mirror of
https://github.com/torvalds/linux.git
synced 2026-10-10 12:28:02 +02:00
ksmbd: fix AsyncId zeroed before use in smb2_lock() cancel response
release_async_work() zeroes work->async_id before the CANCELLED path calls smb2_send_interim_resp(work, STATUS_CANCELLED), which reads work->async_id to build the response's AsyncId field. The cancellation response for a cancelled blocked-lock request is sent with AsyncId=0 instead of the id the client received in the original STATUS_PENDING response for this request. Checked against every other release_async_work() call site in this file: smb2_read()/smb2_write() don't send a further async response afterward (their status goes out on the synchronous path instead), and smb2_notify()'s two async paths already transfer the id to a separate struct before releasing, so this reordering is scoped to smb2_lock() only. Send the STATUS_CANCELLED response while work->async_id is still valid, then release the async work afterward. Signed-off-by: Gael Blivet <gael.blivet@gmail.com> Assisted-by: Claude:claude-sonnet-5 Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
This commit is contained in:
parent
08f41323f5
commit
7b46161088
|
|
@ -9319,22 +9319,25 @@ int smb2_lock(struct ksmbd_work *work)
|
|||
spin_unlock(&fp->f_lock);
|
||||
|
||||
list_del(&smb_lock->llist);
|
||||
release_async_work(work);
|
||||
|
||||
if (work->state == KSMBD_WORK_ACTIVE)
|
||||
goto retry;
|
||||
|
||||
locks_free_lock(flock);
|
||||
|
||||
if (work->state == KSMBD_WORK_CANCELLED) {
|
||||
rsp->hdr.Status = STATUS_CANCELLED;
|
||||
kfree(smb_lock);
|
||||
smb2_send_interim_resp(work,
|
||||
STATUS_CANCELLED);
|
||||
release_async_work(work);
|
||||
locks_free_lock(flock);
|
||||
work->send_no_response = 1;
|
||||
goto out;
|
||||
}
|
||||
|
||||
release_async_work(work);
|
||||
|
||||
if (work->state == KSMBD_WORK_ACTIVE)
|
||||
goto retry;
|
||||
|
||||
locks_free_lock(flock);
|
||||
|
||||
rsp->hdr.Status =
|
||||
STATUS_RANGE_NOT_LOCKED;
|
||||
kfree(smb_lock);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user