *groupname)
18046185db85Sdougm {
18056185db85Sdougm 	xmlNodePtr node = NULL;
18066185db85Sdougm 
18076185db85Sdougm 	if (sa_valid_group_name(groupname)) {
180857b448deSdougm 		node = xmlNewChild(impl_handle->tree, NULL, (xmlChar *)"group",
180957b448deSdougm 		    NULL);
181057b448deSdougm 		if (node != NULL) {
181157b448deSdougm 			xmlSetProp(node, (xmlChar *)"name",
181257b448deSdougm 			    (xmlChar *)groupname);
181357b448deSdougm 			xmlSetProp(node, (xmlChar *)"state",
181457b448deSdougm 			    (xmlChar *)"enabled");
181557b448deSdougm 		}
18166185db85Sdougm 	}
18176185db85Sdougm 	return ((sa_group_t)node);
18186185db85Sdougm }
18196185db85Sdougm 
18206185db85Sdougm /*
18216185db85Sdougm  * _sa_create_zfs_group(group, groupname)
18226185db85Sdougm  *
18236185db85Sdougm  * Create a ZFS subgroup under the specified group. This may
18246185db85Sdougm  * eventually form the basis of general sub-groups, but is currently
18256185db85Sdougm  * restricted to ZFS.
18266185db85Sdougm  */
18276185db85Sdougm sa_group_t
18286185db85Sdougm _sa_create_zfs_group(sa_group_t group, char *groupname)
18296185db85Sdougm {
18306185db85Sdougm 	xmlNodePtr node = NULL;
18316185db85Sdougm 
183257b448deSdougm 	node = xmlNewChild((xmlNodePtr)group, NULL, (xmlChar *)"group", NULL);
18336185db85Sdougm 	if (node != NULL) {
18346185db85Sdougm 		xmlSetProp(node, (xmlChar *)"name", (xmlChar *)groupname);
18356185db85Sdougm 		xmlSetProp(node, (xmlChar *)"state", (xmlChar *)"enabled");
18366185db85Sdougm 	}
18376185db85Sdougm 
18386185db85Sdougm 	return ((sa_group_t)node);
18396185db85Sdougm }
18406185db85Sdougm 
18416185db85Sdougm /*
18426185db85Sdougm  * sa_create_group(groupname, *error)
18436185db85Sdougm  *
18446185db85Sdougm  * Create a new group with groupname.  Need to validate that it is a
18456185db85Sdougm  * legal name for SMF and the construct the SMF service instance of
18466185db85Sdougm  * svc:/network/shares/group to implement the group. All necessary
18476185db85Sdougm  * operational properties must be added to the group at this point
18486185db85Sdougm  * (via the SMF transaction model).
18496185db85Sdougm  */
18506185db85Sdougm sa_group_t
1851549ec3ffSdougm sa_create_group(sa_handle_t handle, char *groupname, int *error)
18526185db85Sdougm {
18536185db85Sdougm 	xmlNodePtr node = NULL;
18546185db85Sdougm 	sa_group_t group;
18556185db85Sdougm 	int ret;
185657b448deSdougm 	char rbacstr[SA_STRSIZE];
1857549ec3ffSdougm 	sa_handle_impl_t impl_handle = (sa_handle_impl_t)handle;
18586185db85Sdougm 
18596185db85Sdougm 	ret = SA_OK;
18606185db85Sdougm 
1861549ec3ffSdougm 	if (impl_handle == NULL || impl_handle->scfhandle == NULL) {
186257b448deSdougm 		ret = SA_SYSTEM_ERR;
186357b448deSdougm 		goto err;
18646185db85Sdougm 	}
18656185db85Sdougm 
1866549ec3ffSdougm 	group = sa_get_group(handle, groupname);
18676185db85Sdougm 	if (group != NULL) {
186857b448deSdougm 		ret = SA_DUPLICATE_NAME;
18696185db85Sdougm 	} else {
187057b448deSdougm 		if (sa_valid_group_name(groupname)) {
187157b448deSdougm 			node = xmlNewChild(impl_handle->tree, NULL,
187257b448deSdougm 			    (xmlChar *)"group", NULL);
187357b448deSdougm 			if (node != NULL) {
187457b448deSdougm 				xmlSetProp(node, (xmlChar *)"name",
187557b448deSdougm 				    (xmlChar *)groupname);
187657b448deSdougm 				/* default to the group being enabled */
187757b448deSdougm 				xmlSetProp(node, (xmlChar *)"state",
187857b448deSdougm 				    (xmlChar *)"enabled");
187957b448deSdougm 				ret = sa_create_instance(impl_handle->scfhandle,
188057b448deSdougm 				    groupname);
188157b448deSdougm 				if (ret == SA_OK) {
188257b448deSdougm 					ret = sa_start_transaction(
188357b448deSdougm 					    impl_handle->scfhandle,
188457b448deSdougm 					    "operation");
188557b448deSdougm 				}
188657b448deSdougm 				if (ret == SA_OK) {
188757b448deSdougm 					ret = sa_set_property(
188857b448deSdougm 					    impl_handle->scfhandle,
188957b448deSdougm 					    "state", "enabled");
189057b448deSdougm 					if (ret == SA_OK) {
189157b448deSdougm 						ret = sa_end_transaction(
1892*5b6e0c46Sdougm 						    impl_handle->scfhandle,
1893*5b6e0c46Sdougm 						    impl_handle);
189457b448deSdougm 					} else {
189557b448deSdougm 						sa_abort_transaction(
189657b448deSdougm 						    impl_handle->scfhandle);
189757b448deSdougm 					}
189857b448deSdougm 				}
189957b448deSdougm 				if (ret == SA_OK) {
190057b448deSdougm 					/* initialize the RBAC strings */
190157b448deSdougm 					ret = sa_start_transaction(
190257b448deSdougm 					    impl_handle->scfhandle,
190357b448deSdougm 					    "general");
190457b448deSdougm 					if (ret == SA_OK) {
190557b448deSdougm 						(void) snprintf(rbacstr,
190657b448deSdougm 						    sizeof (rbacstr), "%s.%s",
190757b448deSdougm 						    SA_RBAC_MANAGE, groupname);
190857b448deSdougm 						ret = sa_set_property(
190957b448deSdougm 						    impl_handle->scfhandle,
19106185db85Sdougm 						    "action_authorization",
19116185db85Sdougm 						    rbacstr);
191257b448deSdougm 					}
191357b448deSdougm 					if (ret == SA_OK) {
191457b448deSdougm 						(void) snprintf(rbacstr,
191557b448deSdougm 						    sizeof (rbacstr), "%s.%s",
191657b448deSdougm 						    SA_RBAC_VALUE, groupname);
191757b448deSdougm 						ret = sa_set_property(
191857b448deSdougm 						    impl_handle->scfhandle,
19196185db85Sdougm 						    "value_authorization",
19206185db85Sdougm 						    rbacstr);
192157b448deSdougm 					}
192257b448deSdougm 					if (ret == SA_OK) {
192357b448deSdougm 						ret = sa_end_transaction(
1924*5b6e0c46Sdougm 						    impl_handle->scfhandle,
1925*5b6e0c46Sdougm 						    impl_handle);
192657b448deSdougm 					} else {
192757b448deSdougm 						sa_abort_transaction(
192857b448deSdougm 						    impl_handle->scfhandle);
192957b448deSdougm 					}
193057b448deSdougm 				}
193157b448deSdougm 				if (ret != SA_OK) {
193257b448deSdougm 					/*
193357b448deSdougm 					 * Couldn't commit the group
193457b448deSdougm 					 * so we need to undo
193557b448deSdougm 					 * internally.
193657b448deSdougm 					 */
193757b448deSdougm 					xmlUnlinkNode(node);
193857b448deSdougm 					xmlFreeNode(node);
193957b448deSdougm 					node = NULL;
194057b448deSdougm 				}
19416185db85Sdougm 			} else {
194257b448deSdougm 				ret = SA_NO_MEMORY;
19436185db85Sdougm 			}
19446185db85Sdougm 		} else {
194557b448deSdougm 			ret = SA_INVALID_NAME;
19466185db85Sdougm 		}
19476185db85Sdougm 	}
19486185db85Sdougm err:
19496185db85Sdougm 	if (error != NULL)
195057b448deSdougm 		*error = ret;
19516185db85Sdougm 	return ((sa_group_t)node);
19526185db85Sdougm }
19536185db85Sdougm 
19546185db85Sdougm /*
19556185db85Sdougm  * sa_remove_group(group)
19566185db85Sdougm  *
19576185db85Sdougm  * Remove the specified group. This deletes from the SMF repository.
19586185db85Sdougm  * All property groups and properties are removed.
19596185db85Sdougm  */
19606185db85Sdougm 
19616185db85Sdougm int
19626185db85Sdougm sa_remove_group(sa_group_t group)
19636185db85Sdougm {
19646185db85Sdougm 	char *name;
19656185db85Sdougm 	int ret = SA_OK;
1966549ec3ffSdougm 	sa_handle_impl_t impl_handle;
19676185db85Sdougm 
1968549ec3ffSdougm 	impl_handle = (sa_handle_impl_t)sa_find_group_handle(group);
1969549ec3ffSdougm 	if (impl_handle != NULL) {
197057b448deSdougm 		name = sa_get_group_attr(group, "name");
197157b448deSdougm 		if (name != NULL) {
197257b448deSdougm 			ret = sa_delete_instance(impl_handle->scfhandle, name);
197357b448deSdougm 			sa_free_attr_string(name);
197457b448deSdougm 		}
197557b448deSdougm 		xmlUnlinkNode((xmlNodePtr)group); /* make sure unlinked */
197657b448deSdougm 		xmlFreeNode((xmlNodePtr)group);   /* now it is gone */
1977549ec3ffSdougm 	} else {
197857b448deSdougm 		ret = SA_SYSTEM_ERR;
19796185db85Sdougm 	}
19806185db85Sdougm 	return (ret);
19816185db85Sdougm }
19826185db85Sdougm 
19836185db85Sdougm /*
19846185db85Sdougm  * sa_update_config()
19856185db85Sdougm  *
19866185db85Sdougm  * Used to update legacy files that need to be updated in bulk
19876185db85Sdougm  * Currently, this is a placeholder and will go away in a future
19886185db85Sdougm  * release.
19896185db85Sdougm  */
19906185db85Sdougm 
19916185db85Sdougm int
1992549ec3ffSdougm sa_update_config(sa_handle_t handle)
19936185db85Sdougm {
19946185db85Sdougm 	/*
19956185db85Sdougm 	 * do legacy files first so we can tell when they change.
19966185db85Sdougm 	 * This will go away when we start updating individual records
19976185db85Sdougm 	 * rather than the whole file.
19986185db85Sdougm 	 */
1999549ec3ffSdougm 	update_legacy_config(handle);
20006185db85Sdougm 	return (SA_OK);
20016185db85Sdougm }
20026185db85Sdougm 
20036185db85Sdougm /*
20046185db85Sdougm  * get_node_attr(node, tag)
20056185db85Sdougm  *
2006da6c28aaSamw  * Get the specified tag(attribute) if it exists on the node.  This is
20076185db85Sdougm  * used internally by a number of attribute oriented functions.
20086185db85Sdougm  */
20096185db85Sdougm 
20106185db85Sdougm static char *
20116185db85Sdougm get_node_attr(void *nodehdl, char *tag)
20126185db85Sdougm {
20136185db85Sdougm 	xmlNodePtr node = (xmlNodePtr)nodehdl;
20146185db85Sdougm 	xmlChar *name = NULL;
20156185db85Sdougm 
201657b448deSdougm 	if (node != NULL)
20176185db85Sdougm 		name = xmlGetProp(node, (xmlChar *)tag);
20186185db85Sdougm 	return ((char *)name);
20196185db85Sdougm }
20206185db85Sdougm 
20216185db85Sdougm /*
20226185db85Sdougm  * get_node_attr(node, tag)
20236185db85Sdougm  *
2024da6c28aaSamw  * Set the specified tag(attribute) to the specified value This is
20256185db85Sdougm  * used internally by a number of attribute oriented functions. It
20266185db85Sdougm  * doesn't update the repository, only the internal document state.
20276185db85Sdougm  */
20286185db85Sdougm 
20296185db85Sdougm void
20306185db85Sdougm set_node_attr(void *nodehdl, char *tag, char *value)
20316185db85Sdougm {
20326185db85Sdougm 	xmlNodePtr node = (xmlNodePtr)nodehdl;
20336185db85Sdougm 	if (node != NULL && tag != NULL) {
203457b448deSdougm 		if (value != NULL)
20356185db85Sdougm 			xmlSetProp(node, (xmlChar *)tag, (xmlChar *)value);
203657b448deSdougm 		else
20376185db85Sdougm 			xmlUnsetProp(node, (xmlChar *)tag);
20386185db85Sdougm 	}
20396185db85Sdougm }
20406185db85Sdougm 
20416185db85Sdougm /*
20426185db85Sdougm  * sa_get_group_attr(group, tag)
20436185db85Sdougm  *
20446185db85Sdougm  * Get the specied attribute, if defined, for the group.
20456185db85Sdougm  */
20466185db85Sdougm 
20476185db85Sdougm char *
20486185db85Sdougm sa_get_group_attr(sa_group_t group, char *tag)
20496185db85Sdougm {
20506185db85Sdougm 	return (get_node_attr((void *)group, tag));
20516185db85Sdougm }
20526185db85Sdougm 
20536185db85Sdougm /*
20546185db85Sdougm  * sa_set_group_attr(group, tag, value)
20556185db85Sdougm  *
20566185db85Sdougm  * set the specified tag/attribute on the group using value as its
20576185db85Sdougm  * value.
20586185db85Sdougm  *
20596185db85Sdougm  * This will result in setting the property in the SMF repository as
20606185db85Sdougm  * well as in the internal document.
20616185db85Sdougm  */
20626185db85Sdougm 
20636185db85Sdougm int
20646185db85Sdougm sa_set_group_attr(sa_group_t group, char *tag, char *value)
20656185db85Sdougm {
20666185db85Sdougm 	int ret;
20676185db85Sdougm 	char *groupname;
2068549ec3ffSdougm 	sa_handle_impl_t impl_handle;
20696185db85Sdougm 
2070da6c28aaSamw 	/*
2071da6c28aaSamw 	 * ZFS group/subgroup doesn't need the handle so shortcut.
2072da6c28aaSamw 	 */
2073da6c28aaSamw 	if (sa_group_is_zfs(group)) {
2074da6c28aaSamw 		set_node_attr((void *)group, tag, value);
2075da6c28aaSamw 		return (SA_OK);
2076da6c28aaSamw 	}
2077da6c28aaSamw 
2078549ec3ffSdougm 	impl_handle = (sa_handle_impl_t)sa_find_group_handle(group);
2079549ec3ffSdougm 	if (impl_handle != NULL) {
208057b448deSdougm 		groupname = sa_get_group_attr(group, "name");
208157b448deSdougm 		ret = sa_get_instance(impl_handle->scfhandle, groupname);
2082549ec3ffSdougm 		if (ret == SA_OK) {
208357b448deSdougm 			set_node_attr((void *)group, tag, value);
208457b448deSdougm 			ret = sa_start_transaction(impl_handle->scfhandle,
208557b448deSdougm 			    "operation");
208657b448deSdougm 			if (ret == SA_OK) {
208757b448deSdougm 				ret = sa_set_property(impl_handle->scfhandle,
208857b448deSdougm 				    tag, value);
208957b448deSdougm 				if (ret == SA_OK)
2090573b0c00Sdougm 					ret = sa_end_transaction(
2091*5b6e0c46Sdougm 					    impl_handle->scfhandle,
2092*5b6e0c46Sdougm 					    impl_handle);
209357b448deSdougm 				else
209457b448deSdougm 					sa_abort_transaction(
209557b448deSdougm 					    impl_handle->scfhandle);
209657b448deSdougm 			}
2097573b0c00Sdougm 			if (ret == SA_SYSTEM_ERR)
2098573b0c00Sdougm 				ret = SA_NO_PERMISSION;
20996185db85Sdougm 		}
210057b448deSdougm 		if (groupname != NULL)
210157b448deSdougm 			sa_free_attr_string(groupname);
2102549ec3ffSdougm 	} else {
210357b448deSdougm 		ret = SA_SYSTEM_ERR;
21046185db85Sdougm 	}
21056185db85Sdougm 	return (ret);
21066185db85Sdougm }
21076185db85Sdougm 
21086185db85Sdougm /*
21096185db85Sdougm  * sa_get_share_attr(share, tag)
21106185db85Sdougm  *
21116185db85Sdougm  * Return the value of the tag/attribute set on the specified
21126185db85Sdougm  * share. Returns NULL if the tag doesn't exist.
21136185db85Sdougm  */
21146185db85Sdougm 
21156185db85Sdougm char *
21166185db85Sdougm sa_get_share_attr(sa_share_t share, char *tag)
21176185db85Sdougm {
21186185db85Sdougm 	return (get_node_attr((void *)share, tag));
21196185db85Sdougm }
21206185db85Sdougm 
21216185db85Sdougm /*
21226185db85Sdougm  * _sa_set_share_description(share, description)
21236185db85Sdougm  *
2124da6c28aaSamw  * Add a description tag with text contents to the specified share.  A
2125da6c28aaSamw  * separate XML tag is used rather than a property. This can also be
2126da6c28aaSamw  * used with resources.
21276185db85Sdougm  */
21286185db85Sdougm 
21296185db85Sdougm xmlNodePtr
2130da6c28aaSamw _sa_set_share_description(void *share, char *content)
21316185db85Sdougm {
21326185db85Sdougm 	xmlNodePtr node;
213357b448deSdougm 	node = xmlNewChild((xmlNodePtr)share, NULL, (xmlChar *)"description",
213457b448deSdougm 	    NULL);
21356185db85Sdougm 	xmlNodeSetContent(node, (xmlChar *)content);
21366185db85Sdougm 	return (node);
21376185db85Sdougm }
21386185db85Sdougm 
21396185db85Sdougm /*
21406185db85Sdougm  * sa_set_share_attr(share, tag, value)
21416185db85Sdougm  *
21426185db85Sdougm  * Set the share attribute specified by tag to the specified value. In
21436185db85Sdougm  * the case of "resource", enforce a no duplicates in a group rule. If
21446185db85Sdougm  * the share is not transient, commit the changes to the repository
21456185db85Sdougm  * else just update the share internally.
21466185db85Sdougm  */
21476185db85Sdougm 
21486185db85Sdougm int
21496185db85Sdougm sa_set_share_attr(sa_share_t share, char *tag, char *value)
21506185db85Sdougm {
21516185db85Sdougm 	sa_group_t group;
21526185db85Sdougm 	sa_share_t resource;
21536185db85Sdougm 	int ret = SA_OK;
21546185db85Sdougm 
21556185db85Sdougm 	group = sa_get_parent_group(share);
21566185db85Sdougm 
21576185db85Sdougm 	/*
21586185db85Sdougm 	 * There are some attributes that may have specific
21596185db85Sdougm 	 * restrictions on them. Initially, only "resource" has
21606185db85Sdougm 	 * special meaning that needs to be checked. Only one instance
21616185db85Sdougm 	 * of a resource name may exist within a group.
21626185db85Sdougm 	 */
21636185db85Sdougm 
21646185db85Sdougm 	if (strcmp(tag, "resource") == 0) {
216557b448deSdougm 		resource = sa_get_resource(group, value);
216657b448deSdougm 		if (resource != share && resource != NULL)
216757b448deSdougm 			ret = SA_DUPLICATE_NAME;
21686185db85Sdougm 	}
21696185db85Sdougm 	if (ret == SA_OK) {
217057b448deSdougm 		set_node_attr((void *)share, tag, value);
217157b448deSdougm 		if (group != NULL) {
217257b448deSdougm 			char *type;
217357b448deSdougm 			/* we can probably optimize this some */
217457b448deSdougm 			type = sa_get_share_attr(share, "type");
217557b448deSdougm 			if (type == NULL || strcmp(type, "transient") != 0) {
217657b448deSdougm 				sa_handle_impl_t impl_handle;
217757b448deSdougm 				impl_handle =
217857b448deSdougm 				    (sa_handle_impl_t)sa_find_group_handle(
217957b448deSdougm 				    group);
218057b448deSdougm 				if (impl_handle != NULL) {
218157b448deSdougm 					ret = sa_commit_share(
218257b448deSdougm 					    impl_handle->scfhandle, group,
218357b448deSdougm 					    share);
218457b448deSdougm 				} else {
218557b448deSdougm 					ret = SA_SYSTEM_ERR;
218657b448deSdougm 				}
218757b448deSdougm 			}
218857b448deSdougm 			if (type != NULL)
218957b448deSdougm 				sa_free_attr_string(type);
2190549ec3ffSdougm 		}
21916185db85Sdougm 	}
21926185db85Sdougm 	return (ret);
21936185db85Sdougm }
21946185db85Sdougm 
21956185db85Sdougm /*
21966185db85Sdougm  * sa_get_property_attr(prop, tag)
21976185db85Sdougm  *
21986185db85Sdougm  * Get the value of the specified property attribute. Standard
21996185db85Sdougm  * attributes are "type" and "value".
22006185db85Sdougm  */
22016185db85Sdougm 
22026185db85Sdougm char *
22036185db85Sdougm sa_get_property_attr(sa_property_t prop, char *tag)
22046185db85Sdougm {
22056185db85Sdougm 	return (get_node_attr((void *)prop, tag));
22066185db85Sdougm }
22076185db85Sdougm 
22086185db85Sdougm /*
22096185db85Sdougm  * sa_get_optionset_attr(prop, tag)
22106185db85Sdougm  *
22116185db85Sdougm  * Get the value of the specified property attribute. Standard
22126185db85Sdougm  * attribute is "type".
22136185db85Sdougm  */
22146185db85Sdougm 
22156185db85Sdougm char *
22166185db85Sdougm sa_get_optionset_attr(sa_property_t optionset, char *tag)
22176185db85Sdougm {
22186185db85Sdougm 	return (get_node_attr((void *)optionset, tag));
22196185db85Sdougm 
22206185db85Sdougm }
22216185db85Sdougm 
22226185db85Sdougm /*
22236185db85Sdougm  * sa_set_optionset_attr(optionset, tag, value)
22246185db85Sdougm  *
22256185db85Sdougm  * Set the specified attribute(tag) to the specified value on the
22266185db85Sdougm  * optionset.
22276185db85Sdougm  */
22286185db85Sdougm 
22296185db85Sdougm void
22306185db85Sdougm sa_set_optionset_attr(sa_group_t optionset, char *tag, char *value)
22316185db85Sdougm {
22326185db85Sdougm 	set_node_attr((void *)optionset, tag, value);
22336185db85Sdougm }
22346185db85Sdougm 
22356185db85Sdougm /*
22366185db85Sdougm  * sa_free_attr_string(string)
22376185db85Sdougm  *
22386185db85Sdougm  * Free the string that was returned in one of the sa_get_*_attr()
22396185db85Sdougm  * functions.
22406185db85Sdougm  */
22416185db85Sdougm 
22426185db85Sdougm void
22436185db85Sdougm sa_free_attr_string(char *string)
22446185db85Sdougm {
22456185db85Sdougm 	xmlFree((xmlChar *)string);
22466185db85Sdougm }
22476185db85Sdougm 
22486185db85Sdougm /*
22496185db85Sdougm  * sa_get_optionset(group, proto)
22506185db85Sdougm  *
22516185db85Sdougm  * Return the optionset, if it exists, that is associated with the
22526185db85Sdougm  * specified protocol.
22536185db85Sdougm  */
22546185db85Sdougm 
22556185db85Sdougm sa_optionset_t
22566185db85Sdougm sa_get_optionset(void *group, char *proto)
22576185db85Sdougm {
22586185db85Sdougm 	xmlNodePtr node;
22596185db85Sdougm 	xmlChar *value = NULL;
22606185db85Sdougm 
22616185db85Sdougm 	for (node = ((xmlNodePtr)group)->children; node != NULL;
226257b448deSdougm 	    node = node->next) {
22636185db85Sdougm 		if (xmlStrcmp(node->name, (xmlChar *)"optionset") == 0) {
226457b448deSdougm 			value = xmlGetProp(node, (xmlChar *)"type");
226557b448deSdougm 			if (proto != NULL) {
226657b448deSdougm 				if (value != NULL &&
226757b448deSdougm 				    xmlStrcmp(value, (xmlChar *)proto) == 0) {
226857b448deSdougm 					break;
226957b448deSdougm 				}
227057b448deSdougm 				if (value != NULL) {
227157b448deSdougm 					xmlFree(value);
227257b448deSdougm 					value = NULL;
227357b448deSdougm 				}
227457b448deSdougm 			} else {
227557b448deSdougm 				break;
22766185db85Sdougm 			}
22776185db85Sdougm 		}
22786185db85Sdougm 	}
22796185db85Sdougm 	if (value != NULL)
228057b448deSdougm 		xmlFree(value);
22816185db85Sdougm 	return ((sa_optionset_t)node);
22826185db85Sdougm }
22836185db85Sdougm 
22846185db85Sdougm /*
22856185db85Sdougm  * sa_get_next_optionset(optionset)
22866185db85Sdougm  *
22876185db85Sdougm  * Return the next optionset in the group. NULL if this was the last.
22886185db85Sdougm  */
22896185db85Sdougm 
22906185db85Sdougm sa_optionset_t
22916185db85Sdougm sa_get_next_optionset(sa_optionset_t optionset)
22926185db85Sdougm {
22936185db85Sdougm 	xmlNodePtr node;
22946185db85Sdougm 
22956185db85Sdougm 	for (node = ((xmlNodePtr)optionset)->next; node != NULL;
229657b448deSdougm 	    node = node->next) {
22976185db85Sdougm 		if (xmlStrcmp(node->name, (xmlChar *)"optionset") == 0) {
22986185db85Sdougm 			break;
22996185db85Sdougm 		}
23006185db85Sdougm 	}
23016185db85Sdougm 	return ((sa_optionset_t)node);
23026185db85Sdougm }
23036185db85Sdougm 
23046185db85Sdougm /*
23056185db85Sdougm  * sa_get_security(group, sectype, proto)
23066185db85Sdougm  *
23076185db85Sdougm  * Return the security optionset. The internal name is a hold over
23086185db85Sdougm  * from the implementation and will be changed before the API is
23096185db85Sdougm  * finalized. This is really a named optionset that can be negotiated
23106185db85Sdougm  * as a group of properties (like NFS security options).
23116185db85Sdougm  */
23126185db85Sdougm 
23136185db85Sdougm sa_security_t
23146185db85Sdougm sa_get_security(sa_group_t group, char *sectype, char *proto)
23156185db85Sdougm {
23166185db85Sdougm 	xmlNodePtr node;
23176185db85Sdougm 	xmlChar *value = NULL;
23186185db85Sdougm 
23196185db85Sdougm 	for (node = ((xmlNodePtr)group)->children; node != NULL;
232057b448deSdougm 	    node = node->next) {
232157b448deSdougm 		if (xmlStrcmp(node->name, (xmlChar *)"security") == 0) {
232257b448deSdougm 			if (proto != NULL) {
232357b448deSdougm 				value = xmlGetProp(node, (xmlChar *)"type");
232457b448deSdougm 				if (value == NULL ||
232557b448deSdougm 				    (value != NULL &&
232657b448deSdougm 				    xmlStrcmp(value, (xmlChar *)proto) != 0)) {
232757b448deSdougm 					/* it doesn't match so continue */
232857b448deSdougm 					xmlFree(value);
232957b448deSdougm 					value = NULL;
233057b448deSdougm 					continue;
233157b448deSdougm 				}
233257b448deSdougm 			}
233357b448deSdougm 			if (value != NULL) {
233457b448deSdougm 				xmlFree(value);
233557b448deSdougm 				value = NULL;
233657b448deSdougm 			}
233757b448deSdougm 			/* potential match */
233857b448deSdougm 			if (sectype != NULL) {
233957b448deSdougm 				value = xmlGetProp(node, (xmlChar *)"sectype");
234057b448deSdougm 				if (value != NULL &&
234157b448deSdougm 				    xmlStrcmp(value, (xmlChar *)sectype) == 0) {
234257b448deSdougm 					break;
234357b448deSdougm 				}
234457b448deSdougm 			} else {
234557b448deSdougm 				break;
234657b448deSdougm 			}
23476185db85Sdougm 		}
23486185db85Sdougm 		if (value != NULL) {
234957b448deSdougm 			xmlFree(value);
235057b448deSdougm 			value = NULL;
23516185db85Sdougm 		}
23526185db85Sdougm 	}
23536185db85Sdougm 	if (value != NULL)
235457b448deSdougm 		xmlFree(value);
23556185db85Sdougm 	return ((sa_security_t)node);
23566185db85Sdougm }
23576185db85Sdougm 
23586185db85Sdougm /*
23596185db85Sdougm  * sa_get_next_security(security)
23606185db85Sdougm  *
23616185db85Sdougm  * Get the next security optionset if one exists.
23626185db85Sdougm  */
23636185db85Sdougm 
23646185db85Sdougm sa_security_t
23656185db85Sdougm sa_get_next_security(sa_security_t security)
23666185db85Sdougm {
23676185db85Sdougm 	xmlNodePtr node;
23686185db85Sdougm 
23696185db85Sdougm 	for (node = ((xmlNodePtr)security)->next; node != NULL;
237057b448deSdougm 	    node = node->next) {
23716185db85Sdougm 		if (xmlStrcmp(node->name, (xmlChar *)"security") == 0) {
23726185db85Sdougm 			break;
23736185db85Sdougm 		}
23746185db85Sdougm 	}
23756185db85Sdougm 	return ((sa_security_t)node);
23766185db85Sdougm }
23776185db85Sdougm 
23786185db85Sdougm /*
23796185db85Sdougm  * sa_get_property(optionset, prop)
23806185db85Sdougm  *
23816185db85Sdougm  * Get the property object with the name specified in prop from the
23826185db85Sdougm  * optionset.
