[PATCH 3/3] ksmbd: preserve unreadable named streams on open

From: DaeMyung Kang

Date: Thu Oct 08 2026 - 11:29:52 EST


A write-only client can open an existing named stream with FILE_OPEN_IF
without permission to read the underlying file. The case-insensitive
lookup finds the xattr name, but querying its value length then fails
with -EACCES. smb2_set_stream_name_xattr() treats every negative result
as a missing stream and replaces the existing xattr with an empty value.

A failed xattr list is not proof that the stream is absent either:
for example, -ENOMEM can lead to the same empty replacement. Preserve
listing errors and create a stream only for -ENOENT or -ENODATA. The
latter can occur if the xattr is removed between listing its name and
querying its value. Return other lookup errors without changing the
stream.

A write-only FILE_OPEN now reports access denied instead of name not
found. FILE_OVERWRITE_IF and FILE_SUPERSEDE on an unreadable stream
also fail instead of appearing to replace it. Stream writes and EOF
changes already need to read the old value, so such handles cannot
update the stream after opening either.

Fixes: e2f34481b24d ("cifsd: add server-side procedures for SMB3")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: DaeMyung Kang <charsyam@xxxxxxxxx>
---
fs/smb/server/smb2pdu.c | 2 ++
fs/smb/server/vfs.c | 6 +++++-
2 files changed, 7 insertions(+), 1 deletion(-)

diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index 4d43de74f..52a19871d 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -3420,6 +3420,8 @@ static noinline int smb2_set_stream_name_xattr(const struct path *path,
xattr_stream_size, xattr_stream_name);
if (rc >= 0)
return 0;
+ if (rc != -ENOENT && rc != -ENODATA)
+ return rc;

if (fp->cdoption == FILE_OPEN_LE) {
if (!strcmp(stream_name, "AFP_AfpInfo") &&
diff --git a/fs/smb/server/vfs.c b/fs/smb/server/vfs.c
index 7020b7de3..3fa0e26e5 100644
--- a/fs/smb/server/vfs.c
+++ b/fs/smb/server/vfs.c
@@ -1952,7 +1952,11 @@ ssize_t ksmbd_vfs_casexattr_len(struct mnt_idmap *idmap,
ssize_t value_len = -ENOENT, xattr_list_len;

xattr_list_len = ksmbd_vfs_listxattr(dentry, &xattr_list);
- if (xattr_list_len <= 0)
+ if (xattr_list_len < 0) {
+ value_len = xattr_list_len;
+ goto out;
+ }
+ if (!xattr_list_len)
goto out;

for (name = xattr_list; name - xattr_list < xattr_list_len;
--
2.43.0