[PATCH 0/3] ksmbd: fix three named stream bugs
From: DaeMyung Kang
Date: Thu Oct 08 2026 - 11:33:48 EST
Hi Namjae,
This series fixes three independent named stream bugs:
1. A read at or beyond the end of a non-empty stream returns
STATUS_INVALID_PARAMETER instead of STATUS_END_OF_FILE.
2. Opening an existing stream with different letter case keeps the
client's spelling in the handle. Later writes and removal can
target a different xattr from the one that was opened.
3. A write-only FILE_OPEN_IF on an existing stream can replace its
value with an empty xattr when the value-length lookup fails with
-EACCES.
The series applies to ksmbd-for-next at 5d2b1ab54e9a ("ksmbd: fix
named stream write and EOF handling"). Each fix is in a separate
patch, with its own Fixes tag and stable Cc.
I built the resulting kernel with CONFIG_SMB_SERVER=y and tested it
through SMB2.1 in a QEMU guest. Reads at and past stream EOF returned
STATUS_END_OF_FILE. A stream created as Foo was read, modified and
removed through foo, with one named stream in the listing. On a 0222
file, a write-only user opening an existing stream with FILE_OPEN_IF
received STATUS_ACCESS_DENIED and the original value remained intact;
without patch 3, the same sequence emptied the stream. The same user
could still create a new stream.
Patch 2 has a minor textual conflict in linux-next with the VFS tree's
const mnt_idmap conversion. The resolution keeps both the const
qualifier and the new actual_name argument.
Concurrent creation of case-variant stream names remains a separate
issue.
DaeMyung Kang (3):
ksmbd: return end of file for reads past a named stream's data
ksmbd: use the existing xattr name for a named stream
ksmbd: preserve unreadable named streams on open
fs/smb/server/smb2pdu.c | 10 ++++++----
fs/smb/server/vfs.c | 17 +++++++++++++----
fs/smb/server/vfs.h | 2 +-
3 files changed, 20 insertions(+), 9 deletions(-)
--
2.43.0