]> wimlib.net Git - wimlib/blobdiff - src/win32.c
overwrite_wim_inplace(): cleanup
[wimlib] / src / win32.c
index 2b26e1cdbdebd72fe9b7c72475fad79d2b98245f..f2e7eeb08988464c43db05f4eb3f9850a381d150 100644 (file)
  * along with wimlib; if not, see http://www.gnu.org/licenses/.
  */
 
-#ifndef __WIN32__
-#  error "This file contains Windows code"
-#endif
+#ifdef __WIN32__
 
 #include "config.h"
 #include <windows.h>
 #include <ntdef.h>
 #include <wchar.h>
-#include <shlwapi.h> /* shlwapi.h for PathMatchSpecA() */
+#include <shlwapi.h> /* shlwapi.h for PathMatchSpecW() */
 #ifdef ERROR /* windows.h defines this */
 #  undef ERROR
 #endif
 #include "lookup_table.h"
 #include "security.h"
 #include "endianness.h"
+#include <pthread.h>
 
 #include <errno.h>
 
+#define MAX_GET_SD_ACCESS_DENIED_WARNINGS 1
+#define MAX_GET_SACL_PRIV_NOTHELD_WARNINGS 1
+struct win32_capture_state {
+       unsigned long num_get_sd_access_denied;
+       unsigned long num_get_sacl_priv_notheld;
+};
+
+#define MAX_SET_SD_ACCESS_DENIED_WARNINGS 1
+#define MAX_SET_SACL_PRIV_NOTHELD_WARNINGS 1
 
+#ifdef ENABLE_ERROR_MESSAGES
+static void
+win32_error(u32 err_code)
+{
+       wchar_t *buffer;
+       DWORD nchars;
+       nchars = FormatMessageW(FORMAT_MESSAGE_FROM_SYSTEM |
+                                   FORMAT_MESSAGE_ALLOCATE_BUFFER,
+                               NULL, err_code, 0,
+                               (wchar_t*)&buffer, 0, NULL);
+       if (nchars == 0) {
+               ERROR("Error printing error message! "
+                     "Computer will self-destruct in 3 seconds.");
+       } else {
+               ERROR("Win32 error: %ls", buffer);
+               LocalFree(buffer);
+       }
+}
+#else /* ENABLE_ERROR_MESSAGES */
+#  define win32_error(err_code)
+#endif /* !ENABLE_ERROR_MESSAGES */
 
 /* Pointers to functions that are not available on all targetted versions of
  * Windows (XP and later).  NOTE: The WINAPI annotations seem to be important; I
@@ -70,7 +99,7 @@ win32_global_init()
 
        if (hKernel32 == NULL) {
                DEBUG("Loading Kernel32.dll");
-               hKernel32 = LoadLibraryA("Kernel32.dll");
+               hKernel32 = LoadLibraryW(L"Kernel32.dll");
                if (hKernel32 == NULL) {
                        err = GetLastError();
                        WARNING("Can't load Kernel32.dll");
@@ -106,38 +135,20 @@ win32_global_cleanup()
        }
 }
 
-static const wchar_t *access_denied_msg =
+static const wchar_t *capture_access_denied_msg =
 L"         If you are not running this program as the administrator, you may\n"
  "         need to do so, so that all data and metadata can be backed up.\n"
  "         Otherwise, there may be no way to access the desired data or\n"
  "         metadata without taking ownership of the file or directory.\n"
  ;
 
-#ifdef ENABLE_ERROR_MESSAGES
-void
-win32_error(u32 err_code)
-{
-       wchar_t *buffer;
-       DWORD nchars;
-       nchars = FormatMessageW(FORMAT_MESSAGE_FROM_SYSTEM |
-                                   FORMAT_MESSAGE_ALLOCATE_BUFFER,
-                               NULL, err_code, 0,
-                               (wchar_t*)&buffer, 0, NULL);
-       if (nchars == 0) {
-               ERROR("Error printing error message! "
-                     "Computer will self-destruct in 3 seconds.");
-       } else {
-               ERROR("Win32 error: %ls", buffer);
-               LocalFree(buffer);
-       }
-}
-
-void
-win32_error_last()
-{
-       win32_error(GetLastError());
-}
-#endif
+static const wchar_t *apply_access_denied_msg =
+L"If you are not running this program as the administrator, you may\n"
+ "          need to do so, so that all data and metadata can be extracted\n"
+ "          exactly as the origignal copy.  However, if you do not care that\n"
+ "          the security descriptors are extracted correctly, you could run\n"
+ "          `wimlib-imagex apply' with the --no-acls flag instead.\n"
+ ;
 
 static HANDLE
 win32_open_existing_file(const wchar_t *path, DWORD dwDesiredAccess)
@@ -159,29 +170,58 @@ win32_open_file_data_only(const wchar_t *path)
 }
 
 int
-win32_read_file(const wchar_t *filename,
-               void *handle, u64 offset, size_t size, void *buf)
+read_win32_file_prefix(const struct lookup_table_entry *lte,
+                      u64 size,
+                      consume_data_callback_t cb,
+                      void *ctx_or_buf,
+                      int _ignored_flags)
 {
-       HANDLE h = handle;
+       int ret;
+       void *out_buf;
        DWORD err;
-       DWORD bytesRead;
-       LARGE_INTEGER liOffset = {.QuadPart = offset};
+       u64 bytes_remaining;
 
-       wimlib_assert(size <= 0xffffffff);
+       HANDLE hFile = win32_open_file_data_only(lte->file_on_disk);
+       if (hFile == INVALID_HANDLE_VALUE) {
+               err = GetLastError();
+               ERROR("Failed to open \"%ls\"", lte->file_on_disk);
+               win32_error(err);
+               ret = WIMLIB_ERR_OPEN;
+               goto out;
+       }
 
-       if (SetFilePointerEx(h, liOffset, NULL, FILE_BEGIN))
-               if (ReadFile(h, buf, size, &bytesRead, NULL) && bytesRead == size)
-                       return 0;
-       err = GetLastError();
-       ERROR("Error reading \"%ls\"", filename);
-       win32_error(err);
-       return WIMLIB_ERR_READ;
-}
+       if (cb)
+               out_buf = alloca(WIM_CHUNK_SIZE);
+       else
+               out_buf = ctx_or_buf;
 
-void
-win32_close_file(void *handle)
-{
-       CloseHandle((HANDLE)handle);
+       bytes_remaining = size;
+       while (bytes_remaining) {
+               DWORD bytesToRead, bytesRead;
+
+               bytesToRead = min(WIM_CHUNK_SIZE, bytes_remaining);
+               if (!ReadFile(h, out_buf, bytesToRead, &bytesRead, NULL) ||
+                   bytesRead != bytesToRead)
+               {
+                       err = GetLastError();
+                       ERROR("Failed to read data from \"%ls\"", lte->file_on_disk);
+                       win32_error(err);
+                       ret = WIMLIB_ERR_READ;
+                       goto out_close_handle;
+               }
+               bytes_remaining -= bytesRead;
+               if (cb) {
+                       ret = cb(out_buf, bytesRead, ctx_or_buf);
+                       if (ret)
+                               goto out_close_handle;
+               } else {
+                       out_buf += bytesRead;
+               }
+       }
+out_close_handle:
+       CloseHandle(hFile);
+out:
+       return ret;
 }
 
 static u64
@@ -204,23 +244,31 @@ win32_get_short_name(struct wim_dentry *dentry, const wchar_t *path)
                memcpy(dentry->short_name, dat.cAlternateFileName, n);
                dentry->short_name_nbytes = short_name_nbytes;
        }
+       /* If we can't read the short filename for some reason, we just ignore
+        * the error and assume the file has no short name.  I don't think this
+        * should be an issue, since the short names are essentially obsolete
+        * anyway. */
        return 0;
 }
 
 static int
 win32_get_security_descriptor(struct wim_dentry *dentry,
                              struct sd_set *sd_set,
-                             const wchar_t *path)
+                             const wchar_t *path,
+                             struct win32_capture_state *state,
+                             int add_image_flags)
 {
        SECURITY_INFORMATION requestedInformation;
        DWORD lenNeeded = 0;
        BOOL status;
        DWORD err;
+       unsigned long n;
 
        requestedInformation = DACL_SECURITY_INFORMATION |
                               SACL_SECURITY_INFORMATION |
                               OWNER_SECURITY_INFORMATION |
                               GROUP_SECURITY_INFORMATION;
+again:
        /* Request length of security descriptor */
        status = GetFileSecurityW(path, requestedInformation,
                                  NULL, 0, &lenNeeded);
@@ -243,11 +291,39 @@ win32_get_security_descriptor(struct wim_dentry *dentry,
                }
        }
 
-       if (err == ERROR_ACCESS_DENIED) {
-               WARNING("Failed to read security descriptor of \"%ls\": "
-                       "Access denied!\n%ls", path, access_denied_msg);
+       if (add_image_flags & WIMLIB_ADD_IMAGE_FLAG_STRICT_ACLS)
+               goto fail;
+
+       switch (err) {
+       case ERROR_PRIVILEGE_NOT_HELD:
+               if (requestedInformation & SACL_SECURITY_INFORMATION) {
+                       n = state->num_get_sacl_priv_notheld++;
+                       requestedInformation &= ~SACL_SECURITY_INFORMATION;
+                       if (n < MAX_GET_SACL_PRIV_NOTHELD_WARNINGS) {
+                               WARNING(
+"We don't have enough privileges to read the full security\n"
+"          descriptor of \"%ls\"!\n"
+"          Re-trying with SACL omitted.\n", path);
+                       } else if (n == MAX_GET_SACL_PRIV_NOTHELD_WARNINGS) {
+                               WARNING(
+"Suppressing further privileges not held error messages when reading\n"
+"          security descriptors.");
+                       }
+                       goto again;
+               }
+               /* Fall through */
+       case ERROR_ACCESS_DENIED:
+               n = state->num_get_sd_access_denied++;
+               if (n < MAX_GET_SD_ACCESS_DENIED_WARNINGS) {
+                       WARNING("Failed to read security descriptor of \"%ls\": "
+                               "Access denied!\n%ls", path, capture_access_denied_msg);
+               } else if (n == MAX_GET_SD_ACCESS_DENIED_WARNINGS) {
+                       WARNING("Suppressing further access denied errors messages i"
+                               "when reading security descriptors");
+               }
                return 0;
-       } else {
+       default:
+fail:
                ERROR("Failed to read security descriptor of \"%ls\"", path);
                win32_error(err);
                return WIMLIB_ERR_READ;
@@ -256,40 +332,45 @@ win32_get_security_descriptor(struct wim_dentry *dentry,
 
 static int
 win32_build_dentry_tree_recursive(struct wim_dentry **root_ret,
-                                 const wchar_t *path,
-                                 const size_t path_num_chars,
+                                 wchar_t *path,
+                                 size_t path_num_chars,
                                  struct wim_lookup_table *lookup_table,
+                                 struct wim_inode_table *inode_table,
                                  struct sd_set *sd_set,
-                                 const struct capture_config *config,
+                                 const struct wimlib_capture_config *config,
                                  int add_image_flags,
-                                 wimlib_progress_func_t progress_func);
+                                 wimlib_progress_func_t progress_func,
+                                 struct win32_capture_state *state);
 
 /* Reads the directory entries of directory using a Win32 API and recursively
  * calls win32_build_dentry_tree() on them. */
 static int
 win32_recurse_directory(struct wim_dentry *root,
-                       const wchar_t *dir_path,
-                       const size_t dir_path_num_chars,
+                       wchar_t *dir_path,
+                       size_t dir_path_num_chars,
                        struct wim_lookup_table *lookup_table,
+                       struct wim_inode_table *inode_table,
                        struct sd_set *sd_set,
-                       const struct capture_config *config,
+                       const struct wimlib_capture_config *config,
                        int add_image_flags,
-                       wimlib_progress_func_t progress_func)
+                       wimlib_progress_func_t progress_func,
+                       struct win32_capture_state *state)
 {
        WIN32_FIND_DATAW dat;
        HANDLE hFind;
        DWORD err;
        int ret;
 
-       {
-               /* Begin reading the directory by calling FindFirstFileW.
-                * Unlike UNIX opendir(), FindFirstFileW has file globbing built
-                * into it.  But this isn't what we actually want, so just add a
-                * dummy glob to get all entries. */
-               wchar_t pattern_buf[dir_path_num_chars + 3];
-               swprintf(pattern_buf, L"%ls/*", dir_path);
-               hFind = FindFirstFileW(pattern_buf, &dat);
-       }
+       /* Begin reading the directory by calling FindFirstFileW.  Unlike UNIX
+        * opendir(), FindFirstFileW has file globbing built into it.  But this
+        * isn't what we actually want, so just add a dummy glob to get all
+        * entries. */
+       dir_path[dir_path_num_chars] = L'/';
+       dir_path[dir_path_num_chars + 1] = L'*';
+       dir_path[dir_path_num_chars + 2] = L'\0';
+       hFind = FindFirstFileW(dir_path, &dat);
+       dir_path[dir_path_num_chars] = L'\0';
+
        if (hFind == INVALID_HANDLE_VALUE) {
                err = GetLastError();
                if (err == ERROR_FILE_NOT_FOUND) {
@@ -303,33 +384,39 @@ win32_recurse_directory(struct wim_dentry *root,
        ret = 0;
        do {
                /* Skip . and .. entries */
-               if (wcscmp(dat.cFileName, L".") && wcscmp(dat.cFileName, L".."))
-               {
-                       size_t filename_num_chars = wcslen(dat.cFileName);
-                       size_t new_path_num_chars = dir_path_num_chars + 1 +
-                                                   filename_num_chars;
-                       wchar_t new_path[new_path_num_chars + 1];
-
-                       swprintf(new_path, L"%ls/%ls", dir_path, dat.cFileName);
-
-                       struct wim_dentry *child;
-                       ret = win32_build_dentry_tree_recursive(&child,
-                                                               new_path,
-                                                               new_path_num_chars,
-                                                               lookup_table,
-                                                               sd_set,
-                                                               config,
-                                                               add_image_flags,
-                                                               progress_func);
-                       if (ret)
-                               goto out_find_close;
-                       if (child)
-                               dentry_add_child(root, child);
-               }
+               if (dat.cFileName[0] == L'.' &&
+                   (dat.cFileName[1] == L'\0' ||
+                    (dat.cFileName[1] == L'.' &&
+                     dat.cFileName[2] == L'\0')))
+                       continue;
+               size_t filename_len = wcslen(dat.cFileName);
+
+               dir_path[dir_path_num_chars] = L'/';
+               wmemcpy(dir_path + dir_path_num_chars + 1,
+                       dat.cFileName,
+                       filename_len + 1);
+
+               struct wim_dentry *child;
+               size_t path_len = dir_path_num_chars + 1 + filename_len;
+               ret = win32_build_dentry_tree_recursive(&child,
+                                                       dir_path,
+                                                       path_len,
+                                                       lookup_table,
+                                                       inode_table,
+                                                       sd_set,
+                                                       config,
+                                                       add_image_flags,
+                                                       progress_func,
+                                                       state);
+               dir_path[dir_path_num_chars] = L'\0';
+               if (ret)
+                       goto out_find_close;
+               if (child)
+                       dentry_add_child(root, child);
        } while (FindNextFileW(hFind, &dat));
        err = GetLastError();
        if (err != ERROR_NO_MORE_FILES) {
-               ERROR("Failed to read directory \"%s\"", dir_path);
+               ERROR("Failed to read directory \"%ls\"", dir_path);
                win32_error(err);
                if (ret == 0)
                        ret = WIMLIB_ERR_READ;
@@ -389,47 +476,6 @@ win32_capture_reparse_point(HANDLE hFile,
                                       bytesReturned - 8, lookup_table);
 }
 
-/* Calculate the SHA1 message digest of a Win32 data stream, which may be either
- * an unnamed or named data stream.
- *
- * @path:      Path to the file, with the stream noted at the end for named
- *              streams.  UTF-16LE encoding.
- *
- * @hash:       On success, the SHA1 message digest of the stream is written to
- *              this location.
- *
- * Returns 0 on success; nonzero on failure.
- */
-static int
-win32_sha1sum(const wchar_t *path, u8 hash[SHA1_HASH_SIZE])
-{
-       HANDLE hFile;
-       SHA_CTX ctx;
-       u8 buf[32768];
-       DWORD bytesRead;
-       int ret;
-
-       hFile = win32_open_file_data_only(path);
-       if (hFile == INVALID_HANDLE_VALUE)
-               return WIMLIB_ERR_OPEN;
-
-       sha1_init(&ctx);
-       for (;;) {
-               if (!ReadFile(hFile, buf, sizeof(buf), &bytesRead, NULL)) {
-                       ret = WIMLIB_ERR_READ;
-                       goto out_close_handle;
-               }
-               if (bytesRead == 0)
-                       break;
-               sha1_update(&ctx, buf, bytesRead);
-       }
-       ret = 0;
-       sha1_final(hash, &ctx);
-out_close_handle:
-       CloseHandle(hFile);
-       return ret;
-}
-
 /* Scans an unnamed or named stream of a Win32 file (not a reparse point
  * stream); calculates its SHA1 message digest and either creates a `struct
  * wim_lookup_table_entry' in memory for it, or uses an existing 'struct
@@ -529,39 +575,27 @@ win32_capture_stream(const wchar_t *path,
        swprintf(spath, L"%ls%ls%ls%ls",
                 relpath_prefix, path, colonchar, stream_name);
 
-       ret = win32_sha1sum(spath, hash);
-       if (ret) {
-               err = GetLastError();
-               ERROR("Failed to read \"%ls\" to calculate SHA1sum", spath);
-               win32_error(err);
+       /* Make a new wim_lookup_table_entry */
+       lte = new_lookup_table_entry();
+       if (!lte) {
+               ret = WIMLIB_ERR_NOMEM;
                goto out_free_spath;
        }
+       lte->file_on_disk = spath;
+       spath = NULL;
+       lte->resource_location = RESOURCE_WIN32;
+       lte->resource_entry.original_size = (u64)dat->StreamSize.QuadPart;
 
-       lte = __lookup_resource(lookup_table, hash);
-       if (lte) {
-               /* Use existing wim_lookup_table_entry that has the same SHA1
-                * message digest */
-               lte->refcnt++;
-       } else {
-               /* Make a new wim_lookup_table_entry */
-               lte = new_lookup_table_entry();
-               if (!lte) {
-                       ret = WIMLIB_ERR_NOMEM;
-                       goto out_free_spath;
-               }
-               lte->file_on_disk = spath;
-               lte->win32_file_on_disk_fp = INVALID_HANDLE_VALUE;
-               spath = NULL;
-               lte->resource_location = RESOURCE_WIN32;
-               lte->resource_entry.original_size = (uint64_t)dat->StreamSize.QuadPart;
-               lte->resource_entry.size = (uint64_t)dat->StreamSize.QuadPart;
-               copy_hash(lte->hash, hash);
-               lookup_table_insert(lookup_table, lte);
-       }
-       if (is_named_stream)
+       u32 stream_id;
+       if (is_named_stream) {
+               stream_id = ads_entry->stream_id;
                ads_entry->lte = lte;
-       else
+       } else {
+               stream_id = 0;
                inode->i_lte = lte;
+       }
+
+       lookup_table_insert_unhashed(lookup_table, lte, inode, stream_id);
 out_free_spath:
        FREE(spath);
 out:
@@ -619,9 +653,10 @@ win32_capture_streams(const wchar_t *path,
                        return 0;
                } else {
                        if (err == ERROR_ACCESS_DENIED) {
+                               /* XXX This maybe should be an error. */
                                WARNING("Failed to look up data streams "
                                        "of \"%ls\": Access denied!\n%ls",
-                                       path, access_denied_msg);
+                                       path, capture_access_denied_msg);
                                return 0;
                        } else {
                                ERROR("Failed to look up data streams "
@@ -649,11 +684,16 @@ out_find_close:
        FindClose(hFind);
        return ret;
 unnamed_only:
+       /* FindFirstStreamW() API is not available.  Only capture the unnamed
+        * data stream. */
        if (inode->i_attributes &
             (FILE_ATTRIBUTE_REPARSE_POINT | FILE_ATTRIBUTE_DIRECTORY))
        {
                ret = 0;
        } else {
+               /* Just create our own WIN32_FIND_STREAM_DATA for an unnamed
+                * stream to reduce the code to a call to the
+                * already-implemented win32_capture_stream() */
                wcscpy(dat.cStreamName, L"::$DATA");
                dat.StreamSize.QuadPart = file_size;
                ret = win32_capture_stream(path,
@@ -666,13 +706,15 @@ unnamed_only:
 
 static int
 win32_build_dentry_tree_recursive(struct wim_dentry **root_ret,
-                                 const wchar_t *path,
-                                 const size_t path_num_chars,
+                                 wchar_t *path,
+                                 size_t path_num_chars,
                                  struct wim_lookup_table *lookup_table,
+                                 struct wim_inode_table *inode_table,
                                  struct sd_set *sd_set,
-                                 const struct capture_config *config,
+                                 const struct wimlib_capture_config *config,
                                  int add_image_flags,
-                                 wimlib_progress_func_t progress_func)
+                                 wimlib_progress_func_t progress_func,
+                                 struct win32_capture_state *state)
 {
        struct wim_dentry *root = NULL;
        struct wim_inode *inode;
@@ -680,13 +722,13 @@ win32_build_dentry_tree_recursive(struct wim_dentry **root_ret,
        u64 file_size;
        int ret = 0;
 
-       if (exclude_path(path, config, true)) {
+       if (exclude_path(path, path_num_chars, config, true)) {
                if (add_image_flags & WIMLIB_ADD_IMAGE_FLAG_ROOT) {
                        ERROR("Cannot exclude the root directory from capture");
                        ret = WIMLIB_ERR_INVALID_CAPTURE_CONFIG;
                        goto out;
                }
-               if ((add_image_flags & WIMLIB_ADD_IMAGE_FLAG_VERBOSE)
+               if ((add_image_flags & WIMLIB_ADD_IMAGE_FLAG_EXCLUDE_VERBOSE)
                    && progress_func)
                {
                        union wimlib_progress_info info;
@@ -726,32 +768,36 @@ win32_build_dentry_tree_recursive(struct wim_dentry **root_ret,
                goto out_close_handle;
        }
 
-       /* Create a WIM dentry */
-       ret = new_dentry_with_timeless_inode(path_basename_with_len(path, path_num_chars),
-                                            &root);
+       /* Create a WIM dentry with an associated inode, which may be shared */
+       ret = inode_table_new_dentry(inode_table,
+                                    path_basename_with_len(path, path_num_chars),
+                                    ((u64)file_info.nFileIndexHigh << 32) |
+                                        (u64)file_info.nFileIndexLow,
+                                    file_info.dwVolumeSerialNumber,
+                                    &root);
+       if (ret)
+               goto out_close_handle;
+
+       ret = win32_get_short_name(root, path);
        if (ret)
                goto out_close_handle;
 
-       /* Start preparing the associated WIM inode */
        inode = root->d_inode;
 
+       if (inode->i_nlink > 1) /* Shared inode; nothing more to do */
+               goto out_close_handle;
+
        inode->i_attributes = file_info.dwFileAttributes;
        inode->i_creation_time = FILETIME_to_u64(&file_info.ftCreationTime);
        inode->i_last_write_time = FILETIME_to_u64(&file_info.ftLastWriteTime);
        inode->i_last_access_time = FILETIME_to_u64(&file_info.ftLastAccessTime);
-       inode->i_ino = ((u64)file_info.nFileIndexHigh << 32) |
-                       (u64)file_info.nFileIndexLow;
-
        inode->i_resolved = 1;
-       add_image_flags &= ~(WIMLIB_ADD_IMAGE_FLAG_ROOT | WIMLIB_ADD_IMAGE_FLAG_SOURCE);
 
-       /* Get DOS name and security descriptor (if any). */
-       ret = win32_get_short_name(root, path);
-       if (ret)
-               goto out_close_handle;
+       add_image_flags &= ~(WIMLIB_ADD_IMAGE_FLAG_ROOT | WIMLIB_ADD_IMAGE_FLAG_SOURCE);
 
        if (!(add_image_flags & WIMLIB_ADD_IMAGE_FLAG_NO_ACLS)) {
-               ret = win32_get_security_descriptor(root, sd_set, path);
+               ret = win32_get_security_descriptor(root, sd_set, path, state,
+                                                   add_image_flags);
                if (ret)
                        goto out_close_handle;
        }
@@ -775,12 +821,16 @@ win32_build_dentry_tree_recursive(struct wim_dentry **root_ret,
                                              path,
                                              path_num_chars,
                                              lookup_table,
+                                             inode_table,
                                              sd_set,
                                              config,
                                              add_image_flags,
-                                             progress_func);
+                                             progress_func,
+                                             state);
        } else if (inode->i_attributes & FILE_ATTRIBUTE_REPARSE_POINT) {
-               /* Reparse point: save the reparse tag and data */
+               /* Reparse point: save the reparse tag and data.  Alternate data
+                * streams are not captured, if it's even possible for a reparse
+                * point to have alternate data streams... */
                ret = win32_capture_reparse_point(hFile,
                                                  inode,
                                                  lookup_table,
@@ -804,13 +854,46 @@ out:
        return ret;
 }
 
+static void
+win32_do_capture_warnings(const struct win32_capture_state *state,
+                         int add_image_flags)
+{
+       if (state->num_get_sacl_priv_notheld == 0 &&
+           state->num_get_sd_access_denied == 0)
+               return;
+
+       WARNING("");
+       WARNING("Built dentry tree successfully, but with the following problem(s):");
+       if (state->num_get_sacl_priv_notheld != 0) {
+               WARNING("Could not capture SACL (System Access Control List)\n"
+                       "          on %lu files or directories.",
+                       state->num_get_sacl_priv_notheld);
+       }
+       if (state->num_get_sd_access_denied != 0) {
+               WARNING("Could not capture security descriptor at all\n"
+                       "          on %lu files or directories.",
+                       state->num_get_sd_access_denied);
+       }
+       WARNING(
+          "Try running the program as the Administrator to make sure all the\n"
+"          desired metadata has been captured exactly.  However, if you\n"
+"          do not care about capturing security descriptors correctly, then\n"
+"          nothing more needs to be done%ls\n",
+       (add_image_flags & WIMLIB_ADD_IMAGE_FLAG_NO_ACLS) ? L"." :
+         L", although you might consider\n"
+"          passing the --no-acls flag to `wimlib-imagex capture' or\n"
+"          `wimlib-imagex append' to explicitly capture no security\n"
+"          descriptors.\n");
+}
+
 /* Win32 version of capturing a directory tree */
 int
 win32_build_dentry_tree(struct wim_dentry **root_ret,
                        const wchar_t *root_disk_path,
                        struct wim_lookup_table *lookup_table,
+                       struct wim_inode_table *inode_table,
                        struct sd_set *sd_set,
-                       const struct capture_config *config,
+                       const struct wimlib_capture_config *config,
                        int add_image_flags,
                        wimlib_progress_func_t progress_func,
                        void *extra_arg)
@@ -818,7 +901,8 @@ win32_build_dentry_tree(struct wim_dentry **root_ret,
        size_t path_nchars;
        wchar_t *path;
        int ret;
-       
+       struct win32_capture_state state;
+
        path_nchars = wcslen(root_disk_path);
        if (path_nchars > 32767)
                return WIMLIB_ERR_INVALID_PARAM;
@@ -831,28 +915,25 @@ win32_build_dentry_tree(struct wim_dentry **root_ret,
        if (!path)
                return WIMLIB_ERR_NOMEM;
 
+       wmemcpy(path, root_disk_path, path_nchars + 1);
+
+       memset(&state, 0, sizeof(state));
        ret = win32_build_dentry_tree_recursive(root_ret,
                                                path,
                                                path_nchars,
                                                lookup_table,
+                                               inode_table,
                                                sd_set,
                                                config,
                                                add_image_flags,
-                                               progress_func);
+                                               progress_func,
+                                               &state);
        FREE(path);
+       if (ret == 0)
+               win32_do_capture_warnings(&state, add_image_flags);
        return ret;
 }
 
-/* Replacement for POSIX fnmatch() (partial functionality only) */
-int
-fnmatch(const wchar_t *pattern, const wchar_t *string, int flags)
-{
-       if (PathMatchSpecW(string, pattern))
-               return 0;
-       else
-               return FNM_NOMATCH;
-}
-
 static int
 win32_set_reparse_data(HANDLE h,
                       u32 reparse_tag,
@@ -920,6 +1001,113 @@ win32_set_reparse_data(HANDLE h,
        return 0;
 }
 
+static int
+win32_set_compressed(HANDLE hFile, const wchar_t *path)
+{
+       USHORT format = COMPRESSION_FORMAT_DEFAULT;
+       DWORD bytesReturned = 0;
+       if (!DeviceIoControl(hFile, FSCTL_SET_COMPRESSION,
+                            &format, sizeof(USHORT),
+                            NULL, 0,
+                            &bytesReturned, NULL))
+       {
+               /* Warning only */
+               DWORD err = GetLastError();
+               WARNING("Failed to set compression flag on \"%ls\"", path);
+               win32_error(err);
+       }
+       return 0;
+}
+
+static int
+win32_set_sparse(HANDLE hFile, const wchar_t *path)
+{
+       DWORD bytesReturned = 0;
+       if (!DeviceIoControl(hFile, FSCTL_SET_SPARSE,
+                            NULL, 0,
+                            NULL, 0,
+                            &bytesReturned, NULL))
+       {
+               /* Warning only */
+               DWORD err = GetLastError();
+               WARNING("Failed to set sparse flag on \"%ls\"", path);
+               win32_error(err);
+       }
+       return 0;
+}
+
+/*
+ * Sets the security descriptor on an extracted file.
+ */
+static int
+win32_set_security_data(const struct wim_inode *inode,
+                       const wchar_t *path,
+                       struct apply_args *args)
+{
+       PSECURITY_DESCRIPTOR descriptor;
+       unsigned long n;
+       DWORD err;
+
+       descriptor = wim_const_security_data(args->w)->descriptors[inode->i_security_id];
+
+       SECURITY_INFORMATION securityInformation = DACL_SECURITY_INFORMATION |
+                                                  SACL_SECURITY_INFORMATION |
+                                                  OWNER_SECURITY_INFORMATION |
+                                                  GROUP_SECURITY_INFORMATION;
+again:
+       if (SetFileSecurityW(path, securityInformation, descriptor))
+               return 0;
+       err = GetLastError();
+       if (args->extract_flags & WIMLIB_EXTRACT_FLAG_STRICT_ACLS)
+               goto fail;
+       switch (err) {
+       case ERROR_PRIVILEGE_NOT_HELD:
+               if (securityInformation & SACL_SECURITY_INFORMATION) {
+                       n = args->num_set_sacl_priv_notheld++;
+                       securityInformation &= ~SACL_SECURITY_INFORMATION;
+                       if (n < MAX_SET_SACL_PRIV_NOTHELD_WARNINGS) {
+                               WARNING(
+"We don't have enough privileges to set the full security\n"
+"          descriptor on \"%ls\"!\n", path);
+                               if (args->num_set_sd_access_denied +
+                                   args->num_set_sacl_priv_notheld == 1)
+                               {
+                                       WARNING("%ls", apply_access_denied_msg);
+                               }
+                               WARNING("Re-trying with SACL omitted.\n", path);
+                       } else if (n == MAX_GET_SACL_PRIV_NOTHELD_WARNINGS) {
+                               WARNING(
+"Suppressing further 'privileges not held' error messages when setting\n"
+"          security descriptors.");
+                       }
+                       goto again;
+               }
+               /* Fall through */
+       case ERROR_INVALID_OWNER:
+       case ERROR_ACCESS_DENIED:
+               n = args->num_set_sd_access_denied++;
+               if (n < MAX_SET_SD_ACCESS_DENIED_WARNINGS) {
+                       WARNING("Failed to set security descriptor on \"%ls\": "
+                               "Access denied!\n", path);
+                       if (args->num_set_sd_access_denied +
+                           args->num_set_sacl_priv_notheld == 1)
+                       {
+                               WARNING("%ls", apply_access_denied_msg);
+                       }
+               } else if (n == MAX_SET_SD_ACCESS_DENIED_WARNINGS) {
+                       WARNING(
+"Suppressing further access denied error messages when setting\n"
+"          security descriptors");
+               }
+               return 0;
+       default:
+fail:
+               ERROR("Failed to set security descriptor on \"%ls\"", path);
+               win32_error(err);
+               return WIMLIB_ERR_WRITE;
+       }
+}
+
 
 static int
 win32_extract_chunk(const void *buf, size_t len, u64 offset, void *arg)
@@ -947,12 +1135,113 @@ do_win32_extract_stream(HANDLE hStream, struct wim_lookup_table_entry *lte)
                                    win32_extract_chunk, hStream);
 }
 
+static bool
+path_is_root_of_drive(const wchar_t *path)
+{
+       if (!*path)
+               return false;
+
+       if (*path != L'/' && *path != L'\\') {
+               if (*(path + 1) == L':')
+                       path += 2;
+               else
+                       return false;
+       }
+       while (*path == L'/' || *path == L'\\')
+               path++;
+       return (*path == L'\0');
+}
+
+static DWORD
+win32_get_create_flags_and_attributes(DWORD i_attributes)
+{
+       DWORD attributes;
+
+       /*
+        * Some attributes cannot be set by passing them to CreateFile().  In
+        * particular:
+        *
+        * FILE_ATTRIBUTE_DIRECTORY:
+        *   CreateDirectory() must be called instead of CreateFile().
+        *
+        * FILE_ATTRIBUTE_SPARSE_FILE:
+        *   Needs an ioctl.
+        *   See: win32_set_sparse().
+        *
+        * FILE_ATTRIBUTE_COMPRESSED:
+        *   Not clear from the documentation, but apparently this needs an
+        *   ioctl as well.
+        *   See: win32_set_compressed().
+        *
+        * FILE_ATTRIBUTE_REPARSE_POINT:
+        *   Needs an ioctl, with the reparse data specified.
+        *   See: win32_set_reparse_data().
+        *
+        * In addition, clear any file flags in the attributes that we don't
+        * want, but also specify FILE_FLAG_OPEN_REPARSE_POINT and
+        * FILE_FLAG_BACKUP_SEMANTICS as we are a backup application.
+        */
+       attributes = i_attributes & ~(FILE_ATTRIBUTE_SPARSE_FILE |
+                                     FILE_ATTRIBUTE_COMPRESSED |
+                                     FILE_ATTRIBUTE_REPARSE_POINT |
+                                     FILE_ATTRIBUTE_DIRECTORY |
+                                     FILE_FLAG_DELETE_ON_CLOSE |
+                                     FILE_FLAG_NO_BUFFERING |
+                                     FILE_FLAG_OPEN_NO_RECALL |
+                                     FILE_FLAG_OVERLAPPED |
+                                     FILE_FLAG_RANDOM_ACCESS |
+                                     /*FILE_FLAG_SESSION_AWARE |*/
+                                     FILE_FLAG_SEQUENTIAL_SCAN |
+                                     FILE_FLAG_WRITE_THROUGH);
+       return attributes |
+              FILE_FLAG_OPEN_REPARSE_POINT |
+              FILE_FLAG_BACKUP_SEMANTICS;
+}
+
+static bool
+inode_has_special_attributes(const struct wim_inode *inode)
+{
+       return (inode->i_attributes & (FILE_ATTRIBUTE_COMPRESSED |
+                                      FILE_ATTRIBUTE_REPARSE_POINT |
+                                      FILE_ATTRIBUTE_SPARSE_FILE)) != 0;
+}
+
+static int
+win32_set_special_attributes(HANDLE hFile, const struct wim_inode *inode,
+                            struct wim_lookup_table_entry *unnamed_stream_lte,
+                            const wchar_t *path)
+{
+       int ret;
+
+       if (inode->i_attributes & FILE_ATTRIBUTE_REPARSE_POINT) {
+               DEBUG("Setting reparse data on \"%ls\"", path);
+               ret = win32_set_reparse_data(hFile, inode->i_reparse_tag,
+                                            unnamed_stream_lte, path);
+               if (ret)
+                       return ret;
+       }
+
+       if (inode->i_attributes & FILE_ATTRIBUTE_COMPRESSED) {
+               DEBUG("Setting compression flag on \"%ls\"", path);
+               ret = win32_set_compressed(hFile, path);
+               if (ret)
+                       return ret;
+       }
+
+       if (inode->i_attributes & FILE_ATTRIBUTE_SPARSE_FILE) {
+               DEBUG("Setting sparse flag on \"%ls\"", path);
+               ret = win32_set_sparse(hFile, path);
+               if (ret)
+                       return ret;
+       }
+       return 0;
+}
+
 static int
 win32_extract_stream(const struct wim_inode *inode,
                     const wchar_t *path,
                     const wchar_t *stream_name_utf16,
-                    struct wim_lookup_table_entry *lte,
-                    const struct wim_security_data *security_data)
+                    struct wim_lookup_table_entry *lte)
 {
        wchar_t *stream_path;
        HANDLE h;
@@ -960,17 +1249,6 @@ win32_extract_stream(const struct wim_inode *inode,
        DWORD err;
        DWORD creationDisposition = CREATE_ALWAYS;
 
-       SECURITY_ATTRIBUTES *secattr;
-
-       if (security_data && inode->i_security_id != -1) {
-               secattr = alloca(sizeof(*secattr));
-               secattr->nLength = sizeof(*secattr);
-               secattr->lpSecurityDescriptor = security_data->descriptors[inode->i_security_id];
-               secattr->bInheritHandle = FALSE;
-       } else {
-               secattr = NULL;
-       }
-
        if (stream_name_utf16) {
                /* Named stream.  Create a buffer that contains the UTF-16LE
                 * string [.\]@path:@stream_name_utf16.  This is needed to
@@ -1009,9 +1287,16 @@ win32_extract_stream(const struct wim_inode *inode,
                 * the call to CreateFileW() will merely open the directory that
                 * was already created rather than creating a new file. */
                if (inode->i_attributes & FILE_ATTRIBUTE_DIRECTORY) {
-                       if (!CreateDirectoryW(stream_path, secattr)) {
+                       if (!CreateDirectoryW(stream_path, NULL)) {
                                err = GetLastError();
-                               if (err != ERROR_ALREADY_EXISTS) {
+                               switch (err) {
+                               case ERROR_ALREADY_EXISTS:
+                                       break;
+                               case ERROR_ACCESS_DENIED:
+                                       if (path_is_root_of_drive(path))
+                                               break;
+                                       /* Fall through */
+                               default:
                                        ERROR("Failed to create directory \"%ls\"",
                                              stream_path);
                                        win32_error(err);
@@ -1020,7 +1305,7 @@ win32_extract_stream(const struct wim_inode *inode,
                                }
                        }
                        DEBUG("Created directory \"%ls\"", stream_path);
-                       if (!(inode->i_attributes & FILE_ATTRIBUTE_REPARSE_POINT)) {
+                       if (!inode_has_special_attributes(inode)) {
                                ret = 0;
                                goto out;
                        }
@@ -1030,13 +1315,11 @@ win32_extract_stream(const struct wim_inode *inode,
 
        DEBUG("Opening \"%ls\"", stream_path);
        h = CreateFileW(stream_path,
-                       GENERIC_WRITE,
+                       GENERIC_READ | GENERIC_WRITE,
                        0,
-                       secattr,
+                       NULL,
                        creationDisposition,
-                       FILE_FLAG_OPEN_REPARSE_POINT |
-                           FILE_FLAG_BACKUP_SEMANTICS |
-                           inode->i_attributes,
+                       win32_get_create_flags_and_attributes(inode->i_attributes),
                        NULL);
        if (h == INVALID_HANDLE_VALUE) {
                err = GetLastError();
@@ -1046,14 +1329,13 @@ win32_extract_stream(const struct wim_inode *inode,
                goto fail;
        }
 
-       if (inode->i_attributes & FILE_ATTRIBUTE_REPARSE_POINT &&
-           stream_name_utf16 == NULL)
-       {
-               DEBUG("Setting reparse data on \"%ls\"", path);
-               ret = win32_set_reparse_data(h, inode->i_reparse_tag, lte, path);
+       if (stream_name_utf16 == NULL && inode_has_special_attributes(inode)) {
+               ret = win32_set_special_attributes(h, inode, lte, path);
                if (ret)
                        goto fail_close_handle;
-       } else {
+       }
+
+       if (!(inode->i_attributes & FILE_ATTRIBUTE_REPARSE_POINT)) {
                if (lte) {
                        DEBUG("Extracting \"%ls\" (len = %"PRIu64")",
                              stream_path, wim_resource_size(lte));
@@ -1093,15 +1375,13 @@ out:
  */
 static int
 win32_extract_streams(const struct wim_inode *inode,
-                     const wchar_t *path, u64 *completed_bytes_p,
-                     const struct wim_security_data *security_data)
+                     const wchar_t *path, u64 *completed_bytes_p)
 {
        struct wim_lookup_table_entry *unnamed_lte;
        int ret;
 
        unnamed_lte = inode_unnamed_lte_resolved(inode);
-       ret = win32_extract_stream(inode, path, NULL, unnamed_lte,
-                                  security_data);
+       ret = win32_extract_stream(inode, path, NULL, unnamed_lte);
        if (ret)
                goto out;
        if (unnamed_lte)
@@ -1119,8 +1399,7 @@ win32_extract_streams(const struct wim_inode *inode,
                        ret = win32_extract_stream(inode,
                                                   path,
                                                   ads_entry->stream_name,
-                                                  ads_entry->lte,
-                                                  NULL);
+                                                  ads_entry->lte);
                        if (ret)
                                break;
                        if (ads_entry->lte)
@@ -1133,10 +1412,11 @@ out:
 
 /* Extract a file, directory, reparse point, or hard link to an
  * already-extracted file using the Win32 API */
-int win32_do_apply_dentry(const wchar_t *output_path,
-                         size_t output_path_num_chars,
-                         struct wim_dentry *dentry,
-                         struct apply_args *args)
+int
+win32_do_apply_dentry(const wchar_t *output_path,
+                     size_t output_path_num_chars,
+                     struct wim_dentry *dentry,
+                     struct apply_args *args)
 {
        int ret;
        struct wim_inode *inode = dentry->d_inode;
@@ -1147,28 +1427,29 @@ int win32_do_apply_dentry(const wchar_t *output_path,
                 * hard link. */
                DEBUG("Creating hard link \"%ls => %ls\"",
                      output_path, inode->i_extracted_file);
-               if (CreateHardLinkW(output_path, inode->i_extracted_file, NULL)) {
-                       ret = 0;
-               } else {
+               if (!CreateHardLinkW(output_path, inode->i_extracted_file, NULL)) {
                        err = GetLastError();
                        ERROR("Can't create hard link \"%ls => %ls\"",
                              output_path, inode->i_extracted_file);
-                       ret = WIMLIB_ERR_LINK;
                        win32_error(err);
+                       return WIMLIB_ERR_LINK;
                }
        } else {
                /* Create the file, directory, or reparse point, and extract the
                 * data streams. */
-               const struct wim_security_data *security_data;
-               if (args->extract_flags & WIMLIB_EXTRACT_FLAG_NOACLS)
-                       security_data = NULL;
-               else
-                       security_data = wim_const_security_data(args->w);
-
                ret = win32_extract_streams(inode, output_path,
-                                           &args->progress.extract.completed_bytes,
-                                           security_data);
-               if (ret == 0 && inode->i_nlink > 1) {
+                                           &args->progress.extract.completed_bytes);
+               if (ret)
+                       return ret;
+
+               if (inode->i_security_id >= 0 &&
+                   !(args->extract_flags & WIMLIB_EXTRACT_FLAG_NO_ACLS))
+               {
+                       ret = win32_set_security_data(inode, output_path, args);
+                       if (ret)
+                               return ret;
+               }
+               if (inode->i_nlink > 1) {
                        /* Save extracted path for a later call to
                         * CreateHardLinkW() if this inode has multiple links.
                         * */
@@ -1177,7 +1458,7 @@ int win32_do_apply_dentry(const wchar_t *output_path,
                                ret = WIMLIB_ERR_NOMEM;
                }
        }
-       return ret;
+       return 0;
 }
 
 /* Set timestamps on an extracted file using the Win32 API */
@@ -1189,7 +1470,6 @@ win32_do_apply_dentry_timestamps(const wchar_t *path,
 {
        DWORD err;
        HANDLE h;
-       int ret;
        const struct wim_inode *inode = dentry->d_inode;
 
        DEBUG("Opening \"%ls\" to set timestamps", path);
@@ -1230,16 +1510,21 @@ out:
 int
 fsync(int fd)
 {
-       HANDLE h = (HANDLE)_get_osfhandle(fd);
+       DWORD err;
+       HANDLE h;
+
+       h = (HANDLE)_get_osfhandle(fd);
        if (h == INVALID_HANDLE_VALUE) {
+               err = GetLastError();
                ERROR("Could not get Windows handle for file descriptor");
-               win32_error(GetLastError());
+               win32_error(err);
                errno = EBADF;
                return -1;
        }
        if (!FlushFileBuffers(h)) {
+               err = GetLastError();
                ERROR("Could not flush file buffers to disk");
-               win32_error(GetLastError());
+               win32_error(err);
                errno = EIO;
                return -1;
        }
@@ -1263,33 +1548,30 @@ realpath(const wchar_t *path, wchar_t *resolved_path)
 {
        DWORD ret;
        wimlib_assert(resolved_path == NULL);
+       DWORD err;
 
        ret = GetFullPathNameW(path, 0, NULL, NULL);
-       if (!ret)
+       if (!ret) {
+               err = GetLastError();
                goto fail_win32;
+       }
 
        resolved_path = TMALLOC(ret);
        if (!resolved_path)
-               goto fail;
+               goto out;
        ret = GetFullPathNameW(path, ret, resolved_path, NULL);
        if (!ret) {
+               err = GetLastError();
                free(resolved_path);
+               resolved_path = NULL;
                goto fail_win32;
        }
-       return resolved_path;
+       goto out;
 fail_win32:
-       win32_error(GetLastError());
-fail:
-       return NULL;
-}
-
-char *
-nl_langinfo(nl_item item)
-{
-       wimlib_assert(item == CODESET);
-       static char buf[64];
-       strcpy(buf, "Unknown");
-       return buf;
+       win32_error(err);
+       errno = -1;
+out:
+       return resolved_path;
 }
 
 /* rename() on Windows fails if the destination file exists.  And we need to
@@ -1305,11 +1587,21 @@ win32_rename_replacement(const wchar_t *oldpath, const wchar_t *newpath)
                ERROR("MoveFileEx(): Can't rename \"%ls\" to \"%ls\"",
                      oldpath, newpath);
                win32_error(err);
-               errno = 0;
+               errno = -1;
                return -1;
        }
 }
 
+/* Replacement for POSIX fnmatch() (partial functionality only) */
+int
+fnmatch(const wchar_t *pattern, const wchar_t *string, int flags)
+{
+       if (PathMatchSpecW(string, pattern))
+               return 0;
+       else
+               return FNM_NOMATCH;
+}
+
 /* truncate() replacement */
 int
 win32_truncate_replacement(const wchar_t *path, off_t size)
@@ -1336,8 +1628,26 @@ fail_close_handle:
 fail:
        if (err == NO_ERROR)
                err = GetLastError();
-       ERROR("Can't truncate %ls to %"PRIu64" bytes", path, size);
+       ERROR("Can't truncate \"%ls\" to %"PRIu64" bytes", path, size);
        win32_error(err);
        errno = -1;
        return -1;
 }
+
+
+/* This really could be replaced with _wcserror_s, but this doesn't seem to
+ * actually be available in MSVCRT.DLL on Windows XP (perhaps it's statically
+ * linked in by Visual Studio...?). */
+extern int
+win32_strerror_r_replacement(int errnum, wchar_t *buf, size_t buflen)
+{
+       static pthread_mutex_t strerror_lock = PTHREAD_MUTEX_INITIALIZER;
+
+       pthread_mutex_lock(&strerror_lock);
+       mbstowcs(buf, strerror(errnum), buflen);
+       buf[buflen - 1] = '\0';
+       pthread_mutex_unlock(&strerror_lock);
+       return 0;
+}
+
+#endif /* __WIN32__ */