[PATCH 1/3] ksmbd: return end of file for reads past a named stream's data
From: DaeMyung Kang
Date: Thu Oct 08 2026 - 11:27:55 EST
A READ on a non-empty named stream at or beyond its end fails with
STATUS_INVALID_PARAMETER. ksmbd_vfs_stream_read() returns -EINVAL when
the offset is not below the stream length, and smb2_read() maps -EINVAL
to that status.
smb2_read() already turns a zero-byte read into STATUS_END_OF_FILE, the
status a regular file returns at its end, and an empty stream already
takes that path. Return 0 instead of -EINVAL so that non-empty streams
do the same. Clients that read a stream until end of file otherwise get
an error once they have read all of its data.
The buffered copychunk path converts a zero-byte source read to -EIO,
as it does for a regular file that shrinks during copying.
Fixes: 2ae1a6cc4302 ("cifsd: fix potential read overflow in ksmbd_vfs_stream_read()")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: DaeMyung Kang <charsyam@xxxxxxxxx>
---
fs/smb/server/vfs.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/smb/server/vfs.c b/fs/smb/server/vfs.c
index 74cd8007a..ae9f9a693 100644
--- a/fs/smb/server/vfs.c
+++ b/fs/smb/server/vfs.c
@@ -269,7 +269,7 @@ static int ksmbd_vfs_stream_read(struct ksmbd_file *fp, char *buf, loff_t *pos,
return (int)v_len;
if (v_len <= *pos) {
- count = -EINVAL;
+ count = 0;
goto free_buf;
}
--
2.43.0