ksmbd: Windows 11 SMB 3.1.1 interoperability fixes - #2637
Open
vfsci-bot[bot] wants to merge 2 commits into
Open
vfsci-bot[bot] wants to merge 2 commits into
vfsci-bot[bot] wants to merge 2 commits into
Conversation
added 2 commits
September 20, 2026 11:03
In SMB 3.1.1, clients such as Windows 11 send chained compressed
write requests containing multiple payload segments (for example,
None + Pattern_V1) when transferring zero-heavy or compressible
files.
According to MS-SMB2 section 2.2.42.2.1, the first payload header in
a chained compression transform MUST have SMB2_COMPRESSION_FLAG_CHAINED
(0x0001) set. Trailing payload headers in the chain correspond to
subsequent payloads, where the specification defines
SMB2_COMPRESSION_FLAG_NONE (0x0000).
However, Windows clients do not always explicitly zero the 16-bit
Flags field on subsequent payload headers during chunk construction
(as described in MS-SMB2 section 3.1.4.4 step 2), leaving residual
bits in the Flags field.
smb_decompress_chained() currently enforces:
(!first && flags != cpu_to_le16(SMB2_COMPRESSION_FLAG_NONE))
returning -EINVAL if any trailing payload has non-zero flags. When
this occurs during large file writes (such as copying VHDX files),
ksmbd breaks the connection receive loop and abruptly terminates
the TCP connection with ECONNRESET (-104), causing Windows clients to
fail with error 0x8007003B (ERROR_UNEXP_NET_ERR).
Fix this by relaxing the flags requirement on trailing payloads in
smb_decompress_chained(). Conforming chains still strictly require
SMB2_COMPRESSION_FLAG_CHAINED on the first payload header, but for
subsequent payloads, only reject headers that attempt to initiate an
invalid nested chain (SMB2_COMPRESSION_FLAG_CHAINED). All payload
lengths, decompression algorithms, and total uncompressed output sizes
continue to be strictly validated against the transform's
OriginalCompressedSegmentSize.
Assisted-by: OpenCode:gpt-6-astra
Signed-off-by: Omkar Chandorkar <gotenksIN@aospa.co>
Named pipe handles are tracked in sess->rpc_handle_list rather than sess->file_table.idr. The generic IOCTL file lookup therefore returns -ENOENT and STATUS_OBJECT_NAME_NOT_FOUND for valid Windows 11 FSCTL_PIPE_TRANSCEIVE requests. Validate the RPC handle under rpc_lock and bypass the regular file lookup only when the handle exists. Return STATUS_FILE_CLOSED for invalid handles. Populate response file IDs before dispatching the transceive request. Assisted-by: OpenCode:gpt-6-astra Signed-off-by: Omkar Chandorkar <gotenksIN@aospa.co>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Series: https://patchwork.kernel.org/project/linux-fsdevel/list/?series=1169605
Submitter: Omkar Chandorkar
Version: 2
Patches: 2/2
Message-ID:
<20260920053126.28654-1-gotenksIN@aospa.co>Base: vfs.base.ci
Lore: https://lore.kernel.org/linux-fsdevel/20260920053126.28654-1-gotenksIN@aospa.co
Automated by ml2pr