Linux CIFS filesystem development
 help / color / mirror / Atom feed
* [PATCH v2] ksmbd: fix partial normalized name responses
@ 2026-09-14 11:15 Namjae Jeon
  2026-09-14 11:15 ` [PATCH v2] ksmbd: keep compound responses on query info errors Namjae Jeon
  2026-09-14 23:48 ` [PATCH v2] ksmbd: fix partial normalized name responses ChenXiaoSong
  0 siblings, 2 replies; 4+ messages in thread
From: Namjae Jeon @ 2026-09-14 11:15 UTC (permalink / raw)
  To: linux-cifs
  Cc: senozhatsky, tom, atteh.mailbox, chenxiaosong, chenxiaosong,
	Namjae Jeon, Mobin Aydinfar

Windows may request FILE_NORMALIZED_NAME_INFORMATION with an output
buffer that only fits the fixed portion of the variable-length response.
Treat the fixed portion as FILE_NORMALIZED_NAME_INFORMATION_SIZE so ksmbd
returns STATUS_BUFFER_OVERFLOW instead of STATUS_INFO_LENGTH_MISMATCH.

This avoids rejecting valid partial normalized-name responses.

Fixes: 6b8b79226bc3 ("ksmbd: fix partial file information responses")
Reported-by: Mobin Aydinfar <mobin@mobintestserver.ir>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
---
 fs/smb/server/smb2pdu.c | 3 +++
 fs/smb/server/smb2pdu.h | 1 +
 2 files changed, 4 insertions(+)

diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index 8acc5174530b..0436b7c898b1 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -7312,6 +7312,9 @@ static int smb2_get_info_file(struct ksmbd_work *work,
 		case FILE_ALTERNATE_NAME_INFORMATION:
 			fixed_len = FILE_ALTERNATE_NAME_INFORMATION_SIZE;
 			break;
+		case FILE_NORMALIZED_NAME_INFORMATION:
+			fixed_len = FILE_NORMALIZED_NAME_INFORMATION_SIZE;
+			break;
 		case FILE_STREAM_INFORMATION:
 			fixed_len = FILE_STREAM_INFORMATION_SIZE;
 			break;
diff --git a/fs/smb/server/smb2pdu.h b/fs/smb/server/smb2pdu.h
index a6200d8630e2..ca8e27f7b712 100644
--- a/fs/smb/server/smb2pdu.h
+++ b/fs/smb/server/smb2pdu.h
@@ -212,6 +212,7 @@ struct file_sparse {
 #define FILE_ALLOCATION_INFORMATION_SIZE      19
 #define FILE_END_OF_FILE_INFORMATION_SIZE     20
 #define FILE_ALTERNATE_NAME_INFORMATION_SIZE  8
+#define FILE_NORMALIZED_NAME_INFORMATION_SIZE 8
 #define FILE_STREAM_INFORMATION_SIZE          32
 #define FILE_PIPE_INFORMATION_SIZE            23
 #define FILE_PIPE_LOCAL_INFORMATION_SIZE      24
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* [PATCH v2] ksmbd: keep compound responses on query info errors
  2026-09-14 11:15 [PATCH v2] ksmbd: fix partial normalized name responses Namjae Jeon
@ 2026-09-14 11:15 ` Namjae Jeon
  2026-09-14 23:49   ` ChenXiaoSong
  2026-09-14 23:48 ` [PATCH v2] ksmbd: fix partial normalized name responses ChenXiaoSong
  1 sibling, 1 reply; 4+ messages in thread
From: Namjae Jeon @ 2026-09-14 11:15 UTC (permalink / raw)
  To: linux-cifs
  Cc: senozhatsky, tom, atteh.mailbox, chenxiaosong, chenxiaosong,
	Namjae Jeon, Mobin Aydinfar

Do not reset the RFC1002 length of the complete response when a query
info buffer is too small. The current command will add its error response
through ksmbd_iov_pin_rsp(), while resetting the base length can truncate
earlier responses in a compound request.

This lets ksmbd return the earlier responses and the query-info error
response together. Remove the now-unused rsp_org parameter from the pipe
query-info helpers.

Fixes: e2b76ab8b5c9 ("ksmbd: add support for read compound")
Reported-by: Mobin Aydinfar <mobin@mobintestserver.ir>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
---
 fs/smb/server/smb2pdu.c | 31 ++++++++++++-------------------
 1 file changed, 12 insertions(+), 19 deletions(-)

diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index 0436b7c898b1..6b8809f67b92 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -6275,21 +6275,18 @@ int smb2_query_dir(struct ksmbd_work *work)
  * @reqOutputBufferLength:	max buffer length expected in command response
  * @fixed_len:			minimum fixed response length
  * @rsp:		query info response buffer contains output buffer length
- * @rsp_org:		base response buffer pointer in case of chained response
  *
  * Return:	0 on success, otherwise error
  */
 static int buffer_check_err(int reqOutputBufferLength,
 			    unsigned int fixed_len,
-			    struct smb2_query_info_rsp *rsp,
-			    void *rsp_org)
+			    struct smb2_query_info_rsp *rsp)
 {
 	unsigned int output_len = le32_to_cpu(rsp->OutputBufferLength);
 
 	if (reqOutputBufferLength < fixed_len) {
 		pr_err("Invalid Buffer Size Requested\n");
 		rsp->hdr.Status = STATUS_INFO_LENGTH_MISMATCH;
-		*(__be32 *)rsp_org = cpu_to_be32(sizeof(struct smb2_hdr));
 		return -EINVAL;
 	}
 
@@ -6300,8 +6297,7 @@ static int buffer_check_err(int reqOutputBufferLength,
 	return 0;
 }
 
-static void get_standard_info_pipe(struct smb2_query_info_rsp *rsp,
-				   void *rsp_org)
+static void get_standard_info_pipe(struct smb2_query_info_rsp *rsp)
 {
 	struct smb2_file_standard_info *sinfo;
 
@@ -6316,8 +6312,7 @@ static void get_standard_info_pipe(struct smb2_query_info_rsp *rsp,
 		cpu_to_le32(sizeof(struct smb2_file_standard_info));
 }
 
-static void get_internal_info_pipe(struct smb2_query_info_rsp *rsp, u64 num,
-				   void *rsp_org)
+static void get_internal_info_pipe(struct smb2_query_info_rsp *rsp, u64 num)
 {
 	struct smb2_file_internal_info *file_info;
 
@@ -6331,8 +6326,7 @@ static void get_internal_info_pipe(struct smb2_query_info_rsp *rsp, u64 num,
 
 static int smb2_get_info_file_pipe(struct ksmbd_session *sess,
 				   struct smb2_query_info_req *req,
-				   struct smb2_query_info_rsp *rsp,
-				   void *rsp_org)
+				   struct smb2_query_info_rsp *rsp)
 {
 	u64 id;
 	int rc;
@@ -6357,16 +6351,16 @@ static int smb2_get_info_file_pipe(struct ksmbd_session *sess,
 
 	switch (req->FileInfoClass) {
 	case FILE_STANDARD_INFORMATION:
-		get_standard_info_pipe(rsp, rsp_org);
+		get_standard_info_pipe(rsp);
 		rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
 				      le32_to_cpu(rsp->OutputBufferLength),
-				      rsp, rsp_org);
+				      rsp);
 		break;
 	case FILE_INTERNAL_INFORMATION:
-		get_internal_info_pipe(rsp, id, rsp_org);
+		get_internal_info_pipe(rsp, id);
 		rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
 				      le32_to_cpu(rsp->OutputBufferLength),
-				      rsp, rsp_org);
+				      rsp);
 		break;
 	default:
 		ksmbd_debug(SMB, "smb2_info_file_pipe for %u not supported\n",
@@ -7202,8 +7196,7 @@ static int smb2_get_info_file(struct ksmbd_work *work,
 	if (test_share_config_flag(work->tcon->share_conf,
 				   KSMBD_SHARE_FLAG_PIPE)) {
 		/* smb2 info file called for pipe */
-		rc = smb2_get_info_file_pipe(work->sess, req, rsp,
-					       work->response_buf);
+		rc = smb2_get_info_file_pipe(work->sess, req, rsp);
 		goto iov_pin_out;
 	}
 
@@ -7321,7 +7314,7 @@ static int smb2_get_info_file(struct ksmbd_work *work,
 		}
 		rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
 				      fixed_len,
-				      rsp, work->response_buf);
+				      rsp);
 	}
 	ksmbd_fd_put(work, fp);
 
@@ -7592,7 +7585,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
 	}
 	rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
 			      fixed_len,
-			      rsp, work->response_buf);
+			      rsp);
 	path_put(&path);
 
 	if (!rc)
@@ -7706,7 +7699,7 @@ static int smb2_get_info_sec(struct ksmbd_work *work,
 	rsp->OutputBufferLength = cpu_to_le32(secdesclen);
 	rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
 			      le32_to_cpu(rsp->OutputBufferLength),
-			      rsp, work->response_buf);
+			      rsp);
 	if (rc)
 		goto err_out;
 
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [PATCH v2] ksmbd: fix partial normalized name responses
  2026-09-14 11:15 [PATCH v2] ksmbd: fix partial normalized name responses Namjae Jeon
  2026-09-14 11:15 ` [PATCH v2] ksmbd: keep compound responses on query info errors Namjae Jeon
@ 2026-09-14 23:48 ` ChenXiaoSong
  1 sibling, 0 replies; 4+ messages in thread
From: ChenXiaoSong @ 2026-09-14 23:48 UTC (permalink / raw)
  To: Namjae Jeon, linux-cifs
  Cc: senozhatsky, tom, atteh.mailbox, chenxiaosong, Mobin Aydinfar

Reviewed-by: ChenXiaoSong <chenxiaosong@kylinos.cn>

On 9/14/2026 7:15 PM, Namjae Jeon wrote:
> Windows may request FILE_NORMALIZED_NAME_INFORMATION with an output
> buffer that only fits the fixed portion of the variable-length response.
> Treat the fixed portion as FILE_NORMALIZED_NAME_INFORMATION_SIZE so ksmbd
> returns STATUS_BUFFER_OVERFLOW instead of STATUS_INFO_LENGTH_MISMATCH.
> 
> This avoids rejecting valid partial normalized-name responses.
> 
> Fixes: 6b8b79226bc3 ("ksmbd: fix partial file information responses")
> Reported-by: Mobin Aydinfar<mobin@mobintestserver.ir>
> Signed-off-by: Namjae Jeon<linkinjeon@kernel.org>
> ---
>   fs/smb/server/smb2pdu.c | 3 +++
>   fs/smb/server/smb2pdu.h | 1 +
>   2 files changed, 4 insertions(+)

-- 
ChenXiaoSong <chenxiaosong@chenxiaosong.com>
Chinese Homepage: https://chenxiaosong.com
English Homepage: https://chenxiaosong.com/en


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH v2] ksmbd: keep compound responses on query info errors
  2026-09-14 11:15 ` [PATCH v2] ksmbd: keep compound responses on query info errors Namjae Jeon
@ 2026-09-14 23:49   ` ChenXiaoSong
  0 siblings, 0 replies; 4+ messages in thread
From: ChenXiaoSong @ 2026-09-14 23:49 UTC (permalink / raw)
  To: Namjae Jeon, linux-cifs
  Cc: senozhatsky, tom, atteh.mailbox, chenxiaosong, Mobin Aydinfar

Reviewed-by: ChenXiaoSong <chenxiaosong@kylinos.cn>

On 9/14/2026 7:15 PM, Namjae Jeon wrote:
> Do not reset the RFC1002 length of the complete response when a query
> info buffer is too small. The current command will add its error response
> through ksmbd_iov_pin_rsp(), while resetting the base length can truncate
> earlier responses in a compound request.
> 
> This lets ksmbd return the earlier responses and the query-info error
> response together. Remove the now-unused rsp_org parameter from the pipe
> query-info helpers.
> 
> Fixes: e2b76ab8b5c9 ("ksmbd: add support for read compound")
> Reported-by: Mobin Aydinfar<mobin@mobintestserver.ir>
> Signed-off-by: Namjae Jeon<linkinjeon@kernel.org>
> ---
>   fs/smb/server/smb2pdu.c | 31 ++++++++++++-------------------
>   1 file changed, 12 insertions(+), 19 deletions(-)

-- 
ChenXiaoSong <chenxiaosong@chenxiaosong.com>
Chinese Homepage: https://chenxiaosong.com
English Homepage: https://chenxiaosong.com/en


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-09-14 23:49 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-14 11:15 [PATCH v2] ksmbd: fix partial normalized name responses Namjae Jeon
2026-09-14 11:15 ` [PATCH v2] ksmbd: keep compound responses on query info errors Namjae Jeon
2026-09-14 23:49   ` ChenXiaoSong
2026-09-14 23:48 ` [PATCH v2] ksmbd: fix partial normalized name responses ChenXiaoSong

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox