Commit Graph

1465200 Commits

Author SHA1 Message Date
Gael Blivet
5838cfd611 ksmbd: validate out_buf_len before FSCTL_CREATE_OR_GET_OBJECT_ID and FSCTL_GET_REPARSE_POINT writes
Both cases write a fixed-size response structure into rsp->Buffer
without first checking that out_buf_len (the space smb2_ioctl()
actually has available, computed by smb2_calc_max_out_buf_len() from
the client's OutputBufferLength minus space already consumed earlier
in a compound request) is large enough. Every comparable case in this
same switch (FSCTL_SRV_ENUMERATE_SNAPSHOTS, FSCTL_GET_COMPRESSION,
FSCTL_VALIDATE_NEGOTIATE_INFO, FSCTL_SRV_REQUEST_RESUME_KEY,
FSCTL_SRV_COPYCHUNK) validates this first; these two don't.

A client can send a compound SMB2 request where an earlier command in
the same compound chain consumes most of work->response_buf, leaving
smb2_calc_max_out_buf_len() only a few bytes of out_buf_len for a
trailing FSCTL_CREATE_OR_GET_OBJECT_ID or FSCTL_GET_REPARSE_POINT.
Both then unconditionally write their full fixed-size structure
(64 bytes and 8 bytes respectively) at rsp->Buffer[0] regardless,
overflowing past the actual remaining space in the response buffer.

Add the same out_buf_len check used by every other fixed-size-response
case in this function, before the write.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Gael Blivet <gael.blivet@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:40 +09:00
Gael Blivet
c1d7bbfc5e ksmbd: fix durable handle v2 default timeout units (60 -> 60000)
When a client's Durable Handle Request V2 sets Timeout=0 ("let the
server choose"), fp->durable_timeout was set to 60. Every other use
of this field is in milliseconds: DURABLE_HANDLE_MAX_TIMEOUT (300000)
in smb2pdu.h, the nonzero branch immediately above
(min_t(unsigned int, dh_info.timeout, DURABLE_HANDLE_MAX_TIMEOUT),
where dh_info.timeout is the wire value and already milliseconds per
spec), and the scavenger in vfs_cache.c, which adds it directly to
jiffies_to_msecs(jiffies).

60 is off by 1000x: the handle becomes scavenger-eligible 60
milliseconds after close instead of 60 seconds. A client requesting
Timeout=0 is relying entirely on the server's default to cover the
gap between a dropped connection and its reconnect -- 60ms is not
enough time for even a fast network blip to be detected and
reconnected, so any real disruption loses the race and a subsequent
DH2C reconnect fails with a durable-handle lookup miss instead of
succeeding.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Gael Blivet <gael.blivet@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:39 +09:00
Gael Blivet
445b2244b6 ksmbd: route stream FileDispositionInformation through stream delete flag
ksmbd_fd_set_delete_pending()/ksmbd_fd_clear_delete_pending()
to keep a stream's FileDispositionInformation from marking the whole
file for deletion, but used the inode-wide S_DEL_ON_CLS_STREAM flag to
do it -- the exact same problem class the commit was fixing, one level
up.

S_DEL_ON_CLS_STREAM lives on the shared ksmbd_inode, not on any
specific stream handle. If a file has multiple stream handles open and
one gets marked delete-pending via FileDispositionInformation, the
flag can't record *which* stream should be deleted: whichever stream
handle happens to close first (not necessarily the one that was
actually marked) sees S_DEL_ON_CLS_STREAM set and has its xattr
removed. Two clients (or two handles from the same client) touching
different streams on the same file can end up deleting the wrong one.

ksmbd_inode_pending_delete() has the same issue: it only checks
S_DEL_PENDING, which is never set for a stream handle, so a client
querying FileStandardInformation.DeletePending on a stream marked via
this path would incorrectly see 0.

Track this per-handle instead (stream_del_pending on struct
ksmbd_file), matching the file itself rather than the shared inode.
ksmbd_fd_set_delete_on_close() (the CREATE-time FILE_DELETE_ON_CLOSE
option, a separate call path from FileDispositionInformation) still
uses the inode-wide flag; __ksmbd_inode_close() now checks both, since
either one should trigger removing the stream's xattr on close.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Gael Blivet <gael.blivet@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:39 +09:00
Namjae Jeon
7f07791522 ksmbd: handle empty QUERY_ALLOCATED_RANGES output
FSCTL_QUERY_ALLOCATED_RANGES can be issued with a valid input buffer but
without room for an output range.  Do not reject the request before
looking at the file layout.  If the query would produce a range, return
STATUS_BUFFER_TOO_SMALL.  If it produces no ranges, return success with an
empty output.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:39 +09:00
Namjae Jeon
86c84cc760 ksmbd: allow FSCTL_SET_SPARSE without input buffer
FSCTL_SET_SPARSE without an input buffer sets a file sparse.  Treat a
zero-length input buffer as SetSparse=true and keep rejecting truncated
non-empty buffers.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:38 +09:00
Namjae Jeon
31169f4177 ksmbd: reject FSCTL_SET_SPARSE on directories
FSCTL_SET_SPARSE applies to files.  Return STATUS_INVALID_PARAMETER when a
client sends it for a directory handle instead of setting the sparse file
attribute on the directory.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:38 +09:00
Namjae Jeon
159e727f76 ksmbd: persist FSCTL_SET_SPARSE state
Advertise FILE_SUPPORTS_SPARSE_FILES so clients can use FSCTL_SET_SPARSE.
Do not mark regular files sparse just because sparse support is advertised;
FILE_ATTRIBUTE_SPARSE_FILE should reflect the state set by
FSCTL_SET_SPARSE.

Persist the sparse attribute in the DOS attribute xattr regardless of
the store dos attributes setting.  Restore the sparse and compressed bits
from that xattr when only those emulated attributes need to be preserved.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:37 +09:00
Namjae Jeon
962b9df472 ksmbd: preserve compression state across opens
The compression state can be emulated with the DOS attribute xattr when the
backing filesystem cannot store it directly.  Do not limit that state to
shares with store dos attributes enabled, otherwise a file reopened through
another handle can lose FILE_ATTRIBUTE_COMPRESSED in file information
responses.

Load only the compressed bit from the DOS attribute xattr when store dos
attributes is disabled.  Keep the normal DOS attribute behavior unchanged
when it is enabled.  Also avoid clearing an already restored compressed
bit just because the backing filesystem does not report FS_COMPR_FL.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:37 +09:00
Namjae Jeon
bea20b6516 ksmbd: preserve compression state in set basic info
FILE_ATTRIBUTE_COMPRESSED is controlled by FSCTL_SET_COMPRESSION and should
not be set directly through FileBasicInformation.  Keep the existing
compression state when updating basic attributes and ignore the compressed
bit supplied by the client in the basic information request.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:37 +09:00
Namjae Jeon
0fb327626a ksmbd: support file compression attributes
Advertise file compression support and keep the compression state in the
per-file DOS attributes when the backing filesystem cannot apply the
compression flag directly.  FSCTL_SET_COMPRESSION should still update the
state returned by FSCTL_GET_COMPRESSION and file compression information in
that case.

When a new object is created under a compressed directory, inherit the
compression attribute from the parent.  If FILE_NO_COMPRESSION is
specified, clear the compression state after creation and let it override
inheritance for both files and directories.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:36 +09:00
ChenXiaoSong
49f6a48586 smb/server: use MSG_EOR for async interim response
Two kernel_sendmsg() calls can still use the same TCP skb if the first skb
can take more data. This can happen when ksmbd sends two SMB2 responses
very close to each other.

Without MSG_EOR, TCP can append the next sendmsg data to the previous skb.
Then STATUS_PENDING and the later response can be put into the same TCP
skb. MSG_EOR marks the skb as end of record, so TCP will not collapse the
next sendmsg data into it.

Example:

  smbtorture //${server_ip}/export -U${username}%${password} smb2.compound_async.write_write

  Client request:

    Write Request Len:64 Off:0, File: compound_async_write_write; Write Request Len:64 Off:64

  Before this patch, server responses:

    Write Response, File: compound_async_write_write
    Write Response
      SMB2, STATUS_PENDING, Write Response, MessageId 7
      SMB2, Write Response, MessageId 7

  After this patch:

    Write Response, File: compound_async_write_write
    Write Response, Error: STATUS_PENDING
    Write Response

Signed-off-by: ChenXiaoSong <chenxiaosong@kylinos.cn>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:36 +09:00
ChenXiaoSong
0977715850 smb/server: introduce struct ksmbd_transport_write
Put the arguments of ksmbd_transport_ops ->writev() into a struct.
This makes the function call shorter and easier to read.

Add __ksmbd_conn_write() for the common write code. A later patch will use
it for another write helper.

No functional change.

Signed-off-by: ChenXiaoSong <chenxiaosong@kylinos.cn>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:36 +09:00
ChenXiaoSong
906a622163 smb/server: send compound prefix before async pending response
When the last request in a compound request becomes async, ksmbd sends a
STATUS_PENDING response for it. But the responses for previous requests in
the same compound request are still kept in the same response buffer.

Send these previous responses first. Clear NextCommand for the last
response in this part, sign it again if needed, and reset the iov state.
After that, the async request sends STATUS_PENDING first, and sends the
real response later. Both are separate responses.

Example:

  smbtorture //${server_ip}/export -U${username}%${password} smb2.compound_async.write_write

  Client request:

    Write Request Len:64 Off:0, File: compound_async_write_write; Write Request Len:64 Off:64

  Before this patch, STATUS_PENDING Write Response is the first of
  several responses:

    Write Response, Error: STATUS_PENDING
    Write Response, File: compound_async_write_write; Write Response

  But STATUS_PENDING Write Response should be in the middle of several
  responses, after this patch:

    Write Response, File: compound_async_write_write
    Write Response
      SMB2, STATUS_PENDING, Write Response, MessageId 7
      SMB2, Write Response, MessageId 7

Signed-off-by: ChenXiaoSong <chenxiaosong@kylinos.cn>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:35 +09:00
Namjae Jeon
7c5d98b515 ksmbd: distinguish unknown RPC pipe names
Unknown RPC pipe names and malformed CREATE parameters both use
-EINVAL. Mapping that errno to STATUS_OBJECT_NAME_NOT_FOUND therefore
also hides invalid request parameters as a missing pipe.

Return -ENOENT when RPC method lookup cannot find a supported pipe and
map only that error to STATUS_OBJECT_NAME_NOT_FOUND. Preserve
STATUS_INVALID_PARAMETER for -EINVAL returned by request validation.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:35 +09:00
Gael Blivet
13e82e2cbd ksmbd: clear stale sparse attribute on non-sparse shares
smb2_update_xattrs() copies the DOS SPARSE attribute bit verbatim from
the stored xattr into the in-memory file attributes, without checking
whether the share is currently advertising FILE_SUPPORTS_SPARSE_FILES.
A file whose xattr has a stale SPARSE bit (set by a previous client,
or from before the share was reconfigured) would keep reporting as
sparse even after sparse-file support is turned off for the share.
This matters for Time Machine: sparsebundle band files rely on
accurate sparse-file status being reported, since macOS decides
whether to issue FSCTL_SET_SPARSE based on it. Mask the bit out when
the share doesn't currently advertise sparse-file support.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Gael Blivet <gael.blivet@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:35 +09:00
Gael Blivet
92db30225e ksmbd: quiet mdssvc RPC log spam
macOS routinely probes the mdssvc RPC pipe to check for Spotlight
search support. __rpc_method() already falls through to returning 0
(unsupported) for it via the default case, but that path also logs
"Unsupported RPC: mdssvc" via pr_err on every single probe -- which
happens often enough during normal macOS browsing/backup activity to
spam the kernel log. Add an explicit case that returns the same value
without the log line; behavior is unchanged, this only removes noise
for an expected, routine client behavior.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Gael Blivet <gael.blivet@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:35 +09:00
Gael Blivet
9870bbb55a ksmbd: return STATUS_OBJECT_NAME_NOT_FOUND for unknown IPC pipe names
create_smb2_pipe() maps ksmbd_session_rpc_open() failing with -EINVAL
(pipe name not recognized/supported) to STATUS_INVALID_PARAMETER.
macOS Time Machine's backupd treats STATUS_INVALID_PARAMETER on a
pipe open as a fatal error and aborts the backup immediately, whereas
STATUS_OBJECT_NAME_NOT_FOUND is handled gracefully -- the client just
treats that particular pipe as unavailable and continues.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Gael Blivet <gael.blivet@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:34 +09:00
Gael Blivet
a9417bb188 ksmbd: report actual xattr value length for stream EndOfFile/AllocationSize
fp->stream.size holds the byte length of the mangled xattr *name*
string (it's used as the attr_name_len argument when looking up the
xattr), not the size of the stream's actual data. CREATE and every
QUERY_INFO handler that reports EndOfFile/AllocationSize for a stream
handle used fp->stream.size directly, so clients received a bogus
size derived from the internal xattr key name length instead of the
stream's real content length.

Add ksmbd_stream_eof() to query the xattr's actual value length via
ksmbd_vfs_casexattr_len(), and use it at every site that reports a
stream handle's size: the CREATE response, get_file_standard_info(),
get_file_all_info(), get_file_network_open_info(), and
find_file_posix_info().

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Gael Blivet <gael.blivet@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:34 +09:00
Gael Blivet
495ade881b ksmbd: route stream FileDispositionInformation through stream delete flag
set_file_disposition_info() calls ksmbd_set_inode_pending_delete() /
ksmbd_clear_inode_pending_delete() unconditionally, which always sets
S_DEL_PENDING on the whole inode (ci->m_flags), regardless of whether
the handle being closed is a regular file or an alternate data stream.

Requesting delete-pending on a single stream handle (e.g. deleting
just an alternate data stream some clients keep alongside a file)
would therefore incorrectly schedule deletion of the entire file's
data, not just the stream.

Add ksmbd_fd_set_delete_pending()/ksmbd_fd_clear_delete_pending(),
following the same stream-vs-whole-file routing pattern already used
by ksmbd_fd_set_delete_on_close() for the CREATE-time DeleteOnClose
option, and switch set_file_disposition_info() to use them.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Gael Blivet <gael.blivet@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:34 +09:00
Gael Blivet
d68d4b3293 ksmbd: fix off-by-one rejecting minimal COPYCHUNK query-limits request
The FSCTL_COPYCHUNK/FSCTL_COPYCHUNK_WRITE input length check uses
in_buf_len <= sizeof(struct copychunk_ioctl_req), which rejects a
buffer that is exactly sizeof(struct copychunk_ioctl_req) bytes -- the
minimal, valid request containing only the fixed header with
ChunkCount=0 and no chunk entries, used by clients to query the
server's copy limits before issuing a real copychunk.

Since copychunk_ioctl_req ends in a flexible array member, the correct
minimum is that the buffer covers the fixed header, so use
offsetof(..., Chunks) with '<' instead of '<=' against sizeof(): same
value, but the boundary case is now correctly accepted.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Gael Blivet <gael.blivet@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:33 +09:00
Namjae Jeon
f4ce7da9b3 ksmbd: handle AAPL stream copy length mismatch
macOS can reuse the main file's chunk list when issuing a copychunk
request for alternate data streams. The requested source range can
therefore exceed the length of the xattr-backed stream and currently
fails with STATUS_INVALID_VIEW_SIZE.

For AAPL connections copying between two streams, limit the actual copy
to the available source data while reporting the requested chunk length
as written. Keep the source range validation unchanged for non-AAPL
connections and requests involving a regular file.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:33 +09:00
Namjae Jeon
8482150a07 ksmbd: support copychunk for alternate data streams
Copychunk rejects requests when either handle refers to an alternate
data stream. These streams are stored in extended attributes and cannot
be passed directly to vfs_copy_file_range().

Use the bounded buffered copy path when a source or destination is a
stream. Obtain the source length from the stream extended attribute and
perform I/O through the existing stream-aware read and write helpers.
Keep vfs_copy_file_range() and its fallback for regular files only.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:33 +09:00
Namjae Jeon
f7c0366e0a ksmbd: preserve access denied status for copychunk
The copychunk error mapping handles -EACCES in an independent if
statement. The following error chain therefore reaches its final else
clause and overwrites STATUS_ACCESS_DENIED with
STATUS_UNEXPECTED_IO_ERROR.

