* [PATCH 2/3] ksmbd: fix partial normalized name responses
@ 2026-09-13 11:35 Namjae Jeon
2026-09-13 15:45 ` ChenXiaoSong
2026-09-14 2:38 ` ChenXiaoSong
0 siblings, 2 replies; 8+ messages in thread
From: Namjae Jeon @ 2026-09-13 11:35 UTC (permalink / raw)
To: linux-cifs
Cc: senozhatsky, tom, atteh.mailbox, chenxiaosong, chenxiaosong,
Namjae Jeon, Mobin Aydinfar
Windows may request FILE_NORMALIZED_NAME_INFORMATION with an output
buffer that only fits the fixed portion of the variable-length response.
Treat the fixed portion as FILE_ALTERNATE_NAME_INFORMATION_SIZE so ksmbd
returns STATUS_BUFFER_OVERFLOW instead of STATUS_INFO_LENGTH_MISMATCH.
This avoids rejecting valid partial normalized-name responses.
Fixes: 6b8b79226bc3 ("ksmbd: fix partial file information responses")
Reported-by: Mobin Aydinfar <mobin@mobintestserver.ir>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
---
fs/smb/server/smb2pdu.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index f4d96799e1d2..38cddbf3e6ed 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -7318,6 +7318,9 @@ static int smb2_get_info_file(struct ksmbd_work *work,
case FILE_ALTERNATE_NAME_INFORMATION:
fixed_len = FILE_ALTERNATE_NAME_INFORMATION_SIZE;
break;
+ case FILE_NORMALIZED_NAME_INFORMATION:
+ fixed_len = FILE_ALTERNATE_NAME_INFORMATION_SIZE;
+ break;
case FILE_STREAM_INFORMATION:
fixed_len = FILE_STREAM_INFORMATION_SIZE;
break;
--
2.25.1
^ permalink raw reply related [flat|nested] 8+ messages in thread* Re: [PATCH 2/3] ksmbd: fix partial normalized name responses
2026-09-13 11:35 [PATCH 2/3] ksmbd: fix partial normalized name responses Namjae Jeon
@ 2026-09-13 15:45 ` ChenXiaoSong
2026-09-14 1:18 ` Namjae Jeon
2026-09-14 2:38 ` ChenXiaoSong
1 sibling, 1 reply; 8+ messages in thread
From: ChenXiaoSong @ 2026-09-13 15:45 UTC (permalink / raw)
To: Namjae Jeon
Cc: senozhatsky, tom, atteh.mailbox, chenxiaosong, Mobin Aydinfar,
linux-cifs
Should we define a new macro FILE_NORMALIZED_NAME_INFORMATION_SIZE?
On 9/13/2026 7:35 PM, Namjae Jeon wrote:
> + case FILE_NORMALIZED_NAME_INFORMATION:
> + fixed_len = FILE_ALTERNATE_NAME_INFORMATION_SIZE;
--
ChenXiaoSong <chenxiaosong@chenxiaosong.com>
Chinese Homepage: https://chenxiaosong.com
English Homepage: https://chenxiaosong.com/en
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH 2/3] ksmbd: fix partial normalized name responses
2026-09-13 11:35 [PATCH 2/3] ksmbd: fix partial normalized name responses Namjae Jeon
2026-09-13 15:45 ` ChenXiaoSong
@ 2026-09-14 2:38 ` ChenXiaoSong
2026-09-14 2:52 ` ChenXiaoSong
2026-09-14 3:38 ` Namjae Jeon
1 sibling, 2 replies; 8+ messages in thread
From: ChenXiaoSong @ 2026-09-14 2:38 UTC (permalink / raw)
To: Namjae Jeon
Cc: senozhatsky, tom, atteh.mailbox, chenxiaosong, Mobin Aydinfar,
linux-cifs
Hi Namjae,
According to MS-FSA 2.1.5.12.30:
https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-fsa/3d5c68f8-fbc5-4f94-a51d-3600a319fd45
Set AvailableNameLength to BlockAlignTruncate((OutputBufferSize -
FieldOffset(FILE_NAME_INFORMATION.FileName)), 2).
It seems that the following changes are also needed:
```
smb2_get_info_file()
{
unsigned int req_output_len = le32_to_cpu(req->OutputBufferLength);
...
case FILE_NORMALIZED_NAME_INFORMATION:
fixed_len = FILE_NORMALIZED_NAME_INFORMATION_SIZE;
req_output_len = round_down(req_output_len, 2);
break;
...
rc = buffer_check_err(req_output_len, fixed_len, rsp);
}
```
By the way, it seems that `struct smb2_file_alt_name_info` should be
renamed to `struct smb2_file_name_info`, since both
FILE_ALTERNATE_NAME_INFORMATION and FILE_NORMALIZED_NAME_INFORMATION use
this structure. See:
- MS-FSA 2.1.5.12.4 FileAlternateNameInformation:
https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-fsa/5051d021-8d06-4b7e-94e3-55b118193427
- MS-FSA 2.1.5.12.30 FileNormalizedNameInformation:
https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-fsa/3d5c68f8-fbc5-4f94-a51d-3600a319fd45
On 9/13/26 19:35, Namjae Jeon wrote:
> Windows may request FILE_NORMALIZED_NAME_INFORMATION with an output
> buffer that only fits the fixed portion of the variable-length response.
> Treat the fixed portion as FILE_ALTERNATE_NAME_INFORMATION_SIZE so ksmbd
> returns STATUS_BUFFER_OVERFLOW instead of STATUS_INFO_LENGTH_MISMATCH.
>
> This avoids rejecting valid partial normalized-name responses.
>
> Fixes: 6b8b79226bc3 ("ksmbd: fix partial file information responses")
> Reported-by: Mobin Aydinfar <mobin@mobintestserver.ir>
> Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
> ---
> fs/smb/server/smb2pdu.c | 3 +++
> 1 file changed, 3 insertions(+)
>
> diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
> index f4d96799e1d2..38cddbf3e6ed 100644
> --- a/fs/smb/server/smb2pdu.c
> +++ b/fs/smb/server/smb2pdu.c
> @@ -7318,6 +7318,9 @@ static int smb2_get_info_file(struct ksmbd_work *work,
> case FILE_ALTERNATE_NAME_INFORMATION:
> fixed_len = FILE_ALTERNATE_NAME_INFORMATION_SIZE;
> break;
> + case FILE_NORMALIZED_NAME_INFORMATION:
> + fixed_len = FILE_ALTERNATE_NAME_INFORMATION_SIZE;
> + break;
> case FILE_STREAM_INFORMATION:
> fixed_len = FILE_STREAM_INFORMATION_SIZE;
> break;
--
ChenXiaoSong <chenxiaosong@chenxiaosong.com>
Chinese Homepage: https://chenxiaosong.com
English Homepage: https://chenxiaosong.com/en
^ permalink raw reply [flat|nested] 8+ messages in thread* Re: [PATCH 2/3] ksmbd: fix partial normalized name responses
2026-09-14 2:38 ` ChenXiaoSong
@ 2026-09-14 2:52 ` ChenXiaoSong
2026-09-14 3:38 ` Namjae Jeon
1 sibling, 0 replies; 8+ messages in thread
From: ChenXiaoSong @ 2026-09-14 2:52 UTC (permalink / raw)
To: Namjae Jeon
Cc: senozhatsky, tom, atteh.mailbox, chenxiaosong, Mobin Aydinfar,
linux-cifs
If needed, I would be happy to help send v2.
And it would be better to use FILE_NAME_INFORMATION_SIZE (should be
changed to 8) instead of FILE_ALTERNATE_NAME_INFORMATION_SIZE.
```
smb2_get_info_file()
{
...
case FILE_ALTERNATE_NAME_INFORMATION:
case FILE_NORMALIZED_NAME_INFORMATION:
fixed_len = FILE_NAME_INFORMATION_SIZE; // 8
...
}
```
On 9/14/26 10:38, ChenXiaoSong wrote:
> Hi Namjae,
>
> According to MS-FSA 2.1.5.12.30: https://learn.microsoft.com/en-us/
> openspecs/windows_protocols/ms-fsa/3d5c68f8-fbc5-4f94-a51d-3600a319fd45
>
> Set AvailableNameLength to BlockAlignTruncate((OutputBufferSize -
> FieldOffset(FILE_NAME_INFORMATION.FileName)), 2).
>
> It seems that the following changes are also needed:
> ```
> smb2_get_info_file()
> {
> unsigned int req_output_len = le32_to_cpu(req-
> >OutputBufferLength);
> ...
> case FILE_NORMALIZED_NAME_INFORMATION:
> fixed_len = FILE_NORMALIZED_NAME_INFORMATION_SIZE;
> req_output_len = round_down(req_output_len, 2);
> break;
> ...
> rc = buffer_check_err(req_output_len, fixed_len, rsp);
> }
> ```
>
> By the way, it seems that `struct smb2_file_alt_name_info` should be
> renamed to `struct smb2_file_name_info`, since both
> FILE_ALTERNATE_NAME_INFORMATION and FILE_NORMALIZED_NAME_INFORMATION use
> this structure. See:
> - MS-FSA 2.1.5.12.4 FileAlternateNameInformation: https://
> learn.microsoft.com/en-us/openspecs/windows_protocols/ms-
> fsa/5051d021-8d06-4b7e-94e3-55b118193427
> - MS-FSA 2.1.5.12.30 FileNormalizedNameInformation: https://
> learn.microsoft.com/en-us/openspecs/windows_protocols/ms-fsa/3d5c68f8-
> fbc5-4f94-a51d-3600a319fd45
--
ChenXiaoSong <chenxiaosong@chenxiaosong.com>
Chinese Homepage: https://chenxiaosong.com
English Homepage: https://chenxiaosong.com/en
^ permalink raw reply [flat|nested] 8+ messages in thread* Re: [PATCH 2/3] ksmbd: fix partial normalized name responses
2026-09-14 2:38 ` ChenXiaoSong
2026-09-14 2:52 ` ChenXiaoSong
@ 2026-09-14 3:38 ` Namjae Jeon
2026-09-14 4:26 ` ChenXiaoSong
1 sibling, 1 reply; 8+ messages in thread
From: Namjae Jeon @ 2026-09-14 3:38 UTC (permalink / raw)
To: ChenXiaoSong
Cc: senozhatsky, tom, atteh.mailbox, chenxiaosong, Mobin Aydinfar,
linux-cifs
On Mon, Sep 14, 2026 at 11:38 AM ChenXiaoSong
<chenxiaosong@chenxiaosong.com> wrote:
>
> Hi Namjae,
>
> According to MS-FSA 2.1.5.12.30:
> https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-fsa/3d5c68f8-fbc5-4f94-a51d-3600a319fd45
>
> Set AvailableNameLength to BlockAlignTruncate((OutputBufferSize -
> FieldOffset(FILE_NAME_INFORMATION.FileName)), 2).
>
> It seems that the following changes are also needed:
> ```
> smb2_get_info_file()
> {
> unsigned int req_output_len = le32_to_cpu(req->OutputBufferLength);
> ...
> case FILE_NORMALIZED_NAME_INFORMATION:
> fixed_len = FILE_NORMALIZED_NAME_INFORMATION_SIZE;
> req_output_len = round_down(req_output_len, 2);
> break;
> ...
> rc = buffer_check_err(req_output_len, fixed_len, rsp);
> }
> ```
>
> By the way, it seems that `struct smb2_file_alt_name_info` should be
> renamed to `struct smb2_file_name_info`, since both
> FILE_ALTERNATE_NAME_INFORMATION and FILE_NORMALIZED_NAME_INFORMATION use
> this structure. See:
> - MS-FSA 2.1.5.12.4 FileAlternateNameInformation:
> https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-fsa/5051d021-8d06-4b7e-94e3-55b118193427
> - MS-FSA 2.1.5.12.30 FileNormalizedNameInformation:
> https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-fsa/3d5c68f8-fbc5-4f94-a51d-3600a319fd45
I think that both of them are changed in another patches.
^ permalink raw reply [flat|nested] 8+ messages in thread
end of thread, other threads:[~2026-09-14 13:49 UTC | newest]
Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-13 11:35 [PATCH 2/3] ksmbd: fix partial normalized name responses Namjae Jeon
2026-09-13 15:45 ` ChenXiaoSong
2026-09-14 1:18 ` Namjae Jeon
2026-09-14 2:38 ` ChenXiaoSong
2026-09-14 2:52 ` ChenXiaoSong
2026-09-14 3:38 ` Namjae Jeon
2026-09-14 4:26 ` ChenXiaoSong
2026-09-14 13:49 ` Namjae Jeon
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.