From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B95E144CF59; Wed, 23 Sep 2026 14:55:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790175344; cv=none; b=HRNV412TDl3LrdzKcYx++MrzMQ7cZ19IPQPKVy5yPMSTlEdruXPEfdousY1waLWeBk0nq+4xpNyLvarg4ERkm+l8uzykkRToc8QPE0U6SRZRYvFuM7c8Sy8mDrvBoPFiNoTQY7Gw+dD0TbKeaY8Qti7tkQ6SoT3oMl8bHtydNBc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790175344; c=relaxed/simple; bh=phQKAKm0DufV+fraW7DGrFVr0qB//lDsTopXYJQB1J0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=mRG9yREt5PBF9X5TKmxJ7Gf4a+NCjAwJ65F2LJIW66LZ7GmeJnPdPSH2GUAuEva+IKFaj+h+nWui2Tz9iAyhRzT/P6oWcB0yGjhqPY2XIG79F5AzcB5a39EMxgLSH+bL3qIjZCvbbdvHTc99MRyRqQmwsVVzQh02R3nvB54sq7Q= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=byp5Fnj/; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="byp5Fnj/" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 191F71F000FF; Wed, 23 Sep 2026 14:55:41 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790175342; bh=tYGhySObvoC8OPohJMhUL128K6o7kGL6PzBu2NDlroE=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=byp5Fnj/H+lm+QYOMEqAcuQOmY2b7Szw7NLal9QCHGLjcoxXoS2e9szgIPdgfms+z LWh0AJFG0kZU0GfGn1EnyXVWPhL/t7ihAoTjnvzgwLwy99bZEfZDJKIA9tMacL8Lu7 25rgyf/ujn/PKD8qWdkOuDqLhzC2k3hKFuPLe3Vw= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, April Cardenas , Namjae Jeon , Bharath S M , Paulo Alcantara , Sasha Levin Subject: [PATCH 6.18 398/398] smb/client: send lease break ACKs thru correct session for multiuser mounts Date: Wed, 23 Sep 2026 16:07:52 +0200 Message-ID: <20260923140653.784729319@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260923140643.441954610@linuxfoundation.org> References: <20260923140643.441954610@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.18-stable review patch. If anyone has any objections, please let me know. ------------------ From: April Cardenas [ Upstream commit ebc5660132ddd244b57f03ed324922013a3d7363 ] Currently, when cifs_oplock_break handles a break request from the server it searches for the appropriate tlink to handle the request but incorrectly uses the current fsuid as the search key, eventually causing read errors for users with multiuser mounts on NetApp. Fix this by using the tlink from the cfile struct instead to respond through the correct session. As breaks are handled in a worker thread, the current fsuid isn't guaranteed to match the session that the break is intended for. This means that cifs_sb_tlink may search the rbtree using the wrong fsuid, and return a tlink with an incorrect session than the lease break was intended for. As a result, the breaks may be ACKed through an incorrect session. While it seems that Samba/Windows Servers 2016-2025 ignore this as long as the lease key is correct, we ran into a case where if you're using NetApp ONTAP or Azure NetApp Files they will reject the ACK and return `STATUS_LOCK_NOT_GRANTED` errors on any future read requests a user may initiate through their still held open file handle, and the server will eventually close the file. In the dmesg logs, the user may see errors like these: CIFS: Status code returned 0xc0000128 STATUS_FILE_CLOSED CIFS: VFS: Send error in read = -9 With a multiuser mount using NetApp, this issue is really easy for users to hit on a wide variety of kernel versions by attempting to copy a file from the share to the local machine through GNOME Files/Nautilus. This copy will always result in Nautilus throwing a `Bad File Descriptor` error to the user and fail. With this fix, you can copy files through Nautilus without issue. >>>From looking at the traces, it seems that glib will open the file first, and call listxattr before actually attempting to copy the file data. The listxattr call always triggers a break, causing the copy to fail. The proposed fix returns to the way the client grabbed the tlink before commit e8f5f849ffce2 ("cifs: fix potential oops in cifs_oplock_break"). The bulk of that commit (checking for list empty) remains untouched, and I think the change to using cifs_sb_tlink was intended to avoid a NULL/ERR deference on the tlink as well as update the reference count. I believe this fix should preserve those safety properties, but of course I'd appreciate any corrections here. Fixes: e8f5f849ffce2 ("cifs: fix potential oops in cifs_oplock_break") Cc: stable@vger.kernel.org Signed-off-by: April Cardenas Reviewed-by: Namjae Jeon Reviewed-by: Bharath S M Signed-off-by: Paulo Alcantara [ Removed now-unused sb and cifs_sb declarations from cifs_oplock_break(). ] Signed-off-by: Sasha Levin Signed-off-by: Greg Kroah-Hartman --- fs/smb/client/file.c | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) --- a/fs/smb/client/file.c +++ b/fs/smb/client/file.c @@ -3148,8 +3148,6 @@ void cifs_oplock_break(struct work_struc struct cifsFileInfo *cfile = container_of(work, struct cifsFileInfo, oplock_break); struct inode *inode = d_inode(cfile->dentry); - struct super_block *sb = inode->i_sb; - struct cifs_sb_info *cifs_sb = CIFS_SB(sb); struct cifsInodeInfo *cinode = CIFS_I(inode); struct cifs_tcon *tcon; struct TCP_Server_Info *server; @@ -3162,8 +3160,8 @@ void cifs_oplock_break(struct work_struc wait_on_bit(&cinode->flags, CIFS_INODE_PENDING_WRITERS, TASK_UNINTERRUPTIBLE); - tlink = cifs_sb_tlink(cifs_sb); - if (IS_ERR(tlink)) { + tlink = cifs_get_tlink(cfile->tlink); + if (IS_ERR_OR_NULL(tlink)) { /* drop the reference taken when the break was queued */ _cifsFileInfo_put(cfile, false /* do not wait for ourself */, false); goto out;