From nobody Mon Sep 28 09:58:46 2026 Received: from mail-pz2-f25.google.com (mail-pz2-f25.google.com [74.125.228.25]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4003D331EB5 for ; Sat, 26 Sep 2026 06:50:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.228.25 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790405425; cv=none; b=WS3T2I3fiOcXxT6PbfkR43Qb8N8ec8NVw3g79afOIHszkH9KlbtiyYd3ZwlaLlGtfgwOm80KUq3nbhT2ucnZX4vU5J2MIYJgaczg7Ywm9k040ddS2MNzEb3+Y7+RYpnW0AoLkqeWjhbhkQDoBkMs3pPKg7IkwxwaOlx1ZNK+PTc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790405425; c=relaxed/simple; bh=e+Ut2QFN7CI3vbeEn82zMl57Xjd0B2AHAqke8Cvb+i0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=UrensWVxyL0EdAHU6utotlaCbJ2ua2DwrBsYNcVIUlCoiqZYR0di3hJIyF2ezdy34g8kgo8424od3FxPLvZ/Ovm0ZhjSamJWujKfLXmrv8/qD5Lp1UV6AHWAvna30QSu2iURKE/8c+vbQeCz4fCKThx6inQRLJv6m81MQwQlD3k= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=nebusec.ai; spf=pass smtp.mailfrom=nebusec.ai; dkim=pass (2048-bit key) header.d=nebusec.ai header.i=@nebusec.ai header.b=fABC+22k; arc=none smtp.client-ip=74.125.228.25 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=nebusec.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nebusec.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nebusec.ai header.i=@nebusec.ai header.b="fABC+22k" Received: by mail-pz2-f25.google.com with SMTP id 41be03b00d2f7-cc1cebad4aeso488004a12.2 for ; Fri, 25 Sep 2026 23:50:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nebusec.ai; s=google; t=1790405422; x=1791010222; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=OSTQl7TWfO/HBakXURDp6p7BA/fXMZ8rsqfWWwwFT8M=; b=fABC+22k9AnXokgT5PO+rqln/2f6yH/LaqEm3h464Kr+CVkAgEKmr+dtV754XCIdFJ gS/boBd30josbZsaM4VxP/sVQOb6e58fXS7Bj72DWrRwiGrTlyp0t6CDEfp7wQ4yEG0h mv7AwdOZoCdRbRvMJXRxb5jIkSoangh62wJitp8cFRp0SXIsKKuw1gRmtLUMk7xJMwO/ LVmavxAgUHOQq1Py12b95nkGbTX610DRXn7fm1C3h5IrVULj0CSzOWo92G9U/5DeysX4 ajft3VI4BpyvkzTezCmr84Cm4SXcLRQMT6yH1yqTI5iJBqkLk5kYrwwF4SfZV5CBgn93 A97w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790405422; x=1791010222; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=OSTQl7TWfO/HBakXURDp6p7BA/fXMZ8rsqfWWwwFT8M=; b=1Yc+DUEvxdndP8oZQ6mK/jLTutc5VBp/WST0lhOqjQ50L9O01hdNA4RmINkgrAFYZB 2NXUoyIKyKtT0VmcC997KO10igLZnkpaSC2hpm2bjQDkt/vYDz0fW7DPvo5elQB28/+0 eyu+GZg1FMtFvl52uBX6vBU0UJm2+rrMyMfsnBjYjPW/fL2c23eK82XvIhZzQrHBvsrX L4MVL5TNLxE5+MCy9yFqZcwNrr/1YsV6bn8ty+hCoOeNyI5X2dpUuvODxVkvUNIJqaI/ dy7x3U9d3uvZzxc/Edjkuo9vzXobbacC3eb/xbT6U3pUNFkj/3UE9hdPIGA8Ui88+9xZ WoxQ== X-Forwarded-Encrypted: i=1; AKwUvBzA2U3BbGY3pYOjstkylPZtTE2BmZH7GEaJUQRy8z8ZajlTfBB0LmPdUslgrg+cdl/4vfXlJceGDj8hiII=@vger.kernel.org X-Gm-Message-State: AFuF++l6MSylJ+wE5ApEJzGJnLEYVX3KtNzi3271smZSNGBCVBQXnJ0p 846DSwvNE13n5xdgqKAwWpj/SvBm/iDnyZ9Yr9ToeAbcY7FsXjNnU5HjnU2pdw1ZiF6Q X-Gm-Gg: AYBFou1RLvisxqKx1mb80xp2rQCIO/GY7hMq+lz9e/zERNifQAYp3QI2k1FqR5WZAFH XlCNtRYW6ILHXShg4dC/lE7wz6p3AlNePSCUebaqmLiroC+ZKWjrMEYY2u6QxtlsftRGfBQTvrI Dk0QbrknzrfiZjCtmroSnrgS5daNwaoIGWS5OnEMYfHPx2h1Dd1zEwx/7z5IPXbx3R/fcweOy84 aZ2gdeJfbL3JvzkR4LdHQyodJ667StpsCAi/7bdHiJNo8DRkMObx/f7IFMGzZ3ZVrj6/A3rh9ZU cHiOgKeJCCYHn0Ez4XyXba5Hy7f2v84UAh8D61vFuKUFxmZGXf2jANYnj2KnOCAvMCdVLX8yVJK 79yYwiF3N4QAwUft6t0vmYcrkCwb/1d1cEvBEWIOLZ3MGQsN5xea0ls+wOrM9KmAuyBwQ8itMkq 6qKe88n+GJjdeSrEyqdwzzSqTZChtv4jdcXb1GSx9JoFzpOuoqt9YRUHPSKgh2YzLSoEKPsGeVn a2Br/0iINhpIzAgmpjKmEjwPQkulQ== X-Received: by 2002:a17:90b:44:b0:3a0:cc33:2285 with SMTP id 98e67ed59e1d1-3a0cc3324bcmr2093889a91.22.1790405422398; Fri, 25 Sep 2026 23:50:22 -0700 (PDT) Received: from 954df21a5119.. ([122.51.212.64]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-3a0b498fb12sm3447327a91.0.2026.09.25.23.50.18 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 25 Sep 2026 23:50:21 -0700 (PDT) From: Zihan Xi To: sfrench@samba.org Cc: zihanx@nebusec.ai, pc@manguebit.org, ronniesahlberg@gmail.com, sprasad@microsoft.com, tom@talpey.com, bharathsm@microsoft.com, pshilovsky@samba.org, aaptel@suse.com, pali@kernel.org, linux-cifs@vger.kernel.org, samba-technical@lists.samba.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH v5 1/6] smb: client: fix create context out-of-bounds reads Date: Sat, 26 Sep 2026 06:49:21 +0000 Message-ID: <3e9396339a0bc331aa8d7dcd319a750b827a67f8.1790398755.git.zihanx@nebusec.ai> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" smb2_parse_contexts() validates the complete create-context area but does not limit each record to its Next field before dispatching it. A malformed chain can therefore expose bytes beyond the current context to a handler. The QFid handler also used a full response-structure cast although it only reads DiskFileId. The SMB2/SMB3 lease parsers made the same layout assumption: they read LeaseState and LeaseFlags at canonical offsets rather than at DataOffset. A valid non-canonical DataOffset could therefore yield unrelated in-bounds data, while a short DataLength was still accepted. Limit each context to its Next value, reject offsets before the context header, and reject malformed chains. Bound the name range by the current context and do not dispatch a known handler when DataLength is zero. Read the QFid DiskFileId only when the context data covers that field. Parse the lease context from DataOffset and require DataLength to match the v1 or v2 lease_context size used by ksmbd. A size mismatch skips lease parsing without failing the open. Fixes: b8c32dbb0deb ("CIFS: Request SMB2.1 leases") Fixes: f047390a097e ("CIFS: Add create lease v2 context for SMB3") Fixes: 89a5bfa350fa ("smb3: optimize open to not send query file internal i= nfo") Cc: stable@vger.kernel.org Reported-by: Vega Assisted-by: LLM Co-developed-by: Luxing Yin Signed-off-by: Luxing Yin Signed-off-by: Zihan Xi --- changes in v5: - Rerolled the series after fixing a NULL dereference reported by the kernel test robot Smatch analysis in patch 5: https://lore.kernel.org/r/202609241449.HlHmnZFZ-lkp@intel.com/ - v4 Link: https://lore.kernel.org/all/cover.1789478666.git.zihanx@nebuse= c.ai/ changes in v4: - Reject NameOffset and DataOffset values before the context header and use checked arithmetic for the name range. - Bound the name range by the current record and skip known-handler dispatch when DataLength is zero. - Parse lease data from DataOffset and require exact v1/v2 payload sizes. - Add the SMB3 lease v2 Fixes attribution for f047390a097e. - v3 Link: https://lore.kernel.org/all/cover.1788516372.git.zihanx@nebuse= c.ai/ changes in v3: - Split the POSIX handler check into a separate patch and corrected the parser Fixes history. - v2 Link: https://lore.kernel.org/all/cover.1787486936.git.zihanx@nebuse= c.ai/ changes in v2: - Bound each response context by Next and reject malformed chains. - Read QFid DiskFileId only when DataLength covers the payload. - Extend the SMB2 lease minimum through the LeaseFlags field. - Add a POSIX handler check for the three fixed fields. - v1 Link: https://lore.kernel.org/all/eb1bc35611f91bd10a4772400b37fac26f= 660956.1782579150.git.xizh2024@lzu.edu.cn/ --- fs/smb/client/smb2ops.c | 28 ++++++++++++++++++-------- fs/smb/client/smb2pdu.c | 44 +++++++++++++++++++++++++++++++---------- 2 files changed, 54 insertions(+), 18 deletions(-) diff --git a/fs/smb/client/smb2ops.c b/fs/smb/client/smb2ops.c index 192649fec25d5..749cee88fc38d 100644 --- a/fs/smb/client/smb2ops.c +++ b/fs/smb/client/smb2ops.c @@ -4437,25 +4437,37 @@ smb3_create_lease_buf(u8 *lease_key, u8 oplock, u8 = *parent_lease_key, __le32 fla static __u8 smb2_parse_lease_buf(void *buf, __u16 *epoch, char *lease_key) { - struct create_lease *lc =3D (struct create_lease *)buf; + struct create_context *cc =3D buf; + struct lease_context lc; =20 *epoch =3D 0; /* not used */ - if (lc->lcontext.LeaseFlags & SMB2_LEASE_FLAG_BREAK_IN_PROGRESS_LE) + if (le32_to_cpu(cc->DataLength) !=3D sizeof(lc)) + return 0; + + memcpy(&lc, (u8 *)cc + le16_to_cpu(cc->DataOffset), sizeof(lc)); + if (lc.LeaseFlags & SMB2_LEASE_FLAG_BREAK_IN_PROGRESS_LE) return SMB2_OPLOCK_LEVEL_NOCHANGE; - return le32_to_cpu(lc->lcontext.LeaseState); + return le32_to_cpu(lc.LeaseState); } =20 static __u8 smb3_parse_lease_buf(void *buf, __u16 *epoch, char *lease_key) { - struct create_lease_v2 *lc =3D (struct create_lease_v2 *)buf; + struct create_context *cc =3D buf; + struct lease_context_v2 lc; + + if (le32_to_cpu(cc->DataLength) !=3D sizeof(lc)) { + *epoch =3D 0; + return 0; + } =20 - *epoch =3D le16_to_cpu(lc->lcontext.Epoch); - if (lc->lcontext.LeaseFlags & SMB2_LEASE_FLAG_BREAK_IN_PROGRESS_LE) + memcpy(&lc, (u8 *)cc + le16_to_cpu(cc->DataOffset), sizeof(lc)); + *epoch =3D le16_to_cpu(lc.Epoch); + if (lc.LeaseFlags & SMB2_LEASE_FLAG_BREAK_IN_PROGRESS_LE) return SMB2_OPLOCK_LEVEL_NOCHANGE; if (lease_key) - memcpy(lease_key, &lc->lcontext.LeaseKey, SMB2_LEASE_KEY_SIZE); - return le32_to_cpu(lc->lcontext.LeaseState); + memcpy(lease_key, lc.LeaseKey, SMB2_LEASE_KEY_SIZE); + return le32_to_cpu(lc.LeaseState); } =20 static unsigned int diff --git a/fs/smb/client/smb2pdu.c b/fs/smb/client/smb2pdu.c index 4ce165e40657f..7a6627400ba30 100644 --- a/fs/smb/client/smb2pdu.c +++ b/fs/smb/client/smb2pdu.c @@ -2378,11 +2378,17 @@ create_reconnect_durable_buf(struct cifs_fid *fid) static void parse_query_id_ctxt(struct create_context *cc, struct smb2_file_all_info *= buf) { - struct create_disk_id_rsp *pdisk_id =3D (struct create_disk_id_rsp *)cc; + u16 doff =3D le16_to_cpu(cc->DataOffset); + u32 dlen =3D le32_to_cpu(cc->DataLength); + u8 *beg; =20 - cifs_dbg(FYI, "parse query id context 0x%llx 0x%llx\n", - pdisk_id->DiskFileId, pdisk_id->VolumeId); - buf->IndexNumber =3D pdisk_id->DiskFileId; + if (dlen < sizeof(__le64)) + return; + + beg =3D (u8 *)cc + doff; + memcpy(&buf->IndexNumber, beg, sizeof(__le64)); + cifs_dbg(FYI, "parse query id context 0x%llx\n", + le64_to_cpu(buf->IndexNumber)); } =20 static void @@ -2430,6 +2436,7 @@ int smb2_parse_contexts(struct TCP_Server_Info *serve= r, struct smb2_create_rsp *rsp =3D rsp_iov->iov_base; struct create_context *cc; size_t rem, off, len; + size_t cc_len; size_t doff, dlen; size_t noff, nlen; char *name; @@ -2452,29 +2459,41 @@ int smb2_parse_contexts(struct TCP_Server_Info *ser= ver, buf->IndexNumber =3D 0; =20 while (rem >=3D sizeof(*cc)) { + off =3D le32_to_cpu(cc->Next); + if (off) { + if ((off & 0x7) || off >=3D rem || off < sizeof(*cc)) + return -EINVAL; + cc_len =3D off; + } else { + cc_len =3D rem; + } + doff =3D le16_to_cpu(cc->DataOffset); dlen =3D le32_to_cpu(cc->DataLength); - if (check_add_overflow(doff, dlen, &len) || len > rem) + if (doff < sizeof(*cc) || + check_add_overflow(doff, dlen, &len) || len > cc_len) return -EINVAL; =20 noff =3D le16_to_cpu(cc->NameOffset); nlen =3D le16_to_cpu(cc->NameLength); - if (noff + nlen > doff) + if (noff < sizeof(*cc) || + check_add_overflow(noff, nlen, &len) || len > cc_len || + (dlen && len > doff)) return -EINVAL; =20 name =3D (char *)cc + noff; switch (nlen) { case 4: - if (!strncmp(name, SMB2_CREATE_REQUEST_LEASE, 4)) { + if (dlen && !strncmp(name, SMB2_CREATE_REQUEST_LEASE, 4)) { *oplock =3D server->ops->parse_lease_buf(cc, epoch, lease_key); - } else if (buf && + } else if (dlen && buf && !strncmp(name, SMB2_CREATE_QUERY_ON_DISK_ID, 4)) { parse_query_id_ctxt(cc, buf); } break; case 16: - if (posix && !memcmp(name, smb3_create_tag_posix, 16)) + if (dlen && posix && !memcmp(name, smb3_create_tag_posix, 16)) parse_posix_ctxt(cc, buf, posix); break; default: @@ -2486,13 +2505,18 @@ int smb2_parse_contexts(struct TCP_Server_Info *ser= ver, } =20 off =3D le32_to_cpu(cc->Next); - if (!off) + if (!off) { + rem =3D 0; break; + } if (check_sub_overflow(rem, off, &rem)) return -EINVAL; cc =3D (struct create_context *)((u8 *)cc + off); } =20 + if (rem) + return -EINVAL; + if (rsp->OplockLevel !=3D SMB2_OPLOCK_LEVEL_LEASE) *oplock =3D rsp->OplockLevel; =20 --=20 2.43.0 From nobody Mon Sep 28 09:58:46 2026 Received: from mail-pz2-f42.google.com (mail-pz2-f42.google.com [74.125.228.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8282D148850 for ; Sat, 26 Sep 2026 06:50:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.228.42 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790405429; cv=none; b=kNIZEDZmouv53T7Nh3GyDtiT7cxqwHQ/xeS8+EKGt1BUuNod04TflPg8FHWu0nAVh2zlTk7twCzXcxQ8OKf3KaNkUkkRVXuJGb559J5BH31V/C07Z3oB//PBTyqMSE4ZAEgEOQ8diTlMT7rHhj+i/fRpoTeZq+QywAZAMi0PBK4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790405429; c=relaxed/simple; bh=rTGUtv+wPxJk5mSmM4Tl3xXZ3LO/rYIRQAR1R4Hrk/0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=iYgGfhaL4/tX7HbWKOUMCcG4J/FOav/hozziCHYyCPq7t7PWGHu1RZ9pHw7mqvoYRfsoSqvnFfNJn0hOemvkzr1zSbuPJUw1Uprmfpk+5Dxl1o6cr5ep3ajj0wQCrz1HsDSNrVytGAHFnPy5/JXcnaA2U2YFcQkp+7nZH+3BUJ8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=nebusec.ai; spf=pass smtp.mailfrom=nebusec.ai; dkim=pass (2048-bit key) header.d=nebusec.ai header.i=@nebusec.ai header.b=hpLG9uZU; arc=none smtp.client-ip=74.125.228.42 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=nebusec.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nebusec.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nebusec.ai header.i=@nebusec.ai header.b="hpLG9uZU" Received: by mail-pz2-f42.google.com with SMTP id 41be03b00d2f7-cc797656e44so332839a12.2 for ; Fri, 25 Sep 2026 23:50:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nebusec.ai; s=google; t=1790405428; x=1791010228; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=qaSz2GdVx8A7Ex+8pGM2lnZM5Ln+swsfQUfhuKBlALc=; b=hpLG9uZU96Qg3rkcWdkfKnGm+i7V5Wf6ritlkyqDjD3CX8HzWCeeFVv3188EnXspUj mZIbG5z/uTBPFCi2UIZgZVM0u0AZ8ew1+XT/X3WgcU3zKOqd0S1022/BfhTeu7yMZfDV I//JIxg+e5/nbuW5EXKhldO/O+fN2dEizs0DSY0+b1gS6m/1BjtG5Q/MsZ11ZGaaXO1b iLr9M+gyOdsDLHQu29oXvSH3oqU1O6YtLgwvjras+krA4zHqZpVhg+2tKTcrtePlCZJV z3M9B/lR/71m/KCWeqGSWW+r408XcxKmMOJKLixVow9zYYTTadBgEltyvxqt1L7qZmWA SYKA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790405428; x=1791010228; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=qaSz2GdVx8A7Ex+8pGM2lnZM5Ln+swsfQUfhuKBlALc=; b=cAtl5nxQVlT2QdDSUfdAW9eJPqZZnhvWt4cxb8UB/TIFUSrXy2PxHX7LabttCaUW0C v4MUzU9pYt9ZeFN47pEj8zHBm0jfcQLhF68E7dppi29BSB1CewvLifFQzqS0OG5e3v74 hSx/u/ZpCj6BC/P+ynQoZLwuE+d4t+meoAvBeF+O1S7jdL0cnTST4EkuAUuBiHKQ9Lmd kgqSe+Ekf4GXDoJRxl+f4hc+ZL6TfCKETfGarL49MOh60OLRDytOQ3zvV6IT/w5Kkxuu bnnMCoQwV4blreeJ7ptdGQHMVSyccZ99jP1pisMQ1RVInVEkiKf2ETnoOpOZFNr1mk3r YXgg== X-Forwarded-Encrypted: i=1; AKwUvBwEMLXLd0FVI2Cf7v1Paf3hPcs3lEtQS22aL3+LEQjBUtdz/hBsKURXk7AC042aya4JcrZrnSV6z+pd6qg=@vger.kernel.org X-Gm-Message-State: AFq9FYIKYecUrLiYLHSD8RmHUg2N/2Vo/50mlrGBMkc272UaoZGCZQgQ 6cI0HaBcspOXLzsPyTJTw/qwodk6AyCGqcaegT2Z/9+YiZiF1thtS1eQWCMKxi6pfdJRGc9CQ9C KpOIgXA== X-Gm-Gg: AYBFou1ehLV8RrSWbjii9+oiR27GT1JcqXxV6350K8ilbTY/tppT+Afb9meraOpb9yl bwgsUqRWUJXYYUcFHI4XypAfJpUdbH6y0K9dbS7t63jjEilciS03J0ElYJ8NGRjtABsdSgkHf87 LOEcrhN6FFfZrc7GoAHCQN2MZy9dSHagOh/8A50OApniEAzfNvWanBR4Uy7JpDkl+EbFnBPQV5g uZIOVoDlYK/AbdsFeQvu2agQJdi9g0n0JKpcEcW035oTkK3XDWWBs0/yjRk3zoglPEPexr8Iecy tFxR3KB9cJyN3k6GZRPX4MYoMxLDC4BBPZ9v5p+mDsFDf92EYUKEefX/m8rEhVwZ9DaVX0T3VDf El5hwGv6pdftigVo90Ez9a0t72phZX+ieUsvYlkHwrFawGdllEfw6uUsYXLCFrXSouVOSWs5peu A4CsOzL04QFd0yXlh8WdtlJWFl+ZRPYcadq9WfstCzNL3jf3uL976mzRTiuFgNwPU19+WznuLAy Cut+89kfDIpCUAHZvo74PJqYO9QSA== X-Received: by 2002:a17:90b:314e:b0:39e:5ade:f9de with SMTP id 98e67ed59e1d1-3a098b431dbmr6905351a91.26.1790405427689; Fri, 25 Sep 2026 23:50:27 -0700 (PDT) Received: from 954df21a5119.. ([122.51.212.64]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-3a0b498fb12sm3447327a91.0.2026.09.25.23.50.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 25 Sep 2026 23:50:27 -0700 (PDT) From: Zihan Xi To: sfrench@samba.org Cc: zihanx@nebusec.ai, pc@manguebit.org, ronniesahlberg@gmail.com, sprasad@microsoft.com, tom@talpey.com, bharathsm@microsoft.com, pshilovsky@samba.org, aaptel@suse.com, pali@kernel.org, linux-cifs@vger.kernel.org, samba-technical@lists.samba.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH v5 2/6] smb: client: validate POSIX create context length Date: Sat, 26 Sep 2026 06:49:22 +0000 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" parse_posix_ctxt() reads the fixed nlink, reparse_tag, and mode fields before checking that the POSIX create context contains them. A short context can pass the generic checks and still make these fixed-width reads run past its declared data. The current in-tree smb2_open_file() path passes a NULL posix pointer, so this handler is not reached on the ordinary open path. Still require the POSIX data to cover all three fields before reading them because the helper performs those unguarded reads. Keep the existing soft-failure behavior so malformed optional metadata does not fail the open. Fixes: 69dda3059e7a ("cifs: add SMB2_open() arg to return POSIX data") Cc: stable@vger.kernel.org Reported-by: Vega Assisted-by: LLM Co-developed-by: Luxing Yin Signed-off-by: Luxing Yin Signed-off-by: Zihan Xi --- changes in v5: - Rerolled the series after fixing a NULL dereference reported by the kernel test robot Smatch analysis in patch 5: https://lore.kernel.org/r/202609241449.HlHmnZFZ-lkp@intel.com/ - v4 Link: https://lore.kernel.org/all/cover.1789478666.git.zihanx@nebuse= c.ai/ changes in v4: - Keep the handler-level minimum check and preserve soft failure for malformed optional POSIX metadata. - v3 Link: https://lore.kernel.org/all/cover.1788516372.git.zihanx@nebuse= c.ai/ changes in v3: - Split the POSIX handler check into a separate patch and corrected the parser Fixes history. - v2 Link: https://lore.kernel.org/all/cover.1787486936.git.zihanx@nebuse= c.ai/ changes in v2: - Add the POSIX handler check for the three fixed fields. - v1 Link: https://lore.kernel.org/all/eb1bc35611f91bd10a4772400b37fac26f= 660956.1782579150.git.xizh2024@lzu.edu.cn/ --- fs/smb/client/smb2pdu.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/fs/smb/client/smb2pdu.c b/fs/smb/client/smb2pdu.c index 7a6627400ba30..1b2ca3b2c2f87 100644 --- a/fs/smb/client/smb2pdu.c +++ b/fs/smb/client/smb2pdu.c @@ -2395,12 +2395,15 @@ static void parse_posix_ctxt(struct create_context *cc, struct smb2_file_all_info *inf= o, struct create_posix_rsp *posix) { - int sid_len; u8 *beg =3D (u8 *)cc + le16_to_cpu(cc->DataOffset); - u8 *end =3D beg + le32_to_cpu(cc->DataLength); + u32 dlen =3D le32_to_cpu(cc->DataLength); + u8 *end =3D beg + dlen; + int sid_len; u8 *sid; =20 memset(posix, 0, sizeof(*posix)); + if (dlen < 3 * sizeof(__le32)) + return; =20 posix->nlink =3D get_unaligned_le32(beg); posix->reparse_tag =3D get_unaligned_le32(beg + 4); --=20 2.43.0 From nobody Mon Sep 28 09:58:46 2026 Received: from mail-pj2-f41.google.com (mail-pj2-f41.google.com [74.125.227.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5036A363C59 for ; Sat, 26 Sep 2026 06:50:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.227.169 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790405435; cv=none; b=QybqpPvIJRcMlDO6ozbX4tgKN0J2+4mWVLBLEhq8Q4eLhj8JsqG0SmH3300Ca20zDh3Ewp12hJsvAlko3dYtjdQxr86LMkPANUgpzFJLcIlF6OvlX1rZnxjn7/TGO1jcWWeXIR8x9hVN24yPtHUNVontwLOwjL2EkGNN/xWNbHg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790405435; c=relaxed/simple; bh=HXXQDQFDe6y3nQ/vamf6MNCnBdaQPhLlVMTawKOpJl4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=RXhWIwH2wNpkC9Scu9XiKoKBqUcM7pmPJX49HfniZ9QVxJ0O+mxp26x9On1DSdG3h9AHRsPy2dE4/igPQqy/yo1HXLKFqCxK9i7G3igdNHS/N1dnYWXiszL/V102xjGGERQRQ2mI7uqcbv2VCbI43uEhWYoB8ewKp7oCkfa12Js= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=nebusec.ai; spf=pass smtp.mailfrom=nebusec.ai; dkim=pass (2048-bit key) header.d=nebusec.ai header.i=@nebusec.ai header.b=KKJcTB+L; arc=none smtp.client-ip=74.125.227.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=nebusec.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nebusec.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nebusec.ai header.i=@nebusec.ai header.b="KKJcTB+L" Received: by mail-pj2-f41.google.com with SMTP id 98e67ed59e1d1-3a0bcdf41a3so698839a91.2 for ; Fri, 25 Sep 2026 23:50:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nebusec.ai; s=google; t=1790405434; x=1791010234; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=kwLyN45KcXkMlGV64Woz+4zZ99i3stRGQEp+uIa/oYs=; b=KKJcTB+LXHmibGJJ8l1Bqq3mYXAP4jyXdZuMimyTM04u+yyqEOTfusm+2t/Xj/OVfN 4vOZ3e0WLVHnuDgkHMlUwmwdkthIulyoHGsmDjzPIcmNMilG929opSJAXMlrSEvGbKOd dz+PBTof1cWGtoh1QUKJs8RuMBAqbDd3ss6Ye4x+qey17O18w6gDRDya2CZMLfjrwHzk o2gVYgEngdweL1u/MKB2ym7mGWRpxHd6FCVZMoKl+H7U5laeDH0HlBP0cQIDkY9uyM7e X5jcqP3c/ks6TAGv7uH/C1NTen1VLVSsWzKDXWyzHi1ethPQkwcRuryoKqPIP4KUqem9 ujrg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790405434; x=1791010234; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=kwLyN45KcXkMlGV64Woz+4zZ99i3stRGQEp+uIa/oYs=; b=TzXFPTXILunEiDJKuSWOK2K9wYQTjc1awfLms6zRHnwcqXx9UKCeCNNfnTjfGpRwzl GFE5Em4uLZJE95bH6z9sXvWIXlTA6SLnek4F8DNuRXx4UCGB/Il0PVo5sDOnxvUutepJ HEdLKRzHVuUn7GBbyJpXZDsckomAju6LsvN3shySUaizNLhMF+5SgiX/5bCpLKDedWSU Hc0qbS1H74Xf3kRAS7CwhXBg6LCVVNtADaBrvB8AGAe3Y/+nttYWIhcwDfUbTa1N5fHx 0dMwXB3mcrwyuck/rgna7pH91bMQw143u4cz8y3D/XjJMJc885WeFRO5qZUPSQ9rLyGn i0Kg== X-Forwarded-Encrypted: i=1; AKwUvBxQIht5PRqfJtD0ZNzHnPObGKm0i1TftAu0OrHhRtoicCzPmAYMNaqJGBJaistLOtI5MTmXhFCwh3XBiOo=@vger.kernel.org X-Gm-Message-State: AFq9FYLFJVMdzTNsL6ypSJu7eBpXyxRC8a2FWXvSUHV3TP9DwPCttJ80 5NIZCGBr6fYi3czwgN81BaOuvgruuzCR6K1c+stTzELG/VcHFfxHKKDnVEhBy2RqUEBD X-Gm-Gg: AYBFou2UEBFwT0pi6XE49NuEQ960S8Ap8rELKpadcez0FS0WPQDbA+1Td8dNvuWJaXF SR5Ggy+ViC1I3PKeQowiMX+9DSFpjvpzQoxAuiFnhwjMMfepmOfXnyXm2aJMFgQhN+z0ATtdIhW K85b2G81Y5wnzk+1zlvVWsNSriwraQELu2JZrxj8vfwAYEZRf/tdqaCoU6CIYKlfxMctKgbS9IF xJ19INSFCFhJvU3M1LZc+CSCEsMV/Kie4cppta3NU21cTs/9hA+DBzfCnkfNHccnCfO729Sx630 /bpRsUCAnDLwjPezUIex9FxIiwFmHqyYaRRhecUyJ6NGo842kevlEX3ywFIZ1endN6i7BmVu6f6 be9sgOv2pYDPSWS3f24aKiiGLQDZVKSY9FqW3O1BekK4Knnt9vuiivzYtS8CGul+7tsd0oT+cT3 wUt+FVlZKzb2Fr4Qbs1MGERjLdtq1nxgiFfrQnTsxxohJOiI6Wo9YMI67u3XRTBNhLOXkZ+bo1d efJyVPHWJswQhAYo2vtnQqfaGLKc1E= X-Received: by 2002:a17:90b:2785:b0:39e:6795:f7da with SMTP id 98e67ed59e1d1-3a09875ee61mr7024834a91.19.1790405433480; Fri, 25 Sep 2026 23:50:33 -0700 (PDT) Received: from 954df21a5119.. ([122.51.212.64]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-3a0b498fb12sm3447327a91.0.2026.09.25.23.50.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 25 Sep 2026 23:50:32 -0700 (PDT) From: Zihan Xi To: sfrench@samba.org Cc: zihanx@nebusec.ai, pc@manguebit.org, ronniesahlberg@gmail.com, sprasad@microsoft.com, tom@talpey.com, bharathsm@microsoft.com, pshilovsky@samba.org, aaptel@suse.com, pali@kernel.org, linux-cifs@vger.kernel.org, samba-technical@lists.samba.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH v5 3/6] smb: client: close handle after create-context parsing failure Date: Sat, 26 Sep 2026 06:49:23 +0000 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" SMB2_open() accounts a successful CREATE response as a remote open before parsing its create contexts. If smb2_parse_contexts() rejects malformed context data, SMB2_open() returns without closing the handle, leaving the server-side handle open and num_remote_opens elevated. Close the handle after a post-CREATE context parsing failure so the error path releases the remote resource and balances the open count. Fixes: af1689a9b770 ("smb: client: fix potential OOBs in smb2_parse_context= s()") Cc: stable@vger.kernel.org Reported-by: Vega Assisted-by: LLM Co-developed-by: Luxing Yin Signed-off-by: Luxing Yin Signed-off-by: Zihan Xi --- changes in v5: - Rerolled the series after fixing a NULL dereference reported by the kernel test robot Smatch analysis in patch 5: https://lore.kernel.org/r/202609241449.HlHmnZFZ-lkp@intel.com/ - v4 Link: https://lore.kernel.org/all/cover.1789478666.git.zihanx@nebuse= c.ai/ changes in v4: - Keep post-CREATE cleanup for parser failures and document the existing best-effort close behavior. - v3 Link: https://lore.kernel.org/all/cover.1788516372.git.zihanx@nebuse= c.ai/ changes in v3: - Split the POSIX handler check into a separate patch and corrected the parser Fixes history. - v2 Link: https://lore.kernel.org/all/cover.1787486936.git.zihanx@nebuse= c.ai/ changes in v2: - Add cleanup after a create-context parsing failure. - v1 Link: https://lore.kernel.org/all/eb1bc35611f91bd10a4772400b37fac26f= 660956.1782579150.git.xizh2024@lzu.edu.cn/ --- fs/smb/client/smb2pdu.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/fs/smb/client/smb2pdu.c b/fs/smb/client/smb2pdu.c index 1b2ca3b2c2f87..12973f2e26b16 100644 --- a/fs/smb/client/smb2pdu.c +++ b/fs/smb/client/smb2pdu.c @@ -3414,6 +3414,9 @@ SMB2_open(const unsigned int xid, struct cifs_open_pa= rms *oparms, __le16 *path, =20 rc =3D smb2_parse_contexts(server, &rsp_iov, &oparms->fid->epoch, oparms->fid->lease_key, oplock, file_info, posix); + if (rc) + SMB2_close(xid, tcon, oparms->fid->persistent_fid, + oparms->fid->volatile_fid); =20 trace_smb3_open_done(xid, rsp->PersistentFileId, tcon->tid, ses->Suid, oparms->create_options, oparms->desired_access, --=20 2.43.0 From nobody Mon Sep 28 09:58:46 2026 Received: from mail-pz2-f39.google.com (mail-pz2-f39.google.com [74.125.228.39]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9852639B96A for ; Sat, 26 Sep 2026 06:50:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.228.39 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790405442; cv=none; b=T6+JM5d8z3YInvx7Fgzxy+/rQPMIVJYYw3rF5v1pN612yi1J83Q9VGm4X8QLfY6SwZp9Hn1Tw7kg8gM3hMcN1tUww5rzvZ2kaBT3Fgz/oq5OMNy2j0C4zSv4bwUegW+f8Kn+hqGZDBbzw9ZkhxqxSAoAlcW3f+9+zR9C0W0nbXg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790405442; c=relaxed/simple; bh=mFXrpdHur6ulVZ7FvboHg5CLmQFWfcNDbSrvMkyHvmM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=c/y5uUXJrFQT91ceyOS1EoXTS+tr1/6dnPDlfhABSCc69yID7UOCa88gW3f86KZXjZ/WdtuTyJa0CrcEy2WQJ3WVfbfzu9hEc792GY70Ly1tQ87yMB40lVqvU6OquufzEIqdURskfi801PsVFqXaleEERBi1ODaWr7b/k5U9H/8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=nebusec.ai; spf=pass smtp.mailfrom=nebusec.ai; dkim=pass (2048-bit key) header.d=nebusec.ai header.i=@nebusec.ai header.b=Ru1lt7nS; arc=none smtp.client-ip=74.125.228.39 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=nebusec.