public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* [PATCH 0/8] cifs: Fix support for NFS-style reparse points
@ 2024-09-28 21:59 Pali Rohár
  2024-09-28 21:59 ` [PATCH 1/8] smb: Update comments about some reparse point tags Pali Rohár
                   ` (7 more replies)
  0 siblings, 8 replies; 26+ messages in thread
From: Pali Rohár @ 2024-09-28 21:59 UTC (permalink / raw)
  To: Steve French, Paulo Alcantara, Ronnie Sahlberg; +Cc: linux-cifs, linux-kernel

For NFS-style reparse points in the current Linux SMB client I found few
buffer overflows and then incompatibility issues related to char/block
devices and symlinks. In this patch series I'm addressing these issues.
I also located commits which introduced these issues, I put them into
Fixes lines of commit messages.

Test cases against Windows server which exports one directory over both
SMB and NFS protocols. On Linux is mounted that directory to /mnt/nfs
and /mnt/smb via different protocols.

  mknod /mnt/nfs/char c 1 3
  stat /mnt/smb/char
  mknod /mnt/nfs/block b 8 0
  stat /mnt/smb/block
  ln -s abc\\abc /mnt/nfs/symlink
  stat /mnt/smb/symlink
  ls -l /mnt/smb

ls -l or stat over SMB should show the same information about char, block
and symlink as over NFS. And vice-versa.

Please look and check the buffer overflow issue as these buffer lengths
are always nightmares to handle correctly.

Pali Rohár (8):
  smb: Update comments about some reparse point tags
  cifs: Remove intermediate object of failed create reparse call
  cifs: Fix parsing NFS-style char/block devices
  cifs: Fix creating NFS-style char/block devices
  cifs: Fix buffer overflow when parsing NFS reparse points
  cifs: Do not convert delimiter when parsing NFS-style symlinks
  cifs: Validate content of NFS reparse point buffer
  cifs: Rename posix to nfs in parse_reparse_posix() and
    reparse_posix_data

 fs/smb/client/cifsglob.h  |  2 +-
 fs/smb/client/cifspdu.h   |  2 +-
 fs/smb/client/reparse.c   | 53 +++++++++++++++++++++++++++++++--------
 fs/smb/client/reparse.h   | 12 ++++++---
 fs/smb/client/smb2inode.c | 21 ++++++++++++++--
 fs/smb/common/smb2pdu.h   |  2 +-
 fs/smb/common/smbfsctl.h  |  7 +++---
 7 files changed, 77 insertions(+), 22 deletions(-)

-- 
2.20.1


^ permalink raw reply	[flat|nested] 26+ messages in thread

end of thread, other threads:[~2024-09-30 21:33 UTC | newest]

Thread overview: 26+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-09-28 21:59 [PATCH 0/8] cifs: Fix support for NFS-style reparse points Pali Rohár
2024-09-28 21:59 ` [PATCH 1/8] smb: Update comments about some reparse point tags Pali Rohár
2024-09-28 21:59 ` [PATCH 2/8] cifs: Remove intermediate object of failed create reparse call Pali Rohár
2024-09-29 12:53   ` Pali Rohár
2024-09-29 14:03   ` [PATCH v2] " Pali Rohár
2024-09-29 16:01     ` Steve French
2024-09-30 15:25   ` [PATCH 2/8] " Paulo Alcantara
2024-09-30 17:20     ` Pali Rohár
2024-09-30 21:33       ` Paulo Alcantara
2024-09-30 20:25   ` [PATCH v3] " Pali Rohár
2024-09-30 21:33     ` Steve French
2024-09-28 21:59 ` [PATCH 3/8] cifs: Fix parsing NFS-style char/block devices Pali Rohár
2024-09-28 21:59 ` [PATCH 4/8] cifs: Fix creating " Pali Rohár
2024-09-29  0:18   ` Steve French
2024-09-29  0:44     ` Pali Rohár
     [not found]       ` <CAH2r5mvbUhcW_c46oUiHzfPg97n5qiRg9kzpCkmzG9uHygOF3g@mail.gmail.com>
2024-09-29  0:51         ` Pali Rohár
2024-09-28 21:59 ` [PATCH 5/8] cifs: Fix buffer overflow when parsing NFS reparse points Pali Rohár
2024-09-29 10:22   ` [PATCH v2] " Pali Rohár
2024-09-28 21:59 ` [PATCH 6/8] cifs: Do not convert delimiter when parsing NFS-style symlinks Pali Rohár
2024-09-28 21:59 ` [PATCH 7/8] cifs: Validate content of NFS reparse point buffer Pali Rohár
2024-09-28 21:59 ` [PATCH 8/8] cifs: Rename posix to nfs in parse_reparse_posix() and reparse_posix_data Pali Rohár
2024-09-29  4:57   ` Steve French
2024-09-29  9:09     ` Ralph Boehme
2024-09-29  9:26       ` Pali Rohár
2024-09-29 12:52         ` Ralph Boehme
2024-09-29 15:43           ` Steve French

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox