* [PATCH v2] ksmbd: fix partial normalized name responses
@ 2026-09-14 11:15 Namjae Jeon
2026-09-14 11:15 ` [PATCH v2] ksmbd: keep compound responses on query info errors Namjae Jeon
2026-09-14 23:48 ` [PATCH v2] ksmbd: fix partial normalized name responses ChenXiaoSong
0 siblings, 2 replies; 4+ messages in thread
From: Namjae Jeon @ 2026-09-14 11:15 UTC (permalink / raw)
To: linux-cifs
Cc: senozhatsky, tom, atteh.mailbox, chenxiaosong, chenxiaosong,
Namjae Jeon, Mobin Aydinfar
Windows may request FILE_NORMALIZED_NAME_INFORMATION with an output
buffer that only fits the fixed portion of the variable-length response.
Treat the fixed portion as FILE_NORMALIZED_NAME_INFORMATION_SIZE so ksmbd
returns STATUS_BUFFER_OVERFLOW instead of STATUS_INFO_LENGTH_MISMATCH.
This avoids rejecting valid partial normalized-name responses.
Fixes: 6b8b79226bc3 ("ksmbd: fix partial file information responses")
Reported-by: Mobin Aydinfar <mobin@mobintestserver.ir>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
---
fs/smb/server/smb2pdu.c | 3 +++
fs/smb/server/smb2pdu.h | 1 +
2 files changed, 4 insertions(+)
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index 8acc5174530b..0436b7c898b1 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -7312,6 +7312,9 @@ static int smb2_get_info_file(struct ksmbd_work *work,
case FILE_ALTERNATE_NAME_INFORMATION:
fixed_len = FILE_ALTERNATE_NAME_INFORMATION_SIZE;
break;
+ case FILE_NORMALIZED_NAME_INFORMATION:
+ fixed_len = FILE_NORMALIZED_NAME_INFORMATION_SIZE;
+ break;
case FILE_STREAM_INFORMATION:
fixed_len = FILE_STREAM_INFORMATION_SIZE;
break;
diff --git a/fs/smb/server/smb2pdu.h b/fs/smb/server/smb2pdu.h
index a6200d8630e2..ca8e27f7b712 100644
--- a/fs/smb/server/smb2pdu.h
+++ b/fs/smb/server/smb2pdu.h
@@ -212,6 +212,7 @@ struct file_sparse {
#define FILE_ALLOCATION_INFORMATION_SIZE 19
#define FILE_END_OF_FILE_INFORMATION_SIZE 20
#define FILE_ALTERNATE_NAME_INFORMATION_SIZE 8
+#define FILE_NORMALIZED_NAME_INFORMATION_SIZE 8
#define FILE_STREAM_INFORMATION_SIZE 32
#define FILE_PIPE_INFORMATION_SIZE 23
#define FILE_PIPE_LOCAL_INFORMATION_SIZE 24
--
2.25.1
^ permalink raw reply related [flat|nested] 4+ messages in thread* [PATCH v2] ksmbd: keep compound responses on query info errors 2026-09-14 11:15 [PATCH v2] ksmbd: fix partial normalized name responses Namjae Jeon @ 2026-09-14 11:15 ` Namjae Jeon 2026-09-14 23:49 ` ChenXiaoSong 2026-09-14 23:48 ` [PATCH v2] ksmbd: fix partial normalized name responses ChenXiaoSong 1 sibling, 1 reply; 4+ messages in thread From: Namjae Jeon @ 2026-09-14 11:15 UTC (permalink / raw) To: linux-cifs Cc: senozhatsky, tom, atteh.mailbox, chenxiaosong, chenxiaosong, Namjae Jeon, Mobin Aydinfar Do not reset the RFC1002 length of the complete response when a query info buffer is too small. The current command will add its error response through ksmbd_iov_pin_rsp(), while resetting the base length can truncate earlier responses in a compound request. This lets ksmbd return the earlier responses and the query-info error response together. Remove the now-unused rsp_org parameter from the pipe query-info helpers. Fixes: e2b76ab8b5c9 ("ksmbd: add support for read compound") Reported-by: Mobin Aydinfar <mobin@mobintestserver.ir> Signed-off-by: Namjae Jeon <linkinjeon@kernel.org> --- fs/smb/server/smb2pdu.c | 31 ++++++++++++------------------- 1 file changed, 12 insertions(+), 19 deletions(-) diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c