fs/smb/server/smb2pdu.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)
From: Xu Rao <raoxu@uniontech.com>
fsctl_copychunk() maps errors from ksmbd_vfs_copy_file_ranges() to SMB
status codes. For -EACCES it first sets STATUS_ACCESS_DENIED, but the
following -EAGAIN test starts a separate if/else-if chain. Because
-EACCES does not match that chain, its final else immediately overwrites
the status with STATUS_UNEXPECTED_IO_ERROR.
MS-SMB2 section 3.3.5.15.6 requires FSCTL_SRV_COPYCHUNK and
FSCTL_SRV_COPYCHUNK_WRITE to fail with STATUS_ACCESS_DENIED when the
source open lacks FILE_READ_DATA or the destination open lacks
FILE_WRITE_DATA or FILE_APPEND_DATA. ksmbd_vfs_copy_file_ranges()
returns -EACCES when its source or destination access check fails, so the
current control flow reports a protocol-visible permission failure as an
unrelated I/O error.
Make the -EAGAIN condition part of the same else-if chain so the -EACCES
mapping is preserved.
Fixes: e2f34481b24d ("cifsd: add server-side procedures for SMB3")
Cc: stable@vger.kernel.org
Signed-off-by: Xu Rao <raoxu@uniontech.com>
---
fs/smb/server/smb2pdu.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index bec692bca1ca..416bf1e55c81 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -8524,7 +8524,7 @@ static int fsctl_copychunk(struct ksmbd_work *work,
if (ret < 0) {
if (ret == -EACCES)
rsp->hdr.Status = STATUS_ACCESS_DENIED;
- if (ret == -EAGAIN)
+ else if (ret == -EAGAIN)
rsp->hdr.Status = STATUS_FILE_LOCK_CONFLICT;
else if (ret == -EBADF)
rsp->hdr.Status = STATUS_INVALID_HANDLE;
--
2.50.1
Thanks for your patch. This bug has already been fixed in the
ksmbd-for-next-next branch:
https://github.com/smfrench/smb3-kernel/commit/35e11e324a2f97d2974ef08d308063c9c5f9e9d8
On 7/31/26 15:20, raoxu wrote:
> From: Xu Rao <raoxu@uniontech.com>
>
> fsctl_copychunk() maps errors from ksmbd_vfs_copy_file_ranges() to SMB
> status codes. For -EACCES it first sets STATUS_ACCESS_DENIED, but the
> following -EAGAIN test starts a separate if/else-if chain. Because
> -EACCES does not match that chain, its final else immediately overwrites
> the status with STATUS_UNEXPECTED_IO_ERROR.
>
> MS-SMB2 section 3.3.5.15.6 requires FSCTL_SRV_COPYCHUNK and
> FSCTL_SRV_COPYCHUNK_WRITE to fail with STATUS_ACCESS_DENIED when the
> source open lacks FILE_READ_DATA or the destination open lacks
> FILE_WRITE_DATA or FILE_APPEND_DATA. ksmbd_vfs_copy_file_ranges()
> returns -EACCES when its source or destination access check fails, so the
> current control flow reports a protocol-visible permission failure as an
> unrelated I/O error.
>
> Make the -EAGAIN condition part of the same else-if chain so the -EACCES
> mapping is preserved.
>
> Fixes: e2f34481b24d ("cifsd: add server-side procedures for SMB3")
> Cc: stable@vger.kernel.org
> Signed-off-by: Xu Rao <raoxu@uniontech.com>
> ---
> fs/smb/server/smb2pdu.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
> index bec692bca1ca..416bf1e55c81 100644
> --- a/fs/smb/server/smb2pdu.c
> +++ b/fs/smb/server/smb2pdu.c
> @@ -8524,7 +8524,7 @@ static int fsctl_copychunk(struct ksmbd_work *work,
> if (ret < 0) {
> if (ret == -EACCES)
> rsp->hdr.Status = STATUS_ACCESS_DENIED;
> - if (ret == -EAGAIN)
> + else if (ret == -EAGAIN)
> rsp->hdr.Status = STATUS_FILE_LOCK_CONFLICT;
> else if (ret == -EBADF)
> rsp->hdr.Status = STATUS_INVALID_HANDLE;
> --
> 2.50.1
>
>
--
ChenXiaoSong <chenxiaosong@chenxiaosong.com>
Chinese Homepage: https://chenxiaosong.com
English Homepage: https://chenxiaosong.com/en
Reviewed-by: ChenXiaoSong <chenxiaosong@kylinos.cn>
On 7/31/26 15:20, raoxu wrote:
> From: Xu Rao <raoxu@uniontech.com>
>
> fsctl_copychunk() maps errors from ksmbd_vfs_copy_file_ranges() to SMB
> status codes. For -EACCES it first sets STATUS_ACCESS_DENIED, but the
> following -EAGAIN test starts a separate if/else-if chain. Because
> -EACCES does not match that chain, its final else immediately overwrites
> the status with STATUS_UNEXPECTED_IO_ERROR.
>
> MS-SMB2 section 3.3.5.15.6 requires FSCTL_SRV_COPYCHUNK and
> FSCTL_SRV_COPYCHUNK_WRITE to fail with STATUS_ACCESS_DENIED when the
> source open lacks FILE_READ_DATA or the destination open lacks
> FILE_WRITE_DATA or FILE_APPEND_DATA. ksmbd_vfs_copy_file_ranges()
> returns -EACCES when its source or destination access check fails, so the
> current control flow reports a protocol-visible permission failure as an
> unrelated I/O error.
>
> Make the -EAGAIN condition part of the same else-if chain so the -EACCES
> mapping is preserved.
>
> Fixes: e2f34481b24d ("cifsd: add server-side procedures for SMB3")
> Cc: stable@vger.kernel.org
> Signed-off-by: Xu Rao <raoxu@uniontech.com>
> ---
> fs/smb/server/smb2pdu.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
> index bec692bca1ca..416bf1e55c81 100644
> --- a/fs/smb/server/smb2pdu.c
> +++ b/fs/smb/server/smb2pdu.c
> @@ -8524,7 +8524,7 @@ static int fsctl_copychunk(struct ksmbd_work *work,
> if (ret < 0) {
> if (ret == -EACCES)
> rsp->hdr.Status = STATUS_ACCESS_DENIED;
> - if (ret == -EAGAIN)
> + else if (ret == -EAGAIN)
> rsp->hdr.Status = STATUS_FILE_LOCK_CONFLICT;
> else if (ret == -EBADF)
> rsp->hdr.Status = STATUS_INVALID_HANDLE;
> --
> 2.50.1
>
>
--
ChenXiaoSong <chenxiaosong@chenxiaosong.com>
Chinese Homepage: https://chenxiaosong.com
English Homepage: https://chenxiaosong.com/en
© 2016 - 2026 Red Hat, Inc.