From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5959853B326; Thu, 17 Sep 2026 17:05:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789664703; cv=none; b=PJDH24bfHiK3vzwTZrgs/bvaMeUgfPa47twdypp1SmDcNF6XOA0uth3E2fI41uSITqbvsYFTtPz0vrgQ4btQkjAnT5+hUXCh2OhVTIuMntJoTmC+2x10LE1VBhN9rGEBXTxsRQqCp3BcSn1KKuSSxXIYKkgObJOd6VyB+SPcabY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789664703; c=relaxed/simple; bh=d8PNqG9mkro3o97d9oNlmya2E8iT/cJZzW8Gq+xJa+0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=LobwH3NWetuq+UoFUdtTizCRBOycC/R+yncC2o+yQfR6uswSpxMz/xl+n/JuanIubouuavhIdeEzgu1imC/iGmJLueNDaSFbHYRbvKWUff3EU1wP/vl647U7NESaWUc9UPGj+ZLMlQXPgP457uGSP18Xgg/sYr6HjcfLzcbGWU0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=FL7V1iJw; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="FL7V1iJw" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 75F561F000FF; Thu, 17 Sep 2026 17:05:01 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789664702; bh=ulYSnnoAFGNr6Hm+0acdNHNX1m/DTCkcuX7BvMhtLms=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=FL7V1iJw2Kd+uTNcr9rVMj/TUYbYYqy9wFNMUuHDnU8I3JXHm7ITafTfPQyrpdSI0 86voDY/4nTiKfDuCIg32U2bRnVv1Zfqb/nV9c8ggR1H+mcKBpiq9W/aPvIcvK85rZG RxTWW/L4StOViTeO6pMFT0Qy5jPe2r1SNMyAriSQ= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Namjae Jeon , Steve French , Sasha Levin Subject: [PATCH 6.18 0459/1250] ksmbd: apply create security descriptor first Date: Thu, 17 Sep 2026 16:04:14 +0100 Message-ID: <20260917151604.424436848@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260917151551.901433442@linuxfoundation.org> References: <20260917151551.901433442@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.18-stable review patch. If anyone has any objections, please let me know. ------------------ From: Namjae Jeon [ Upstream commit ba3cf6ee4f0eacc1f8c607b80188e3b32ef5e0e3 ] smb2.create.aclfile creates files with an SMB2_CREATE_SD_BUFFER create context and expects the resulting security descriptor to match the descriptor supplied by the client. ksmbd currently tries to inherit the parent DACL first and only parses the SMB2_CREATE_SD_BUFFER context when DACL inheritance fails. If inheritance succeeds, the explicit security descriptor supplied on create is ignored. This breaks create requests that include owner/group information in the security descriptor. Apply the create security descriptor first when the context is present. Fall back to the existing inherited/default ACL path only when no create security descriptor was supplied. Signed-off-by: Namjae Jeon Signed-off-by: Steve French Signed-off-by: Sasha Levin --- fs/smb/server/smb2pdu.c | 16 +++++++++------- 1 file changed, 9 insertions(+), 7 deletions(-) diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c index c15dde5193d4b..116873feda9c9 100644 --- a/fs/smb/server/smb2pdu.c +++ b/fs/smb/server/smb2pdu.c @@ -3400,14 +3400,16 @@ int smb2_open(struct ksmbd_work *work) if (posix_acl_rc) ksmbd_debug(SMB, "inherit posix acl failed : %d\n", posix_acl_rc); - if (test_share_config_flag(work->tcon->share_conf, - KSMBD_SHARE_FLAG_ACL_XATTR)) { - rc = smb_inherit_dacl(conn, &path, sess->user->uid, - sess->user->gid); - } + rc = smb2_create_sd_buffer(work, req, &path); + if (rc && rc != -ENOENT) + goto err_out; - if (rc) { - rc = smb2_create_sd_buffer(work, req, &path); + if (rc == -ENOENT) { + if (test_share_config_flag(work->tcon->share_conf, + KSMBD_SHARE_FLAG_ACL_XATTR)) { + rc = smb_inherit_dacl(conn, &path, sess->user->uid, + sess->user->gid); + } if (rc) { if (posix_acl_rc) ksmbd_vfs_set_init_posix_acl(idmap, -- 2.53.0