From: Stefan Metzmacher <metze@samba.org>
To: linux-cifs@vger.kernel.org, samba-technical@lists.samba.org
Cc: metze@samba.org, "Namjae Jeon" <linkinjeon@kernel.org>,
"Paulo Alcantara" <pc@manguebit.org>,
"Tom Talpey" <tom@talpey.com>, 레드팀하고싶어요 <ihopenre@gmail.com>
Subject: [PATCH 0/3] smb: smbdirect: fix listener backlog leak and teardown races
Date: Mon, 5 Oct 2026 20:35:49 +0200 [thread overview]
Message-ID: <cover.1791224972.git.metze@samba.org> (raw)
Hi Namjae,
These fix a set of problems in the shared smbdirect module
(fs/smb/smbdirect/), reached through the listener/accept path, which in
practice is driven by ksmbd for incoming SMB Direct connections.
The main one is a pre-authentication remote denial of service: the
listener keeps every accepted connection on a fixed-size backlog
(listen.pending, limit 10 for ksmbd). A connection is only removed from
that backlog on the success path (promotion to listen.ready after a
completed negotiate, or dequeue by accept()). A connection that is
accepted at the RDMA level but then fails before it is accepted by the
upper layer - negotiate timeout, peer disconnect, or an invalid
negotiate request - is never removed, so its backlog slot is leaked.
After about ten such events the listener rejects every new connection
with -EBUSY and SMB Direct stays unusable until the service is
restarted. An unauthenticated peer can trigger this with ~10 aborted
connections.
This was reported by 레드팀하고싶어요 <ihopenre@gmail.com>:
https://lore.kernel.org/linux-cifs/CANTrAmxL5sWU8Sn29JAGZvSq5PBB2OA+VKA0MHsZJMesagtfzA@mail.gmail.com/
The series:
- smbdirect_socket_destroy_sync() no longer waits for
RDMA_CM_EVENT_DISCONNECTED after rdma_disconnect(). That wait could
take very long (until the rdma cm gives up, e.g. a peer that just
vanished) or never complete if the event already happened and the
status was overwritten. rdma_destroy_id() in
smbdirect_socket_destroy() is enough to stop further events; the
rest of the disconnect protocol is handled by the rdma core
asynchronously. This also makes releasing orphaned sockets
(next patch) non-blocking.
- A failed, not-yet-accepted child of a listener now moves itself to a
new listen.orphaned list at the end of its cleanup work and queues
listen.purge_orphaned_work, which releases it, so it no longer leaks
its backlog slot (nor its struct sock / RDMA resources) for the
lifetime of the listener. sc->accept.listener is only changed under
listener->listen.lock, and whoever clears it owns the release;
the listener is freed via kfree_rcu() so a child can dereference it
under rcu_read_lock(). This is the DoS fix.
- smbdirect_socket_accept() no longer hands out a socket that failed
after it was put on the ready list (e.g. the peer disconnected in
the meantime); it checks first_error / the status under listen.lock,
orphans such a socket and tries the next one.
I tested the reproducer and the problem is fixed
and I run various xfstests.
I think these are important and should go into 7.3
Stefan Metzmacher (3):
smb: smbdirect: don't wait for RDMA_CM_EVENT_DISCONNECTED in
smbdirect_socket_destroy_sync()
smb: smbdirect: release failed pending sockets of a listener
smb: smbdirect: don't hand out already failed sockets in
smbdirect_socket_accept()
fs/smb/smbdirect/accept.c | 122 ++++++++++++++++++++++++++--------
fs/smb/smbdirect/connection.c | 12 ++--
fs/smb/smbdirect/internal.h | 2 +
fs/smb/smbdirect/listen.c | 116 ++++++++++++++++++++++++++++++--
fs/smb/smbdirect/socket.c | 113 +++++++++++++++++++++++++++----
fs/smb/smbdirect/socket.h | 37 +++++++++++
6 files changed, 352 insertions(+), 50 deletions(-)
--
2.43.0
next reply other threads:[~2026-10-05 18:36 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-05 18:35 Stefan Metzmacher [this message]
2026-10-05 18:35 ` [PATCH 1/3] smb: smbdirect: don't wait for RDMA_CM_EVENT_DISCONNECTED in smbdirect_socket_destroy_sync() Stefan Metzmacher
2026-10-05 18:35 ` [PATCH 2/3] smb: smbdirect: release failed pending sockets of a listener Stefan Metzmacher
2026-10-05 18:35 ` [PATCH 3/3] smb: smbdirect: don't hand out already failed sockets in smbdirect_socket_accept() Stefan Metzmacher
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=cover.1791224972.git.metze@samba.org \
--to=metze@samba.org \
--cc=ihopenre@gmail.com \
--cc=linkinjeon@kernel.org \
--cc=linux-cifs@vger.kernel.org \
--cc=pc@manguebit.org \
--cc=samba-technical@lists.samba.org \
--cc=tom@talpey.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox