From: nanx95726@gmail.com
To: smfrench@gmail.com, linkinjeon@kernel.org, tom@talpey.com,
senozhatsky@chromium.org, chenxiaosong@kylinos.cn
Cc: linux-cifs@vger.kernel.org, Hang Nan <nanx95726@gmail.com>
Subject: [PATCH v4 3/3] ksmbd: test maximal-access DACL walk boundary
Date: Wed, 19 Aug 2026 11:30:13 +0800 [thread overview]
Message-ID: <20260819033013.46824-4-nanx95726@gmail.com> (raw)
In-Reply-To: <20260819033013.46824-1-nanx95726@gmail.com>
From: Hang Nan <nanx95726@gmail.com>
Add a maximal-access variant of the smb_check_perm_dacl() boundary
test. The in-boundary ACE grants read access, while a trailing ACE
beyond the declared DACL size grants write access.
Verify that maximal-access calculation includes the in-boundary
permission and ignores the trailing permission.
Suggested-by: ChenXiaoSong <chenxiaosong@kylinos.cn>
Signed-off-by: Hang Nan <nanx95726@gmail.com>
Reviewed-by: ChenXiaoSong <chenxiaosong@kylinos.cn>
---
fs/smb/server/tests/smbacl_kunit.c | 47 ++++++++++++++++++++++++++++--
1 file changed, 44 insertions(+), 3 deletions(-)
diff --git a/fs/smb/server/tests/smbacl_kunit.c b/fs/smb/server/tests/smbacl_kunit.c
index 391b1f5d181c..33496b4d31a3 100644
--- a/fs/smb/server/tests/smbacl_kunit.c
+++ b/fs/smb/server/tests/smbacl_kunit.c
@@ -12,10 +12,11 @@
* sits beyond struct smb_acl::size; stopping at the declared DACL
* size (the fixed behaviour) rejects it.
*
- * - ksmbd_smb_check_perm_dacl_boundary: drives the real
+ * - ksmbd_smb_check_perm_dacl_boundary and
+ * ksmbd_smb_check_perm_dacl_maximal_boundary: drive the real
* smb_check_perm_dacl() with a descriptor stored through ksmbd's own
- * NTACL xattr path on a tmpfs file, and asserts that a post-boundary
- * ACE is not selected for a regular access check.
+ * NTACL xattr path on a tmpfs file, and assert that a post-boundary
+ * ACE is not selected for either a regular or maximal access check.
*/
#include <kunit/test.h>
@@ -242,9 +243,49 @@ static void ksmbd_smb_check_perm_dacl_boundary_test(struct kunit *test)
fput(file);
}
+static void
+ksmbd_smb_check_perm_dacl_maximal_boundary_test(struct kunit *test)
+{
+ struct file *file;
+ struct smb_ntsd *pntsd;
+ __le32 daccess = FILE_MAXIMAL_ACCESS_LE;
+ int ntsd_size, rc;
+
+ /*
+ * The in-boundary ACE grants read access. The trailing ACE grants
+ * write access, which must not be included in the maximal access mask.
+ */
+ pntsd = build_boundary_ntsd(test, &test_owner_sid, FILE_READ_DATA,
+ FILE_WRITE_DATA, &ntsd_size);
+ KUNIT_ASSERT_NOT_NULL(test, pntsd);
+
+ file = shmem_file_setup("ksmbd-kunit-dacl-maximal", 0,
+ mk_vma_flags(VMA_NORESERVE_BIT));
+ KUNIT_ASSERT_NOT_ERR_OR_NULL(test, file);
+
+ rc = ksmbd_vfs_set_sd_xattr(NULL, mnt_idmap(file->f_path.mnt),
+ &file->f_path, pntsd, ntsd_size,
+ false);
+ KUNIT_EXPECT_EQ(test, 0, rc);
+ if (rc)
+ goto out;
+
+ rc = smb_check_perm_dacl(NULL, &file->f_path, &daccess,
+ FILE_MAXIMAL_ACCESS_LE, 0, false);
+ KUNIT_EXPECT_EQ(test, 0, rc);
+ if (rc)
+ goto out;
+
+ KUNIT_EXPECT_TRUE(test, le32_to_cpu(daccess) & FILE_READ_DATA);
+ KUNIT_EXPECT_FALSE(test, le32_to_cpu(daccess) & FILE_WRITE_DATA);
+out:
+ fput(file);
+}
+
static struct kunit_case ksmbd_smbacl_test_cases[] = {
KUNIT_CASE(ksmbd_dacl_walk_must_stop_at_declared_size),
KUNIT_CASE(ksmbd_smb_check_perm_dacl_boundary_test),
+ KUNIT_CASE(ksmbd_smb_check_perm_dacl_maximal_boundary_test),
{}
};
--
2.55.0
next prev parent reply other threads:[~2026-08-19 3:31 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-19 3:30 [PATCH v4 0/3] ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size nanx95726
2026-08-19 3:30 ` [PATCH v4 1/3] ksmbd: add KUnit test for the DACL walk boundary nanx95726
2026-08-19 3:30 ` [PATCH v4 2/3] ksmbd: test smb_check_perm_dacl() " nanx95726
2026-08-19 3:30 ` nanx95726 [this message]
2026-08-20 0:45 ` [PATCH v4 0/3] ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size Namjae Jeon
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260819033013.46824-4-nanx95726@gmail.com \
--to=nanx95726@gmail.com \
--cc=chenxiaosong@kylinos.cn \
--cc=linkinjeon@kernel.org \
--cc=linux-cifs@vger.kernel.org \
--cc=senozhatsky@chromium.org \
--cc=smfrench@gmail.com \
--cc=tom@talpey.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.