From: DaeMyung Kang <charsyam@gmail.com>
To: Namjae Jeon <linkinjeon@kernel.org>
Cc: Sergey Senozhatsky <senozhatsky@chromium.org>,
Tom Talpey <tom@talpey.com>,
ChenXiaoSong <chenxiaosong@chenxiaosong.com>,
linux-cifs@vger.kernel.org, linux-kernel@vger.kernel.org,
DaeMyung Kang <charsyam@gmail.com>,
stable@vger.kernel.org
Subject: [PATCH 3/3] ksmbd: preserve unreadable named streams on open
Date: Fri, 9 Oct 2026 00:25:37 +0900 [thread overview]
Message-ID: <20261008152537.4147299-4-charsyam@gmail.com> (raw)
In-Reply-To: <20261008152537.4147299-1-charsyam@gmail.com>
A write-only client can open an existing named stream with FILE_OPEN_IF
without permission to read the underlying file. The case-insensitive
lookup finds the xattr name, but querying its value length then fails
with -EACCES. smb2_set_stream_name_xattr() treats every negative result
as a missing stream and replaces the existing xattr with an empty value.
A failed xattr list is not proof that the stream is absent either:
for example, -ENOMEM can lead to the same empty replacement. Preserve
listing errors and create a stream only for -ENOENT or -ENODATA. The
latter can occur if the xattr is removed between listing its name and
querying its value. Return other lookup errors without changing the
stream.
A write-only FILE_OPEN now reports access denied instead of name not
found. FILE_OVERWRITE_IF and FILE_SUPERSEDE on an unreadable stream
also fail instead of appearing to replace it. Stream writes and EOF
changes already need to read the old value, so such handles cannot
update the stream after opening either.
Fixes: e2f34481b24d ("cifsd: add server-side procedures for SMB3")
Cc: stable@vger.kernel.org
Signed-off-by: DaeMyung Kang <charsyam@gmail.com>
---
fs/smb/server/smb2pdu.c | 2 ++
fs/smb/server/vfs.c | 6 +++++-
2 files changed, 7 insertions(+), 1 deletion(-)
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index 4d43de74f..52a19871d 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -3420,6 +3420,8 @@ static noinline int smb2_set_stream_name_xattr(const struct path *path,
xattr_stream_size, xattr_stream_name);
if (rc >= 0)
return 0;
+ if (rc != -ENOENT && rc != -ENODATA)
+ return rc;
if (fp->cdoption == FILE_OPEN_LE) {
if (!strcmp(stream_name, "AFP_AfpInfo") &&
diff --git a/fs/smb/server/vfs.c b/fs/smb/server/vfs.c
index 7020b7de3..3fa0e26e5 100644
--- a/fs/smb/server/vfs.c
+++ b/fs/smb/server/vfs.c
@@ -1952,7 +1952,11 @@ ssize_t ksmbd_vfs_casexattr_len(struct mnt_idmap *idmap,
ssize_t value_len = -ENOENT, xattr_list_len;
xattr_list_len = ksmbd_vfs_listxattr(dentry, &xattr_list);
- if (xattr_list_len <= 0)
+ if (xattr_list_len < 0) {
+ value_len = xattr_list_len;
+ goto out;
+ }
+ if (!xattr_list_len)
goto out;
for (name = xattr_list; name - xattr_list < xattr_list_len;
--
2.43.0
next prev parent reply other threads:[~2026-10-08 15:26 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 15:25 [PATCH 0/3] ksmbd: fix three named stream bugs DaeMyung Kang
2026-10-08 15:25 ` [PATCH 1/3] ksmbd: return end of file for reads past a named stream's data DaeMyung Kang
2026-10-08 15:25 ` [PATCH 2/3] ksmbd: use the existing xattr name for a named stream DaeMyung Kang
2026-10-08 15:25 ` DaeMyung Kang [this message]
2026-10-09 2:24 ` [PATCH 0/3] ksmbd: fix three named stream bugs Namjae Jeon
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261008152537.4147299-4-charsyam@gmail.com \
--to=charsyam@gmail.com \
--cc=chenxiaosong@chenxiaosong.com \
--cc=linkinjeon@kernel.org \
--cc=linux-cifs@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=senozhatsky@chromium.org \
--cc=stable@vger.kernel.org \
--cc=tom@talpey.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®