23836185db85Sdougm  */
23846185db85Sdougm 
23856185db85Sdougm sa_property_t
23866185db85Sdougm sa_get_property(sa_optionset_t optionset, char *prop)
23876185db85Sdougm {
23886185db85Sdougm 	xmlNodePtr node = (xmlNodePtr)optionset;
23896185db85Sdougm 	xmlChar *value = NULL;
23906185db85Sdougm 
23916185db85Sdougm 	if (optionset == NULL)
239257b448deSdougm 		return (NULL);
23936185db85Sdougm 
23946185db85Sdougm 	for (node = node->children; node != NULL;
239557b448deSdougm 	    node = node->next) {
239657b448deSdougm 		if (xmlStrcmp(node->name, (xmlChar *)"option") == 0) {
239757b448deSdougm 			if (prop == NULL)
239857b448deSdougm 				break;
239957b448deSdougm 			value = xmlGetProp(node, (xmlChar *)"type");
240057b448deSdougm 			if (value != NULL &&
240157b448deSdougm 			    xmlStrcmp(value, (xmlChar *)prop) == 0) {
240257b448deSdougm 				break;
240357b448deSdougm 			}
240457b448deSdougm 			if (value != NULL) {
240557b448deSdougm 				xmlFree(value);
240657b448deSdougm 				value = NULL;
240757b448deSdougm 			}
24086185db85Sdougm 		}
24096185db85Sdougm 	}
24106185db85Sdougm 	if (value != NULL)
24116185db85Sdougm 		xmlFree(value);
24126185db85Sdougm 	if (node != NULL && xmlStrcmp(node->name, (xmlChar *)"option") != 0) {
241357b448deSdougm 		/*
241457b448deSdougm 		 * avoid a non option node -- it is possible to be a
241557b448deSdougm 		 * text node
241657b448deSdougm 		 */
241757b448deSdougm 		node = NULL;
24186185db85Sdougm 	}
24196185db85Sdougm 	return ((sa_property_t)node);
24206185db85Sdougm }
24216185db85Sdougm 
24226185db85Sdougm /*
24236185db85Sdougm  * sa_get_next_property(property)
24246185db85Sdougm  *
24256185db85Sdougm  * Get the next property following the specified property. NULL if
24266185db85Sdougm  * this was the last.
24276185db85Sdougm  */
24286185db85Sdougm 
24296185db85Sdougm sa_property_t
24306185db85Sdougm sa_get_next_property(sa_property_t property)
24316185db85Sdougm {
24326185db85Sdougm 	xmlNodePtr node;
24336185db85Sdougm 
24346185db85Sdougm 	for (node = ((xmlNodePtr)property)->next; node != NULL;
243557b448deSdougm 	    node = node->next) {
24366185db85Sdougm 		if (xmlStrcmp(node->name, (xmlChar *)"option") == 0) {
24376185db85Sdougm 			break;
24386185db85Sdougm 		}
24396185db85Sdougm 	}
24406185db85Sdougm 	return ((sa_property_t)node);
24416185db85Sdougm }
24426185db85Sdougm 
24436185db85Sdougm /*
24446185db85Sdougm  * sa_set_share_description(share, content)
24456185db85Sdougm  *
24466185db85Sdougm  * Set the description of share to content.
24476185db85Sdougm  */
24486185db85Sdougm 
24496185db85Sdougm int
24506185db85Sdougm sa_set_share_description(sa_share_t share, char *content)
24516185db85Sdougm {
24526185db85Sdougm 	xmlNodePtr node;
24536185db85Sdougm 	sa_group_t group;
24546185db85Sdougm 	int ret = SA_OK;
24556185db85Sdougm 
24566185db85Sdougm 	for (node = ((xmlNodePtr)share)->children; node != NULL;
245757b448deSdougm 	    node = node->next) {
24586185db85Sdougm 		if (xmlStrcmp(node->name, (xmlChar *)"description") == 0) {
24596185db85Sdougm 			break;
24606185db85Sdougm 		}
24616185db85Sdougm 	}
24626185db85Sdougm 	/* no existing description but want to add */
24636185db85Sdougm 	if (node == NULL && content != NULL) {
24646185db85Sdougm 		/* add a description */
246557b448deSdougm 		node = _sa_set_share_description(share, content);
24666185db85Sdougm 	} else if (node != NULL && content != NULL) {
24676185db85Sdougm 		/* update a description */
24686185db85Sdougm 		xmlNodeSetContent(node, (xmlChar *)content);
24696185db85Sdougm 	} else if (node != NULL && content == NULL) {
24706185db85Sdougm 		/* remove an existing description */
24716185db85Sdougm 		xmlUnlinkNode(node);
24726185db85Sdougm 		xmlFreeNode(node);
24736185db85Sdougm 	}
2474da6c28aaSamw 	group = sa_get_parent_group(share);
2475da6c28aaSamw 	if (group != NULL && sa_is_persistent(share)) {
247657b448deSdougm 		sa_handle_impl_t impl_handle;
247757b448deSdougm 		impl_handle = (sa_handle_impl_t)sa_find_group_handle(group);
247857b448deSdougm 		if (impl_handle != NULL) {
247957b448deSdougm 			ret = sa_commit_share(impl_handle->scfhandle, group,
248057b448deSdougm 			    share);
248157b448deSdougm 		} else {
248257b448deSdougm 			ret = SA_SYSTEM_ERR;
248357b448deSdougm 		}
2484549ec3ffSdougm 	}
24856185db85Sdougm 	return (ret);
24866185db85Sdougm }
24876185db85Sdougm 
24886185db85Sdougm /*
24896185db85Sdougm  * fixproblemchars(string)
24906185db85Sdougm  *
24916185db85Sdougm  * don't want any newline or tab characters in the text since these
24926185db85Sdougm  * could break display of data and legacy file formats.
24936185db85Sdougm  */
24946185db85Sdougm static void
24956185db85Sdougm fixproblemchars(char *str)
24966185db85Sdougm {
24976185db85Sdougm 	int c;
24986185db85Sdougm 	for (c = *str; c != '\0'; c = *++str) {
249957b448deSdougm 		if (c == '\t' || c == '\n')
250057b448deSdougm 			*str = ' ';
250157b448deSdougm 		else if (c == '"')
250257b448deSdougm 			*str = '\'';
25036185db85Sdougm 	}
25046185db85Sdougm }
25056185db85Sdougm 
25066185db85Sdougm /*
25076185db85Sdougm  * sa_get_share_description(share)
25086185db85Sdougm  *
25096185db85Sdougm  * Return the description text for the specified share if it
25106185db85Sdougm  * exists. NULL if no description exists.
25116185db85Sdougm  */
25126185db85Sdougm 
25136185db85Sdougm char *
25146185db85Sdougm sa_get_share_description(sa_share_t share)
25156185db85Sdougm {
25166185db85Sdougm 	xmlChar *description = NULL;
25176185db85Sdougm 	xmlNodePtr node;
25186185db85Sdougm 
25196185db85Sdougm 	for (node = ((xmlNodePtr)share)->children; node != NULL;
252057b448deSdougm 	    node = node->next) {
252157b448deSdougm 		if (xmlStrcmp(node->name, (xmlChar *)"description") == 0) {
252257b448deSdougm 			break;
252357b448deSdougm 		}
25246185db85Sdougm 	}
25256185db85Sdougm 	if (node != NULL) {
2526da6c28aaSamw 		description = xmlNodeGetContent(node);
252757b448deSdougm 		fixproblemchars((char *)description);
25286185db85Sdougm 	}
25296185db85Sdougm 	return ((char *)description);
25306185db85Sdougm }
25316185db85Sdougm 
25326185db85Sdougm /*
25336185db85Sdougm  * sa_free(share_description(description)
25346185db85Sdougm  *
25356185db85Sdougm  * Free the description string.
25366185db85Sdougm  */
25376185db85Sdougm 
25386185db85Sdougm void
25396185db85Sdougm sa_free_share_description(char *description)
25406185db85Sdougm {
25416185db85Sdougm 	xmlFree((xmlChar *)description);
25426185db85Sdougm }
25436185db85Sdougm 
25446185db85Sdougm /*
25456185db85Sdougm  * sa_create_optionset(group, proto)
25466185db85Sdougm  *
25476185db85Sdougm  * Create an optionset for the specified protocol in the specied
25486185db85Sdougm  * group. This is manifested as a property group within SMF.
25496185db85Sdougm  */
25506185db85Sdougm 
25516185db85Sdougm sa_optionset_t
25526185db85Sdougm sa_create_optionset(sa_group_t group, char *proto)
25536185db85Sdougm {
25546185db85Sdougm 	sa_optionset_t optionset;
25556185db85Sdougm 	sa_group_t parent = group;
2556da6c28aaSamw 	sa_share_t share = NULL;
2557da6c28aaSamw 	int err = SA_OK;
2558da6c28aaSamw 	char *id = NULL;
25596185db85Sdougm 
25606185db85Sdougm 	optionset = sa_get_optionset(group, proto);
25616185db85Sdougm 	if (optionset != NULL) {
25626185db85Sdougm 		/* can't have a duplicate protocol */
256357b448deSdougm 		optionset = NULL;
25646185db85Sdougm 	} else {
2565da6c28aaSamw 		/*
2566da6c28aaSamw 		 * Account for resource names being slightly
2567da6c28aaSamw 		 * different.
2568da6c28aaSamw 		 */
2569da6c28aaSamw 		if (sa_is_share(group)) {
2570da6c28aaSamw 			/*
2571da6c28aaSamw 			 * Transient shares do not have an "id" so not an
2572da6c28aaSamw 			 * error to not find one.
2573da6c28aaSamw 			 */
2574da6c28aaSamw 			id = sa_get_share_attr((sa_share_t)group, "id");
2575da6c28aaSamw 		} else if (sa_is_resource(group)) {
2576da6c28aaSamw 			share = sa_get_resource_parent(
2577da6c28aaSamw 			    (sa_resource_t)group);
2578da6c28aaSamw 			id = sa_get_resource_attr(share, "id");
2579da6c28aaSamw 
2580da6c28aaSamw 			/* id can be NULL if the group is transient (ZFS) */
2581da6c28aaSamw 			if (id == NULL && sa_is_persistent(group))
2582da6c28aaSamw 				err = SA_NO_MEMORY;
2583da6c28aaSamw 		}
2584da6c28aaSamw 		if (err == SA_NO_MEMORY) {
2585da6c28aaSamw 			/*
2586da6c28aaSamw 			 * Couldn't get the id for the share or
2587da6c28aaSamw 			 * resource. While this could be a
2588da6c28aaSamw 			 * configuration issue, it is most likely an
2589da6c28aaSamw 			 * out of memory. In any case, fail the create.
2590da6c28aaSamw 			 */
2591da6c28aaSamw 			return (NULL);
2592da6c28aaSamw 		}
2593da6c28aaSamw 
259457b448deSdougm 		optionset = (sa_optionset_t)xmlNewChild((xmlNodePtr)group,
259557b448deSdougm 		    NULL, (xmlChar *)"optionset", NULL);
25966185db85Sdougm 		/*
25976185db85Sdougm 		 * only put to repository if on a group and we were
25986185db85Sdougm 		 * able to create an optionset.
25996185db85Sdougm 		 */
260057b448deSdougm 		if (optionset != NULL) {
260157b448deSdougm 			char oname[SA_STRSIZE];
260257b448deSdougm 			char *groupname;
26036185db85Sdougm 
2604da6c28aaSamw 			/*
2605da6c28aaSamw 			 * Need to get parent group in all cases, but also get
2606da6c28aaSamw 			 * the share if this is a resource.
2607da6c28aaSamw 			 */
2608da6c28aaSamw 			if (sa_is_share(group)) {
260957b448deSdougm 				parent = sa_get_parent_group((sa_share_t)group);
2610da6c28aaSamw 			} else if (sa_is_resource(group)) {
2611da6c28aaSamw 				share = sa_get_resource_parent(
2612da6c28aaSamw 				    (sa_resource_t)group);
2613da6c28aaSamw 				parent = sa_get_parent_group(share);
2614da6c28aaSamw 			}
26156185db85Sdougm 
261657b448deSdougm 			sa_set_optionset_attr(optionset, "type", proto);
26176185db85Sdougm 
261857b448deSdougm 			(void) sa_optionset_name(optionset, oname,
261957b448deSdougm 			    sizeof (oname), id);
262057b448deSdougm 			groupname = sa_get_group_attr(parent, "name");
2621da6c28aaSamw 			if (groupname != NULL && sa_is_persistent(group)) {
262257b448deSdougm 				sa_handle_impl_t impl_handle;
2623da6c28aaSamw 				impl_handle =
2624da6c28aaSamw 				    (sa_handle_impl_t)sa_find_group_handle(
2625da6c28aaSamw 				    group);
262657b448deSdougm 				assert(impl_handle != NULL);
262757b448deSdougm 				if (impl_handle != NULL) {
262857b448deSdougm 					(void) sa_get_instance(
2629da6c28aaSamw 					    impl_handle->scfhandle, groupname);
263057b448deSdougm 					(void) sa_create_pgroup(
263157b448deSdougm 					    impl_handle->scfhandle, oname);
263257b448deSdougm 				}
263357b448deSdougm 			}
263457b448deSdougm 			if (groupname != NULL)
263557b448deSdougm 				sa_free_attr_string(groupname);
26366185db85Sdougm 		}
26376185db85Sdougm 	}
2638da6c28aaSamw 
2639da6c28aaSamw 	if (id != NULL)
2640da6c28aaSamw 		sa_free_attr_string(id);
26416185db85Sdougm 	return (optionset);
26426185db85Sdougm }
26436185db85Sdougm 
26446185db85Sdougm /*
26456185db85Sdougm  * sa_get_property_parent(property)
26466185db85Sdougm  *
26476185db85Sdougm  * Given a property, return the object it is a property of. This will
26486185db85Sdougm  * be an optionset of some type.
26496185db85Sdougm  */
26506185db85Sdougm 
26516185db85Sdougm static sa_optionset_t
26526185db85Sdougm sa_get_property_parent(sa_property_t property)
26536185db85Sdougm {
26546185db85Sdougm 	xmlNodePtr node = NULL;
26556185db85Sdougm 
265657b448deSdougm 	if (property != NULL)
265757b448deSdougm 		node = ((xmlNodePtr)property)->parent;
26586185db85Sdougm 	return ((sa_optionset_t)node);
26596185db85Sdougm }
26606185db85Sdougm 
26616185db85Sdougm /*
26626185db85Sdougm  * sa_get_optionset_parent(optionset)
26636185db85Sdougm  *
26646185db85Sdougm  * Return the parent of the specified optionset. This could be a group
26656185db85Sdougm  * or a share.
