]> www.infradead.org Git - users/hch/misc.git/commitdiff
cifs: Fix struct FILE_ALL_INFO
authorPali Rohár <pali@kernel.org>
Sun, 29 Dec 2024 14:31:05 +0000 (15:31 +0100)
committerSteve French <stfrench@microsoft.com>
Fri, 31 Jan 2025 18:51:44 +0000 (12:51 -0600)
struct FILE_ALL_INFO for level 263 (0x107) used by QPathInfo does not have
any IndexNumber, AccessFlags, IndexNumber1, CurrentByteOffset, Mode or
AlignmentRequirement members. So remove all of them.

Also adjust code in move_cifs_info_to_smb2() function which converts struct
FILE_ALL_INFO to struct smb2_file_all_info.

Fixed content of struct FILE_ALL_INFO was verified that is correct against:
* [MS-CIFS] section 2.2.8.3.10 SMB_QUERY_FILE_ALL_INFO
* Samba server implementation of trans2 query file/path for level 263
* Packet structure tests against Windows SMB servers

This change fixes CIFSSMBQFileInfo() and CIFSSMBQPathInfo() functions which
directly copy received FILE_ALL_INFO network buffers into kernel structures
of FILE_ALL_INFO type.

struct FILE_ALL_INFO is the response structure returned by the SMB server.
So the incorrect definition of this structure can lead to returning bogus
information in stat() call.

Signed-off-by: Pali Rohár <pali@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
fs/smb/client/cifsglob.h
fs/smb/client/cifspdu.h

index ee9754fad3e8af50de9857ce7c602c7c4d4f3112..5ba6b46fe9d1ef3e32c1d821bb340deb2d714993 100644 (file)
@@ -2203,11 +2203,13 @@ static inline size_t ntlmssp_workstation_name_size(const struct cifs_ses *ses)
 
 static inline void move_cifs_info_to_smb2(struct smb2_file_all_info *dst, const FILE_ALL_INFO *src)
 {
-       memcpy(dst, src, (size_t)((u8 *)&src->AccessFlags - (u8 *)src));
-       dst->AccessFlags = src->AccessFlags;
-       dst->CurrentByteOffset = src->CurrentByteOffset;
-       dst->Mode = src->Mode;
-       dst->AlignmentRequirement = src->AlignmentRequirement;
+       memcpy(dst, src, (size_t)((u8 *)&src->EASize - (u8 *)src));
+       dst->IndexNumber = 0;
+       dst->EASize = src->EASize;
+       dst->AccessFlags = 0;
+       dst->CurrentByteOffset = 0;
+       dst->Mode = 0;
+       dst->AlignmentRequirement = 0;
        dst->FileNameLength = src->FileNameLength;
 }
 
index 84743f3d7c5121ab2568909fe20634c4d8ca0854..48d0d6f439cf456b07c7bdf9a0f36447dd93be2a 100644 (file)
@@ -2290,13 +2290,7 @@ typedef struct { /* data block encoding of response to level 263 QPathInfo */
        __u8 DeletePending;
        __u8 Directory;
        __u16 Pad2;
-       __le64 IndexNumber;
        __le32 EASize;
-       __le32 AccessFlags;
-       __u64 IndexNumber1;
-       __le64 CurrentByteOffset;
-       __le32 Mode;
-       __le32 AlignmentRequirement;
        __le32 FileNameLength;
        union {
                char __pad;