Join the -EACCES check to the remaining error chain so an access failure
is returned as STATUS_ACCESS_DENIED.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:33 +09:00
Namjae Jeon
fd309860ef ksmbd: preserve data during overlapping copy chunk
Copying an overlapping range within the same file through
do_splice_direct() can overwrite source data that has not yet been
read. This corrupts the destination when the target range starts
inside and after the source range.

Handle overlapping ranges with a bounded temporary buffer. Copy from
the end when the destination follows the source and from the beginning
otherwise, providing memmove semantics without allocating the entire
copy length.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:32 +09:00
Namjae Jeon
c1c200924f ksmbd: return complete resume key response
The FSCTL_SRV_REQUEST_RESUME_KEY response contains a mandatory
four-byte context field after ContextLength.

Defining the context as a flexible array excludes it from
sizeof(struct resume_key_ioctl_rsp), so ksmbd sends only 28 bytes
instead of the required 32 bytes. The truncated response cannot be
decoded and results in an NDR buffer size error.

Define the reserved context as a fixed four-byte field. This makes the
response size match the wire format and ensures the field is zeroed and
included in OutputCount.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:32 +09:00
Namjae Jeon
d4ef8821fd ksmbd: support empty snapshot enumeration
FSCTL_SRV_ENUM_SNAPS is currently unimplemented, causing clients to
treat shadow-copy enumeration as unsupported even when the share simply
has no snapshots.

Handle the count-only SRV_SNAPSHOT_ARRAY request and return a valid
empty snapshot list after validating the file handle and minimum output
buffer size. Report a two-byte empty UTF-16 MULTI_SZ array and zero
snapshot counts.

This allows smb2.ioctl.shadow_copy to run without a snapshot backend.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:32 +09:00
Namjae Jeon
d112661f95 ksmbd: require read control for security information
SMB2 QUERY_INFO security requests currently return owner, group, and DACL
information without checking the access granted to the opened handle. A
handle opened with only SYNCHRONIZE or READ_ATTRIBUTES can consequently
read the security descriptor.

Require READ_CONTROL when OWNER_SECINFO, GROUP_SECINFO, or DACL_SECINFO
is requested and return STATUS_ACCESS_DENIED otherwise.

This fixes smb2.getinfo.getinfo_access.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:31 +09:00
Namjae Jeon
10aeff72ab ksmbd: support normalized name information
FILE_NORMALIZED_NAME_INFORMATION is not handled and is returned as
STATUS_INVALID_INFO_CLASS. SMB 3.1.1 clients use this information class
to obtain the share-relative path with the on-disk name casing.

Build the normalized path from the opened dentry, remove the leading
share-relative separator, and recover the canonical named-stream casing
from its backing xattr. Return an empty name for the share root and
STATUS_NOT_SUPPORTED for dialects older than SMB 3.1.1.

Also distinguish a named $DATA stream on a directory from the unnamed
data stream so that directory:stream:$DATA can be opened normally.

This fixes smb2.getinfo.normalized.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:31 +09:00
Namjae Jeon
2103add92a ksmbd: return buffer too small for short security queries
SMB2 QUERY_INFO security requests with an output buffer too small for
the self-relative security descriptor header can fall through descriptor
construction and be reported as STATUS_INVALID_INFO_CLASS.

After validating the file handle, reject buffers shorter than struct
smb_ntsd with STATUS_BUFFER_TOO_SMALL before building the descriptor.

This fixes smb2.getinfo.qsec_buffercheck.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:31 +09:00
Namjae Jeon
6b8b79226b ksmbd: fix partial file information responses
Variable-length file information handlers use the client output length
while constructing the response. FILE_ALL_INFORMATION can consequently
return -EINVAL before the common buffer check, while stream information
can stop building the complete result too early.

Build the complete response within the available server response buffer
and apply the client output length only when selecting the final status
and transmitted length. Use the protocol-defined fixed sizes for all,
alternate-name, and stream information to distinguish
STATUS_INFO_LENGTH_MISMATCH from STATUS_BUFFER_OVERFLOW.