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nebusec.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nebusec.ai header.i=@nebusec.ai header.b="Ru1lt7nS" Received: by mail-pz2-f39.google.com with SMTP id 41be03b00d2f7-cc7979d1dedso350082a12.3 for ; Fri, 25 Sep 2026 23:50:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nebusec.ai; s=google; t=1790405440; x=1791010240; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=8BskrzkXLwZJX8rcZQGp1wKf7XH5Yk+fLwNViAloYy8=; b=Ru1lt7nSkiIx3L3AdhhedyAfa+NZf2ZEffPDWUYttcVnKdoYcNlHFkV34W49/4mY8O 4J5u5Jf4j5at8U2FwGMTgW5kx7dy0bOIb5AnryZz4o/E2S3QpPFC/pL6G7vJlZE+jqWW O/Czs7h4ta3xgNsPFPJsoUcLx6FdCmUVAozn9/fBhMlA/lOnVd0aykq7XXCNofTWHB8Y GZXmrKYFfcvx0U0dgPMeDmAhGpufIy+hFvbaDjwRcnd7cAaPWXgkIZUG4VwnEXZ1WFGB PRDLPIO9gYry/vhsKJcUUgtPR7veYjxE7uqycfRqbIj7R3nK3nuvR6xkOToWfeqQYXQd G7YQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790405440; x=1791010240; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=8BskrzkXLwZJX8rcZQGp1wKf7XH5Yk+fLwNViAloYy8=; b=I2PZkArgsJULWmCS09nF8lk+rgDq1fBoO24dF0tgrXCDjYfASgxxCgYeWPVenDT9Rf Ep3GJIEOMKMzHnb887ByMWQj6heNkocW4a5zHWQvZz0qS+DhV49tS1WtiPdKUab9Wd2S XHUb7sCqj0yKamS7EoCqCXARvTMwPPcPPAY7RZ8aCQHmAanzIjS04jbW+8ZAMn6bhWot i0PIclh92AsnkDxv9SvCe+KCsyuKLHJH4/JJUmxyQ6eRSsSiFnDUweD8n2AdPDrEbGz6 UbCp/0gI1EVVumGhM2UVqEXUTo/Ao902I7A6wrlaDETrRRGzHn9Fl5JmhXwQ/PEt2/Pj TVNg== X-Forwarded-Encrypted: i=1; AKwUvBylZooM+bHj7GZ8VRB0pK+bqA85MPncNCSIJt10c1Oo35Af3RPgr5dNuB/OIsZ1tuj9nXn53QxZlT/UB24=@vger.kernel.org X-Gm-Message-State: AFq9FYIh+17FI51IG1jQWRtgFtBYeBVFxghjN4boVJ7GijdHAjfQFo4/ fxDsBZLmUCcd4VfvPmKlMyKLSGGTQYwEh1tpnGDh3GVtmdO4ZKpsJ+pdtJWo5unQMKZG X-Gm-Gg: AYBFou3FKTmvfgvA0O9NT9OCPdZUtZ+UdlPwfQY4U65QpfssCPHOKHSxLusSiXYpFe6 ma9s+pFX5XbVuGNApj5l9wdPJQBwnirUoCekCBY+zdLJcVpJc3/rUYjmrSQv6arFJL23FKedyIr g0ap5T28D3r/fdTLFWXWlzbGaKZgY2p70UY8OTdJQMStTdIRgSXGaLsDmucr7/akD8Kcbeqd4Bx ungESWPRpSLUbFWf9+4HL1irQlqlSVSmPEoeSMRUBUTAzFuY1egyVsDnF+4h4/mdY8vB8LyxZsi c6Y8ACGVb1nSJcy2rwSoELfy316On/4jPCOoI7pWa3zW0sBeYVni/B9lT9WmCuMD9mZunp0hfHf OEFo00WR+1DqZ7K9c3pEhEdV/Zqe5SOSClqFKVAyYKlIHfLT6mjczh8cJ4dW30P0VWJvxfjW4tB ve6T5SrZ10V9a6FMHngzU2J+yd1EHUfWjSuWaVXiKtfT+ESJwFiASDLpZxlfFIXAZqY3U7Fvk65 G1AS60pGMOxYgwiCXCLWtt6G08tKg== X-Received: by 2002:a17:90a:d883:b0:3a0:2900:f577 with SMTP id 98e67ed59e1d1-3a098dff5b4mr6227823a91.51.1790405439780; Fri, 25 Sep 2026 23:50:39 -0700 (PDT) Received: from 954df21a5119.. ([122.51.212.64]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-3a0b498fb12sm3447327a91.0.2026.09.25.23.50.35 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 25 Sep 2026 23:50:39 -0700 (PDT) From: Zihan Xi To: sfrench@samba.org Cc: zihanx@nebusec.ai, pc@manguebit.org, ronniesahlberg@gmail.com, sprasad@microsoft.com, tom@talpey.com, bharathsm@microsoft.com, pshilovsky@samba.org, aaptel@suse.com, pali@kernel.org, linux-cifs@vger.kernel.org, samba-technical@lists.samba.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH v5 4/6] smb: client: clean up failed cached directory opens Date: Sat, 26 Sep 2026 06:49:24 +0000 Message-ID: <4f216702a1f10927e20ed5295cd1a04a895978ea.1790398755.git.zihanx@nebusec.ai> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" open_cached_dir() sends CREATE and QUERY_INFO as a compound request. If the CREATE succeeds but a later command returns an error, the function must retain the CREATE FID so common cleanup can issue SMB2_close(). It also must not treat a response error as a valid CREATE. Validate the CREATE response before using its fields, record the FIDs, and mark the handle open before handling errors from later compound commands. Move the -EREMCHG reconnect handling before response validation so a missing response does not hide the reconnect request. Count the handle when it is marked open; confirmed close responses decrement the counter, while existing close retry behavior remains best effort on transport failures. Fixes: b0f6df737a1c ("cifs: cache FILE_ALL_INFO for the shared root handle") Cc: stable@vger.kernel.org Reported-by: Vega Assisted-by: LLM Co-developed-by: Luxing Yin Signed-off-by: Luxing Yin Signed-off-by: Zihan Xi --- changes in v5: - Rerolled the series after fixing a NULL dereference reported by the kernel test robot Smatch analysis in patch 5: https://lore.kernel.org/r/202609241449.HlHmnZFZ-lkp@intel.com/ - v4 Link: https://lore.kernel.org/all/cover.1789478666.git.zihanx@nebuse= c.ai/ changes in v4: - Validate CREATE status and FIDs before marking the cached-directory han= dle open, preserve reconnect handling, and balance cleanup accounting. - Keep the cached-directory Fixes attribution at b0f6df737a1c. - v3 Link: https://lore.kernel.org/all/cover.1788516372.git.zihanx@nebuse= c.ai/ changes in v3: - Split the POSIX handler check into a separate patch and corrected the parser Fixes history. - v2 Link: https://lore.kernel.org/all/cover.1787486936.git.zihanx@nebuse= c.ai/ changes in v2: - Add cached-directory cleanup for failed compound opens. - v1 Link: https://lore.kernel.org/all/eb1bc35611f91bd10a4772400b37fac26f= 660956.1782579150.git.xizh2024@lzu.edu.cn/ --- fs/smb/client/cached_dir.c | 32 ++++++++++++++++++++++---------- 1 file changed, 22 insertions(+), 10 deletions(-) diff --git a/fs/smb/client/cached_dir.c b/fs/smb/client/cached_dir.c index 88d5e9a32f28b..647fa26da4d24 100644 --- a/fs/smb/client/cached_dir.c +++ b/fs/smb/client/cached_dir.c @@ -8,6 +8,7 @@ #include #include "cifsglob.h" #include "cifsproto.h" +#include "../common/smb2status.h" #include "cifs_debug.h" #include "smb2proto.h" #include "cached_dir.h" @@ -323,25 +324,37 @@ int open_cached_dir(unsigned int xid, struct cifs_tco= n *tcon, rc =3D compound_send_recv(xid, ses, server, flags, 2, rqst, resp_buftype, rsp_iov); - if (rc) { - if (rc =3D=3D -EREMCHG) { - tcon->need_reconnect =3D true; - pr_warn_once("server share %s deleted\n", - tcon->tree_name); - } - goto oshr_free; + if (rc =3D=3D -EREMCHG) { + tcon->need_reconnect =3D true; + pr_warn_once("server share %s deleted\n", + tcon->tree_name); } - cfid->is_open =3D true; =20 - spin_lock(&cfids->cfid_list_lock); + if (!rsp_iov[0].iov_base || rsp_iov[0].iov_len < sizeof(*o_rsp)) { + if (!rc) + rc =3D -EIO; + goto oshr_free; + } =20 o_rsp =3D (struct smb2_create_rsp *)rsp_iov[0].iov_base; + if (o_rsp->hdr.Status !=3D STATUS_SUCCESS) { + if (!rc) + rc =3D -EIO; + goto oshr_free; + } + oparms.fid->persistent_fid =3D o_rsp->PersistentFileId; oparms.fid->volatile_fid =3D o_rsp->VolatileFileId; #ifdef CONFIG_CIFS_DEBUG2 oparms.fid->mid =3D le64_to_cpu(o_rsp->hdr.MessageId); #endif /* CIFS_DEBUG2 */ + cfid->is_open =3D true; + atomic_inc(&tcon->num_remote_opens); =20 + if (rc) + goto oshr_free; + + spin_lock(&cfids->cfid_list_lock); =20 if (o_rsp->OplockLevel !