26666185db85Sdougm  */
26676185db85Sdougm 
26686185db85Sdougm static sa_group_t
26696185db85Sdougm sa_get_optionset_parent(sa_optionset_t optionset)
26706185db85Sdougm {
26716185db85Sdougm 	xmlNodePtr node = NULL;
26726185db85Sdougm 
267357b448deSdougm 	if (optionset != NULL)
267457b448deSdougm 		node = ((xmlNodePtr)optionset)->parent;
26756185db85Sdougm 	return ((sa_group_t)node);
26766185db85Sdougm }
26776185db85Sdougm 
26786185db85Sdougm /*
26796185db85Sdougm  * zfs_needs_update(share)
26806185db85Sdougm  *
26816185db85Sdougm  * In order to avoid making multiple updates to a ZFS share when
26826185db85Sdougm  * setting properties, the share attribute "changed" will be set to
2683da6c28aaSamw  * true when a property is added or modified.  When done adding
26846185db85Sdougm  * properties, we can then detect that an update is needed.  We then
26856185db85Sdougm  * clear the state here to detect additional changes.
26866185db85Sdougm  */
26876185db85Sdougm 
26886185db85Sdougm static int
26896185db85Sdougm zfs_needs_update(sa_share_t share)
26906185db85Sdougm {
26916185db85Sdougm 	char *attr;
26926185db85Sdougm 	int result = 0;
26936185db85Sdougm 
26946185db85Sdougm 	attr = sa_get_share_attr(share, "changed");
26956185db85Sdougm 	if (attr != NULL) {
269657b448deSdougm 		sa_free_attr_string(attr);
26976185db85Sdougm 		result = 1;
26986185db85Sdougm 	}
26996185db85Sdougm 	set_node_attr((void *)share, "changed", NULL);
27006185db85Sdougm 	return (result);
27016185db85Sdougm }
27026185db85Sdougm 
27036185db85Sdougm /*
27046185db85Sdougm  * zfs_set_update(share)
27056185db85Sdougm  *
27066185db85Sdougm  * Set the changed attribute of the share to true.
27076185db85Sdougm  */
27086185db85Sdougm 
27096185db85Sdougm static void
27106185db85Sdougm zfs_set_update(sa_share_t share)
27116185db85Sdougm {
27126185db85Sdougm 	set_node_attr((void *)share, "changed", "true");
27136185db85Sdougm }
27146185db85Sdougm 
27156185db85Sdougm /*
27166185db85Sdougm  * sa_commit_properties(optionset, clear)
27176185db85Sdougm  *
27186185db85Sdougm  * Check if SMF or ZFS config and either update or abort the pending
27196185db85Sdougm  * changes.
27206185db85Sdougm  */
27216185db85Sdougm 
27226185db85Sdougm int
27236185db85Sdougm sa_commit_properties(sa_optionset_t optionset, int clear)
27246185db85Sdougm {
27256185db85Sdougm 	sa_group_t group;
27266185db85Sdougm 	sa_group_t parent;
27276185db85Sdougm 	int zfs = 0;
27286185db85Sdougm 	int needsupdate = 0;
27296185db85Sdougm 	int ret = SA_OK;
2730549ec3ffSdougm 	sa_handle_impl_t impl_handle;
27316185db85Sdougm 
27326185db85Sdougm 	group = sa_get_optionset_parent(optionset);
27336185db85Sdougm 	if (group != NULL && (sa_is_share(group) || is_zfs_group(group))) {
273457b448deSdougm 		/* only update ZFS if on a share */
273557b448deSdougm 		parent = sa_get_parent_group(group);
273657b448deSdougm 		zfs++;
273757b448deSdougm 		if (parent != NULL && is_zfs_group(parent))
273857b448deSdougm 			needsupdate = zfs_needs_update(group);
273957b448deSdougm 		else
274057b448deSdougm 			zfs = 0;
27416185db85Sdougm 	}
27426185db85Sdougm 	if (zfs) {
274357b448deSdougm 		if (!clear && needsupdate)
274457b448deSdougm 			ret = sa_zfs_update((sa_share_t)group);
27456185db85Sdougm 	} else {
274657b448deSdougm 		impl_handle = (sa_handle_impl_t)sa_find_group_handle(group);
274757b448deSdougm 		if (impl_handle != NULL) {
274857b448deSdougm 			if (clear) {
274957b448deSdougm 				(void) sa_abort_transaction(
275057b448deSdougm 				    impl_handle->scfhandle);
275157b448deSdougm 			} else {
275257b448deSdougm 				ret = sa_end_transaction(
2753*5b6e0c46Sdougm 				    impl_handle->scfhandle, impl_handle);
275457b448deSdougm 			}
275557b448deSdougm 		} else {
275657b448deSdougm 			ret = SA_SYSTEM_ERR;
275757b448deSdougm 		}
27586185db85Sdougm 	}
27596185db85Sdougm 	return (ret);
27606185db85Sdougm }
27616185db85Sdougm 
27626185db85Sdougm /*
27636185db85Sdougm  * sa_destroy_optionset(optionset)
27646185db85Sdougm  *
2765da6c28aaSamw  * Remove the optionset from its group. Update the repository to
27666185db85Sdougm  * reflect this change.
27676185db85Sdougm  */
27686185db85Sdougm 
27696185db85Sdougm int
27706185db85Sdougm sa_destroy_optionset(sa_optionset_t optionset)
27716185db85Sdougm {
277257b448deSdougm 	char name[SA_STRSIZE];
27736185db85Sdougm 	int len;
27746185db85Sdougm 	int ret;
27756185db85Sdougm 	char *id = NULL;
27766185db85Sdougm 	sa_group_t group;
27776185db85Sdougm 	int ispersist = 1;
27786185db85Sdougm 
27796185db85Sdougm 	/* now delete the prop group */
27806185db85Sdougm 	group = sa_get_optionset_parent(optionset);
2781da6c28aaSamw 	if (group != NULL) {
2782da6c28aaSamw 		if (sa_is_resource(group)) {
2783da6c28aaSamw 			sa_resource_t resource = group;
2784da6c28aaSamw 			sa_share_t share = sa_get_resource_parent(resource);
2785da6c28aaSamw 			group = sa_get_parent_group(share);
2786da6c28aaSamw 			id = sa_get_share_attr(share, "id");
2787da6c28aaSamw 		} else if (sa_is_share(group)) {
2788da6c28aaSamw 			id = sa_get_share_attr((sa_share_t)group, "id");
2789da6c28aaSamw 		}
2790da6c28aaSamw 		ispersist = sa_is_persistent(group);
27916185db85Sdougm 	}
27926185db85Sdougm 	if (ispersist) {
279357b448deSdougm 		sa_handle_impl_t impl_handle;
279457b448deSdougm 		len = sa_optionset_name(optionset, name, sizeof (name), id);
279557b448deSdougm 		impl_handle = (sa_handle_impl_t)sa_find_group_handle(group);
279657b448deSdougm 		if (impl_handle != NULL) {
279757b448deSdougm 			if (len > 0) {
279857b448deSdougm 				ret = sa_delete_pgroup(impl_handle->scfhandle,
279957b448deSdougm 				    name);
280057b448deSdougm 			}
280157b448deSdougm 		} else {
280257b448deSdougm 			ret = SA_SYSTEM_ERR;
2803549ec3ffSdougm 		}
28046185db85Sdougm 	}
28056185db85Sdougm 	xmlUnlinkNode((xmlNodePtr)optionset);
28066185db85Sdougm 	xmlFreeNode((xmlNodePtr)optionset);
28076185db85Sdougm 	if (id != NULL)
280857b448deSdougm 		sa_free_attr_string(id);
28096185db85Sdougm 	return (ret);
28106185db85Sdougm }
28116185db85Sdougm 
28126185db85Sdougm /* private to the implementation */
28136185db85Sdougm int
28146185db85Sdougm _sa_remove_optionset(sa_optionset_t optionset)
28156185db85Sdougm {
28166185db85Sdougm 	int ret = SA_OK;
28176185db85Sdougm 
28186185db85Sdougm 	xmlUnlinkNode((xmlNodePtr)optionset);
28196185db85Sdougm 	xmlFreeNode((xmlNodePtr)optionset);
28206185db85Sdougm 	return (ret);
28216185db85Sdougm }
28226185db85Sdougm 
28236185db85Sdougm /*
28246185db85Sdougm  * sa_create_security(group, sectype, proto)
28256185db85Sdougm  *
28266185db85Sdougm  * Create a security optionset (one that has a type name and a
28276185db85Sdougm  * proto). Security is left over from a pure NFS implementation. The
28286185db85Sdougm  * naming will change in the future when the API is released.
28296185db85Sdougm  */
28306185db85Sdougm sa_security_t
28316185db85Sdougm sa_create_security(sa_group_t group, char *sectype, char *proto)
28326185db85Sdougm {
28336185db85Sdougm 	sa_security_t security;
28346185db85Sdougm 	char *id = NULL;
28356185db85Sdougm 	sa_group_t parent;
28366185db85Sdougm 	char *groupname = NULL;
28376185db85Sdougm 
28386185db85Sdougm 	if (group != NULL && sa_is_share(group)) {
283957b448deSdougm 		id = sa_get_share_attr((sa_share_t)group, "id");
284057b448deSdougm 		parent = sa_get_parent_group(group);
284157b448deSdougm 		if (parent != NULL)
284257b448deSdougm 			groupname = sa_get_group_attr(parent, "name");
28436185db85Sdougm 	} else if (group != NULL) {
284457b448deSdougm 		groupname = sa_get_group_attr(group, "name");
28456185db85Sdougm 	}
28466185db85Sdougm 
28476185db85Sdougm 	security = sa_get_security(group, sectype, proto);
28486185db85Sdougm 	if (security != NULL) {
28496185db85Sdougm 		/* can't have a duplicate security option */
28506185db85Sdougm 		security = NULL;
28516185db85Sdougm 	} else {
28526185db85Sdougm 		security = (sa_security_t)xmlNewChild((xmlNodePtr)group,
285357b448deSdougm 		    NULL, (xmlChar *)"security", NULL);
28546185db85Sdougm 		if (security != NULL) {
285557b448deSdougm 			char oname[SA_STRSIZE];
28566185db85Sdougm 			sa_set_security_attr(security, "type", proto);
28576185db85Sdougm 
28586185db85Sdougm 			sa_set_security_attr(security, "sectype", sectype);
28596185db85Sdougm 			(void) sa_security_name(security, oname,
286057b448deSdougm 			    sizeof (oname), id);
2861da6c28aaSamw 			if (groupname != NULL && sa_is_persistent(group)) {
286257b448deSdougm 				sa_handle_impl_t impl_handle;
286357b448deSdougm 				impl_handle =
286457b448deSdougm 				    (sa_handle_impl_t)sa_find_group_handle(
286557b448deSdougm 				    group);
286657b448deSdougm 				if (impl_handle != NULL) {
286757b448deSdougm 					(void) sa_get_instance(
286857b448deSdougm 					    impl_handle->scfhandle, groupname);
286957b448deSdougm 					(void) sa_create_pgroup(
287057b448deSdougm 					    impl_handle->scfhandle, oname);
287157b448deSdougm 				}
28726185db85Sdougm 			}
28736185db85Sdougm 		}
28746185db85Sdougm 	}
28756185db85Sdougm 	if (groupname != NULL)
287657b448deSdougm 		sa_free_attr_string(groupname);
28776185db85Sdougm 	return (security);
28786185db85Sdougm }
28796185db85Sdougm 
28806185db85Sdougm /*
28816185db85Sdougm  * sa_destroy_security(security)
28826185db85Sdougm  *
28836185db85Sdougm  * Remove the specified optionset from the document and the
28846185db85Sdougm  * configuration.
28856185db85Sdougm  */
28866185db85Sdougm 
28876185db85Sdougm int
28886185db85Sdougm sa_destroy_security(sa_security_t security)
28896185db85Sdougm {
289057b448deSdougm 	char name[SA_STRSIZE];
28916185db85Sdougm 	int len;
28926185db85Sdougm 	int ret = SA_OK;
28936185db85Sdougm 	char *id = NULL;
28946185db85Sdougm 	sa_group_t group;
28956185db85Sdougm 	int iszfs = 0;
28966185db85Sdougm 	int ispersist = 1;
28976185db85Sdougm 
28986185db85Sdougm 	group = sa_get_optionset_parent(security);
28996185db85Sdougm 
29006185db85Sdougm 	if (group != NULL)
290157b448deSdougm 		iszfs = sa_group_is_zfs(group);
29026185db85Sdougm 
29036185db85Sdougm 	if (group != NULL && !iszfs) {
290457b448deSdougm 		if (sa_is_share(group))
2905da6c28aaSamw 			ispersist = sa_is_persistent(group);
290657b448deSdougm 		id = sa_get_share_attr((sa_share_t)group, "id");
29076185db85Sdougm 	}
29086185db85Sdougm 	if (ispersist) {
290957b448deSdougm 		len = sa_security_name(security, name, sizeof (name), id);
291057b448deSdougm 		if (!iszfs && len > 0) {
291157b448deSdougm 			sa_handle_impl_t impl_handle;
291257b448deSdougm 			impl_handle =
291357b448deSdougm 			    (sa_handle_impl_t)sa_find_group_handle(group);
291457b448deSdougm 			if (impl_handle != NULL) {
291557b448deSdougm 				ret = sa_delete_pgroup(impl_handle->scfhandle,
291657b448deSdougm 				    name);
291757b448deSdougm 			} else {
291857b448deSdougm 				ret = SA_SYSTEM_ERR;
291957b448deSdougm 			}
2920549ec3ffSdougm 		}
29216185db85Sdougm 	}
29226185db85Sdougm 	xmlUnlinkNode((xmlNodePtr)security);
29236185db85Sdougm 	xmlFreeNode((xmlNodePtr)security);
292457b448deSdougm 	if (iszfs)
292557b448deSdougm 		ret = sa_zfs_update(group);
29266185db85Sdougm 	if (id != NULL)
292757b448deSdougm 		sa_free_attr_string(id);
29286185db85Sdougm 	return (ret);
29296185db85Sdougm }
29306185db85Sdougm 
29316185db85Sdougm /*
29326185db85Sdougm  * sa_get_security_attr(optionset, tag)
29336185db85Sdougm  *
29346185db85Sdougm  * Return the specified attribute value from the optionset.
29356185db85Sdougm  */
29366185db85Sdougm 
29376185db85Sdougm char *
29386185db85Sdougm sa_get_security_attr(sa_property_t optionset, char *tag)
29396185db85Sdougm {
29406185db85Sdougm 	return (get_node_attr((void *)optionset, tag));
29416185db85Sdougm 
29426185db85Sdougm }
29436185db85Sdougm 
29446185db85Sdougm /*
29456185db85Sdougm  * sa_set_security_attr(optionset, tag, value)
29466185db85Sdougm  *
29476185db85Sdougm  * Set the optioset attribute specied by tag to the specified value.
29486185db85Sdougm  */
29496185db85Sdougm 
29506185db85Sdougm void
29516185db85Sdougm sa_set_security_attr(sa_group_t optionset, char *tag, char *value)
29526185db85Sdougm {
29536185db85Sdougm 	set_node_attr((void *)optionset, tag, value);
29546185db85Sdougm }
29556185db85Sdougm 
29566185db85Sdougm /*
29576185db85Sdougm  * is_nodetype(node, type)
29586185db85Sdougm  *
29596185db85Sdougm  * Check to see if node is of the type specified.
29606185db85Sdougm  */
29616185db85Sdougm 
29626185db85Sdougm static int
29636185db85Sdougm is_nodetype(void *node, char *type)
29646185db85Sdougm {
29656185db85Sdougm 	return (strcmp((char *)((xmlNodePtr)node)->name, type) == 0);
29666185db85Sdougm }
29676185db85Sdougm 
296857b448deSdougm /*
296957b448deSdougm  * add_or_update()
297057b448deSdougm  *
297157b448deSdougm  * Add or update a property. Pulled out of sa_set_prop_by_prop for
297257b448deSdougm  * readability.
297357b448deSdougm  */
297457b448deSdougm static int
297557b448deSdougm add_or_update(scfutilhandle_t *scf_handle, int type, scf_value_t *value,
297657b448deSdougm     scf_transaction_entry_t *entry, char *name, char *valstr)
297757b448deSdougm {
297857b448deSdougm 	int ret = SA_SYSTEM_ERR;
297957b448deSdougm 
298057b448deSdougm 	if (value != NULL) {
298157b448deSdougm 		if (type == SA_PROP_OP_ADD)
298257b448deSdougm 			ret = scf_transaction_property_new(scf_handle->trans,
298357b448deSdougm 			    entry, name, SCF_TYPE_ASTRING);
298457b448deSdougm 		else
298557b448deSdougm 			ret = scf_transaction_property_change(scf_handle->trans,
298657b448deSdougm 			    entry, name, SCF_TYPE_ASTRING);
298757b448deSdougm 		if (ret == 0) {
298857b448deSdougm 			ret = scf_value_set_astring(value, valstr);
298957b448deSdougm 			if (ret == 0)
299057b448deSdougm 				ret = scf_entry_add_value(entry, value);
299157b448deSdougm 			if (ret == 0)
299257b448deSdougm 				return (ret);
299357b448deSdougm 			scf_value_destroy(value);
299457b448deSdougm 		} else {
299557b448deSdougm 			scf_entry_destroy(entry);
299657b448deSdougm 		}
299757b448deSdougm 	}
299857b448deSdougm 	return (SA_SYSTEM_ERR);
299957b448deSdougm }
300057b448deSdougm 
30016185db85Sdougm /*
30026185db85Sdougm  * sa_set_prop_by_prop(optionset, group, prop, type)
30036185db85Sdougm  *
30046185db85Sdougm  * Add/remove/update the specified property prop into the optionset or
30056185db85Sdougm  * share. If a share, sort out which property group based on GUID. In
30066185db85Sdougm  * all cases, the appropriate transaction is set (or ZFS share is
30076185db85Sdougm  * marked as needing an update)
30086185db85Sdougm  */
30096185db85Sdougm 
30106185db85Sdougm static int
30116185db85Sdougm sa_set_prop_by_prop(sa_optionset_t optionset, sa_group_t group,
30126185db85Sdougm 			sa_property_t prop, int type)
30136185db85Sdougm {
30146185db85Sdougm 	char *name;
30156185db85Sdougm 	char *valstr;
30166185db85Sdougm 	int ret = SA_OK;
30176185db85Sdougm 	scf_transaction_entry_t *entry;
30186185db85Sdougm 	scf_value_t *value;
30196185db85Sdougm 	int opttype; /* 1 == optionset, 0 == security */
30206185db85Sdougm 	char *id = NULL;
30216185db85Sdougm 	int iszfs = 0;
30226185db85Sdougm 	sa_group_t parent = NULL;
3023da6c28aaSamw 	sa_share_t share = NULL;
3024549ec3ffSdougm 	sa_handle_impl_t impl_handle;
3025549ec3ffSdougm 	scfutilhandle_t  *scf_handle;
30266185db85Sdougm 
3027da6c28aaSamw 	if (!sa_is_persistent(group)) {
30286185db85Sdougm 		/*
30296185db85Sdougm 		 * if the group/share is not persistent we don't need
30306185db85Sdougm 		 * to do anything here
30316185db85Sdougm 		 */
303257b448deSdougm 		return (SA_OK);
30336185db85Sdougm 	}
3034549ec3ffSdougm 	impl_handle = (sa_handle_impl_t)sa_find_group_handle(group);
303557b448deSdougm 	if (impl_handle == NULL || impl_handle->scfhandle == NULL)
303657b448deSdougm 		return (SA_SYSTEM_ERR);
3037549ec3ffSdougm 	scf_handle = impl_handle->scfhandle;
30386185db85Sdougm 	name = sa_get_property_attr(prop, "type");
30396185db85Sdougm 	valstr = sa_get_property_attr(prop, "value");
30406185db85Sdougm 	entry = scf_entry_create(scf_handle->handle);
30416185db85Sdougm 	opttype = is_nodetype((void *)optionset, "optionset");
30426185db85Sdougm 
3043da6c28aaSamw 	/*
3044da6c28aaSamw 	 * Check for share vs. resource since they need slightly
3045da6c28aaSamw 	 * different treatment given the hierarchy.
3046da6c28aaSamw 	 */
30476185db85Sdougm 	if (valstr != NULL && entry != NULL) {
304857b448deSdougm 		if (sa_is_share(group)) {
304957b448deSdougm 			parent = sa_get_parent_group(group);
3050da6c28aaSamw 			share = (sa_share_t)group;
305157b448deSdougm 			if (parent != NULL)
305257b448deSdougm 				iszfs = is_zfs_group(parent);
3053da6c28aaSamw 		} else if (sa_is_resource(group)) {
3054da6c28aaSamw 			share = sa_get_parent_group(group);
3055da6c28aaSamw 			if (share != NULL)
3056da6c28aaSamw 				parent = sa_get_parent_group(share);
305757b448deSdougm 		} else {
305857b448deSdougm 			iszfs = is_zfs_group(group);
30596185db85Sdougm 		}
306057b448deSdougm 		if (!iszfs) {
306157b448deSdougm 			if (scf_handle->trans == NULL) {
306257b448deSdougm 				char oname[SA_STRSIZE];
306357b448deSdougm 				char *groupname = NULL;
3064da6c28aaSamw 				if (share != NULL) {
3065da6c28aaSamw 					if (parent != NULL)
306657b448deSdougm 						groupname =
306757b448deSdougm 						    sa_get_group_attr(parent,
306857b448deSdougm 						    "name");
3069da6c28aaSamw 					id = sa_get_share_attr(
3070da6c28aaSamw 					    (sa_share_t)share, "id");
3071549ec3ffSdougm 				} else {
307257b448deSdougm 					groupname = sa_get_group_attr(group,
307357b448deSdougm 					    "name");
30746185db85Sdougm 				}
307557b448deSdougm 				if (groupname != NULL) {
307657b448deSdougm 					ret = sa_get_instance(scf_handle,
307757b448deSdougm 					    groupname);
307857b448deSdougm 					sa_free_attr_string(groupname);
307957b448deSdougm 				}
308057b448deSdougm 				if (opttype)
308157b448deSdougm 					(void) sa_optionset_name(optionset,
308257b448deSdougm 					    oname, sizeof (oname), id);
308357b448deSdougm 				else
308457b448deSdougm 					(void) sa_security_name(optionset,
308557b448deSdougm 					    oname, sizeof (oname), id);
308657b448deSdougm 				ret = sa_start_transaction(scf_handle, oname);
30876185db85Sdougm 			}
308857b448deSdougm 			if (ret == SA_OK) {
308957b448deSdougm 				switch (type) {
309057b448deSdougm 				case SA_PROP_OP_REMOVE:
309157b448deSdougm 					ret = scf_transaction_property_delete(
309257b448deSdougm 					    scf_handle->trans, entry, name);
309357b448deSdougm 					break;
309457b448deSdougm 				case SA_PROP_OP_ADD:
309557b448deSdougm 				case SA_PROP_OP_UPDATE:
309657b448deSdougm 					value = scf_value_create(
309757b448deSdougm 					    scf_handle->handle);
309857b448deSdougm 					ret = add_or_update(scf_handle, type,
309957b448deSdougm 					    value, entry, name, valstr);
310057b448deSdougm 					break;
310157b448deSdougm 				}
310257b448deSdougm 			}
310357b448deSdougm 		} else {
310457b448deSdougm 			/*
310557b448deSdougm 			 * ZFS update. The calling function would have updated
310657b448deSdougm 			 * the internal XML structure. Just need to flag it as
310757b448deSdougm 			 * changed for ZFS.
310857b448deSdougm 			 */
310957b448deSdougm 			zfs_set_update((sa_share_t)group);
311057b448deSdougm 		}
31116185db85Sdougm 	}
31126185db85Sdougm 
31136185db85Sdougm 	if (name != NULL)
311457b448deSdougm 		sa_free_attr_string(name);
31156185db85Sdougm 	if (valstr != NULL)
311657b448deSdougm 		sa_free_attr_string(valstr);
31176185db85Sdougm 	else if (entry != NULL)
311857b448deSdougm 		scf_entry_destroy(entry);
31196185db85Sdougm 
31206185db85Sdougm 	if (ret == -1)
312157b448deSdougm 		ret = SA_SYSTEM_ERR;
31226185db85Sdougm 
31236185db85Sdougm 	return (ret);
31246185db85Sdougm }
31256185db85Sdougm 
31266185db85Sdougm /*
31276185db85Sdougm  * sa_create_property(name, value)
31286185db85Sdougm  *
31296185db85Sdougm  * Create a new property with the specified name and value.
31306185db85Sdougm  */
31316185db85Sdougm 
31326185db85Sdougm sa_property_t
31336185db85Sdougm sa_create_property(char *name, char *value)
31346185db85Sdougm {
31356185db85Sdougm 	xmlNodePtr node;
31366185db85Sdougm 
31376185db85Sdougm 	node = xmlNewNode(NULL, (xmlChar *)"option");
31386185db85Sdougm 	if (node != NULL) {
31396185db85Sdougm 		xmlSetProp(node, (xmlChar *)"type", (xmlChar *)name);
31406185db85Sdougm 		xmlSetProp(node, (xmlChar *)"value", (xmlChar *)value);
31416185db85Sdougm 	}
31426185db85Sdougm 	return ((sa_property_t)node);
31436185db85Sdougm }
31446185db85Sdougm 
31456185db85Sdougm /*
31466185db85Sdougm  * sa_add_property(object, property)
31476185db85Sdougm  *
31486185db85Sdougm  * Add the specified property to the object. Issue the appropriate
31496185db85Sdougm  * transaction or mark a ZFS object as needing an update.
31506185db85Sdougm  */
31516185db85Sdougm 
31526185db85Sdougm int
31536185db85Sdougm sa_add_property(void *object, sa_property_t property)
31546185db85Sdougm {
31556185db85Sdougm 	int ret = SA_OK;
31566185db85Sdougm 	sa_group_t parent;
31576185db85Sdougm 	sa_group_t group;
31586185db85Sdougm 	char *proto;
31596185db85Sdougm 
31606185db85Sdougm 	proto = sa_get_optionset_attr(object, "type");
31616185db85Sdougm 	if (property != NULL) {
316257b448deSdougm 		if ((ret = sa_valid_property(object, proto, property)) ==
316357b448deSdougm 		    SA_OK) {
316457b448deSdougm 			property = (sa_property_t)xmlAddChild(
316557b448deSdougm 			    (xmlNodePtr)object, (xmlNodePtr)property);
316657b448deSdougm 		} else {
316757b448deSdougm 			if (proto != NULL)
316857b448deSdougm 				sa_free_attr_string(proto);
316957b448deSdougm 			return (ret);
317057b448deSdougm 		}
31716185db85Sdougm 	}
31726185db85Sdougm 
31736185db85Sdougm 	if (proto != NULL)
317457b448deSdougm 		sa_free_attr_string(proto);
31756185db85Sdougm 
31766185db85Sdougm 	parent = sa_get_parent_group(object);
3177da6c28aaSamw 	if (!sa_is_persistent(parent))
317857b448deSdougm 		return (ret);
31796185db85Sdougm 
3180da6c28aaSamw 	if (sa_is_resource(parent)) {
3181da6c28aaSamw 		/*
3182da6c28aaSamw 		 * Resources are children of share.  Need to go up two
3183da6c28aaSamw 		 * levels to find the group but the parent needs to be
3184da6c28aaSamw 		 * the share at this point in order to get the "id".
3185da6c28aaSamw 		 */
3186da6c28aaSamw 		parent = sa_get_parent_group(parent);
318757b448deSdougm 		group = sa_get_parent_group(parent);
3188da6c28aaSamw 	} else if (sa_is_share(parent)) {
3189da6c28aaSamw 		group = sa_get_parent_group(parent);
3190da6c28aaSamw 	} else {
319157b448deSdougm 		group = parent;
3192da6c28aaSamw 	}
3193549ec3ffSdougm 
319457b448deSdougm 	if (property == NULL) {
319557b448deSdougm 		ret = SA_NO_MEMORY;
319657b448deSdougm 	} else {
319757b448deSdougm 		char oname[SA_STRSIZE];
319857b448deSdougm 
319957b448deSdougm 		if (!is_zfs_group(group)) {
320057b448deSdougm 			char *id = NULL;
320157b448deSdougm 			sa_handle_impl_t impl_handle;
320257b448deSdougm 			scfutilhandle_t  *scf_handle;
320357b448deSdougm 
320457b448deSdougm 			impl_handle = (sa_handle_impl_t)sa_find_group_handle(
320557b448deSdougm 			    group);
320657b448deSdougm 			if (impl_handle == NULL ||
320757b448deSdougm 			    impl_handle->scfhandle == NULL)
320857b448deSdougm 				ret = SA_SYSTEM_ERR;
320957b448deSdougm 			if (ret == SA_OK) {
321057b448deSdougm 				scf_handle = impl_handle->scfhandle;
321157b448deSdougm 				if (sa_is_share((sa_group_t)parent)) {
321257b448deSdougm 					id = sa_get_share_attr(
321357b448deSdougm 					    (sa_share_t)parent, "id");
321457b448deSdougm 				}
321557b448deSdougm 				if (scf_handle->trans == NULL) {
321657b448deSdougm 					if (is_nodetype(object, "optionset")) {
321757b448deSdougm 						(void) sa_optionset_name(
321857b448deSdougm 						    (sa_optionset_t)object,
321957b448deSdougm 						    oname, sizeof (oname), id);
322057b448deSdougm 					} else {
322157b448deSdougm 						(void) sa_security_name(
322257b448deSdougm 						    (sa_optionset_t)object,
322357b448deSdougm 						    oname, sizeof (oname), id);
322457b448deSdougm 					}
322557b448deSdougm 					ret = sa_start_transaction(scf_handle,
322657b448deSdougm 					    oname);
322757b448deSdougm 				}
322857b448deSdougm 				if (ret == SA_OK) {
322957b448deSdougm 					char *name;
323057b448deSdougm 					char *value;
323157b448deSdougm 					name = sa_get_property_attr(property,
323257b448deSdougm 					    "type");
323357b448deSdougm 					value = sa_get_property_attr(property,
323457b448deSdougm 					    "value");
323557b448deSdougm 					if (name != NULL && value != NULL) {
323657b448deSdougm 						if (scf_handle->scf_state ==
323757b448deSdougm 						    SCH_STATE_INIT) {
323857b448deSdougm 							ret = sa_set_property(
323957b448deSdougm 							    scf_handle, name,
324057b448deSdougm 							    value);
324157b448deSdougm 						}
324257b448deSdougm 					} else {
324357b448deSdougm 						ret = SA_CONFIG_ERR;
324457b448deSdougm 					}
324557b448deSdougm 					if (name != NULL)
324657b448deSdougm 						sa_free_attr_string(
324757b448deSdougm 						    name);
324857b448deSdougm 					if (value != NULL)
324957b448deSdougm 						sa_free_attr_string(value);
325057b448deSdougm 				}
325157b448deSdougm 				if (id != NULL)
325257b448deSdougm 					sa_free_attr_string(id);
325357b448deSdougm 			}
325457b448deSdougm 		} else {
325557b448deSdougm 			/*
325657b448deSdougm 			 * ZFS is a special case. We do want
325757b448deSdougm 			 * to allow editing property/security
325857b448deSdougm 			 * lists since we can have a better
325957b448deSdougm 			 * syntax and we also want to keep
326057b448deSdougm 			 * things consistent when possible.
326157b448deSdougm 			 *
326257b448deSdougm 			 * Right now, we defer until the
326357b448deSdougm 			 * sa_commit_properties so we can get
326457b448deSdougm 			 * them all at once. We do need to
326557b448deSdougm 			 * mark the share as "changed"
326657b448deSdougm 			 */
326757b448deSdougm 			zfs_set_update((sa_share_t)parent);
32686185db85Sdougm 		}
32696185db85Sdougm 	}
32706185db85Sdougm 	return (ret);
32716185db85Sdougm }
32726185db85Sdougm 
32736185db85Sdougm /*
32746185db85Sdougm  * sa_remove_property(property)
32756185db85Sdougm  *
32766185db85Sdougm  * Remove the specied property from its containing object. Update the
32776185db85Sdougm  * repository as appropriate.
32786185db85Sdougm  */
32796185db85Sdougm 
32806185db85Sdougm int
32816185db85Sdougm sa_remove_property(sa_property_t property)
32826185db85Sdougm {
32836185db85Sdougm 	int ret = SA_OK;
32846185db85Sdougm 
32856185db85Sdougm 	if (property != NULL) {
32866185db85Sdougm 		sa_optionset_t optionset;
32876185db85Sdougm 		sa_group_t group;
32886185db85Sdougm 		optionset = sa_get_property_parent(property);
32896185db85Sdougm 		if (optionset != NULL) {
329057b448deSdougm 			group = sa_get_optionset_parent(optionset);
329157b448deSdougm 			if (group != NULL) {
329257b448deSdougm 				ret = sa_set_prop_by_prop(optionset, group,
329357b448deSdougm 				    property, SA_PROP_OP_REMOVE);
329457b448deSdougm 			}
32956185db85Sdougm 		}
32966185db85Sdougm 		xmlUnlinkNode((xmlNodePtr)property);
32976185db85Sdougm 		xmlFreeNode((xmlNodePtr)property);
32986185db85Sdougm 	} else {
329957b448deSdougm 		ret = SA_NO_SUCH_PROP;
33006185db85Sdougm 	}
33016185db85Sdougm 	return (ret);
33026185db85Sdougm }
33036185db85Sdougm 
33046185db85Sdougm /*
33056185db85Sdougm  * sa_update_property(property, value)
33066185db85Sdougm  *
33076185db85Sdougm  * Update the specified property to the new value.  If value is NULL,
33086185db85Sdougm  * we currently treat this as a remove.
33096185db85Sdougm  */
33106185db85Sdougm 
33116185db85Sdougm int
33126185db85Sdougm sa_update_property(sa_property_t property, char *value)
33136185db85Sdougm {
33146185db85Sdougm 	int ret = SA_OK;
33156185db85Sdougm 	if (value == NULL) {
33166185db85Sdougm 		return (sa_remove_property(property));
33176185db85Sdougm 	} else {
33186185db85Sdougm 		sa_optionset_t optionset;
33196185db85Sdougm 		sa_group_t group;
33206185db85Sdougm 		set_node_attr((void *)property, "value", value);
33216185db85Sdougm 		optionset = sa_get_property_parent(property);
33226185db85Sdougm 		if (optionset != NULL) {
332357b448deSdougm 			group = sa_get_optionset_parent(optionset);
332457b448deSdougm 			if (group != NULL) {
332557b448deSdougm 				ret = sa_set_prop_by_prop(optionset, group,
332657b448deSdougm 				    property, SA_PROP_OP_UPDATE);
332757b448deSdougm 			}
33286185db85Sdougm 		} else {
332957b448deSdougm 			ret = SA_NO_SUCH_PROP;
33306185db85Sdougm 		}
33316185db85Sdougm 	}
33326185db85Sdougm 	return (ret);
33336185db85Sdougm }
33346185db85Sdougm 
33356185db85Sdougm /*
33366185db85Sdougm  * sa_get_protocol_property(propset, prop)
33376185db85Sdougm  *
33386185db85Sdougm  * Get the specified protocol specific property. These are global to
33396185db85Sdougm  * the protocol and not specific to a group or share.
33406185db85Sdougm  */
33416185db85Sdougm 
33426185db85Sdougm sa_property_t
33436185db85Sdougm sa_get_protocol_property(sa_protocol_properties_t propset, char *prop)
33446185db85Sdougm {
33456185db85Sdougm 	xmlNodePtr node = (xmlNodePtr)propset;
33466185db85Sdougm 	xmlChar *value = NULL;
33476185db85Sdougm 
33486185db85Sdougm 	for (node = node->children; node != NULL;
334957b448deSdougm 	    node = node->next) {
335057b448deSdougm 		if (xmlStrcmp(node->name, (xmlChar *)"option") == 0) {
335157b448deSdougm 			if (prop == NULL)
335257b448deSdougm 				break;
335357b448deSdougm 			value = xmlGetProp(node, (xmlChar *)"type");
335457b448deSdougm 			if (value != NULL &&
335557b448deSdougm 			    xmlStrcasecmp(value, (xmlChar *)prop) == 0) {
335657b448deSdougm 				break;
335757b448deSdougm 			}
335857b448deSdougm 			if (value != NULL) {
335957b448deSdougm 				xmlFree(value);
336057b448deSdougm 				value = NULL;
336157b448deSdougm 			}
33626185db85Sdougm 		}
33636185db85Sdougm 	}
33646185db85Sdougm 	if (value != NULL)
33656185db85Sdougm 		xmlFree(value);
33666185db85Sdougm 	if (node != NULL && xmlStrcmp(node->name, (xmlChar *)"option") != 0) {
336757b448deSdougm 		/*
336857b448deSdougm 		 * avoid a non option node -- it is possible to be a
336957b448deSdougm 		 * text node
337057b448deSdougm 		 */
337157b448deSdougm 		node = NULL;
33726185db85Sdougm 	}
33736185db85Sdougm 	return ((sa_property_t)node);
33746185db85Sdougm }
33756185db85Sdougm 
33766185db85Sdougm /*
33776185db85Sdougm  * sa_get_next_protocol_property(prop)
33786185db85Sdougm  *
33796185db85Sdougm  * Get the next protocol specific property in the list.
33806185db85Sdougm  */
33816185db85Sdougm 
33826185db85Sdougm sa_property_t
33836185db85Sdougm sa_get_next_protocol_property(sa_property_t prop)
33846185db85Sdougm {
33856185db85Sdougm 	xmlNodePtr node;
33866185db85Sdougm 
33876185db85Sdougm 	for (node = ((xmlNodePtr)prop)->next; node != NULL;
338857b448deSdougm 	    node = node->next) {
33896185db85Sdougm 		if (xmlStrcmp(node->name, (xmlChar *)"option") == 0) {
33906185db85Sdougm 			break;
33916185db85Sdougm 		}
33926185db85Sdougm 	}
33936185db85Sdougm 	return ((sa_property_t)node);
33946185db85Sdougm }
33956185db85Sdougm 
33966185db85Sdougm /*
33976185db85Sdougm  * sa_set_protocol_property(prop, value)
33986185db85Sdougm  *
33996185db85Sdougm  * Set the specified property to have the new value.  The protocol
34006185db85Sdougm  * specific plugin will then be called to update the property.
34016185db85Sdougm  */
34026185db85Sdougm 
34036185db85Sdougm int
34046185db85Sdougm sa_set_protocol_property(sa_property_t prop, char *value)
34056185db85Sdougm {
34066185db85Sdougm 	sa_protocol_properties_t propset;
34076185db85Sdougm 	char *proto;
34086185db85Sdougm 	int ret = SA_INVALID_PROTOCOL;
34096185db85Sdougm 
34106185db85Sdougm 	propset = ((xmlNodePtr)prop)->parent;
34116185db85Sdougm 	if (propset != NULL) {
341257b448deSdougm 		proto = sa_get_optionset_attr(propset, "type");
341357b448deSdougm 		if (proto != NULL) {
341457b448deSdougm 			set_node_attr((xmlNodePtr)prop, "value", value);
341557b448deSdougm 			ret = sa_proto_set_property(proto, prop);
341657b448deSdougm 			sa_free_attr_string(proto);
341757b448deSdougm 		}
34186185db85Sdougm 	}
34196185db85Sdougm 	return (ret);
34206185db85Sdougm }
34216185db85Sdougm 
34226185db85Sdougm /*
34236185db85Sdougm  * sa_add_protocol_property(propset, prop)
34246185db85Sdougm  *
3425da6c28aaSamw  * Add a new property to the protocol specific property set.
34266185db85Sdougm  */
34276185db85Sdougm 
34286185db85Sdougm int
34296185db85Sdougm sa_add_protocol_property(sa_protocol_properties_t propset, sa_property_t prop)
34306185db85Sdougm {
34316185db85Sdougm 	xmlNodePtr node;
34326185db85Sdougm 
34336185db85Sdougm 	/* should check for legitimacy */
34346185db85Sdougm 	node = xmlAddChild((xmlNodePtr)propset, (xmlNodePtr)prop);
34356185db85Sdougm 	if (node != NULL)
343657b448deSdougm 		return (SA_OK);
34376185db85Sdougm 	return (SA_NO_MEMORY);
34386185db85Sdougm }
34396185db85Sdougm 
34406185db85Sdougm /*
34416185db85Sdougm  * sa_create_protocol_properties(proto)
34426185db85Sdougm  *
3443da6c28aaSamw  * Create a protocol specific property set.
34446185db85Sdougm  */
34456185db85Sdougm 
34466185db85Sdougm sa_protocol_properties_t
34476185db85Sdougm sa_create_protocol_properties(char *proto)
34486185db85Sdougm {
34496185db85Sdougm 	xmlNodePtr node;
345057b448deSdougm 
34516185db85Sdougm 	node = xmlNewNode(NULL, (xmlChar *)"propertyset");
345257b448deSdougm 	if (node != NULL)
345357b448deSdougm 		xmlSetProp(node, (xmlChar *)"type", (xmlChar *)proto);
34546185db85Sdougm 	return (node);
34556185db85Sdougm }
3456da6c28aaSamw 
3457da6c28aaSamw /*
3458da6c28aaSamw  * sa_get_share_resource(share, resource)
3459da6c28aaSamw  *
3460da6c28aaSamw  * Get the named resource from the share, if it exists. If resource is
3461da6c28aaSamw  * NULL, get the first resource.
3462da6c28aaSamw  */
3463da6c28aaSamw 
3464da6c28aaSamw sa_resource_t
3465da6c28aaSamw sa_get_share_resource(sa_share_t share, char *resource)
3466da6c28aaSamw {
3467da6c28aaSamw 	xmlNodePtr node = NULL;
3468da6c28aaSamw 	xmlChar *name;
3469da6c28aaSamw 
3470da6c28aaSamw 	if (share != NULL) {
3471da6c28aaSamw 		for (node = ((xmlNodePtr)share)->children; node != NULL;
3472da6c28aaSamw 		    node = node->next) {
3473da6c28aaSamw 			if (xmlStrcmp(node->name, (xmlChar *)"resource") == 0) {
3474da6c28aaSamw 				if (resource == NULL) {
3475da6c28aaSamw 					/*
3476da6c28aaSamw 					 * We are looking for the first
3477da6c28aaSamw 					 * resource node and not a names
3478da6c28aaSamw 					 * resource.
3479da6c28aaSamw 					 */
3480da6c28aaSamw 					break;
3481da6c28aaSamw 				} else {
3482da6c28aaSamw 					/* is it the correct share? */
3483da6c28aaSamw 					name = xmlGetProp(node,
3484da6c28aaSamw 					    (xmlChar *)"name");
3485da6c28aaSamw 					if (name != NULL &&
3486da6c28aaSamw 					    xmlStrcasecmp(name,
3487da6c28aaSamw 					    (xmlChar *)resource) == 0) {
3488da6c28aaSamw 						xmlFree(name);
3489da6c28aaSamw 						break;
3490da6c28aaSamw 					}
3491da6c28aaSamw 					xmlFree(name);
3492da6c28aaSamw 				}
3493da6c28aaSamw 			}
3494da6c28aaSamw 		}
3495da6c28aaSamw 	}
3496da6c28aaSamw 	return ((sa_resource_t)node);
3497da6c28aaSamw }
3498da6c28aaSamw 
3499da6c28aaSamw /*
3500da6c28aaSamw  * sa_get_next_resource(resource)
3501da6c28aaSamw  *	Return the next share following the specified share
3502da6c28aaSamw  *	from the internal list of shares. Returns NULL if there
3503da6c28aaSamw  *	are no more shares.  The list is relative to the same
3504da6c28aaSamw  *	group.
3505da6c28aaSamw  */
3506da6c28aaSamw sa_share_t
3507da6c28aaSamw sa_get_next_resource(sa_resource_t resource)
3508da6c28aaSamw {
3509da6c28aaSamw 	xmlNodePtr node = NULL;
3510da6c28aaSamw 
3511da6c28aaSamw 	if (resource != NULL) {
3512da6c28aaSamw 		for (node = ((xmlNodePtr)resource)->next; node != NULL;
3513da6c28aaSamw 		    node = node->next) {
3514da6c28aaSamw 			if (xmlStrcmp(node->name, (xmlChar *)"resource") == 0)
3515da6c28aaSamw 				break;
3516da6c28aaSamw 		}
3517da6c28aaSamw 	}
3518da6c28aaSamw 	return ((sa_share_t)node);
3519da6c28aaSamw }
3520da6c28aaSamw 
3521da6c28aaSamw /*
3522da6c28aaSamw  * _sa_get_next_resource_index(share)
3523da6c28aaSamw  *
3524da6c28aaSamw  * get the next resource index number (one greater then current largest)
3525da6c28aaSamw  */
3526da6c28aaSamw 
3527da6c28aaSamw static int
3528da6c28aaSamw _sa_get_next_resource_index(sa_share_t share)
3529da6c28aaSamw {
3530da6c28aaSamw 	sa_resource_t resource;
3531da6c28aaSamw 	int index = 0;
3532da6c28aaSamw 	char *id;
3533da6c28aaSamw 
3534da6c28aaSamw 	for (resource = sa_get_share_resource(share, NULL);
3535da6c28aaSamw 	    resource != NULL;
3536da6c28aaSamw 	    resource = sa_get_next_resource(resource)) {
3537da6c28aaSamw 		id = get_node_attr((void *)resource, "id");
3538da6c28aaSamw 		if (id != NULL) {
3539da6c28aaSamw 			int val;
3540da6c28aaSamw 			val = atoi(id);
3541da6c28aaSamw 			if (val > index)
3542da6c28aaSamw 				index = val;
3543da6c28aaSamw 			sa_free_attr_string(id);
3544da6c28aaSamw 		}
3545da6c28aaSamw 	}
3546da6c28aaSamw 	return (index + 1);
3547da6c28aaSamw }
3548da6c28aaSamw 
3549da6c28aaSamw 
3550da6c28aaSamw /*
3551da6c28aaSamw  * sa_add_resource(share, resource, persist, &err)
3552da6c28aaSamw  *
3553da6c28aaSamw  * Adds a new resource name associated with share. The resource name
3554da6c28aaSamw  * must be unique in the system and will be case insensitive (eventually).
3555da6c28aaSamw  */
3556da6c28aaSamw 
3557da6c28aaSamw sa_resource_t
3558da6c28aaSamw sa_add_resource(sa_share_t share, char *resource, int persist, int *error)
3559da6c28aaSamw {
3560da6c28aaSamw 	xmlNodePtr node;
3561da6c28aaSamw 	int err = SA_OK;
3562da6c28aaSamw 	sa_resource_t res;
3563da6c28aaSamw 	sa_group_t group;
3564da6c28aaSamw 	sa_handle_t handle;
3565da6c28aaSamw 	char istring[8]; /* just big enough for an integer value */
3566da6c28aaSamw 	int index;
3567da6c28aaSamw 
3568da6c28aaSamw 	group = sa_get_parent_group(share);
3569da6c28aaSamw 	handle = sa_find_group_handle(group);
3570da6c28aaSamw 	res = sa_find_resource(handle, resource);
3571da6c28aaSamw 	if (res != NULL) {
3572da6c28aaSamw 		err = SA_DUPLICATE_NAME;
3573da6c28aaSamw 		res = NULL;
3574da6c28aaSamw 	} else {
3575da6c28aaSamw 		node = xmlNewChild((xmlNodePtr)share, NULL,
3576da6c28aaSamw 		    (xmlChar *)"resource", NULL);
3577da6c28aaSamw 		if (node != NULL) {
3578da6c28aaSamw 			xmlSetProp(node, (xmlChar *)"name",
3579da6c28aaSamw 			    (xmlChar *)resource);
3580da6c28aaSamw 			xmlSetProp(node, (xmlChar *)"type", persist ?
3581da6c28aaSamw 			    (xmlChar *)"persist" : (xmlChar *)"transient");
3582da6c28aaSamw 			if (persist != SA_SHARE_TRANSIENT) {
3583da6c28aaSamw 				index = _sa_get_next_resource_index(share);
3584da6c28aaSamw 				(void) snprintf(istring, sizeof (istring), "%d",
3585da6c28aaSamw 				    index);
3586da6c28aaSamw 				xmlSetProp(node, (xmlChar *)"id",
3587da6c28aaSamw 				    (xmlChar *)istring);
3588da6c28aaSamw 				if (!sa_group_is_zfs(group) &&
3589da6c28aaSamw 				    sa_is_persistent((sa_group_t)share)) {
3590da6c28aaSamw 					/* ZFS doesn't use resource names */
3591da6c28aaSamw 					sa_handle_impl_t ihandle;
3592da6c28aaSamw 					ihandle = (sa_handle_impl_t)
3593da6c28aaSamw 					    sa_find_group_handle(
3594da6c28aaSamw 					    group);
3595da6c28aaSamw 					if (ihandle != NULL)
3596da6c28aaSamw 						err = sa_commit_share(
3597da6c28aaSamw 						    ihandle->scfhandle, group,
3598da6c28aaSamw 						    share);
3599da6c28aaSamw 					else
3600da6c28aaSamw 						err = SA_SYSTEM_ERR;
3601da6c28aaSamw 				}
3602da6c28aaSamw 			}
3603da6c28aaSamw 		}
3604da6c28aaSamw 	}
3605da6c28aaSamw 	if (error != NULL)
3606da6c28aaSamw 		*error = err;
3607da6c28aaSamw 	return ((sa_resource_t)node);
3608da6c28aaSamw }
3609da6c28aaSamw 
3610da6c28aaSamw /*
3611da6c28aaSamw  * sa_remove_resource(resource)
3612da6c28aaSamw  *
3613da6c28aaSamw  * Remove the resource name from the share (and the system)
3614da6c28aaSamw  */
3615da6c28aaSamw 
3616da6c28aaSamw int
3617da6c28aaSamw sa_remove_resource(sa_resource_t resource)
3618da6c28aaSamw {
3619da6c28aaSamw 	sa_share_t share;
3620da6c28aaSamw 	sa_group_t group;
3621da6c28aaSamw 	char *type;
3622da6c28aaSamw 	int ret = SA_OK;
3623da6c28aaSamw 	int transient = 0;
362455bf511dSas 	sa_optionset_t opt;
3625da6c28aaSamw 
3626da6c28aaSamw 	share = sa_get_resource_parent(resource);
3627da6c28aaSamw 	type = sa_get_share_attr(share, "type");
3628da6c28aaSamw 	group = sa_get_parent_group(share);
3629da6c28aaSamw 
3630da6c28aaSamw 
3631da6c28aaSamw 	if (type != NULL) {
3632da6c28aaSamw 		if (strcmp(type, "persist") != 0)
3633da6c28aaSamw 			transient = 1;
3634da6c28aaSamw 		sa_free_attr_string(type);
3635da6c28aaSamw 	}
3636da6c28aaSamw 
363755bf511dSas 	/* Disable the resource for all protocols. */
363855bf511dSas 	(void) sa_disable_resource(resource, NULL);
363955bf511dSas 
364055bf511dSas 	/* Remove any optionsets from the resource. */
364155bf511dSas 	for (opt = sa_get_optionset(resource, NULL);
364255bf511dSas 	    opt != NULL;
364355bf511dSas 	    opt = sa_get_next_optionset(opt))
364455bf511dSas 		(void) sa_destroy_optionset(opt);
364555bf511dSas 
3646da6c28aaSamw 	/* Remove from the share */
3647da6c28aaSamw 	xmlUnlinkNode((xmlNode *)resource);
3648da6c28aaSamw 	xmlFreeNode((xmlNode *)resource);
3649da6c28aaSamw 
3650da6c28aaSamw 	/* only do SMF action if permanent and not ZFS */
3651da6c28aaSamw 	if (!transient && !sa_group_is_zfs(group)) {
3652da6c28aaSamw 		sa_handle_impl_t ihandle;
3653da6c28aaSamw 		ihandle = (sa_handle_impl_t)sa_find_group_handle(group);
3654da6c28aaSamw 		if (ihandle != NULL)
3655da6c28aaSamw 			ret = sa_commit_share(ihandle->scfhandle, group, share);
3656da6c28aaSamw 		else
3657da6c28aaSamw 			ret = SA_SYSTEM_ERR;
3658da6c28aaSamw 	}
3659da6c28aaSamw 	return (ret);
3660da6c28aaSamw }
3661da6c28aaSamw 
3662da6c28aaSamw /*
3663da6c28aaSamw  * proto_resource_rename(handle, group, resource, newname)
3664da6c28aaSamw  *
3665da6c28aaSamw  * Helper function for sa_rename_resource that notifies the protocol
3666da6c28aaSamw  * of a resource name change prior to a config repository update.
3667da6c28aaSamw  */
3668da6c28aaSamw static int
3669da6c28aaSamw proto_rename_resource(sa_handle_t handle, sa_group_t group,
3670da6c28aaSamw     sa_resource_t resource, char *newname)
3671da6c28aaSamw {
3672da6c28aaSamw 	sa_optionset_t optionset;
3673da6c28aaSamw 	int ret = SA_OK;
3674da6c28aaSamw 	int err;
3675da6c28aaSamw 
3676da6c28aaSamw 	for (optionset = sa_get_optionset(group, NULL);
3677da6c28aaSamw 	    optionset != NULL;
3678da6c28aaSamw 	    optionset = sa_get_next_optionset(optionset)) {
3679da6c28aaSamw 		char *type;
3680da6c28aaSamw 		type = sa_get_optionset_attr(optionset, "type");
3681da6c28aaSamw 		if (type != NULL) {
3682da6c28aaSamw 			err = sa_proto_rename_resource(handle, type, resource,
3683da6c28aaSamw 			    newname);
3684da6c28aaSamw 			if (err != SA_OK)
3685da6c28aaSamw 				ret = err;
3686da6c28aaSamw 			sa_free_attr_string(type);
3687da6c28aaSamw 		}
3688da6c28aaSamw 	}
3689da6c28aaSamw 	return (ret);
3690da6c28aaSamw }
3691da6c28aaSamw 
3692da6c28aaSamw /*
3693da6c28aaSamw  * sa_rename_resource(resource, newname)
3694da6c28aaSamw  *
3695da6c28aaSamw  * Rename the resource to the new name, if it is unique.
3696da6c28aaSamw  */
3697da6c28aaSamw 
3698da6c28aaSamw int
3699da6c28aaSamw sa_rename_resource(sa_resource_t resource, char *newname)
3700da6c28aaSamw {
3701da6c28aaSamw 	sa_share_t share;
3702da6c28aaSamw 	sa_group_t group = NULL;
3703da6c28aaSamw 	sa_resource_t target;
3704da6c28aaSamw 	int ret = SA_CONFIG_ERR;
3705da6c28aaSamw 	sa_handle_t handle = NULL;
3706da6c28aaSamw 
3707da6c28aaSamw 	share = sa_get_resource_parent(resource);
3708da6c28aaSamw 	if (share == NULL)
3709da6c28aaSamw 		return (ret);
3710da6c28aaSamw 
3711da6c28aaSamw 	group = sa_get_parent_group(share);
3712da6c28aaSamw 	if (group == NULL)
3713da6c28aaSamw 		return (ret);
3714da6c28aaSamw 
3715da6c28aaSamw 	handle = (sa_handle_impl_t)sa_find_group_handle(group);
3716da6c28aaSamw 	if (handle == NULL)
3717da6c28aaSamw 		return (ret);
3718da6c28aaSamw 
3719da6c28aaSamw 	target = sa_find_resource(handle, newname);
3720da6c28aaSamw 	if (target != NULL) {
3721da6c28aaSamw 		ret = SA_DUPLICATE_NAME;
3722da6c28aaSamw 	} else {
3723da6c28aaSamw 		/*
3724da6c28aaSamw 		 * Everything appears to be valid at this
3725da6c28aaSamw 		 * point. Change the name of the active share and then
3726da6c28aaSamw 		 * update the share in the appropriate repository.
3727da6c28aaSamw 		 */
3728da6c28aaSamw 		ret = proto_rename_resource(handle, group, resource, newname);
3729da6c28aaSamw 		set_node_attr(resource, "name", newname);
3730da6c28aaSamw 		if (!sa_group_is_zfs(group) &&
3731da6c28aaSamw 		    sa_is_persistent((sa_group_t)share)) {
3732da6c28aaSamw 			sa_handle_impl_t ihandle = (sa_handle_impl_t)handle;
3733da6c28aaSamw 			ret = sa_commit_share(ihandle->scfhandle, group,
3734da6c28aaSamw 			    share);
3735da6c28aaSamw 		}
3736da6c28aaSamw 	}
3737da6c28aaSamw 	return (ret);
3738da6c28aaSamw }
3739da6c28aaSamw 
3740da6c28aaSamw /*
3741da6c28aaSamw  * sa_get_resource_attr(resource, tag)
3742da6c28aaSamw  *
3743da6c28aaSamw  * Get the named attribute of the resource. "name" and "id" are
3744da6c28aaSamw  * currently defined.  NULL if tag not defined.
3745da6c28aaSamw  */
3746da6c28aaSamw 
3747da6c28aaSamw char *
3748da6c28aaSamw sa_get_resource_attr(sa_resource_t resource, char *tag)
3749da6c28aaSamw {
3750da6c28aaSamw 	return (get_node_attr((void *)resource, tag));
3751da6c28aaSamw }
3752da6c28aaSamw 
3753da6c28aaSamw /*
3754da6c28aaSamw  * sa_set_resource_attr(resource, tag, value)
3755da6c28aaSamw  *
3756da6c28aaSamw  * Get the named attribute of the resource. "name" and "id" are
3757da6c28aaSamw  * currently defined.  NULL if tag not defined. Currently we don't do
3758da6c28aaSamw  * much, but additional checking may be needed in the future.
3759da6c28aaSamw  */
3760da6c28aaSamw 
3761da6c28aaSamw int
3762da6c28aaSamw sa_set_resource_attr(sa_resource_t resource, char *tag, char *value)
3763da6c28aaSamw {
3764da6c28aaSamw 	set_node_attr((void *)resource, tag, value);
3765da6c28aaSamw 	return (SA_OK);
3766da6c28aaSamw }
3767da6c28aaSamw 
3768da6c28aaSamw /*
3769da6c28aaSamw  * sa_get_resource_parent(resource_t)
3770da6c28aaSamw  *
3771da6c28aaSamw  * Returns the share associated with the resource.
