[PATCH 7/7] smb: client: drop the redundant name bounds in cifs_filldir()

From: Diego Oliva

Date: Tue Sep 29 2026 - 05:20:20 EST


cifs_fill_dirent() rejects an entry whose name extends past the end of
the response before it returns, for both of its callers. The two
checks cifs_filldir() applies after the parse can no longer fail: the
one that commit f8cf09a53a0d ("smb: client: bound dirent name against
end of SMB response in cifs_filldir") added tests the same name
against the same end, and the older one, which compares the name
length with the length of the response, is implied by it because the
name starts inside the response. Remove both.

This patch depends on "smb: client: fix OOB read of the resume name
sent in TRANS2_FIND_NEXT2", which added the check to
cifs_fill_dirent().

No functional change intended.

Assisted-by: Bynario AI
Signed-off-by: Diego Oliva <diego@xxxxxxxx>
---
fs/smb/client/readdir.c | 11 -----------
1 file changed, 11 deletions(-)

diff --git a/fs/smb/client/readdir.c b/fs/smb/client/readdir.c
index 1e121c970685..569efdfb7360 100644
--- a/fs/smb/client/readdir.c
+++ b/fs/smb/client/readdir.c
@@ -1016,17 +1016,6 @@ static int cifs_filldir(char *find_entry, struct file *file,
if (rc)
return rc;

- if (de.namelen > max_len) {
- cifs_dbg(VFS, "bad search response length %zd past smb end\n",
- de.namelen);
- return -EINVAL;
- }
-
- if (de.name + de.namelen > end_of_smb) {
- cifs_dbg(VFS, "search entry name extends past end of SMB\n");
- return -EINVAL;
- }
-
/* skip . and .. since we added them first */
if (cifs_entry_is_dot(&de, file_info->srch_inf.unicode))
return 0;
--
2.39.5