=3D SMB2_OPLOCK_LEVEL_LEASE) { spin_unlock(&cfids->cfid_list_lock); @@ -408,7 +421,6 @@ int open_cached_dir(unsigned int xid, struct cifs_tcon = *tcon, close_cached_dir(cfid); } else { *ret_cfid =3D cfid; - atomic_inc(&tcon->num_remote_opens); } kfree(utf16_path); =20 --=20 2.43.0 From nobody Mon Sep 28 09:58:46 2026 Received: from mail-pj2-f41.google.com (mail-pj2-f41.google.com [74.125.227.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A6B0A35A3B1 for ; Sat, 26 Sep 2026 06:50:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.227.169 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790405455; cv=none; b=PHakkNjAzsvq1jvrf1+qe9cDAx+r+iONsyjqgxyiTpGvehVx/9qb24SDtwQntVbxAw3XJQrtYL4d0IfGdoT97n9MNo7uMG60Izga/sQR/+RN7Ocl1JXHcxx8yX7Ll+0OVlbM3IRnxbFLjPA0JNdnKbuxkkwAVYZtMQcmVY2pvok= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790405455; c=relaxed/simple; bh=4dw3Vn9U7kC/yYdw7vp4OAyyRVg5Qnl8bPeOdcmMP6g=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Q+WI6en7dsTjV64tZzqsoy44V87yrwohJMSf5cQQslRVwyu7nb/SwlwoQB2kz5AZOgi6c4osumXUFEZGOOIKeV6Bwc2mNuwx9jo5UgYJWkpdwU4ZMN2ednfNrKcT9Du3Xk0etqVY/XYBPjivPyZvySnfxnOhsIbWffvgqtlLiaQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=nebusec.ai; spf=pass smtp.mailfrom=nebusec.ai; dkim=pass (2048-bit key) header.d=nebusec.ai header.i=@nebusec.ai header.b=EMs0K/lq; arc=none smtp.client-ip=74.125.227.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=nebusec.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nebusec.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nebusec.ai header.i=@nebusec.ai header.b="EMs0K/lq" Received: by mail-pj2-f41.google.com with SMTP id 98e67ed59e1d1-3a0bd71827eso766293a91.0 for ; Fri, 25 Sep 2026 23:50:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nebusec.ai; s=google; t=1790405452; x=1791010252; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=jwgdT7ZCFoFOSetRLVJnhfziX7YK8CC74lAbtlGrzR0=; b=EMs0K/lqoHRPxmJBxSRQcoCB1BP0YiC42G2C+0XUXznh9rQ7H9vfOdVtC/Ow62J+E9 aqkZGqOCEEaT7AkfjWvJlsOsD2UDnM/tUCEHhozgUz8ywCGTSBLY49Oe0KEyBPKh83Wg rxXNs996KzliQwhhG6FRx3Gd7TS9sHuuPCI9ETIrIwg5/eVAcpjn/FVZWXQJyR03Ggky O5SioZITGGGNKXaqCec0Ojw18Lzb6sRin6Y2JlAsSdnmUHrIu61lyrqALAlCMAo3YBj+ vO/KEUgeb2pTMlaTCcJ2ztGdT9oTh9zbv1sooVesB+Pz1Eg4x0KCXek/xKZiMmSjiWvU bbJQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790405452; x=1791010252; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=jwgdT7ZCFoFOSetRLVJnhfziX7YK8CC74lAbtlGrzR0=; b=YOgZ9rVnfk/oSEafFOYF8ghslh+cQk/Zp+7uTm6WnRSYMVNxgavP0L6OwlFU5WiQ5D pdk2sgwFBMNNna3uTwjmPexg07BUm5xgpLVqu4tErHhKJbSCTb32ko3M9FRRmqNz2GyS VpxbSgsBomx2W3650BWkQwvUh5I0DkGRHYeStq7MYAY97XCoRlPyi8y7L4wWv6N5y1Hy ZuU7c3j3g/R1OW68tBuIlNmPiPKin9Cb5YENd5VqZA6UNqAANHMiL2TMauygswFEgBGT CJvJBJZcwYIRvZI/4xfsMGJQzThfZOlWKn4UxV/VYLbC8e0erknvBkiq+vlfThAy+xeu 9nfQ== X-Forwarded-Encrypted: i=1; AKwUvBxuvka35tOcUfvqlKMsw6IVcszvETEqQ17chlCZuC09uvUa8l3VVuoHUq7cf4bRo0yARhemaFX4J5xzGQM=@vger.kernel.org X-Gm-Message-State: AFq9FYJA0pt8/KmbotpxgzpyOICK74FvT6tfif+fCMsU7r0bVy3ED0oY 1lhDuG3OCvFPqR9xTG4whpG5H01rbeNVrxJZHiLWYNWLtdi/141+OzXQAlN0JgkBbmva X-Gm-Gg: AYBFou2BlSOkKeJvF7z1GGr6DyS/J32Vg1p+2x9G3Vkc4US6lqFZFjkQIuDWqpCXrGL TNiKW/a8DD92m9Wgpa3irtNT/NJfCCKYfJlUXDV4dc9HiwxYhBki/v3PqaIEkUJuP+bb7pWk54k /K3f6ovdwPEju1LQ198WSLJTKoWT+qROLpiCWv69XkpjsOrIfpHZdgFz5eWs4k7heuNinnmzmEQ ffdFvmlL5PN4xcPLnDFvcs0JbOiMpF6b654uNPEnWhc9RN8p2aSV448hUzN6hnXuMFzo+vZp646 D/jW3F78eXRGgbEDdJ9tHezQF0oJrQDO3tmDj7+pseIAX+csnsTbJNBlCdadWGAV6Qpm5YHygGk a5b+vUnBtRMXeEnUY68ea8qACctuCLni53xQh5HZg19VKODVRPAe9J94X+Uw7KMnGdWuLXm4Zoa HhTFNUvhFrBHPdNeurGUPHV5Oegn5Z6GxqOM90RsCFTQqFj1dGZzLVa3iXexc3UujALfHLXKdeI 1ctURWtxUYutFpfqqRXBqrAvxqvyff2x+FeJHcU X-Received: by 2002:a17:90b:2e84:b0:3a0:d79d:b6b8 with SMTP id 98e67ed59e1d1-3a0d79db771mr1532843a91.32.1790405451883; Fri, 25 Sep 2026 23:50:51 -0700 (PDT) Received: from 954df21a5119.. ([122.51.212.64]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-3a0b498fb12sm3447327a91.0.2026.09.25.23.50.46 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 25 Sep 2026 23:50:51 -0700 (PDT) From: Zihan Xi To: sfrench@samba.org Cc: zihanx@nebusec.ai, pc@manguebit.org, ronniesahlberg@gmail.com, sprasad@microsoft.com, tom@talpey.com, bharathsm@microsoft.com, pshilovsky@samba.org, aaptel@suse.com, pali@kernel.org, linux-cifs@vger.kernel.org, samba-technical@lists.samba.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH v5 5/6] smb: client: close completed creates on compound wait errors Date: Sat, 26 Sep 2026 06:49:25 +0000 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" compound_send_recv() waits for responses in order. If a later wait is interrupted, or if a later MID fails during response synchronization, an earlier CREATE may already have opened a remote handle. The earlier mid is then released without invoking handle_cancelled_mid(), leaving the remote handle open because no FID was copied to the caller. Mark completed earlier mids as cancelled when a compound wait or MID synchronization aborts. Keep their response buffers attached while the MIDs are synchronized, and transfer them only after synchronization of the processed responses, so the release path can inspect successful CREATE responses and queue SMB2_close() after a later failure. Account for a remote open only after the close work is allocated and before it is queued, since the caller has not yet updated num_remote_opens. Mark the create+close compound used by smb2_unlink() so it is not closed again. Non-CREATE responses and compounds that already include a close keep their existing behavior. Fixes: e0bba0b85481 ("cifs: add compound_send_recv()") Cc: stable@vger.kernel.org Reported-by: Vega Assisted-by: LLM Co-developed-by: Luxing Yin Signed-off-by: Luxing Yin Signed-off-by: Zihan Xi --- changes in v5: - Guard the final preauth-hash update when resp_iov is NULL, fixing the NULL dereference reported by the kernel test robot Smatch analysis: https://lore.kernel.org/r/202609241449.HlHmnZFZ-lkp@intel.com/ - v4 Link: https://lore.kernel.org/all/cover.1789478666.git.zihanx@nebuse= c.ai/ changes in v4: - Keep response buffers attached while MIDs are synchronized so a later MID failure can trigger cancelled-mid cleanup for earlier CREATEs. - Cover MID synchronization and unready-state failures, and defer num_remote_opens accounting until close work allocation succeeds. - Mark smb2_unlink()'s create+close compound to avoid duplicate cleanup. - Correct the Fixes tag to e0bba0b85481. - v3 Link: https://lore.kernel.org/all/cover.1788516372.git.zihanx@nebuse= c.ai/ changes in v3: - Add cleanup for completed CREATEs when a compound wait is interrupted. - v2 Link: https://lore.kernel.org/all/cover.1787486936.git.zihanx@nebuse= c.ai/ changes in v2: - No counterpart in v2. - v1 Link: https://lore.kernel.org/all/eb1bc35611f91bd10a4772400b37fac26f= 660956.1782579150.git.xizh2024@lzu.edu.cn/ --- fs/smb/client/smb2inode.c | 2 +- fs/smb/client/smb2misc.c | 9 ++++-- fs/smb/client/transport.c | 67 +++++++++++++++++++++++++++++++-------- 3 files changed, 61 insertions(+), 17 deletions(-) diff --git a/fs/smb/client/smb2inode.c b/fs/smb/client/smb2inode.c index 213bc298cdf22..6971496dfe8c2 100644 --- a/fs/smb/client/smb2inode.c +++ b/fs/smb/client/smb2inode.c @@ -1104,7 +1104,7 @@ smb2_unlink(const unsigned int xid, struct cifs_tcon = *tcon, const char *name, struct kvec close_iov; int resp_buftype[2]; struct cifs_fid fid; - int flags =3D 0; + int flags =3D CIFS_CP_CREATE_CLOSE_OP; __u8 oplock; int rc; =20 diff --git a/fs/smb/client/smb2misc.c b/fs/smb/client/smb2misc.c index 9068175e57cd0..596388acb31e7 100644 --- a/fs/smb/client/smb2misc.c +++ b/fs/smb/client/smb2misc.c @@ -821,7 +821,8 @@ smb2_cancelled_close_fid(struct work_struct *work) */ static int __smb2_handle_cancelled_cmd(struct cifs_tcon *tcon, __u16 cmd, __u64 mid, - __u64 persistent_fid, __u64 volatile_fid) + __u64 persistent_fid, __u64 volatile_fid, + bool account_remote_open) { struct close_cancelled_open *cancelled; =20 @@ -835,6 +836,8 @@ __smb2_handle_cancelled_cmd(struct cifs_tcon *tcon, __u= 16 cmd, __u64 mid, cancelled->cmd =3D cmd; cancelled->mid =3D mid; INIT_WORK(&cancelled->work, smb2_cancelled_close_fid); + if (account_remote_open) + atomic_inc(&tcon->num_remote_opens); WARN_ON(queue_work(cifsiod_wq, &cancelled->work) =3D=3D false); =20 return 0; @@ -871,7 +874,7 @@ smb2_handle_cancelled_close(struct cifs_tcon *tcon, __u= 64 persistent_fid, spin_unlock(&tcon->tc_lock); =20 rc =3D __smb2_handle_cancelled_cmd(tcon, SMB2_CLOSE_HE, 0, - persistent_fid, volatile_fid); + persistent_fid, volatile_fid, false); if (rc) cifs_put_tcon(tcon, netfs_trace_tcon_ref_put_cancelled_close); =20 @@ -899,7 +902,7 @@ smb2_handle_cancelled_mid(struct mid_q_entry *mid, stru= ct TCP_Server_Info *serve le16_to_cpu(hdr->Command), le64_to_cpu(hdr->MessageId), rsp->PersistentFileId, - rsp->VolatileFileId); + rsp->VolatileFileId, true); if (rc) cifs_put_tcon(tcon, netfs_trace_tcon_ref_put_cancelled_mid); =20 diff --git a/fs/smb/client/transport.c b/fs/smb/client/transport.c index fdf4e50c27ceb..6d25ee126f744 100644 --- a/fs/smb/client/transport.c +++ b/fs/smb/client/transport.c @@ -806,6 +806,18 @@ cifs_cancelled_callback(struct TCP_Server_Info *server= , struct mid_q_entry *mid) release_mid(server, mid); } =20 +static void +cifs_mark_compound_mids_cancelled(struct mid_q_entry **mid, int count) +{ + int i; + + for (i =3D 0; i < count; i++) { + spin_lock(&mid[i]->mid_lock); + mid[i]->wait_cancelled =3D true; + spin_unlock(&mid[i]->mid_lock); + } +} + /* * cifs_pick_channel - pick an eligible channel for network operations * @@ -866,6 +878,7 @@ compound_send_recv(const unsigned int xid, struct cifs_= ses *ses, int *resp_buf_type, struct kvec *resp_iov) { int i, j, optype, rc =3D 0; + int num_processed =3D 0; struct mid_q_entry *mid[MAX_COMPOUND]; bool cancelled_mid[MAX_COMPOUND] =3D {false}; struct cifs_credits credits[MAX_COMPOUND] =3D { @@ -1012,6 +1025,14 @@ compound_send_recv(const unsigned int xid, struct ci= fs_ses *ses, break; } if (rc !=3D 0) { + /* + * A completed CREATE earlier in the compound chain may have + * opened a remote handle even though a later wait was + * interrupted. Mark it cancelled so __release_mid() invokes + * the existing unmatched-open cleanup. + */ + cifs_mark_compound_mids_cancelled(mid, i); + for (; i < num_rqst; i++) { cifs_server_dbg(FYI, "Cancelling wait for mid %llu cmd: %d\n", mid[i]->mid, le16_to_cpu(mid[i]->command)); @@ -1034,6 +1055,14 @@ compound_send_recv(const unsigned int xid, struct ci= fs_ses *ses, =20 rc =3D cifs_sync_mid_result(mid[i], server); if (rc !=3D 0) { + /* + * A previous CREATE may have completed before this + * response failed. Mark it cancelled so its remote + * handle is closed when the mid is released. + */ + cifs_mark_compound_mids_cancelled(mid, i); + /* Keep their response buffers for cancelled-mid cleanup. */ + num_processed =3D 0; /* mark this mid as cancelled to not free it below */ cancelled_mid[i] =3D true; goto out; @@ -1043,13 +1072,24 @@ compound_send_recv(const unsigned int xid, struct c= ifs_ses *ses, mid[i]->mid_state !=3D MID_RESPONSE_READY) { rc =3D smb_EIO1(smb_eio_trace_rx_mid_unready, mid[i]->mid_state); cifs_dbg(FYI, "Bad MID state?\n"); + cifs_mark_compound_mids_cancelled(mid, i); + num_processed =3D 0; goto out; } =20 rc =3D server->ops->check_receive(mid[i], server, flags & CIFS_LOG_ERROR); + num_processed =3D i + 1; + } =20 - if (resp_iov) { +out: + /* + * Delay moving response buffers out of their mids until response + * synchronization completes. This lets cancelled-mid cleanup inspect + * an earlier CREATE response if a later MID fails. + */ + if (resp_iov) { + for (i =3D 0; i < num_processed; i++) { buf =3D (char *)mid[i]->resp_buf; resp_iov[i].iov_base =3D buf; resp_iov[i].iov_len =3D mid[i]->resp_buf_size; @@ -1068,21 +1108,22 @@ compound_send_recv(const unsigned int xid, struct c= ifs_ses *ses, /* * Compounding is never used during session establish. */ - spin_lock(&ses->ses_lock); - if ((ses->ses_status =3D=3D SES_NEW) || (optype & CIFS_NEG_OP) || (optype= & CIFS_SESS_OP)) { - struct kvec iov =3D { - .iov_base =3D resp_iov[0].iov_base, - .iov_len =3D resp_iov[0].iov_len - }; - spin_unlock(&ses->ses_lock); - cifs_server_lock(server); - smb311_update_preauth_hash(ses, server, &iov, 1); - cifs_server_unlock(server); + if (num_processed =3D=3D num_rqst && resp_iov) { spin_lock(&ses->ses_lock); + if ((ses->ses_status =3D=3D SES_NEW) || (optype & CIFS_NEG_OP) || (optyp= e & CIFS_SESS_OP)) { + struct kvec iov =3D { + .iov_base =3D resp_iov[0].iov_base, + .iov_len =3D resp_iov[0].iov_len + }; + spin_unlock(&ses->ses_lock); + cifs_server_lock(server); + smb311_update_preauth_hash(ses, server, &iov, 1); + cifs_server_unlock(server); + spin_lock(&ses->ses_lock); + } + spin_unlock(&ses->ses_lock); } - spin_unlock(&ses->ses_lock); =20 -out: /* * This will dequeue all mids. After this it is important that the * demultiplex_thread will not process any of these mids any further. --=20 2.43.0 From nobody Mon Sep 28 09:58:46 2026 Received: from mail-pj2-f43.google.com (mail-pj2-f43.google.com [74.125.227.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8A320331EB5 for ; Sat, 26 Sep 2026 06:51:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.227.171 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790405461; cv=none; b=K6rIpQEBTEOaK/wuTNCo5TnBhbAT1HjfxexQV6jntkRSK3ZFdZ63H2jOJVHeY30eriMiwc1xy03jRq+OOO+j592v4tdiE994YqiXY3GA1M7w36d+awIcRxjfNcpfnMyKu1dNUwb3yELeLWb+TCEXdIl8iLZ8t2UOkM89A6nuExo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790405461; c=relaxed/simple; bh=JV+17s1GlPD3D2eJMRcu0HMLhAqdoXENHWYjZ9jS8EU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=NXSJ1migbN74nT3qhCS41lDsVoJCYAzUfmrE5uvks8/TwtCRY23wffz6KoFhaDkhegmS8ZsWsVJgTY3Ql6Cp7PgTt3TSbTqeexnXP1yv/xUDP/eVOMAO1UO04EufuTKDQsF5sPLwMyWm7HthoEEbzrUS8tUw2ka8uFbaKnfn3Hw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=nebusec.ai; spf=pass smtp.mailfrom=nebusec.ai; dkim=pass (2048-bit key) header.d=nebusec.ai header.i=@nebusec.ai header.b=mpC6hBfH; arc=none smtp.client-ip=74.125.227.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=nebusec.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nebusec.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nebusec.ai header.i=@nebusec.ai header.b="mpC6hBfH" Received: by mail-pj2-f43.google.com with SMTP id 98e67ed59e1d1-3a0b0fa2055so932579a91.0 for ; Fri, 25 Sep 2026 23:51:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nebusec.ai; s=google; t=1790405460; x=1791010260; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=rxWlpEawRxbGdbb7uamGxHpnCZdOPTti2on2yW0rLRM=; b=mpC6hBfHoXLcLvr03Sj9oiz5ufxcJtyL5GSBzXBecfOE9kH+g9Q4011FYfJ8NPR/cz SzR9TTuajhs0lAZp/nSSymx4EUkVAIqPqX61+PIQ3Gc+3NWcJ/V1T+NjMmy2eOpCB218 /fggIyQVgySPduwDcNpz9QmsDH5bfszbJHGLkWenTUJBv0y5AGSDW8trMnBu6r4C9r/g FziVGC4NIv1xIMiwhWHj4SoOGyLquek/xIlJOCjkUBlzVPAB+Y/bEWxTJpxXJbKbcPhM FyfU/HlgPIALpMTxKwQJbciLWPJq/DJyXnXPNUQybMPg0na7hoRKscVZUrMy52UPGkLS Ct+w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790405460; x=1791010260; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=rxWlpEawRxbGdbb7uamGxHpnCZdOPTti2on2yW0rLRM=; b=wKM8JU26Ep+uQwYg/m+9cjslTriBJz/vbGNOQawFBoSG+o6SLBsm6lms0oKlR9s5wR PIfG4pv9R1hmw1ZMbp0e7laLD7xOQ3WdIrNjVZhqED6mMTVLZRXaS1beTbNwOOcCXcEQ 2ULgjSij7mj8OIX+qOZ/7ieD17v7nQbUAgKAb1f9HpJVpJfGbTQgJWQPEFbY0f7iHFX/ AqBYMXa4aLnR9bO1dYh17+IUjP0uG3OYS/tpqg6rVwX242sR62lVIFiUCpPUGjgbVarU z1WgoDFL2VBcDYc5DI9oQOJ/QLfFoR89+mXKCgO5TZdwLMmkd7KAd4/fGP5OrWfwW6FH acEQ== X-Forwarded-Encrypted: i=1; AKwUvBzl8KWVlqPaUd/hI498T+ut96CU/ShuQEV/71tsqDzU8Wh9xkyp+1v2XRs8jHYYRP9ntdtgZ0ms1M393m8=@vger.kernel.org X-Gm-Message-State: AFq9FYI/d5dSAlalNqA7F9ESXXkC3glVbJTk1tmOa+izCbRfvc/GM2iO //Y5PbUOPQVVzWMGPVStsITplv2JNdqWlQf9/OC4Tj055yiQzHs+QAH2kGVqeV1sg2Xo X-Gm-Gg: AYBFou0vp5vXWl2s6brNhyQJKDdEKJYbbvx+SBvTq/CLK7oJIC8r8gst/hmGq222Y1d ivUha9+4qNPhsDLwJc1hedvlynkiwX0h0sTkWS51EwgT30DOnWHvf+A0WjEPipNQ+4OFfq5IHiw HyjeC1epzKdnvWbyet7bZe63kdO1J1hCQMuuZZ5CubVxcsVCFBTOkuOUGYIXYKA/Ram+SQWRiEO zO2U5QnkmI3+NCvw41KRWWAFvGdiVVnJpAgLqaJjEpXC1QL7CJbUDc/Xq4vPiESVyyBF2idK8n1 hK9gpINP/vJBMP0oYDGw0ej4Pxf8fFXxCnqduHPxtEUaFru6ZTNHxYOaOPHvvxM76x/ZhWTEBnw ClZhQxoUVjLjCu87958pt77jWJjTH/ktuRzJMr2oZA5Lp+IYJqSGp+9uD75kZ2DvTYOcIR9OUVc FRv1zuQcuY/C0vlTt+nodTj0k4wcF0X7WlAfKnqwM/J+2igrdCNkYG3q7eNHCfi1m+VOlPwrOE/ S1et+RlpDufbQRUaOO0NzRrlCpReA== X-Received: by 2002:a17:90b:224b:b0:39e:6a81:f34f with SMTP id 98e67ed59e1d1-3a098bb63femr6356045a91.41.1790405459792; Fri, 25 Sep 2026 23:50:59 -0700 (PDT) Received: from 954df21a5119.. ([122.51.212.64]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-3a0b498fb12sm3447327a91.0.2026.09.25.23.50.53 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 25 Sep 2026 23:50:59 -0700 (PDT) From: Zihan Xi To: sfrench@samba.org Cc: zihanx@nebusec.ai, pc@manguebit.org, ronniesahlberg@gmail.com, sprasad@microsoft.com, tom@talpey.com, bharathsm@microsoft.com, pshilovsky@samba.org, aaptel@suse.com, pali@kernel.org, linux-cifs@vger.kernel.org, samba-technical@lists.samba.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH v5 6/6] smb: client: preserve create-context parsing errors Date: Sat, 26 Sep 2026 06:49:26 +0000 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" smb2_compound_op() saves the result from compound_send_recv() in tmp_rc. For SMB2_OP_OPEN_QUERY it then parses the CREATE contexts, but the final assignment of rc from tmp_rc discards a parsing error. A malformed create-context response can therefore be reported as successful to smb2_query_path_info(). Keep a create-context parsing error in tmp_rc so it survives per-command response processing and is returned to the caller. Fixes: b07687edee99 ("cifs: Improve SMB2+ stat() to work also without FILE_= READ_ATTRIBUTES") Cc: stable@vger.kernel.org Reported-by: Vega Assisted-by: LLM Co-developed-by: Luxing Yin Signed-off-by: Luxing Yin Signed-off-by: Zihan Xi --- changes in v5: - Rerolled the series after fixing a NULL dereference reported by the kernel test robot Smatch analysis in patch 5: https://lore.kernel.org/r/202609241449.HlHmnZFZ-lkp@intel.com/ - v4 Link: https://lore.kernel.org/all/cover.1789478666.git.zihanx@nebuse= c.ai/ changes in v4: - Keep a create-context parsing error in tmp_rc while processing later compound responses. - v3 Link: https://lore.kernel.org/all/cover.1788516372.git.zihanx@nebuse= c.ai/ changes in v3: - No counterpart; this patch is added in the v4 reroll. - v2 Link: https://lore.kernel.org/all/cover.1787486936.git.zihanx@nebuse= c.ai/ changes in v2: - No counterpart in v2. - v1 Link: https://lore.kernel.org/all/eb1bc35611f91bd10a4772400b37fac26f= 660956.1782579150.git.xizh2024@lzu.edu.cn/ --- fs/smb/client/smb2inode.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/fs/smb/client/smb2inode.c b/fs/smb/client/smb2inode.c index 6971496dfe8c2..cedad9daeb220 100644 --- a/fs/smb/client/smb2inode.c +++ b/fs/smb/client/smb2inode.c @@ -582,8 +582,10 @@ static int smb2_compound_op(const unsigned int xid, st= ruct cifs_tcon *tcon, /* smb2_parse_contexts() fills idata->fi.IndexNumber */ rc =3D smb2_parse_contexts(server, &rsp_iov[0], &oparms->fid->epoch, oparms->fid->lease_key, &oplock, &idata->fi, NULL); - if (rc) + if (rc) { cifs_dbg(VFS, "rc: %d parsing context of compound op\n", rc); + tmp_rc =3D rc; + } } =20 for (i =3D 0; i < num_cmds; i++) { --=20 2.43.0