f4a605
From a0618e0eda69d31d090f776a9217a6a3cf76e5da Mon Sep 17 00:00:00 2001
f4a605
From: Jeremy Allison <jra@samba.org>
f4a605
Date: Thu, 21 Oct 2021 16:37:27 -0700
f4a605
Subject: [PATCH 1/7] s3: smbd: Add two tests showing the ability to delete a
f4a605
 directory containing a dangling symlink over SMB2 depends on "delete veto
f4a605
 files" setting.
f4a605
f4a605
Add knownfail.
f4a605
f4a605
BUG: https://bugzilla.samba.org/show_bug.cgi?id=14879
f4a605
f4a605
Signed-off-by: Jeremy Allison <jra@samba.org>
f4a605
Reviewed-by: Ralph Boehme <slow@samba.org>
f4a605
(cherry picked from commit 942123b95923f35a32df4196a072a3ed3468396a)
f4a605
(cherry picked from commit 359517877d6462ff4398401748f921c8b79357a6)
f4a605
---
f4a605
 selftest/knownfail.d/rmdir_dangle_symlink     |   1 +
f4a605
 selftest/target/Samba3.pm                     |   4 +
f4a605
 .../test_delete_veto_files_only_rmdir.sh      | 183 ++++++++++++++++++
f4a605
 source3/selftest/tests.py                     |   3 +
f4a605
 4 files changed, 191 insertions(+)
f4a605
 create mode 100644 selftest/knownfail.d/rmdir_dangle_symlink
f4a605
 create mode 100755 source3/script/tests/test_delete_veto_files_only_rmdir.sh
f4a605
f4a605
diff --git a/selftest/knownfail.d/rmdir_dangle_symlink b/selftest/knownfail.d/rmdir_dangle_symlink
f4a605
new file mode 100644
f4a605
index 00000000000..c775dc5fe15
f4a605
--- /dev/null
f4a605
+++ b/selftest/knownfail.d/rmdir_dangle_symlink
f4a605
@@ -0,0 +1 @@
f4a605
+^samba3.blackbox.test_dangle_rmdir.rmdir can delete directory containing dangling symlink\(fileserver\)
f4a605
diff --git a/selftest/target/Samba3.pm b/selftest/target/Samba3.pm
f4a605
index bbff9d74817..588d7779dd4 100755
f4a605
--- a/selftest/target/Samba3.pm
f4a605
+++ b/selftest/target/Samba3.pm
f4a605
@@ -1584,6 +1584,10 @@ sub setup_fileserver
f4a605
 	veto files = /veto_name*/
f4a605
 	delete veto files = yes
f4a605
 
f4a605
+[delete_veto_files_only]
f4a605
+	path = $veto_sharedir
f4a605
+	delete veto files = yes
f4a605
+
f4a605
 [homes]
f4a605
 	comment = Home directories
f4a605
 	browseable = No
f4a605
diff --git a/source3/script/tests/test_delete_veto_files_only_rmdir.sh b/source3/script/tests/test_delete_veto_files_only_rmdir.sh
f4a605
new file mode 100755
f4a605
index 00000000000..d2c3b2198f7
f4a605
--- /dev/null
f4a605
+++ b/source3/script/tests/test_delete_veto_files_only_rmdir.sh
f4a605
@@ -0,0 +1,183 @@
f4a605
+#!/bin/sh
f4a605
+#
f4a605
+# Check smbclient can (or cannot) delete a directory containing dangling symlinks.
f4a605
+# BUG: https://bugzilla.samba.org/show_bug.cgi?id=14879
f4a605
+#
f4a605
+
f4a605
+if [ $# -lt 6 ]; then
f4a605
+cat <
f4a605
+Usage: $0 SERVER SERVER_IP USERNAME PASSWORD SHAREPATH SMBCLIENT
f4a605
+EOF
f4a605
+exit 1;
f4a605
+fi
f4a605
+
f4a605
+SERVER=${1}
f4a605
+SERVER_IP=${2}
f4a605
+USERNAME=${3}
f4a605
+PASSWORD=${4}
f4a605
+SHAREPATH=${5}
f4a605
+SMBCLIENT=${6}
f4a605
+shift 6
f4a605
+SMBCLIENT="$VALGRIND ${SMBCLIENT}"
f4a605
+ADDARGS="$@"
f4a605
+
f4a605
+incdir=$(dirname "$0")/../../../testprogs/blackbox
f4a605
+. $incdir/subunit.sh
f4a605
+
f4a605
+failed=0
f4a605
+
f4a605
+rmdir_path="$SHAREPATH/dir"
f4a605
+
f4a605
+#
f4a605
+# Using the share "[delete_veto_files_only]" we CAN delete
f4a605
+# a directory containing only a dangling symlink.
f4a605
+#
f4a605
+test_dangle_symlink_delete_veto_rmdir()
f4a605
+{
f4a605
+    local dangle_symlink_path="$rmdir_path/bad_link"
f4a605
+    local tmpfile=$PREFIX/smbclient.in.$$
f4a605
+
f4a605
+    # Create rmdir directory.
f4a605
+    mkdir -p "$rmdir_path"
f4a605
+    # Create dangling symlink underneath.
f4a605
+    ln -s "nowhere-foo" "$dangle_symlink_path"
f4a605
+
f4a605
+    cat > "$tmpfile" <
f4a605
+cd dir
f4a605
+ls
f4a605
+quit
f4a605
+EOF
f4a605
+
f4a605
+    local cmd='CLI_FORCE_INTERACTIVE=yes $SMBCLIENT //$SERVER/delete_veto_files_only -U$USERNAME%$PASSWORD $ADDARGS < $tmpfile 2>&1'
f4a605
+    eval echo "$cmd"
f4a605
+    out=$(eval "$cmd")
f4a605
+    ret=$?
f4a605
+
f4a605
+    # Check for smbclient error.
f4a605
+    if [ $ret != 0 ] ; then
f4a605
+        echo "Failed accessing share delete_veto_files_only - $ret"
f4a605
+        echo "$out"
f4a605
+        return 1
f4a605
+    fi
f4a605
+
f4a605
+    # We should NOT see the dangling symlink file.
f4a605
+    echo "$out" | grep bad_link
f4a605
+    ret=$?
f4a605
+    if [ $ret -eq 0 ] ; then
f4a605
+       echo "Saw dangling symlink bad_link in share delete_veto_files_only"
f4a605
+       echo "$out"
f4a605
+       return 1
f4a605
+    fi
f4a605
+
f4a605
+    # Try and remove the directory, should succeed.
f4a605
+    cat > "$tmpfile" <
f4a605
+rd dir
f4a605
+quit
f4a605
+EOF
f4a605
+
f4a605
+    local cmd='CLI_FORCE_INTERACTIVE=yes $SMBCLIENT //$SERVER/delete_veto_files_only -U$USERNAME%$PASSWORD $ADDARGS < $tmpfile 2>&1'
f4a605
+    eval echo "$cmd"
f4a605
+    out=$(eval "$cmd")
f4a605
+    ret=$?
f4a605
+
f4a605
+    # Check for smbclient error.
f4a605
+    if [ $ret != 0 ] ; then
f4a605
+        echo "Failed accessing share delete_veto_files_only - $ret"
f4a605
+        echo "$out"
f4a605
+        return 1
f4a605
+    fi
f4a605
+
f4a605
+    # We should get no NT_STATUS_ errors.
f4a605
+    echo "$out" | grep NT_STATUS_
f4a605
+    ret=$?
f4a605
+    if [ $ret -eq 0 ] ; then
f4a605
+       echo "Got error NT_STATUS_ in share delete_veto_files_only"
f4a605
+       echo "$out"
f4a605
+       return 1
f4a605
+    fi
f4a605
+
f4a605
+    return 0
f4a605
+}
f4a605
+
f4a605
+#
f4a605
+# Using the share "[veto_files_nodelete]" we CANNOT delete
f4a605
+# a directory containing only a dangling symlink.
f4a605
+#
f4a605
+test_dangle_symlink_veto_files_nodelete()
f4a605
+{
f4a605
+    local dangle_symlink_path="$rmdir_path/bad_link"
f4a605
+    local tmpfile=$PREFIX/smbclient.in.$$
f4a605
+
f4a605
+    # Create rmdir directory.
f4a605
+    mkdir -p "$rmdir_path"
f4a605
+    # Create dangling symlink underneath.
f4a605
+    ln -s "nowhere-foo" "$dangle_symlink_path"
f4a605
+
f4a605
+    cat > "$tmpfile" <
f4a605
+cd dir
f4a605
+ls
f4a605
+quit
f4a605
+EOF
f4a605
+
f4a605
+    local cmd='CLI_FORCE_INTERACTIVE=yes $SMBCLIENT //$SERVER/veto_files_nodelete -U$USERNAME%$PASSWORD $ADDARGS < $tmpfile 2>&1'
f4a605
+    eval echo "$cmd"
f4a605
+    out=$(eval "$cmd")
f4a605
+    ret=$?
f4a605
+
f4a605
+    # Check for smbclient error.
f4a605
+    if [ $ret != 0 ] ; then
f4a605
+        echo "Failed accessing share veto_files_nodelete - $ret"
f4a605
+        echo "$out"
f4a605
+        return 1
f4a605
+    fi
f4a605
+
f4a605
+    # We should NOT see the dangling symlink file.
f4a605
+    echo "$out" | grep bad_link
f4a605
+    ret=$?
f4a605
+    if [ $ret -eq 0 ] ; then
f4a605
+       echo "Saw dangling symlink bad_link in share veto_files_nodelete"
f4a605
+       echo "$out"
f4a605
+       return 1
f4a605
+    fi
f4a605
+
f4a605
+    # Try and remove the directory, should fail with DIRECTORY_NOT_EMPTY.
f4a605
+    cat > "$tmpfile" <
f4a605
+rd dir
f4a605
+quit
f4a605
+EOF
f4a605
+
f4a605
+    local cmd='CLI_FORCE_INTERACTIVE=yes $SMBCLIENT //$SERVER/veto_files_nodelete -U$USERNAME%$PASSWORD $ADDARGS < $tmpfile 2>&1'
f4a605
+    eval echo "$cmd"
f4a605
+    out=$(eval "$cmd")
f4a605
+    ret=$?
f4a605
+
f4a605
+    # Check for smbclient error.
f4a605
+    if [ $ret != 0 ] ; then
f4a605
+        echo "Failed accessing share veto_files_nodelete - $ret"
f4a605
+        echo "$out"
f4a605
+        return 1
f4a605
+    fi
f4a605
+
f4a605
+    # We should get NT_STATUS_DIRECTORY_NOT_EMPTY errors.
f4a605
+    echo "$out" | grep NT_STATUS_DIRECTORY_NOT_EMPTY
f4a605
+    ret=$?
f4a605
+    if [ $ret -ne 0 ] ; then
f4a605
+       echo "Should get NT_STATUS_DIRECTORY_NOT_EMPTY in share veto_files_nodelete"
f4a605
+       echo "$out"
f4a605
+       return 1
f4a605
+    fi
f4a605
+
f4a605
+    return 0
f4a605
+}
f4a605
+
f4a605
+
f4a605
+testit "rmdir can delete directory containing dangling symlink" \
f4a605
+   test_dangle_symlink_delete_veto_rmdir || failed=$(expr "$failed" + 1)
f4a605
+
f4a605
+rm -rf "$rmdir_path"
f4a605
+
f4a605
+testit "rmdir cannot delete directory delete_veto_files_no containing dangling symlink" \
f4a605
+   test_dangle_symlink_veto_files_nodelete || failed=$(expr "$failed" + 1)
f4a605
+
f4a605
+rm -rf "$rmdir_path"
f4a605
+exit "$failed"
f4a605
diff --git a/source3/selftest/tests.py b/source3/selftest/tests.py
f4a605
index 82f32ec4232..330024cf77c 100755
f4a605
--- a/source3/selftest/tests.py
f4a605
+++ b/source3/selftest/tests.py
f4a605
@@ -501,6 +501,9 @@ for env in ["fileserver"]:
f4a605
     plantestsuite("samba3.blackbox.test_veto_rmdir", env,
f4a605
                   [os.path.join(samba3srcdir, "script/tests/test_veto_rmdir.sh"),
f4a605
                   '$SERVER', '$SERVER_IP', '$USERNAME', '$PASSWORD', '$LOCAL_PATH/veto', smbclient3])
f4a605
+    plantestsuite("samba3.blackbox.test_dangle_rmdir", env,
f4a605
+                  [os.path.join(samba3srcdir, "script/tests/test_delete_veto_files_only_rmdir.sh"),
f4a605
+                  '$SERVER', '$SERVER_IP', '$USERNAME', '$PASSWORD', '$LOCAL_PATH/veto', smbclient3])
f4a605
 
