Skip to content

Commit 021840c

Browse files
paliSteve French
authored andcommitted
cifs: Fix struct FILE_ALL_INFO
struct FILE_ALL_INFO for level 263 (0x107) used by QPathInfo does not have any IndexNumber, AccessFlags, IndexNumber1, CurrentByteOffset, Mode or AlignmentRequirement members. So remove all of them. Also adjust code in move_cifs_info_to_smb2() function which converts struct FILE_ALL_INFO to struct smb2_file_all_info. Fixed content of struct FILE_ALL_INFO was verified that is correct against: * [MS-CIFS] section 2.2.8.3.10 SMB_QUERY_FILE_ALL_INFO * Samba server implementation of trans2 query file/path for level 263 * Packet structure tests against Windows SMB servers This change fixes CIFSSMBQFileInfo() and CIFSSMBQPathInfo() functions which directly copy received FILE_ALL_INFO network buffers into kernel structures of FILE_ALL_INFO type. struct FILE_ALL_INFO is the response structure returned by the SMB server. So the incorrect definition of this structure can lead to returning bogus information in stat() call. Signed-off-by: Pali Rohár <pali@kernel.org> Signed-off-by: Steve French <stfrench@microsoft.com>
1 parent 071b8a6 commit 021840c

File tree

2 files changed

+7
-11
lines changed

2 files changed

+7
-11
lines changed

fs/smb/client/cifsglob.h

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -2203,11 +2203,13 @@ static inline size_t ntlmssp_workstation_name_size(const struct cifs_ses *ses)
22032203

22042204
static inline void move_cifs_info_to_smb2(struct smb2_file_all_info *dst, const FILE_ALL_INFO *src)
22052205
{
2206-
memcpy(dst, src, (size_t)((u8 *)&src->AccessFlags - (u8 *)src));
2207-
dst->AccessFlags = src->AccessFlags;
2208-
dst->CurrentByteOffset = src->CurrentByteOffset;
2209-
dst->Mode = src->Mode;
2210-
dst->AlignmentRequirement = src->AlignmentRequirement;
2206+
memcpy(dst, src, (size_t)((u8 *)&src->EASize - (u8 *)src));
2207+
dst->IndexNumber = 0;
2208+
dst->EASize = src->EASize;
2209+
dst->AccessFlags = 0;
2210+
dst->CurrentByteOffset = 0;
2211+
dst->Mode = 0;
2212+
dst->AlignmentRequirement = 0;
22112213
dst->FileNameLength = src->FileNameLength;
22122214
}
22132215

fs/smb/client/cifspdu.h

Lines changed: 0 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2290,13 +2290,7 @@ typedef struct { /* data block encoding of response to level 263 QPathInfo */
22902290
__u8 DeletePending;
22912291
__u8 Directory;
22922292
__u16 Pad2;
2293-
__le64 IndexNumber;
22942293
__le32 EASize;
2295-
__le32 AccessFlags;
2296-
__u64 IndexNumber1;
2297-
__le64 CurrentByteOffset;
2298-
__le32 Mode;
2299-
__le32 AlignmentRequirement;
23002294
__le32 FileNameLength;
23012295
union {
23022296
char __pad;

0 commit comments

Comments
 (0)