mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 0/3] ksmbd: fix some memory leaks in ksmbd_vfs_* functions
@ 2026-06-23  2:12 liuqiangneo
  2026-06-23  2:12 ` [PATCH 1/3] ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr liuqiangneo
                   ` (2 more replies)
  0 siblings, 3 replies; 7+ messages in thread
From: liuqiangneo @ 2026-06-23  2:12 UTC (permalink / raw)
  To: linkinjeon, smfrench, chenxiaosong, senozhatsky, tom
  Cc: linux-cifs, linux-kernel, liuqiangneo, Qiang Liu

From: Qiang Liu <liuqiang@kylinos.cn>

This series fixes several memory leaks in ksmbd_vfs_* functions,
where dynamically allocated buffers were not freed on error paths.

Qiang Liu (3):
  ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr
  ksmbd: fix acl.sd_buf memory leak in ksmbd_vfs_get_sd_xattr
  ksmbd: fix n.data memory leak in ksmbd_vfs_set_dos_attrib_xattr

 fs/smb/server/vfs.c | 13 ++++++++-----
 1 file changed, 8 insertions(+), 5 deletions(-)

-- 
2.43.0


^ permalink raw reply	[flat|nested] 7+ messages in thread

* [PATCH 1/3] ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr
  2026-06-23  2:12 [PATCH 0/3] ksmbd: fix some memory leaks in ksmbd_vfs_* functions liuqiangneo
@ 2026-06-23  2:12 ` liuqiangneo
  2026-06-23  2:28   ` ChenXiaoSong
  2026-06-23  2:12 ` [PATCH 2/3] ksmbd: fix acl.sd_buf memory leak in ksmbd_vfs_get_sd_xattr liuqiangneo
  2026-06-23  2:12 ` [PATCH 3/3] ksmbd: fix n.data memory leak in ksmbd_vfs_set_dos_attrib_xattr liuqiangneo
  2 siblings, 1 reply; 7+ messages in thread
From: liuqiangneo @ 2026-06-23  2:12 UTC (permalink / raw)
  To: linkinjeon, smfrench, chenxiaosong, senozhatsky, tom
  Cc: linux-cifs, linux-kernel, liuqiangneo, Qiang Liu

From: Qiang Liu <liuqiang@kylinos.cn>

Move kfree(sd_ndr.data) into the out cleanup path to avoid memory
leak on error.

Signed-off-by: Qiang Liu <liuqiang@kylinos.cn>
---
 fs/smb/server/vfs.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/smb/server/vfs.c b/fs/smb/server/vfs.c
index 74b0307cb100..febe9f7b54c3 100644
--- a/fs/smb/server/vfs.c
+++ b/fs/smb/server/vfs.c
@@ -1479,8 +1479,8 @@ int ksmbd_vfs_set_sd_xattr(struct ksmbd_conn *conn,
 	if (rc < 0)
 		pr_err("Failed to store XATTR ntacl :%d\n", rc);
 
-	kfree(sd_ndr.data);
 out:
+	kfree(sd_ndr.data);
 	kfree(acl_ndr.data);
 	kfree(smb_acl);
 	kfree(def_smb_acl);
-- 
2.43.0


^ permalink raw reply	[flat|nested] 7+ messages in thread

* [PATCH 2/3] ksmbd: fix acl.sd_buf memory leak in ksmbd_vfs_get_sd_xattr
  2026-06-23  2:12 [PATCH 0/3] ksmbd: fix some memory leaks in ksmbd_vfs_* functions liuqiangneo
  2026-06-23  2:12 ` [PATCH 1/3] ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr liuqiangneo
@ 2026-06-23  2:12 ` liuqiangneo
  2026-06-23  2:44   ` ChenXiaoSong
  2026-06-23  2:12 ` [PATCH 3/3] ksmbd: fix n.data memory leak in ksmbd_vfs_set_dos_attrib_xattr liuqiangneo
  2 siblings, 1 reply; 7+ messages in thread
From: liuqiangneo @ 2026-06-23  2:12 UTC (permalink / raw)
  To: linkinjeon, smfrench, chenxiaosong, senozhatsky, tom
  Cc: linux-cifs, linux-kernel, liuqiangneo, Qiang Liu

From: Qiang Liu <liuqiang@kylinos.cn>

Zero-initialize xattr_ntacl struct and reorder error cleanup labels
to ensure acl.sd_buf is released on all error paths.

Signed-off-by: Qiang Liu <liuqiang@kylinos.cn>
---
 fs/smb/server/vfs.c | 7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

diff --git a/fs/smb/server/vfs.c b/fs/smb/server/vfs.c
index febe9f7b54c3..60b4210d5ab8 100644
--- a/fs/smb/server/vfs.c
+++ b/fs/smb/server/vfs.c
@@ -1496,7 +1496,7 @@ int ksmbd_vfs_get_sd_xattr(struct ksmbd_conn *conn,
 	struct ndr n;
 	struct inode *inode = d_inode(dentry);
 	struct ndr acl_ndr = {0};
-	struct xattr_ntacl acl;
+	struct xattr_ntacl acl = {0};
 	struct xattr_smb_acl *smb_acl = NULL, *def_smb_acl = NULL;
 	__u8 cmp_hash[XATTR_SD_HASH_SIZE] = {0};
 
@@ -1533,6 +1533,7 @@ int ksmbd_vfs_get_sd_xattr(struct ksmbd_conn *conn,
 	*pntsd = acl.sd_buf;
 	if (acl.sd_size < sizeof(struct smb_ntsd)) {
 		pr_err("sd size is invalid\n");
+		rc = -EINVAL;
 		goto out_free;
 	}
 
@@ -1548,12 +1549,12 @@ int ksmbd_vfs_get_sd_xattr(struct ksmbd_conn *conn,
 	kfree(acl_ndr.data);
 	kfree(smb_acl);
 	kfree(def_smb_acl);
+
+free_n_data:
 	if (rc < 0) {
 		kfree(acl.sd_buf);
 		*pntsd = NULL;
 	}
-
-free_n_data:
 	kfree(n.data);
 	return rc;
 }
-- 
2.43.0


^ permalink raw reply	[flat|nested] 7+ messages in thread

* [PATCH 3/3] ksmbd: fix n.data memory leak in ksmbd_vfs_set_dos_attrib_xattr
  2026-06-23  2:12 [PATCH 0/3] ksmbd: fix some memory leaks in ksmbd_vfs_* functions liuqiangneo
  2026-06-23  2:12 ` [PATCH 1/3] ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr liuqiangneo
  2026-06-23  2:12 ` [PATCH 2/3] ksmbd: fix acl.sd_buf memory leak in ksmbd_vfs_get_sd_xattr liuqiangneo
@ 2026-06-23  2:12 ` liuqiangneo
  2026-06-23  2:46   ` ChenXiaoSong
  2 siblings, 1 reply; 7+ messages in thread
From: liuqiangneo @ 2026-06-23  2:12 UTC (permalink / raw)
  To: linkinjeon, smfrench, chenxiaosong, senozhatsky, tom
  Cc: linux-cifs, linux-kernel, liuqiangneo, Qiang Liu

From: Qiang Liu <liuqiang@kylinos.cn>

Free ndr buffer data when ndr_encode_dos_attr() returns error
to avoid memory leak.

Signed-off-by: Qiang Liu <liuqiang@kylinos.cn>
---
 fs/smb/server/vfs.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/fs/smb/server/vfs.c b/fs/smb/server/vfs.c
index 60b4210d5ab8..18d5412081de 100644
--- a/fs/smb/server/vfs.c
+++ b/fs/smb/server/vfs.c
@@ -1568,8 +1568,10 @@ int ksmbd_vfs_set_dos_attrib_xattr(struct mnt_idmap *idmap,
 	int err;
 
 	err = ndr_encode_dos_attr(&n, da);
-	if (err)
+	if (err) {
+		kfree(n.data);
 		return err;
+	}
 
 	err = ksmbd_vfs_setxattr(idmap, path, XATTR_NAME_DOS_ATTRIBUTE,
 				 (void *)n.data, n.offset, 0, get_write);
-- 
2.43.0


^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: [PATCH 1/3] ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr
  2026-06-23  2:12 ` [PATCH 1/3] ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr liuqiangneo
@ 2026-06-23  2:28   ` ChenXiaoSong
  0 siblings, 0 replies; 7+ messages in thread
From: ChenXiaoSong @ 2026-06-23  2:28 UTC (permalink / raw)
  To: liuqiangneo, linkinjeon, smfrench, senozhatsky, tom
  Cc: linux-cifs, linux-kernel, Qiang Liu

Looks good. Feel free to add:
Reviewed-by: ChenXiaoSong <chenxiaosong@kylinos.cn>

On 6/23/26 10:12, liuqiangneo@163.com wrote:
> From: Qiang Liu <liuqiang@kylinos.cn>
> 
> Move kfree(sd_ndr.data) into the out cleanup path to avoid memory
> leak on error.
> 
> Signed-off-by: Qiang Liu <liuqiang@kylinos.cn>
> ---
>   fs/smb/server/vfs.c | 2 +-
>   1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/fs/smb/server/vfs.c b/fs/smb/server/vfs.c
> index 74b0307cb100..febe9f7b54c3 100644
> --- a/fs/smb/server/vfs.c
> +++ b/fs/smb/server/vfs.c
> @@ -1479,8 +1479,8 @@ int ksmbd_vfs_set_sd_xattr(struct ksmbd_conn *conn,
>   	if (rc < 0)
>   		pr_err("Failed to store XATTR ntacl :%d\n", rc);
>   
> -	kfree(sd_ndr.data);
>   out:
> +	kfree(sd_ndr.data);
>   	kfree(acl_ndr.data);
>   	kfree(smb_acl);
>   	kfree(def_smb_acl);

-- 
ChenXiaoSong <chenxiaosong@chenxiaosong.com>
Chinese Homepage: https://chenxiaosong.com
English Homepage: https://chenxiaosong.com/en


^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: [PATCH 2/3] ksmbd: fix acl.sd_buf memory leak in ksmbd_vfs_get_sd_xattr
  2026-06-23  2:12 ` [PATCH 2/3] ksmbd: fix acl.sd_buf memory leak in ksmbd_vfs_get_sd_xattr liuqiangneo
@ 2026-06-23  2:44   ` ChenXiaoSong
  0 siblings, 0 replies; 7+ messages in thread
From: ChenXiaoSong @ 2026-06-23  2:44 UTC (permalink / raw)
  To: liuqiangneo, linkinjeon, smfrench, senozhatsky, tom
  Cc: linux-cifs, linux-kernel, Qiang Liu

The label name `free_n_data` is used to free n.data. Please use a 
different label name.

On 6/23/26 10:12, liuqiangneo@163.com wrote:
> +
> +free_n_data:
>   	if (rc < 0) {
>   		kfree(acl.sd_buf);
>   		*pntsd = NULL;
>   	}
> -
> -free_n_data:
>   	kfree(n.data);
>   	return rc;

-- 
ChenXiaoSong <chenxiaosong@chenxiaosong.com>
Chinese Homepage: https://chenxiaosong.com
English Homepage: https://chenxiaosong.com/en


^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: [PATCH 3/3] ksmbd: fix n.data memory leak in ksmbd_vfs_set_dos_attrib_xattr
  2026-06-23  2:12 ` [PATCH 3/3] ksmbd: fix n.data memory leak in ksmbd_vfs_set_dos_attrib_xattr liuqiangneo
@ 2026-06-23  2:46   ` ChenXiaoSong
  0 siblings, 0 replies; 7+ messages in thread
From: ChenXiaoSong @ 2026-06-23  2:46 UTC (permalink / raw)
  To: liuqiangneo, linkinjeon, smfrench, senozhatsky, tom
  Cc: linux-cifs, linux-kernel, Qiang Liu

We can add a label and use `goto` to free n.data

On 6/23/26 10:12, liuqiangneo@163.com wrote:
> From: Qiang Liu <liuqiang@kylinos.cn>
> 
> Free ndr buffer data when ndr_encode_dos_attr() returns error
> to avoid memory leak.
> 
> Signed-off-by: Qiang Liu <liuqiang@kylinos.cn>
> ---
>   fs/smb/server/vfs.c | 4 +++-
>   1 file changed, 3 insertions(+), 1 deletion(-)
> 
> diff --git a/fs/smb/server/vfs.c b/fs/smb/server/vfs.c
> index 60b4210d5ab8..18d5412081de 100644
> --- a/fs/smb/server/vfs.c
> +++ b/fs/smb/server/vfs.c
> @@ -1568,8 +1568,10 @@ int ksmbd_vfs_set_dos_attrib_xattr(struct mnt_idmap *idmap,
>   	int err;
>   
>   	err = ndr_encode_dos_attr(&n, da);
> -	if (err)
> +	if (err) {
> +		kfree(n.data);
>   		return err;
> +	}
>   
>   	err = ksmbd_vfs_setxattr(idmap, path, XATTR_NAME_DOS_ATTRIBUTE,
>   				 (void *)n.data, n.offset, 0, get_write);

-- 
ChenXiaoSong <chenxiaosong@chenxiaosong.com>
Chinese Homepage: https://chenxiaosong.com
English Homepage: https://chenxiaosong.com/en


^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2026-06-23  2:47 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-06-23  2:12 [PATCH 0/3] ksmbd: fix some memory leaks in ksmbd_vfs_* functions liuqiangneo
2026-06-23  2:12 ` [PATCH 1/3] ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr liuqiangneo
2026-06-23  2:28   ` ChenXiaoSong
2026-06-23  2:12 ` [PATCH 2/3] ksmbd: fix acl.sd_buf memory leak in ksmbd_vfs_get_sd_xattr liuqiangneo
2026-06-23  2:44   ` ChenXiaoSong
2026-06-23  2:12 ` [PATCH 3/3] ksmbd: fix n.data memory leak in ksmbd_vfs_set_dos_attrib_xattr liuqiangneo
2026-06-23  2:46   ` ChenXiaoSong

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®