index 0436b7c898b1..6b8809f67b92 100644 --- a/fs/smb/server/smb2pdu.c +++ b/fs/smb/server/smb2pdu.c @@ -6275,21 +6275,18 @@ int smb2_query_dir(struct ksmbd_work *work) * @reqOutputBufferLength: max buffer length expected in command response * @fixed_len: minimum fixed response length * @rsp: query info response buffer contains output buffer length - * @rsp_org: base response buffer pointer in case of chained response * * Return: 0 on success, otherwise error */ static int buffer_check_err(int reqOutputBufferLength, unsigned int fixed_len, - struct smb2_query_info_rsp *rsp, - void *rsp_org) + struct smb2_query_info_rsp *rsp) { unsigned int output_len = le32_to_cpu(rsp->OutputBufferLength); if (reqOutputBufferLength < fixed_len) { pr_err("Invalid Buffer Size Requested\n"); rsp->hdr.Status = STATUS_INFO_LENGTH_MISMATCH; - *(__be32 *)rsp_org = cpu_to_be32(sizeof(struct smb2_hdr)); return -EINVAL; } @@ -6300,8 +6297,7 @@ static int buffer_check_err(int reqOutputBufferLength, return 0; } -static void get_standard_info_pipe(struct smb2_query_info_rsp *rsp, - void *rsp_org) +static void get_standard_info_pipe(struct smb2_query_info_rsp *rsp) { struct smb2_file_standard_info *sinfo; @@ -6316,8 +6312,7 @@ static void get_standard_info_pipe(struct smb2_query_info_rsp *rsp, cpu_to_le32(sizeof(struct smb2_file_standard_info)); } -static void get_internal_info_pipe(struct smb2_query_info_rsp *rsp, u64 num, - void *rsp_org) +static void get_internal_info_pipe(struct smb2_query_info_rsp *rsp, u64 num) { struct smb2_file_internal_info *file_info; @@ -6331,8 +6326,7 @@ static void get_internal_info_pipe(struct smb2_query_info_rsp *rsp, u64 num, static int smb2_get_info_file_pipe(struct ksmbd_session *sess, struct smb2_query_info_req *req, - struct smb2_query_info_rsp *rsp, - void *rsp_org) + struct smb2_query_info_rsp *rsp) { u64 id; int rc; @@ -6357,16 +6351,16 @@ static int smb2_get_info_file_pipe(struct ksmbd_session *sess, switch (req->FileInfoClass) { case FILE_STANDARD_INFORMATION: - get_standard_info_pipe(rsp, rsp_org); + get_standard_info_pipe(rsp); rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength), le32_to_cpu(rsp->OutputBufferLength), - rsp, rsp_org); + rsp); break; case FILE_INTERNAL_INFORMATION: - get_internal_info_pipe(rsp, id, rsp_org); + get_internal_info_pipe(rsp, id); rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength), le32_to_cpu(rsp->OutputBufferLength), - rsp, rsp_org); + rsp); break; default: ksmbd_debug(SMB, "smb2_info_file_pipe for %u not supported\n", @@ -7202,8 +7196,7 @@ static int smb2_get_info_file(struct ksmbd_work *work, if (test_share_config_flag(work->tcon->share_conf, KSMBD_SHARE_FLAG_PIPE)) { /* smb2 info file called for pipe */ - rc = smb2_get_info_file_pipe(work->sess, req, rsp, - work->response_buf); + rc = smb2_get_info_file_pipe(work->sess, req, rsp); goto iov_pin_out; } @@ -7321,7 +7314,7 @@ static int smb2_get_info_file(struct ksmbd_work *work, } rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength), fixed_len, - rsp, work->response_buf); + rsp); } ksmbd_fd_put(work, fp); @@ -7592,7 +7585,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work, } rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength), fixed_len, - rsp, work->response_buf); + rsp); path_put(&path); if (!rc) @@ -7706,7 +7699,7 @@ static int smb2_get_info_sec(struct ksmbd_work *work, rsp->OutputBufferLength = cpu_to_le32(secdesclen); rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength), le32_to_cpu(rsp->OutputBufferLength), - rsp, work->response_buf); + rsp); if (rc) goto err_out; -- 2.25.1 ^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [PATCH v2] ksmbd: keep compound responses on query info errors 2026-09-14 11:15 ` [PATCH v2] ksmbd: keep compound responses on query info errors Namjae Jeon @ 2026-09-14 23:49 ` ChenXiaoSong 0 siblings, 0 replies; 4+ messages in thread From: ChenXiaoSong @ 2026-09-14 23:49 UTC (permalink / raw) To: Namjae Jeon, linux-cifs Cc: senozhatsky, tom, atteh.mailbox, chenxiaosong, Mobin Aydinfar Reviewed-by: ChenXiaoSong <chenxiaosong@kylinos.cn> On 9/14/2026 7:15 PM, Namjae Jeon wrote: > Do not reset the RFC1002 length of the complete response when a query > info buffer is too small. The current command will add its error response > through ksmbd_iov_pin_rsp(), while resetting the base length can truncate > earlier responses in a compound request. > > This lets ksmbd return the earlier responses and the query-info error > response together. Remove the now-unused rsp_org parameter from the pipe > query-info helpers. > > Fixes: e2b76ab8b5c9 ("ksmbd: add support for read compound") > Reported-by: Mobin Aydinfar<mobin@mobintestserver.ir> > Signed-off-by: Namjae Jeon<linkinjeon@kernel.org> > --- > fs/smb/server/smb2pdu.c | 31 ++++++++++++------------------- > 1 file changed, 12 insertions(+), 19 deletions(-) -- ChenXiaoSong <chenxiaosong@chenxiaosong.com> Chinese Homepage: https://chenxiaosong.com English Homepage: https://chenxiaosong.com/en ^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH v2] ksmbd: fix partial normalized name responses 2026-09-14 11:15 [PATCH v2] ksmbd: fix partial normalized name responses Namjae Jeon 2026-09-14 11:15 ` [PATCH v2] ksmbd: keep compound responses on query info errors Namjae Jeon @ 2026-09-14 23:48 ` ChenXiaoSong 1 sibling, 0 replies; 4+ messages in thread From: ChenXiaoSong @ 2026-09-14 23:48 UTC (permalink / raw) To: Namjae Jeon, linux-cifs Cc: senozhatsky, tom, atteh.mailbox, chenxiaosong, Mobin Aydinfar Reviewed-by: ChenXiaoSong <chenxiaosong@kylinos.cn> On 9/14/2026 7:15 PM, Namjae Jeon wrote: > Windows may request FILE_NORMALIZED_NAME_INFORMATION with an output > buffer that only fits the fixed portion of the variable-length response. > Treat the fixed portion as FILE_NORMALIZED_NAME_INFORMATION_SIZE so ksmbd > returns STATUS_BUFFER_OVERFLOW instead of STATUS_INFO_LENGTH_MISMATCH. > > This avoids rejecting valid partial normalized-name responses. > > Fixes: 6b8b79226bc3 ("ksmbd: fix partial file information responses") > Reported-by: Mobin Aydinfar<mobin@mobintestserver.ir> > Signed-off-by: Namjae Jeon<linkinjeon@kernel.org> > --- > fs/smb/server/smb2pdu.c | 3 +++ > fs/smb/server/smb2pdu.h | 1 + > 2 files changed, 4 insertions(+) -- ChenXiaoSong <chenxiaosong@chenxiaosong.com> Chinese Homepage: https://chenxiaosong.com English Homepage: https://chenxiaosong.com/en ^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-09-14 23:49 UTC | newest] Thread overview: 4+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-09-14 11:15 [PATCH v2] ksmbd: fix partial normalized name responses Namjae Jeon 2026-09-14 11:15 ` [PATCH v2] ksmbd: keep compound responses on query info errors Namjae Jeon 2026-09-14 23:49 ` ChenXiaoSong 2026-09-14 23:48 ` [PATCH v2] ksmbd: fix partial normalized name responses ChenXiaoSong
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox