From 7f07791522a251e2be087d11ae9cd51eb3408f1d Mon Sep 17 00:00:00 2001 From: Namjae Jeon Date: Thu, 9 Jul 2026 20:08:10 +0900 Subject: [PATCH] ksmbd: handle empty QUERY_ALLOCATED_RANGES output FSCTL_QUERY_ALLOCATED_RANGES can be issued with a valid input buffer but without room for an output range. Do not reject the request before looking at the file layout. If the query would produce a range, return STATUS_BUFFER_TOO_SMALL. If it produces no ranges, return success with an empty output. Signed-off-by: Namjae Jeon --- fs/smb/server/smb2pdu.c | 16 ++++++++++++---- 1 file changed, 12 insertions(+), 4 deletions(-) diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c index dc49e41e1a14..41d60c214a07 100644 --- a/fs/smb/server/smb2pdu.c +++ b/fs/smb/server/smb2pdu.c @@ -9085,8 +9085,6 @@ static int fsctl_query_allocated_ranges(struct ksmbd_work *work, u64 id, int ret = 0; *out_count = 0; - if (in_count == 0) - return -EINVAL; start = le64_to_cpu(qar_req->file_offset); length = le64_to_cpu(qar_req->length); @@ -9098,8 +9096,18 @@ static int fsctl_query_allocated_ranges(struct ksmbd_work *work, u64 id, if (!fp) return -ENOENT; - ret = ksmbd_vfs_fqar_lseek(fp, start, length, - qar_rsp, in_count, out_count); + if (!in_count) { + struct file_allocated_range_buffer range; + + ret = ksmbd_vfs_fqar_lseek(fp, start, length, &range, 1, + out_count); + if (!ret && *out_count) + ret = -ENOSPC; + *out_count = 0; + } else { + ret = ksmbd_vfs_fqar_lseek(fp, start, length, + qar_rsp, in_count, out_count); + } if (ret && ret != -E2BIG) *out_count = 0;