[PATCH 2/3] ksmbd: use the existing xattr name for a named stream

From: DaeMyung Kang

Date: Thu Oct 08 2026 - 11:28:45 EST


SMB stream names are case-insensitive, but ksmbd stores each named
stream in an xattr whose name is case-sensitive. Opening an existing
stream finds its xattr with a case-insensitive match, yet the handle
keeps the name as the client spelled it, and every later operation that
needs an exact name uses that spelling:

- a WRITE or an end-of-file change creates a second xattr, so a stream
created as "Foo" and written through "foo" ends up stored twice, and
which value a later lookup returns depends on xattr list order;
- delete-on-close and delete-pending removal can fail with -ENODATA,
or remove only a case-variant copy and leave the original;
- the share mode check compares stream names with strcmp(), so two
opens of the same stream that differ only in case do not conflict.

Have ksmbd_vfs_casexattr_len() copy the matching xattr's name into the
handle when the stream is opened, so later operations use the name
already on disk. The match must have the same length as the name it
replaces; the stream lookup passes a length that includes the
terminating NUL, which already guarantees that, and the check makes the
copy safe for any caller. A stream that does not exist yet keeps the
client's spelling, as before.

smb2_rename() compares and looks up fp->stream.name case-insensitively,
so it behaves the same with either spelling.

Fixes: e2f34481b24d ("cifsd: add server-side procedures for SMB3")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: DaeMyung Kang <charsyam@xxxxxxxxx>
---
fs/smb/server/smb2pdu.c | 8 ++++----
fs/smb/server/vfs.c | 9 +++++++--
fs/smb/server/vfs.h | 2 +-
3 files changed, 12 insertions(+), 7 deletions(-)

diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index 12a43efdb..4d43de74f 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -3341,7 +3341,7 @@ static int smb2_set_ea(struct smb2_ea_info *eabuf, unsigned int buf_len,
path->dentry,
attr_name,
XATTR_USER_PREFIX_LEN +
- eabuf->EaNameLength);
+ eabuf->EaNameLength, NULL);

/* delete the EA only when it exits */
if (rc > 0) {
@@ -3413,11 +3413,11 @@ static noinline int smb2_set_stream_name_xattr(const struct path *path,
fp->stream.name = xattr_stream_name;
fp->stream.size = xattr_stream_size;

- /* Check if there is stream prefix in xattr space */
+ /* Keep the existing xattr's case for subsequent writes and removal. */
rc = ksmbd_vfs_casexattr_len(idmap,
path->dentry,
xattr_stream_name,
- xattr_stream_size);
+ xattr_stream_size, xattr_stream_name);
if (rc >= 0)
return 0;

@@ -3469,7 +3469,7 @@ static loff_t ksmbd_stream_eof(struct ksmbd_file *fp)
ssize_t slen = ksmbd_vfs_casexattr_len(file_mnt_idmap(fp->filp),
fp->filp->f_path.dentry,
fp->stream.name,
- fp->stream.size);
+ fp->stream.size, NULL);
return slen < 0 ? 0 : (loff_t)slen;
}

diff --git a/fs/smb/server/vfs.c b/fs/smb/server/vfs.c
index ae9f9a693..7020b7de3 100644
--- a/fs/smb/server/vfs.c
+++ b/fs/smb/server/vfs.c
@@ -1946,7 +1946,7 @@ int ksmbd_vfs_fill_dentry_attrs(struct ksmbd_work *work,

ssize_t ksmbd_vfs_casexattr_len(struct mnt_idmap *idmap,
struct dentry *dentry, char *attr_name,
- int attr_name_len)
+ int attr_name_len, char *actual_name)
{
char *name, *xattr_list = NULL;
ssize_t value_len = -ENOENT, xattr_list_len;
@@ -1960,8 +1960,13 @@ ssize_t ksmbd_vfs_casexattr_len(struct mnt_idmap *idmap,
ksmbd_debug(VFS, "%s, len %zd\n", name, strlen(name));
if (strncasecmp(attr_name, name, attr_name_len))
continue;
+ if (actual_name && strlen(name) + 1 != attr_name_len)
+ continue;

value_len = ksmbd_vfs_xattr_len(idmap, dentry, name);
+ /* The caller provides attr_name_len bytes for the actual name. */
+ if (value_len >= 0 && actual_name)
+ memcpy(actual_name, name, attr_name_len);
break;
}

@@ -2116,7 +2121,7 @@ int ksmbd_vfs_copy_file_ranges(struct ksmbd_work *work,
src_file_size = ksmbd_vfs_casexattr_len(
file_mnt_idmap(src_fp->filp),
src_fp->filp->f_path.dentry,
- src_fp->stream.name, src_fp->stream.size);
+ src_fp->stream.name, src_fp->stream.size, NULL);
revert_creds(saved_cred);
if (src_file_size < 0)
return src_file_size;
diff --git a/fs/smb/server/vfs.h b/fs/smb/server/vfs.h
index ef3ab3f18..dedb10331 100644
--- a/fs/smb/server/vfs.h
+++ b/fs/smb/server/vfs.h
@@ -116,7 +116,7 @@ ssize_t ksmbd_vfs_getcasexattr(struct mnt_idmap *idmap,
int attr_name_len, char **attr_value);
ssize_t ksmbd_vfs_casexattr_len(struct mnt_idmap *idmap,
struct dentry *dentry, char *attr_name,
- int attr_name_len);
+ int attr_name_len, char *actual_name);
int ksmbd_vfs_setxattr(struct mnt_idmap *idmap,
const struct path *path, const char *attr_name,
void *attr_value, size_t attr_size, int flags,
--
2.43.0