{"id":2225260,"url":"http://patchwork.ozlabs.org/api/1.1/patches/2225260/?format=json","web_url":"http://patchwork.ozlabs.org/project/linux-cifs-client/patch/20260420175125.3341090-1-charsyam@gmail.com/","project":{"id":12,"url":"http://patchwork.ozlabs.org/api/1.1/projects/12/?format=json","name":"Linux CIFS Client","link_name":"linux-cifs-client","list_id":"linux-cifs.vger.kernel.org","list_email":"linux-cifs@vger.kernel.org","web_url":"","scm_url":"","webscm_url":""},"msgid":"<20260420175125.3341090-1-charsyam@gmail.com>","date":"2026-04-20T17:51:25","name":"[2/2] ksmbd: fix CreateOptions sanitization clobbering the whole field","commit_ref":null,"pull_url":null,"state":"new","archived":false,"hash":"9b3eb76c8c73de19fc08b26bcfd5f205270c172a","submitter":{"id":93166,"url":"http://patchwork.ozlabs.org/api/1.1/people/93166/?format=json","name":"CharSyam","email":"charsyam@gmail.com"},"delegate":null,"mbox":"http://patchwork.ozlabs.org/project/linux-cifs-client/patch/20260420175125.3341090-1-charsyam@gmail.com/mbox/","series":[{"id":500659,"url":"http://patchwork.ozlabs.org/api/1.1/series/500659/?format=json","web_url":"http://patchwork.ozlabs.org/project/linux-cifs-client/list/?series=500659","date":"2026-04-20T17:51:25","name":null,"version":1,"mbox":"http://patchwork.ozlabs.org/series/500659/mbox/"}],"comments":"http://patchwork.ozlabs.org/api/patches/2225260/comments/","check":"pending","checks":"http://patchwork.ozlabs.org/api/patches/2225260/checks/","tags":{},"headers":{"Return-Path":"\n <linux-cifs+bounces-10969-incoming=patchwork.ozlabs.org@vger.kernel.org>","X-Original-To":["incoming@patchwork.ozlabs.org","linux-cifs@vger.kernel.org"],"Delivered-To":"patchwork-incoming@legolas.ozlabs.org","Authentication-Results":["legolas.ozlabs.org;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256\n header.s=20251104 header.b=fAq8XLwG;\n\tdkim-atps=neutral","legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org\n (client-ip=2600:3c0a:e001:db::12fc:5321; helo=sea.lore.kernel.org;\n envelope-from=linux-cifs+bounces-10969-incoming=patchwork.ozlabs.org@vger.kernel.org;\n receiver=patchwork.ozlabs.org)","smtp.subspace.kernel.org;\n\tdkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com\n header.b=\"fAq8XLwG\"","smtp.subspace.kernel.org;\n arc=none smtp.client-ip=209.85.210.178","smtp.subspace.kernel.org;\n dmarc=pass (p=none dis=none) header.from=gmail.com","smtp.subspace.kernel.org;\n spf=pass smtp.mailfrom=gmail.com"],"Received":["from sea.lore.kernel.org (sea.lore.kernel.org\n [IPv6:2600:3c0a:e001:db::12fc:5321])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4fztp14QsHz1yD4\n\tfor <incoming@patchwork.ozlabs.org>; Tue, 21 Apr 2026 04:10:49 +1000 (AEST)","from smtp.subspace.kernel.org (conduit.subspace.kernel.org\n [100.90.174.1])\n\tby sea.lore.kernel.org (Postfix) with ESMTP id 29EEF30AF346\n\tfor <incoming@patchwork.ozlabs.org>; Mon, 20 Apr 2026 17:51:37 +0000 (UTC)","from localhost.localdomain (localhost.localdomain [127.0.0.1])\n\tby smtp.subspace.kernel.org (Postfix) with ESMTP id D5BC03A0E97;\n\tMon, 20 Apr 2026 17:51:35 +0000 (UTC)","from mail-pf1-f178.google.com (mail-pf1-f178.google.com\n [209.85.210.178])\n\t(using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))\n\t(No client certificate requested)\n\tby smtp.subspace.kernel.org (Postfix) with ESMTPS id A3EF239D6D5\n\tfor <linux-cifs@vger.kernel.org>; Mon, 20 Apr 2026 17:51:34 +0000 (UTC)","by mail-pf1-f178.google.com with SMTP id\n d2e1a72fcca58-823be54d49cso393876b3a.3\n        for <linux-cifs@vger.kernel.org>;\n Mon, 20 Apr 2026 10:51:34 -0700 (PDT)","from ser8.. ([221.156.231.192])\n        by smtp.gmail.com with ESMTPSA id\n d2e1a72fcca58-82f97eb5ce8sm9299074b3a.61.2026.04.20.10.51.31\n        (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);\n        Mon, 20 Apr 2026 10:51:33 -0700 (PDT)"],"ARC-Seal":"i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116;\n\tt=1776707495; cv=none;\n b=qArQ1pHRR050V4TLSUPGatj5kXhIXH5ZJCUwZfDCBXWbWq470QZI7fYtB5Wf1BNwTEtr0Do0hkJ9SG0/guHGD+vbLE6e64OeLhVvUXLhv4mFuMSBuc5ZVbK+/XT6Eih0EYvuOakyttHEnTEFbTYl0bMnkRlt/NGXl6qNblkgxig=","ARC-Message-Signature":"i=1; a=rsa-sha256; d=subspace.kernel.org;\n\ts=arc-20240116; t=1776707495; c=relaxed/simple;\n\tbh=uam3YtKNdr+siwieCKD8+jNVlZSofiVOKYEtdaCJ0Jc=;\n\th=From:To:Cc:Subject:Date:Message-ID:MIME-Version;\n b=NX+L5bGNs2u3pyZg24gbul8+N22nfQgWoGVbscYpa3QG4TdCaCQJDK335Rzm+L0DR/uiRFUitBlZenC0N7Sgajq1Ttj5/kSvVYJpUkUwnRVHYY+xriokjCuo3kLhtC2Oe/y6fT8lxhYazXBVhmzyQBedBUAQ1n1kiSo+WSqRins=","ARC-Authentication-Results":"i=1; smtp.subspace.kernel.org;\n dmarc=pass (p=none dis=none) header.from=gmail.com;\n spf=pass smtp.mailfrom=gmail.com;\n dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com\n header.b=fAq8XLwG; arc=none smtp.client-ip=209.85.210.178","DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n        d=gmail.com; s=20251104; t=1776707494; x=1777312294;\n darn=vger.kernel.org;\n        h=content-transfer-encoding:mime-version:message-id:date:subject:cc\n         :to:from:from:to:cc:subject:date:message-id:reply-to;\n        bh=Xv8YKf2c4/2CV26eV/yRwUDY1hw9RhAfAYIys2Ru/sM=;\n        b=fAq8XLwGzdXaQqDAu4KgdRdU09jTgK8NBLFzeX/WW88wErAnRcaJKqEL7i5+kPuYoH\n         IvTGN/45WNBP6kk1Xhbzs1F8byafoTnYqA4FdcJi+kpafl5GT/kLpAVSv/9zx3dPUwOl\n         4ksuCprbklA/I74R2/LdhxJzc/rmz478h3LwiU/O0OpU8VVavz0YiR8Gm3pjfmeJPLXa\n         AEY3vG7Y3l1B/zP/wZhWiOOvsJ4AAo8Fs2Y/Ss5X77o+ZkvrbcckOJP3SdQpu2gk4Th+\n         y0j2eiKMlCK85S116M9579K3bYA/RIGcjLsV2WntasSZc1dXLISogHbymDwI3u6eKgCj\n         Wicg==","X-Google-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n        d=1e100.net; s=20251104; t=1776707494; x=1777312294;\n        h=content-transfer-encoding:mime-version:message-id:date:subject:cc\n         :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date\n         :message-id:reply-to;\n        bh=Xv8YKf2c4/2CV26eV/yRwUDY1hw9RhAfAYIys2Ru/sM=;\n        b=UkzplVxB3+zCL2V8Pw0QYyLV6qoKZ6ekbb75GibYNHBxKJuVtY6cnfDG3x0DpRSEzk\n         IrmalMvMaq/uEiKpBMDoIjHDb47FPOB2u7KoU9v23PDOtI9ZonwAsCVuAmmDy9oWti6G\n         3PHJ1fXIYqa83LzGVvnpGB42rl3rYau9wijKpEnlL8xTkba/dkkcpWbgYr8I265ADxwX\n         zMX5qFAx9eY9RZ2ekzGsdjtn5Qstj4QtI38DlfTi4HPVfMyJLMJNdr1KFfPb5vjCeVCN\n         kIePuYT1nIITkStyYDUG7umEFxhH4LokY63n50r30pLhizGfyNt0IVN1qI7d1p7W1WH6\n         KgxA==","X-Forwarded-Encrypted":"i=1;\n AFNElJ/LZt1FAjKj/7LG99ywmVTLhx5c2ssjGCdQH/hoeNzlrenvVz17sJXLhY01YyB0muZUdHPBhuAJs/+O@vger.kernel.org","X-Gm-Message-State":"AOJu0YzHOG2L7rnYX1S0EKARF2K8isbN+86DGbRkd42aCytthtvjgVcw\n\tp7/tQwzyVidq+r7w5IipP149nDTo7ffMiSQunBJbJfPZBwZCYfsxijf3","X-Gm-Gg":"AeBDieuFJk5aK7ZiPHhhAbEmFWrWb68eZY9pVQlEPSXoGpsx5VfoXdIPnTY5SuaD31Y\n\tPJp7yXzPhvyRrtZjr6v/Eo/XdEwKfXZA6IWjChLt82y7HBCkNrzbR/3/Y6l4bNl6OyunoIzQrru\n\tViFb+a1XjFxd0duOOnzoA1CqgMYi2G06ZMeuMOw0WsSQjIQsn8AO93yeRGx0Tb616Ofr7fbPS+r\n\tdFoj2np0Zd/jKjmwudt9rLwm5gP5l3DYvFF1uopfvcSqm/4weyoLiWvr5k1R6pYd7uvSjaziJ+H\n\t4AoSUrNITEj7PyDB7XcPEPhm4JgFX474zFJjpxvhw3gbDrkEa2174SCHmqQnePNVVCcaWOilb5u\n\tQYqx+GJ/OObFcYWrZ5f38ie7Za/OxxqUMF2q/N6Apm/zl2nqGHfNX492tYSe3d5wte2CUcmb0r2\n\tIWCkyyHV3a319zY4wIgEYRKpMU4UQ=","X-Received":"by 2002:a05:6a00:2d03:b0:82f:6a82:4231 with SMTP id\n d2e1a72fcca58-82f8c85475fmr7428020b3a.1.1776707493907;\n        Mon, 20 Apr 2026 10:51:33 -0700 (PDT)","From":"DaeMyung Kang <charsyam@gmail.com>","To":"Namjae Jeon <linkinjeon@kernel.org>,\n\tSteve French <smfrench@gmail.com>","Cc":"Sergey Senozhatsky <senozhatsky@chromium.org>,\n\tTom Talpey <tom@talpey.com>,\n\tlinux-cifs@vger.kernel.org,\n\tlinux-kernel@vger.kernel.org,\n\tDaeMyung Kang <charsyam@gmail.com>","Subject":"[PATCH 2/2] ksmbd: fix CreateOptions sanitization clobbering the\n whole field","Date":"Tue, 21 Apr 2026 02:51:25 +0900","Message-ID":"<20260420175125.3341090-1-charsyam@gmail.com>","X-Mailer":"git-send-email 2.43.0","Precedence":"bulk","X-Mailing-List":"linux-cifs@vger.kernel.org","List-Id":"<linux-cifs.vger.kernel.org>","List-Subscribe":"<mailto:linux-cifs+subscribe@vger.kernel.org>","List-Unsubscribe":"<mailto:linux-cifs+unsubscribe@vger.kernel.org>","MIME-Version":"1.0","Content-Transfer-Encoding":"8bit"},"content":"smb2_open() attempts to clear conflicting CreateOptions bits\n(FILE_SEQUENTIAL_ONLY_LE together with FILE_RANDOM_ACCESS_LE, and\nFILE_NO_COMPRESSION_LE on a directory open), but uses a plain\nassignment of the bitwise negation of the target flag:\n\n\treq->CreateOptions = ~(FILE_SEQUENTIAL_ONLY_LE);\n\treq->CreateOptions = ~(FILE_NO_COMPRESSION_LE);\n\nThis replaces the entire field with 0xFFFFFFFB / 0xFFFFFFEF rather\nthan clearing a single bit. With the SEQUENTIAL/RANDOM case, the\nnext check for FILE_OPEN_BY_FILE_ID_LE | CREATE_TREE_CONNECTION |\nFILE_RESERVE_OPFILTER_LE then trivially matches and a legitimate\nrequest is rejected with -EOPNOTSUPP. With the NO_COMPRESSION case,\nevery downstream test (FILE_DELETE_ON_CLOSE, etc.) operates on a\ncorrupted CreateOptions value.\n\nUse &= ~FLAG to clear only the intended bit in both places.\n---\n fs/smb/server/smb2pdu.c | 4 ++--\n 1 file changed, 2 insertions(+), 2 deletions(-)","diff":"diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c\nindex 6a60f97baa60..38d3bc66912d 100644\n--- a/fs/smb/server/smb2pdu.c\n+++ b/fs/smb/server/smb2pdu.c\n@@ -3063,7 +3063,7 @@ int smb2_open(struct ksmbd_work *work)\n \t} else {\n \t\tif (req->CreateOptions & FILE_SEQUENTIAL_ONLY_LE &&\n \t\t    req->CreateOptions & FILE_RANDOM_ACCESS_LE)\n-\t\t\treq->CreateOptions = ~(FILE_SEQUENTIAL_ONLY_LE);\n+\t\t\treq->CreateOptions &= ~FILE_SEQUENTIAL_ONLY_LE;\n \n \t\tif (req->CreateOptions &\n \t\t    (FILE_OPEN_BY_FILE_ID_LE | CREATE_TREE_CONNECTION |\n@@ -3077,7 +3077,7 @@ int smb2_open(struct ksmbd_work *work)\n \t\t\t\trc = -EINVAL;\n \t\t\t\tgoto err_out2;\n \t\t\t} else if (req->CreateOptions & FILE_NO_COMPRESSION_LE) {\n-\t\t\t\treq->CreateOptions = ~(FILE_NO_COMPRESSION_LE);\n+\t\t\t\treq->CreateOptions &= ~FILE_NO_COMPRESSION_LE;\n \t\t\t}\n \t\t}\n \t}\n","prefixes":["2/2"]}