f4a605
     #
f4a605
     # tar command tests
f4a605
-- 
f4a605
2.33.1
f4a605
f4a605
f4a605
From 47c98fe40101b60d5b5a34eb8ef02106c1da66c9 Mon Sep 17 00:00:00 2001
f4a605
From: Jeremy Allison <jra@samba.org>
f4a605
Date: Mon, 25 Oct 2021 12:01:58 -0700
f4a605
Subject: [PATCH 2/7] s3: VFS: streams_depot. Allow unlinkat to cope with
f4a605
 dangling symlinks.
f4a605
f4a605
BUG: https://bugzilla.samba.org/show_bug.cgi?id=14879
f4a605
f4a605
Signed-off-by: Jeremy Allison <jra@samba.org>
f4a605
Reviewed-by: Ralph Boehme <slow@samba.org>
f4a605
(cherry picked from commit 295d7d026babe3cd5123d0f53adcb16868907f05)
f4a605
(backported from commit 7a4173809a87350bc3580240232978042ec2ceca)
f4a605
[pfilipen@redhat.com: code in 4.15 uses different variable name]
f4a605
---
f4a605
 source3/modules/vfs_streams_depot.c | 10 ++++++++++
f4a605
 1 file changed, 10 insertions(+)
f4a605
f4a605
diff --git a/source3/modules/vfs_streams_depot.c b/source3/modules/vfs_streams_depot.c
f4a605
index a5e02d5a069..dd6376e5fd0 100644
f4a605
--- a/source3/modules/vfs_streams_depot.c
f4a605
+++ b/source3/modules/vfs_streams_depot.c
f4a605
@@ -739,6 +739,16 @@ static int streams_depot_unlink_internal(vfs_handle_struct *handle,
f4a605
 		ret = SMB_VFS_NEXT_LSTAT(handle, smb_fname_base);
f4a605
 	} else {
f4a605
 		ret = SMB_VFS_NEXT_STAT(handle, smb_fname_base);
f4a605
+		if (ret == -1 && (errno == ENOENT || errno == ELOOP)) {
f4a605
+			if (VALID_STAT(smb_fname->st) &&
f4a605
+					S_ISLNK(smb_fname->st.st_ex_mode)) {
f4a605
+				/*
f4a605
+				 * Original name was a link - Could be
f4a605
+				 * trying to remove a dangling symlink.
f4a605
+				 */
f4a605
+				ret = SMB_VFS_NEXT_LSTAT(handle, smb_fname_base);
f4a605
+			}
f4a605
+		}
f4a605
 	}
f4a605
 
f4a605
 	if (ret == -1) {
f4a605
-- 
f4a605
2.33.1
f4a605
f4a605
f4a605
From 474a91d03527a15f7655be3866a9e5eaa405118f Mon Sep 17 00:00:00 2001
f4a605
From: Jeremy Allison <jra@samba.org>
f4a605
Date: Mon, 25 Oct 2021 12:02:43 -0700
f4a605
Subject: [PATCH 3/7] s3: VFS: xattr_tdb. Allow unlinkat to cope with dangling
f4a605
 symlinks.
f4a605
f4a605
BUG: https://bugzilla.samba.org/show_bug.cgi?id=14879
f4a605
f4a605
Signed-off-by: Jeremy Allison <jra@samba.org>
f4a605
Reviewed-by: Ralph Boehme <slow@samba.org>
f4a605
(cherry picked from commit f254be19d6501a4f573843af97963e350a9ee2ed)
f4a605
(backported from commit 0dba0917fd97e975d1daab5b0828644d026c2bc5)
f4a605
[pfilipen@redhat.com: code in 4.15 uses different variable name]
f4a605
---
f4a605
 source3/modules/vfs_xattr_tdb.c | 10 ++++++++++
f4a605
 1 file changed, 10 insertions(+)
f4a605
f4a605
diff --git a/source3/modules/vfs_xattr_tdb.c b/source3/modules/vfs_xattr_tdb.c
f4a605
index d89a1dd0d7d..e06ff9639f1 100644
f4a605
--- a/source3/modules/vfs_xattr_tdb.c
f4a605
+++ b/source3/modules/vfs_xattr_tdb.c
f4a605
@@ -639,6 +639,16 @@ static int xattr_tdb_unlinkat(vfs_handle_struct *handle,
f4a605
 		ret = SMB_VFS_NEXT_LSTAT(handle, smb_fname_tmp);
f4a605
 	} else {
f4a605
 		ret = SMB_VFS_NEXT_STAT(handle, smb_fname_tmp);
f4a605
+		if (ret == -1 && (errno == ENOENT || errno == ELOOP)) {
f4a605
+			if (VALID_STAT(smb_fname->st) &&
f4a605
+					S_ISLNK(smb_fname->st.st_ex_mode)) {
f4a605
+				/*
f4a605
+				 * Original name was a link - Could be
f4a605
+				 * trying to remove a dangling symlink.
f4a605
+				 */
f4a605
+				ret = SMB_VFS_NEXT_LSTAT(handle, smb_fname_tmp);
f4a605
+			}
f4a605
+		}
f4a605
 	}
f4a605
 	if (ret == -1) {
f4a605
 		goto out;
f4a605
-- 
f4a605
2.33.1
f4a605
f4a605
f4a605
From 298a8dac1160ebba56cd84b7e25908e160b88f85 Mon Sep 17 00:00:00 2001
f4a605
From: Jeremy Allison <jra@samba.org>
f4a605
Date: Mon, 25 Oct 2021 12:21:37 -0700
f4a605
Subject: [PATCH 4/7] s3: smbd: Fix rmdir_internals() to do an early return if
f4a605
 lp_delete_veto_files() is not set.
f4a605
f4a605
Fix the comments to match what the code actually does. The
f4a605
exit at the end of the scan directory loop if we find a client
f4a605
visible filename is a change in behavior, but the previous
f4a605
behavior (not exist on visible filename, but delete it) was
f4a605
a bug and in non-tested code. Now it's testd.
f4a605
f4a605
BUG: https://bugzilla.samba.org/show_bug.cgi?id=14879
f4a605
f4a605
Signed-off-by: Jeremy Allison <jra@samba.org>
f4a605
Reviewed-by: Ralph Boehme <slow@samba.org>
f4a605
(cherry picked from commit a37d16e7c55f85e3f2c9c8614755ea6307092d5f)
f4a605
(backported from commit e00fe095e8cf7ab54bc82870b913762d2fdddbad)
f4a605
[pfilipen@redhat.com: rmdir_internals() got refactored in 4.15]
f4a605
---
f4a605
 source3/smbd/close.c | 247 ++++++++++++++++++++++---------------------
f4a605
 1 file changed, 128 insertions(+), 119 deletions(-)
f4a605
f4a605
diff --git a/source3/smbd/close.c b/source3/smbd/close.c
f4a605
index f05619d1886..0c102b9533b 100644
f4a605
--- a/source3/smbd/close.c
f4a605
+++ b/source3/smbd/close.c
f4a605
@@ -938,8 +938,11 @@ static NTSTATUS rmdir_internals(TALLOC_CTX *ctx, files_struct *fsp)
f4a605
 {
f4a605
 	connection_struct *conn = fsp->conn;
f4a605
 	struct smb_filename *smb_dname = fsp->fsp_name;
f4a605
-	const struct loadparm_substitution *lp_sub =
f4a605
-		loadparm_s3_global_substitution();
f4a605
+	SMB_STRUCT_STAT st;
f4a605
+	const char *dname = NULL;
f4a605
+	char *talloced = NULL;
f4a605
+	long dirpos = 0;
f4a605
+	struct smb_Dir *dir_hnd = NULL;
f4a605
 	int ret;
f4a605
 
f4a605
 	SMB_ASSERT(!is_ntfs_stream_smb_fname(smb_dname));
f4a605
@@ -974,143 +977,149 @@ static NTSTATUS rmdir_internals(TALLOC_CTX *ctx, files_struct *fsp)
f4a605
 		return NT_STATUS_OK;
f4a605
 	}
f4a605
 
f4a605
-	if(((errno == ENOTEMPTY)||(errno == EEXIST)) && *lp_veto_files(talloc_tos(), lp_sub, SNUM(conn))) {
f4a605
-		/*
f4a605
-		 * Check to see if the only thing in this directory are
f4a605
-		 * vetoed files/directories. If so then delete them and
f4a605
-		 * retry. If we fail to delete any of them (and we *don't*
f4a605
-		 * do a recursive delete) then fail the rmdir.
f4a605
-		 */
f4a605
-		SMB_STRUCT_STAT st;
f4a605
-		const char *dname = NULL;
f4a605
-		char *talloced = NULL;
f4a605
-		long dirpos = 0;
f4a605
-		struct smb_Dir *dir_hnd = OpenDir(talloc_tos(), conn,
f4a605
-						  smb_dname, NULL,
f4a605
-						  0);
f4a605
-
f4a605
-		if(dir_hnd == NULL) {
f4a605
+	if (!((errno == ENOTEMPTY) || (errno == EEXIST))) {
f4a605
+		DEBUG(3,("rmdir_internals: couldn't remove directory %s : "
f4a605
+			 "%s\n", smb_fname_str_dbg(smb_dname),
f4a605
+			 strerror(errno)));
f4a605
+		return map_nt_error_from_unix(errno);
f4a605
+	}
f4a605
+
f4a605
+	/*
f4a605
+	 * Here we know the initial directory unlink failed with
f4a605
+	 * ENOTEMPTY or EEXIST so we know there are objects within.
f4a605
+	 * If we don't have permission to delete files non
f4a605
+	 * visible to the client just fail the directory delete.
f4a605
+	 */
f4a605
+
f4a605
+	if (!lp_delete_veto_files(SNUM(conn))) {
f4a605
+		errno = ENOTEMPTY;
f4a605
+		goto err;
f4a605
+	}
f4a605
+
f4a605
+	/*
f4a605
+	 * Check to see if the only thing in this directory are
f4a605
+	 * files non-visible to the client. If not, fail the delete.
f4a605
+	 */
f4a605
+
f4a605
+	dir_hnd = OpenDir(talloc_tos(), conn, smb_dname, NULL, 0);
f4a605
+	if (dir_hnd == NULL) {
f4a605
+		errno = ENOTEMPTY;
f4a605
+		goto err;
f4a605
+	}
f4a605
+
f4a605
+	while ((dname = ReadDirName(dir_hnd, &dirpos, &st, &talloced)) != NULL) {
f4a605
+		if((strcmp(dname, ".") == 0) || (strcmp(dname, "..")==0)) {
f4a605
+			TALLOC_FREE(talloced);
f4a605
+			continue;
f4a605
+		}
f4a605
+		if (!is_visible_file(conn,
f4a605
+					dir_hnd,
f4a605
+					dname,
f4a605
+					&st,
f4a605
+					false)) {
f4a605
+			TALLOC_FREE(talloced);
f4a605
+			continue;
f4a605
+		}
f4a605
+		if(!IS_VETO_PATH(conn, dname)) {
f4a605
+			/*
f4a605
+			 * We found a client visible name.
f4a605
+			 * We cannot delete this directory.
f4a605
+			 */
f4a605
+			DBG_DEBUG("got name %s - "
f4a605
+				"can't delete directory %s\n",
f4a605
+				dname,
f4a605
+				fsp_str_dbg(fsp));
f4a605
+			TALLOC_FREE(dir_hnd);
f4a605
+			TALLOC_FREE(talloced);
f4a605
 			errno = ENOTEMPTY;
f4a605
 			goto err;
f4a605
 		}
f4a605
+		TALLOC_FREE(talloced);
f4a605
+	}
f4a605
 
f4a605
-		while ((dname = ReadDirName(dir_hnd, &dirpos, &st,
f4a605
-					    &talloced)) != NULL) {
f4a605
-			if((strcmp(dname, ".") == 0) || (strcmp(dname, "..")==0)) {
f4a605
-				TALLOC_FREE(talloced);
f4a605
-				continue;
f4a605
-			}
f4a605
-			if (!is_visible_file(conn,
f4a605
-						dir_hnd,
f4a605
-						dname,
f4a605
-						&st,
f4a605
-						false)) {
f4a605
-				TALLOC_FREE(talloced);
f4a605
-				continue;
f4a605
-			}
f4a605
-			if(!IS_VETO_PATH(conn, dname)) {
f4a605
-				TALLOC_FREE(dir_hnd);
f4a605
-				TALLOC_FREE(talloced);
f4a605
-				errno = ENOTEMPTY;
f4a605
-				goto err;
f4a605
-			}
f4a605
+	/* Do a recursive delete. */
f4a605
+	RewindDir(dir_hnd,&dirpos);
f4a605
+	while ((dname = ReadDirName(dir_hnd, &dirpos, &st, &talloced)) != NULL) {
f4a605
+		struct smb_filename *smb_dname_full = NULL;
f4a605
+		char *fullname = NULL;
f4a605
+		bool do_break = true;
f4a605
+
f4a605
+		if (ISDOT(dname) || ISDOTDOT(dname)) {
f4a605
+			TALLOC_FREE(talloced);
f4a605
+			continue;
f4a605
+		}
f4a605
+		if (!is_visible_file(conn,
f4a605
+					dir_hnd,
f4a605
+					dname,
f4a605
+					&st,
f4a605
+					false)) {
f4a605
 			TALLOC_FREE(talloced);
f4a605
+			continue;
f4a605
 		}
f4a605
 
f4a605
-		/* We only have veto files/directories.
f4a605
-		 * Are we allowed to delete them ? */
f4a605
+		fullname = talloc_asprintf(ctx,
f4a605
+				"%s/%s",
f4a605
+				smb_dname->base_name,
f4a605
+				dname);
f4a605
 
f4a605
-		if(!lp_delete_veto_files(SNUM(conn))) {
f4a605
-			TALLOC_FREE(dir_hnd);
f4a605
-			errno = ENOTEMPTY;
f4a605
-			goto err;
f4a605
+		if (fullname == NULL) {
f4a605
+			errno = ENOMEM;
f4a605
+			goto err_break;
f4a605
 		}
f4a605
 
f4a605
-		/* Do a recursive delete. */
f4a605
-		RewindDir(dir_hnd,&dirpos);
f4a605
-		while ((dname = ReadDirName(dir_hnd, &dirpos, &st,
f4a605
-					    &talloced)) != NULL) {
f4a605
-			struct smb_filename *smb_dname_full = NULL;
f4a605
-			char *fullname = NULL;
f4a605
-			bool do_break = true;
f4a605
-
f4a605
-			if (ISDOT(dname) || ISDOTDOT(dname)) {
f4a605
-				TALLOC_FREE(talloced);
f4a605
-				continue;
f4a605
-			}
f4a605
-			if (!is_visible_file(conn,
f4a605
-						dir_hnd,
f4a605
-						dname,
f4a605
-						&st,
f4a605
-						false)) {
f4a605
-				TALLOC_FREE(talloced);
f4a605
-				continue;
f4a605
-			}
f4a605
-
f4a605
-			fullname = talloc_asprintf(ctx,
f4a605
-					"%s/%s",
f4a605
-					smb_dname->base_name,
f4a605
-					dname);
f4a605
+		smb_dname_full = synthetic_smb_fname(talloc_tos(),
f4a605
+						fullname,
f4a605
+						NULL,
f4a605
+						NULL,
f4a605
+						smb_dname->twrp,
f4a605
+						smb_dname->flags);
f4a605
+		if (smb_dname_full == NULL) {
f4a605
+			errno = ENOMEM;
f4a605
+			goto err_break;
f4a605
+		}
f4a605
 
f4a605
-			if(!fullname) {
f4a605
-				errno = ENOMEM;
f4a605
+		if(SMB_VFS_LSTAT(conn, smb_dname_full) != 0) {
f4a605
+			goto err_break;
f4a605
+		}
f4a605
+		if(smb_dname_full->st.st_ex_mode & S_IFDIR) {
f4a605
+			int retval;
f4a605
+			if(!recursive_rmdir(ctx, conn,
f4a605
+					    smb_dname_full)) {
f4a605
 				goto err_break;
f4a605
 			}
f4a605
-
f4a605
-			smb_dname_full = synthetic_smb_fname(talloc_tos(),
f4a605
-							fullname,
f4a605
-							NULL,
f4a605
-							NULL,
f4a605
-							smb_dname->twrp,
f4a605
-							smb_dname->flags);
f4a605
-			if (smb_dname_full == NULL) {
f4a605
-				errno = ENOMEM;
f4a605
+			retval = SMB_VFS_UNLINKAT(conn,
f4a605
+					conn->cwd_fsp,
f4a605
+					smb_dname_full,
f4a605
+					AT_REMOVEDIR);
f4a605
+			if(retval != 0) {
f4a605
 				goto err_break;
f4a605
 			}
f4a605
-
f4a605
-			if(SMB_VFS_LSTAT(conn, smb_dname_full) != 0) {
f4a605
+		} else {
f4a605
+			int retval = SMB_VFS_UNLINKAT(conn,
f4a605
+					conn->cwd_fsp,
f4a605
+					smb_dname_full,
f4a605
+					0);
f4a605
+			if(retval != 0) {
f4a605
 				goto err_break;
f4a605
 			}
f4a605
-			if(smb_dname_full->st.st_ex_mode & S_IFDIR) {
f4a605
-				int retval;
f4a605
-				if(!recursive_rmdir(ctx, conn,
f4a605
-						    smb_dname_full)) {
f4a605
-					goto err_break;
f4a605
-				}
f4a605
-				retval = SMB_VFS_UNLINKAT(conn,
f4a605
-						conn->cwd_fsp,
f4a605
-						smb_dname_full,
f4a605
-						AT_REMOVEDIR);
f4a605
-				if(retval != 0) {
f4a605
-					goto err_break;
f4a605
-				}
f4a605
-			} else {
f4a605
-				int retval = SMB_VFS_UNLINKAT(conn,
f4a605
-						conn->cwd_fsp,
f4a605
-						smb_dname_full,
f4a605
-						0);
f4a605
-				if(retval != 0) {
f4a605
-					goto err_break;
f4a605
-				}
f4a605
-			}
f4a605
+		}
f4a605
 
f4a605
-			/* Successful iteration. */
f4a605
-			do_break = false;
f4a605
+		/* Successful iteration. */
f4a605
+		do_break = false;
f4a605
 
f4a605
-		 err_break:
f4a605
-			TALLOC_FREE(fullname);
f4a605
-			TALLOC_FREE(smb_dname_full);
f4a605
-			TALLOC_FREE(talloced);
f4a605
-			if (do_break)
f4a605
-				break;
f4a605
-		}
f4a605
-		TALLOC_FREE(dir_hnd);
f4a605
-		/* Retry the rmdir */
f4a605
-		ret = SMB_VFS_UNLINKAT(conn,
f4a605
-				conn->cwd_fsp,
f4a605
-				smb_dname,
f4a605
-				AT_REMOVEDIR);
f4a605
+	err_break:
f4a605
+		TALLOC_FREE(fullname);
f4a605
+		TALLOC_FREE(smb_dname_full);
f4a605
+		TALLOC_FREE(talloced);
f4a605
+		if (do_break)
f4a605
+			break;
f4a605
 	}
f4a605
+	TALLOC_FREE(dir_hnd);
f4a605
+	/* Retry the rmdir */
f4a605
+	ret = SMB_VFS_UNLINKAT(conn,
f4a605
+			conn->cwd_fsp,
f4a605
+			smb_dname,
f4a605
+			AT_REMOVEDIR);
f4a605
 
f4a605
   err:
f4a605
 
f4a605
-- 
f4a605
2.33.1
f4a605
f4a605
f4a605
From a7075aeedd078c68b57556678fa40907cd66cd08 Mon Sep 17 00:00:00 2001
f4a605
From: Jeremy Allison <jra@samba.org>
f4a605
Date: Mon, 25 Oct 2021 12:32:29 -0700
f4a605
Subject: [PATCH 5/7] s3: smbd: Fix logic in rmdir_internals() to cope with
f4a605
 dangling symlinks.
f4a605
f4a605
Still need to add the same logic in can_delete_directory_fsp()
f4a605
before we can delete the knownfail.
f4a605
f4a605
BUG: https://bugzilla.samba.org/show_bug.cgi?id=14879
f4a605
f4a605
Signed-off-by: Jeremy Allison <jra@samba.org>
f4a605
Reviewed-by: Ralph Boehme <slow@samba.org>
f4a605
(cherry picked from commit 26fecad2e66e91a3913d88ee2e0889f266e91d89)
f4a605
(backported from commit 4793c4d5307472f0eb72f70f7dbf7324744e3f91)
f4a605
[pfilipen@redhat.com: rmdir_internals() got refactored in 4.15]
f4a605
---
f4a605
 source3/smbd/close.c | 103 ++++++++++++++++++++++++++++++++++++++++++-
f4a605
 1 file changed, 101 insertions(+), 2 deletions(-)
f4a605
f4a605
diff --git a/source3/smbd/close.c b/source3/smbd/close.c
f4a605
index 0c102b9533b..81811f703b0 100644
f4a605
--- a/source3/smbd/close.c
f4a605
+++ b/source3/smbd/close.c
f4a605
@@ -1008,10 +1008,14 @@ static NTSTATUS rmdir_internals(TALLOC_CTX *ctx, files_struct *fsp)
f4a605
 	}
f4a605
 
f4a605
 	while ((dname = ReadDirName(dir_hnd, &dirpos, &st, &talloced)) != NULL) {
f4a605
+		struct smb_filename *smb_dname_full = NULL;
f4a605
+		char *fullname = NULL;
f4a605
+
f4a605
 		if((strcmp(dname, ".") == 0) || (strcmp(dname, "..")==0)) {
f4a605
 			TALLOC_FREE(talloced);
f4a605
 			continue;
f4a605
 		}
f4a605
+
f4a605
 		if (!is_visible_file(conn,
f4a605
 					dir_hnd,
f4a605
 					dname,
f4a605
@@ -1020,6 +1024,98 @@ static NTSTATUS rmdir_internals(TALLOC_CTX *ctx, files_struct *fsp)
f4a605
 			TALLOC_FREE(talloced);
f4a605
 			continue;
f4a605
 		}
f4a605
+
f4a605
+		fullname = talloc_asprintf(talloc_tos(),
f4a605
+					   "%s/%s",
f4a605
+					   smb_dname->base_name,
f4a605
+					   dname);
f4a605
+
f4a605
+		if (fullname == NULL) {
f4a605
+			TALLOC_FREE(talloced);
f4a605
+			errno = ENOMEM;
f4a605
+			goto err;
f4a605
+		}
f4a605
+
f4a605
+		smb_dname_full = synthetic_smb_fname(talloc_tos(),
f4a605
+						     fullname,
f4a605
+						     NULL,
f4a605
+						     NULL,
f4a605
+						     smb_dname->twrp,
f4a605
+						     smb_dname->flags);
f4a605
+		if (smb_dname_full == NULL) {
f4a605
+			TALLOC_FREE(talloced);
f4a605
+			TALLOC_FREE(fullname);
f4a605
+			errno = ENOMEM;
f4a605
+			goto err;
f4a605
+		}
f4a605
+
f4a605
+		ret = SMB_VFS_LSTAT(conn, smb_dname_full);
f4a605
+		if (ret != 0) {
f4a605
+			int saved_errno = errno;
f4a605
+			TALLOC_FREE(talloced);
f4a605
+			TALLOC_FREE(fullname);
f4a605
+			TALLOC_FREE(smb_dname_full);
f4a605
+			errno = saved_errno;
f4a605
+			goto err;
f4a605
+		}
f4a605
+
f4a605
+		if (S_ISLNK(smb_dname_full->st.st_ex_mode)) {
f4a605
+			/* Could it be an msdfs link ? */
f4a605
+			if (lp_host_msdfs() &&
f4a605
+				lp_msdfs_root(SNUM(conn))) {
f4a605
+				struct smb_filename *smb_atname;
f4a605
+				smb_atname = synthetic_smb_fname(talloc_tos(),
f4a605
+							dname,
f4a605
+							NULL,
f4a605
+							&smb_dname_full->st,
f4a605
+							fsp->fsp_name->twrp,
f4a605
+							fsp->fsp_name->flags);
f4a605
+				if (smb_atname == NULL) {
f4a605
+					TALLOC_FREE(talloced);
f4a605
+					TALLOC_FREE(fullname);
f4a605
+					TALLOC_FREE(smb_dname_full);
f4a605
+					errno = ENOMEM;
f4a605
+					goto err;
f4a605
+				}
f4a605
+				if (is_msdfs_link(conn, smb_atname)) {
f4a605
+					TALLOC_FREE(talloced);
f4a605
+					TALLOC_FREE(fullname);
f4a605
+					TALLOC_FREE(smb_dname_full);
f4a605
+					TALLOC_FREE(smb_atname);
f4a605
+					DBG_DEBUG("got msdfs link name %s "
f4a605
+						"- can't delete directory %s\n",
f4a605
+						dname,
f4a605
+						fsp_str_dbg(fsp));
f4a605
+					errno = ENOTEMPTY;
f4a605
+					goto err;
f4a605
+				}
f4a605
+				TALLOC_FREE(smb_atname);
f4a605
+			}
f4a605
+
f4a605
+			/* Not a DFS link - could it be a dangling symlink ? */
f4a605
+			ret = SMB_VFS_STAT(conn, smb_dname_full);
f4a605
+			if (ret == -1 && (errno == ENOENT || errno == ELOOP)) {
f4a605
+				/*
f4a605
+				 * Dangling symlink.
f4a605
+				 * Allow delete as "delete veto files = yes"
f4a605
+				 */
f4a605
+				TALLOC_FREE(talloced);
f4a605
+				TALLOC_FREE(fullname);
f4a605
+				TALLOC_FREE(smb_dname_full);
f4a605
+				continue;
f4a605
+			}
f4a605
+
f4a605
+			DBG_DEBUG("got symlink name %s - "
f4a605
+				"can't delete directory %s\n",
f4a605
+				dname,
f4a605
+				fsp_str_dbg(fsp));
f4a605
+			TALLOC_FREE(talloced);
f4a605
+			TALLOC_FREE(fullname);
f4a605
+			TALLOC_FREE(smb_dname_full);
f4a605
+			errno = ENOTEMPTY;
f4a605
+			goto err;
f4a605
+		}
f4a605
+
f4a605
 		if(!IS_VETO_PATH(conn, dname)) {
f4a605
 			/*
f4a605
 			 * We found a client visible name.
f4a605
@@ -1029,12 +1125,15 @@ static NTSTATUS rmdir_internals(TALLOC_CTX *ctx, files_struct *fsp)
f4a605
 				"can't delete directory %s\n",
f4a605
 				dname,
f4a605
 				fsp_str_dbg(fsp));
f4a605
-			TALLOC_FREE(dir_hnd);
f4a605
 			TALLOC_FREE(talloced);
f4a605
+			TALLOC_FREE(fullname);
f4a605
+			TALLOC_FREE(smb_dname_full);
f4a605
 			errno = ENOTEMPTY;
f4a605
 			goto err;
f4a605
 		}
f4a605
 		TALLOC_FREE(talloced);
f4a605
+		TALLOC_FREE(fullname);
f4a605
+		TALLOC_FREE(smb_dname_full);
f4a605
 	}
f4a605
 
f4a605
 	/* Do a recursive delete. */
f4a605
@@ -1114,7 +1213,6 @@ static NTSTATUS rmdir_internals(TALLOC_CTX *ctx, files_struct *fsp)
f4a605
 		if (do_break)
f4a605
 			break;
f4a605
 	}
f4a605
-	TALLOC_FREE(dir_hnd);
f4a605
 	/* Retry the rmdir */
f4a605
 	ret = SMB_VFS_UNLINKAT(conn,
f4a605
 			conn->cwd_fsp,
f4a605
@@ -1123,6 +1221,7 @@ static NTSTATUS rmdir_internals(TALLOC_CTX *ctx, files_struct *fsp)
f4a605
 
f4a605
   err:
f4a605
 
f4a605
+	TALLOC_FREE(dir_hnd);
f4a605
 	if (ret != 0) {
f4a605
 		DEBUG(3,("rmdir_internals: couldn't remove directory %s : "
f4a605
 			 "%s\n", smb_fname_str_dbg(smb_dname),
f4a605
-- 
f4a605
2.33.1
f4a605
f4a605
f4a605
From 843fc3b857cdfd6c7e902acef933d17690815e7e Mon Sep 17 00:00:00 2001
f4a605
From: Jeremy Allison <jra@samba.org>
f4a605
Date: Mon, 25 Oct 2021 12:36:57 -0700
f4a605
Subject: [PATCH 6/7] s3: smbd: Fix logic in can_delete_directory_fsp() to cope
f4a605
 with dangling symlinks.
f4a605
f4a605
Remove knownfail.
f4a605
f4a605
BUG: https://bugzilla.samba.org/show_bug.cgi?id=14879
f4a605
f4a605
Signed-off-by: Jeremy Allison <jra@samba.org>
f4a605
Reviewed-by: Ralph Boehme <slow@samba.org>
f4a605
(cherry picked from commit e9ef970eee5eca8ab3720279c54098e91d2dfda9)
f4a605
(backported from commit 5023dbc04bfad7cc39e8c4de96f40c82e7a0288e)
f4a605
[pfilipen@redhat.com: can_delete_directory_fsp() got refactored in 4.15]
f4a605
---
f4a605
 selftest/knownfail.d/rmdir_dangle_symlink |  1 -
f4a605
 source3/smbd/dir.c                        | 97 +++++++++++++++++++++++
f4a605
 2 files changed, 97 insertions(+), 1 deletion(-)
f4a605
 delete mode 100644 selftest/knownfail.d/rmdir_dangle_symlink
f4a605
f4a605
diff --git a/selftest/knownfail.d/rmdir_dangle_symlink b/selftest/knownfail.d/rmdir_dangle_symlink
f4a605
deleted file mode 100644
f4a605
index c775dc5fe15..00000000000
f4a605
--- a/selftest/knownfail.d/rmdir_dangle_symlink
f4a605
+++ /dev/null
f4a605
@@ -1 +0,0 @@
f4a605
-^samba3.blackbox.test_dangle_rmdir.rmdir can delete directory containing dangling symlink\(fileserver\)
f4a605
diff --git a/source3/smbd/dir.c b/source3/smbd/dir.c
f4a605
index 545c7499f28..96edc8678e5 100644
f4a605
--- a/source3/smbd/dir.c
f4a605
+++ b/source3/smbd/dir.c
f4a605
@@ -1876,6 +1876,8 @@ NTSTATUS can_delete_directory_fsp(files_struct *fsp)
f4a605
 	char *talloced = NULL;
f4a605
 	SMB_STRUCT_STAT st;
f4a605
 	struct connection_struct *conn = fsp->conn;
f4a605
+	struct smb_filename *smb_dname = fsp->fsp_name;
f4a605
+	int ret;
f4a605
 	struct smb_Dir *dir_hnd = OpenDir(talloc_tos(),
f4a605
 					conn,
f4a605
 					fsp->fsp_name,
f4a605
@@ -1887,6 +1889,9 @@ NTSTATUS can_delete_directory_fsp(files_struct *fsp)
f4a605
 	}
f4a605
 
f4a605
 	while ((dname = ReadDirName(dir_hnd, &dirpos, &st, &talloced))) {
f4a605
+		struct smb_filename *smb_dname_full = NULL;
f4a605
+		char *fullname = NULL;
f4a605
+
f4a605
 		if (ISDOT(dname) || (ISDOTDOT(dname))) {
f4a605
 			TALLOC_FREE(talloced);
f4a605
 			continue;
f4a605
@@ -1901,6 +1906,98 @@ NTSTATUS can_delete_directory_fsp(files_struct *fsp)
f4a605
 			continue;
f4a605
 		}
f4a605
 
f4a605
+		fullname = talloc_asprintf(talloc_tos(),
f4a605
+					   "%s/%s",
f4a605
+					   smb_dname->base_name,
f4a605
+					   dname);
f4a605
+
f4a605
+		if (fullname == NULL) {
f4a605
+			TALLOC_FREE(dir_hnd);
f4a605
+			TALLOC_FREE(talloced);
f4a605
+			return NT_STATUS_NO_MEMORY;
f4a605
+		}
f4a605
+
f4a605
+		smb_dname_full = synthetic_smb_fname(talloc_tos(),
f4a605
+						     fullname,
f4a605
+						     NULL,
f4a605
+						     NULL,
f4a605
+						     smb_dname->twrp,
f4a605
+						     smb_dname->flags);
f4a605
+		if (smb_dname_full == NULL) {
f4a605
+			TALLOC_FREE(dir_hnd);
f4a605
+			TALLOC_FREE(talloced);
f4a605
+			TALLOC_FREE(fullname);
f4a605
+			return NT_STATUS_NO_MEMORY;
f4a605
+		}
f4a605
+
f4a605
+		ret = SMB_VFS_LSTAT(conn, smb_dname_full);
f4a605
+		if (ret != 0) {
f4a605
+			TALLOC_FREE(dir_hnd);
f4a605
+			TALLOC_FREE(talloced);
f4a605
+			TALLOC_FREE(fullname);
f4a605
+			TALLOC_FREE(smb_dname_full);
f4a605
+			return map_nt_error_from_unix(errno);
f4a605
+		}
f4a605
+
f4a605
+		if (S_ISLNK(smb_dname_full->st.st_ex_mode)) {
f4a605
+			/* Could it be an msdfs link ? */
f4a605
+			if (lp_host_msdfs() &&
f4a605
+			    lp_msdfs_root(SNUM(conn))) {
f4a605
+				struct smb_filename *smb_atname;
f4a605
+				smb_atname = synthetic_smb_fname(talloc_tos(),
f4a605
+							dname,
f4a605
+							NULL,
f4a605
+							&smb_dname_full->st,
f4a605
+							fsp->fsp_name->twrp,
f4a605
+							fsp->fsp_name->flags);
f4a605
+				if (smb_atname == NULL) {
f4a605
+					TALLOC_FREE(dir_hnd);
f4a605
+					TALLOC_FREE(talloced);
f4a605
+					TALLOC_FREE(fullname);
f4a605
+					TALLOC_FREE(smb_dname_full);
f4a605
+					return NT_STATUS_NO_MEMORY;
f4a605
+				}
f4a605
+				if (is_msdfs_link(conn, smb_atname)) {
f4a605
+					TALLOC_FREE(dir_hnd);
f4a605
+					TALLOC_FREE(talloced);
f4a605
+					TALLOC_FREE(fullname);
f4a605
+					TALLOC_FREE(smb_dname_full);
f4a605
+					TALLOC_FREE(smb_atname);
f4a605
+					DBG_DEBUG("got msdfs link name %s "
f4a605
+						"- can't delete directory %s\n",
f4a605
+						dname,
f4a605
+						fsp_str_dbg(fsp));
f4a605
+					return NT_STATUS_DIRECTORY_NOT_EMPTY;
f4a605
+				}
f4a605
+				TALLOC_FREE(smb_atname);
f4a605
+			}
f4a605
+
f4a605
+			/* Not a DFS link - could it be a dangling symlink ? */
f4a605
+			ret = SMB_VFS_STAT(conn, smb_dname_full);
f4a605
+			if (ret == -1 && (errno == ENOENT || errno == ELOOP)) {
f4a605
+				/*
f4a605
+				 * Dangling symlink.
f4a605
+				 * Allow if "delete veto files = yes"
f4a605
+				 */
f4a605
+				if (lp_delete_veto_files(SNUM(conn))) {
f4a605
+					TALLOC_FREE(talloced);
f4a605
+					TALLOC_FREE(fullname);
f4a605
+					TALLOC_FREE(smb_dname_full);
f4a605
+					continue;
f4a605
+				}
f4a605
+			}
f4a605
+
f4a605
+			DBG_DEBUG("got symlink name %s - "
f4a605
+				"can't delete directory %s\n",
f4a605
+				dname,
f4a605
+				fsp_str_dbg(fsp));
f4a605
+			TALLOC_FREE(dir_hnd);
f4a605
+			TALLOC_FREE(talloced);
f4a605
+			TALLOC_FREE(fullname);
f4a605
+			TALLOC_FREE(smb_dname_full);
f4a605
+			return NT_STATUS_DIRECTORY_NOT_EMPTY;
f4a605
+		}
f4a605
+
f4a605
 		DEBUG(10,("got name %s - can't delete\n",
f4a605
 			 dname ));
f4a605
 		status = NT_STATUS_DIRECTORY_NOT_EMPTY;
f4a605
-- 
f4a605
2.33.1
f4a605
f4a605
f4a605
From 7189ea825d8c9e4777dba737227ead602ad9b651 Mon Sep 17 00:00:00 2001
f4a605
From: Jeremy Allison <jra@samba.org>
f4a605
Date: Mon, 25 Oct 2021 12:42:02 -0700
f4a605
Subject: [PATCH 7/7] s3: docs-xml: Clarify the "delete veto files" paramter.
f4a605
MIME-Version: 1.0
f4a605
Content-Type: text/plain; charset=UTF-8
f4a605
Content-Transfer-Encoding: 8bit
f4a605
f4a605
BUG: https://bugzilla.samba.org/show_bug.cgi?id=14879
f4a605
f4a605
Signed-off-by: Jeremy Allison <jra@samba.org>
f4a605
Reviewed-by: Ralph Boehme <slow@samba.org>
f4a605
f4a605
Autobuild-User(master): Ralph Böhme <slow@samba.org>
f4a605
Autobuild-Date(master): Fri Oct 29 14:57:14 UTC 2021 on sn-devel-184
f4a605
f4a605
(cherry picked from commit 0b818c6b77e972626d0b071bebcf4ce55619fb84)
f4a605
(cherry picked from commit a549dc219cba5bd61969e4919ae4142f52c133ea)
f4a605
---
f4a605
 docs-xml/smbdotconf/filename/deletevetofiles.xml | 9 ++++++---
f4a605
 1 file changed, 6 insertions(+), 3 deletions(-)
f4a605
f4a605
diff --git a/docs-xml/smbdotconf/filename/deletevetofiles.xml b/docs-xml/smbdotconf/filename/deletevetofiles.xml
f4a605
index 581dc05396d..570d4ac60a0 100644
f4a605
--- a/docs-xml/smbdotconf/filename/deletevetofiles.xml
f4a605
+++ b/docs-xml/smbdotconf/filename/deletevetofiles.xml
f4a605
@@ -4,9 +4,12 @@
f4a605
                  xmlns:samba="http://www.samba.org/samba/DTD/samba-doc">
f4a605
 <description>
f4a605
 	<para>This option is used when Samba is attempting to 
f4a605
-	delete a directory that contains one or more vetoed directories 
f4a605
-	(see the <smbconfoption name="veto files"/>
f4a605
-	option).  If this option is set to <constant>no</constant> (the default) then if a vetoed 
f4a605
+	delete a directory that contains one or more vetoed files
f4a605
+	or directories or non-visible files or directories (such
f4a605
+	as dangling symlinks that point nowhere).
f4a605
+	(see the <smbconfoption name="veto files"/>, <smbconfoption name="hide special files"/>,
f4a605
+	<smbconfoption name="hide unreadable"/>, <smbconfoption name="hide unwriteable files"/>
f4a605
+	options).  If this option is set to <constant>no</constant> (the default) then if a vetoed
f4a605
 	directory contains any non-vetoed files or directories then the 
f4a605
 	directory delete will fail. This is usually what you want.</para>
f4a605
 
f4a605
-- 
f4a605
2.33.1
f4a605