3772da6c28aaSamw  */
3773da6c28aaSamw 
3774da6c28aaSamw sa_share_t
3775da6c28aaSamw sa_get_resource_parent(sa_resource_t resource)
3776da6c28aaSamw {
3777da6c28aaSamw 	sa_share_t share = NULL;
3778da6c28aaSamw 
3779da6c28aaSamw 	if (resource != NULL)
3780da6c28aaSamw 		share = (sa_share_t)((xmlNodePtr)resource)->parent;
3781da6c28aaSamw 	return (share);
3782da6c28aaSamw }
3783da6c28aaSamw 
3784da6c28aaSamw /*
3785da6c28aaSamw  * find_resource(group, name)
3786da6c28aaSamw  *
3787da6c28aaSamw  * Find the resource within the group.
3788da6c28aaSamw  */
3789da6c28aaSamw 
3790da6c28aaSamw static sa_resource_t
3791da6c28aaSamw find_resource(sa_group_t group, char *resname)
3792da6c28aaSamw {
3793da6c28aaSamw 	sa_share_t share;
3794da6c28aaSamw 	sa_resource_t resource = NULL;
3795da6c28aaSamw 	char *name;
3796da6c28aaSamw 
3797da6c28aaSamw 	/* Iterate over all the shares and resources in the group. */
3798da6c28aaSamw 	for (share = sa_get_share(group, NULL);
3799da6c28aaSamw 	    share != NULL && resource == NULL;
3800da6c28aaSamw 	    share = sa_get_next_share(share)) {
3801da6c28aaSamw 		for (resource = sa_get_share_resource(share, NULL);
3802da6c28aaSamw 		    resource != NULL;
3803da6c28aaSamw 		    resource = sa_get_next_resource(resource)) {
3804da6c28aaSamw 			name = sa_get_resource_attr(resource, "name");
3805da6c28aaSamw 			if (name != NULL && xmlStrcasecmp((xmlChar*)name,
3806da6c28aaSamw 			    (xmlChar*)resname) == 0) {
3807da6c28aaSamw 				sa_free_attr_string(name);
3808da6c28aaSamw 				break;
3809da6c28aaSamw 			}
3810da6c28aaSamw 			if (name != NULL) {
3811da6c28aaSamw 				sa_free_attr_string(name);
3812da6c28aaSamw 			}
3813da6c28aaSamw 		}
3814da6c28aaSamw 	}
3815da6c28aaSamw 	return (resource);
3816da6c28aaSamw }
3817da6c28aaSamw 
3818da6c28aaSamw /*
3819da6c28aaSamw  * sa_find_resource(name)
3820da6c28aaSamw  *
3821da6c28aaSamw  * Find the named resource in the system.
3822da6c28aaSamw  */
3823da6c28aaSamw 
3824da6c28aaSamw sa_resource_t
3825da6c28aaSamw sa_find_resource(sa_handle_t handle, char *name)
3826da6c28aaSamw {
3827da6c28aaSamw 	sa_group_t group;
3828da6c28aaSamw 	sa_group_t zgroup;
3829da6c28aaSamw 	sa_resource_t resource = NULL;
3830da6c28aaSamw 
3831da6c28aaSamw 	/*
3832da6c28aaSamw 	 * Iterate over all groups and zfs subgroups and check for
3833da6c28aaSamw 	 * resource name in them.
3834da6c28aaSamw 	 */
3835da6c28aaSamw 	for (group = sa_get_group(handle, NULL); group != NULL;
3836da6c28aaSamw 	    group = sa_get_next_group(group)) {
3837da6c28aaSamw 
3838da6c28aaSamw 		if (is_zfs_group(group)) {
3839da6c28aaSamw 			for (zgroup =
3840da6c28aaSamw 			    (sa_group_t)_sa_get_child_node((xmlNodePtr)group,
3841da6c28aaSamw 			    (xmlChar *)"group");
3842da6c28aaSamw 			    zgroup != NULL && resource == NULL;
3843da6c28aaSamw 			    zgroup = sa_get_next_group(zgroup)) {
3844da6c28aaSamw 				resource = find_resource(zgroup, name);
3845da6c28aaSamw 			}
3846da6c28aaSamw 		} else {
3847da6c28aaSamw 			resource = find_resource(group, name);
3848da6c28aaSamw 		}
3849da6c28aaSamw 		if (resource != NULL)
3850da6c28aaSamw 			break;
3851da6c28aaSamw 	}
3852da6c28aaSamw 	return (resource);
3853da6c28aaSamw }
3854da6c28aaSamw 
3855da6c28aaSamw /*
3856da6c28aaSamw  * sa_get_resource(group, resource)
3857da6c28aaSamw  *
3858da6c28aaSamw  * Search all the shares in the specified group for a share with a
3859da6c28aaSamw  * resource name matching the one specified.
3860da6c28aaSamw  *
3861da6c28aaSamw  * In the future, it may be advantageous to allow group to be NULL and
3862da6c28aaSamw  * search all groups but that isn't needed at present.
3863da6c28aaSamw  */
3864da6c28aaSamw 
3865da6c28aaSamw sa_resource_t
3866da6c28aaSamw sa_get_resource(sa_group_t group, char *resource)
3867da6c28aaSamw {
3868da6c28aaSamw 	sa_share_t share = NULL;
3869da6c28aaSamw 	sa_resource_t res = NULL;
3870da6c28aaSamw 
3871da6c28aaSamw 	if (resource != NULL) {
3872da6c28aaSamw 		for (share = sa_get_share(group, NULL);
3873da6c28aaSamw 		    share != NULL && res == NULL;
3874da6c28aaSamw 		    share = sa_get_next_share(share)) {
3875da6c28aaSamw 			res = sa_get_share_resource(share, resource);
3876da6c28aaSamw 		}
3877da6c28aaSamw 	}
3878da6c28aaSamw 	return (res);
3879da6c28aaSamw }
3880da6c28aaSamw 
3881da6c28aaSamw /*
3882da6c28aaSamw  * sa_enable_resource, protocol)
3883da6c28aaSamw  *	Disable the specified share to the specified protocol.
3884da6c28aaSamw  *	If protocol is NULL, then all protocols.
3885da6c28aaSamw  */
3886da6c28aaSamw int
3887da6c28aaSamw sa_enable_resource(sa_resource_t resource, char *protocol)
3888da6c28aaSamw {
3889da6c28aaSamw 	int ret = SA_OK;
3890da6c28aaSamw 	char **protocols;
3891da6c28aaSamw 	int numproto;
3892da6c28aaSamw 
3893da6c28aaSamw 	if (protocol != NULL) {
3894da6c28aaSamw 		ret = sa_proto_share_resource(protocol, resource);
3895da6c28aaSamw 	} else {
3896da6c28aaSamw 		/* need to do all protocols */
3897da6c28aaSamw 		if ((numproto = sa_get_protocols(&protocols)) >= 0) {
3898da6c28aaSamw 			int i, err;
3899da6c28aaSamw 			for (i = 0; i < numproto; i++) {
3900da6c28aaSamw 				err = sa_proto_share_resource(
3901da6c28aaSamw 				    protocols[i], resource);
3902da6c28aaSamw 				if (err != SA_OK)
3903da6c28aaSamw 					ret = err;
3904da6c28aaSamw 			}
3905da6c28aaSamw 			free(protocols);
3906da6c28aaSamw 		}
3907da6c28aaSamw 	}
3908da6c28aaSamw 	if (ret == SA_OK)
3909da6c28aaSamw 		(void) sa_set_resource_attr(resource, "shared", NULL);
3910da6c28aaSamw 
3911da6c28aaSamw 	return (ret);
3912da6c28aaSamw }
3913da6c28aaSamw 
3914da6c28aaSamw /*
3915da6c28aaSamw  * sa_disable_resource(resource, protocol)
3916da6c28aaSamw  *
3917da6c28aaSamw  *	Disable the specified share for the specified protocol.  If
3918da6c28aaSamw  *	protocol is NULL, then all protocols.  If the underlying
3919da6c28aaSamw  *	protocol doesn't implement disable at the resource level, we
3920da6c28aaSamw  *	disable at the share level.
3921da6c28aaSamw  */
3922da6c28aaSamw int
3923da6c28aaSamw sa_disable_resource(sa_resource_t resource, char *protocol)
3924da6c28aaSamw {
3925da6c28aaSamw 	int ret = SA_OK;
3926da6c28aaSamw 	char **protocols;
3927da6c28aaSamw 	int numproto;
3928da6c28aaSamw 
3929da6c28aaSamw 	if (protocol != NULL) {
3930da6c28aaSamw 		ret = sa_proto_unshare_resource(protocol, resource);
3931da6c28aaSamw 		if (ret == SA_NOT_IMPLEMENTED) {
3932da6c28aaSamw 			sa_share_t parent;
3933da6c28aaSamw 			/*
3934da6c28aaSamw 			 * The protocol doesn't implement unshare
3935da6c28aaSamw 			 * resource. That implies that resource names are
3936da6c28aaSamw 			 * simple aliases for this protocol so we need to
3937da6c28aaSamw 			 * unshare the share.
3938da6c28aaSamw 			 */
3939da6c28aaSamw 			parent = sa_get_resource_parent(resource);
3940da6c28aaSamw 			if (parent != NULL)
3941da6c28aaSamw 				ret = sa_disable_share(parent, protocol);
3942da6c28aaSamw 			else
3943da6c28aaSamw 				ret = SA_CONFIG_ERR;
3944da6c28aaSamw 		}
3945da6c28aaSamw 	} else {
3946da6c28aaSamw 		/* need to do all protocols */
3947da6c28aaSamw 		if ((numproto = sa_get_protocols(&protocols)) >= 0) {
3948da6c28aaSamw 			int i, err;
3949da6c28aaSamw 			for (i = 0; i < numproto; i++) {
3950da6c28aaSamw 				err = sa_proto_unshare_resource(protocols[i],
3951da6c28aaSamw 				    resource);
3952da6c28aaSamw 				if (err == SA_NOT_SUPPORTED) {
3953da6c28aaSamw 					sa_share_t parent;
3954da6c28aaSamw 					parent = sa_get_resource_parent(
3955da6c28aaSamw 					    resource);
3956da6c28aaSamw 					if (parent != NULL)
3957da6c28aaSamw 						err = sa_disable_share(parent,
3958da6c28aaSamw 						    protocols[i]);
3959da6c28aaSamw 					else
3960da6c28aaSamw 						err = SA_CONFIG_ERR;
3961da6c28aaSamw 				}
3962da6c28aaSamw 				if (err != SA_OK)
3963da6c28aaSamw 					ret = err;
3964da6c28aaSamw 			}
3965da6c28aaSamw 			free(protocols);
3966da6c28aaSamw 		}
3967da6c28aaSamw 	}
3968da6c28aaSamw 	if (ret == SA_OK)
3969da6c28aaSamw 		(void) sa_set_resource_attr(resource, "shared", NULL);
3970da6c28aaSamw 
3971da6c28aaSamw 	return (ret);
3972da6c28aaSamw }
3973da6c28aaSamw 
3974da6c28aaSamw /*
3975da6c28aaSamw  * sa_set_resource_description(resource, content)
3976da6c28aaSamw  *
3977da6c28aaSamw  * Set the description of share to content.
3978da6c28aaSamw  */
3979da6c28aaSamw 
3980da6c28aaSamw int
3981da6c28aaSamw sa_set_resource_description(sa_resource_t resource, char *content)
3982da6c28aaSamw {
3983da6c28aaSamw 	xmlNodePtr node;
3984da6c28aaSamw 	sa_group_t group;
3985da6c28aaSamw 	sa_share_t share;
3986da6c28aaSamw 	int ret = SA_OK;
3987da6c28aaSamw 
3988da6c28aaSamw 	for (node = ((xmlNodePtr)resource)->children;
3989da6c28aaSamw 	    node != NULL;
3990da6c28aaSamw 	    node = node->next) {
3991da6c28aaSamw 		if (xmlStrcmp(node->name, (xmlChar *)"description") == 0) {
3992da6c28aaSamw 			break;
3993da6c28aaSamw 		}
3994da6c28aaSamw 	}
3995da6c28aaSamw 
3996da6c28aaSamw 	/* no existing description but want to add */
3997da6c28aaSamw 	if (node == NULL && content != NULL) {
3998da6c28aaSamw 		/* add a description */
3999da6c28aaSamw 		node = _sa_set_share_description(resource, content);
4000da6c28aaSamw 	} else if (node != NULL && content != NULL) {
4001da6c28aaSamw 		/* update a description */
4002da6c28aaSamw 		xmlNodeSetContent(node, (xmlChar *)content);
4003da6c28aaSamw 	} else if (node != NULL && content == NULL) {
4004da6c28aaSamw 		/* remove an existing description */
4005da6c28aaSamw 		xmlUnlinkNode(node);
4006da6c28aaSamw 		xmlFreeNode(node);
4007da6c28aaSamw 	}
4008da6c28aaSamw 	share = sa_get_resource_parent(resource);
4009da6c28aaSamw 	group = sa_get_parent_group(share);
4010da6c28aaSamw 	if (group != NULL && sa_is_persistent(share)) {
4011da6c28aaSamw 		sa_handle_impl_t impl_handle;
4012da6c28aaSamw 		impl_handle = (sa_handle_impl_t)sa_find_group_handle(group);
4013da6c28aaSamw 		if (impl_handle != NULL)
4014da6c28aaSamw 			ret = sa_commit_share(impl_handle->scfhandle,
4015da6c28aaSamw 			    group, share);
4016da6c28aaSamw 		else
4017da6c28aaSamw 			ret = SA_SYSTEM_ERR;
4018da6c28aaSamw 	}
4019da6c28aaSamw 	return (ret);
4020da6c28aaSamw }
4021da6c28aaSamw 
4022da6c28aaSamw /*
4023da6c28aaSamw  * sa_get_resource_description(share)
4024da6c28aaSamw  *
4025da6c28aaSamw  * Return the description text for the specified share if it
4026da6c28aaSamw  * exists. NULL if no description exists.
4027da6c28aaSamw  */
4028da6c28aaSamw 
4029da6c28aaSamw char *
4030da6c28aaSamw sa_get_resource_description(sa_resource_t resource)
4031da6c28aaSamw {
4032da6c28aaSamw 	xmlChar *description = NULL;
4033da6c28aaSamw 	xmlNodePtr node;
4034da6c28aaSamw 
4035da6c28aaSamw 	for (node = ((xmlNodePtr)resource)->children; node != NULL;
4036da6c28aaSamw 	    node = node->next) {
4037da6c28aaSamw 		if (xmlStrcmp(node->name, (xmlChar *)"description") == 0)
4038da6c28aaSamw 			break;
4039da6c28aaSamw 	}
4040da6c28aaSamw 	if (node != NULL) {
4041da6c28aaSamw 		description = xmlNodeGetContent(node);
4042da6c28aaSamw 		fixproblemchars((char *)description);
4043da6c28aaSamw 	}
4044da6c28aaSamw 	return ((char *)description);
4045da6c28aaSamw }
4046