This fixes smb2.getinfo.qfile_buffercheck.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:31 +09:00
Guangshuo Li
d40c24634f ksmbd: Do not skip lock checks for single-byte ranges
check_lock_range() uses inclusive ranges. Its callers pass the end
offset as start + length - 1, so start == end represents a valid
single-byte range rather than an empty range.

The start == end shortcut therefore skips mandatory byte-range lock
checks for one-byte reads, writes, copychunk operations and one-byte
truncate ranges. A conflicting lock covering that byte is not checked
and the operation is allowed to proceed.

Remove the shortcut. The truncate size == inode->i_size case is already
handled by only calling check_lock_range() when the new size differs
from the current file size.

Fixes: 5d510ac316 ("ksmbd: skip lock-range check on equal size to avoid size==0 underflow")
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:30 +09:00
Namjae Jeon
0ecd35fac4 ksmbd: return buffer overflow for partial filesystem info
The query-info buffer check returns STATUS_INFO_LENGTH_MISMATCH for
every output buffer smaller than the complete response. Variable-length
filesystem information instead requires STATUS_BUFFER_OVERFLOW when the
fixed portion fits but the complete data does not.

Pass the fixed size for each filesystem information class to the buffer
checker. Keep INFO_LENGTH_MISMATCH for buffers below that size, and
return BUFFER_OVERFLOW with a response truncated to the requested length
for larger partial buffers.

This fixes smb2.getinfo.qfs_buffercheck.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:30 +09:00
Namjae Jeon
8184c425a1 ksmbd: allow I/O on directory named streams
Named streams are stored as extended attributes on the base inode. The
VFS read and write helpers reject directory inodes before or together
with checking whether the handle represents a stream.

Permit read and write operations when a directory-backed handle is a
named stream. Continue rejecting direct I/O on ordinary directory
handles.

This fixes creation of the directory stream in smb2.getinfo.complex.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:30 +09:00
Namjae Jeon
4ea46ea602 ksmbd: protect private extended attributes
SMB clients can currently create an EA named NTACL because SMB EAs are
mapped into the user namespace while the ksmbd security descriptor is
stored as security.NTACL. Allowing the reserved logical name makes the
server-private ACL metadata appear writable through the SMB EA API.

Reject NTACL, DOSATTRIB, and DosStream-prefixed EA names without regard
to case. Filter the same private names from EA query results so stale or
externally-created user namespace attributes cannot be exposed.

This fixes smb2.ea.acl_xattr when acl_xattr_name is configured as
NTACL.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:29 +09:00
Namjae Jeon
497dbc5999 ksmbd: reject delete-on-close for read-only files
DELETE_ON_CLOSE is currently accepted for files carrying the read-only
DOS attribute. The server consequently creates or opens the file and
marks it for deletion instead of returning STATUS_CANNOT_DELETE.

Reject creation of a new read-only file with DELETE_ON_CLOSE. For an
existing file, load the stored DOS attributes before accepting the
create option. Also reject FileDispositionInformation when the opened
file has the read-only attribute.

Preserve the explicit STATUS_CANNOT_DELETE value while unwinding the
CREATE request.

This fixes smb2.delete-on-close-perms.READONLY.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:29 +09:00
Namjae Jeon
5d47ebb279 ksmbd: honor owner rights ACEs in maximal access
The SMB2 create maximal-access context is currently calculated from
POSIX mode bits when the client does not request MAXIMUM_ALLOWED. This
overwrites the access granted by a stored Windows DACL.

Calculate the create-context result with the DACL permission checker.
Recognize the S-1-3-4 Owner Rights SID as applying to the object owner
and process its allow and deny ACEs in ACL order.

When an Owner Rights ACE is present, do not add the owner implicit
READ_CONTROL and WRITE_DAC rights. The Owner Rights ACE replaces those
implicit grants as required by Windows access-check semantics.

Without an Owner Rights ACE, preserve the existing implicit owner grants,
including FILE_READ_ATTRIBUTES and DELETE.

This fixes smb2.acls.OWNER-RIGHTS and its deny variants without regressing
smb2.acls.GENERIC.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:29 +09:00
Namjae Jeon
e5f42cb757 ksmbd: support access-based directory enumeration
SMB shares can advertise access-based directory enumeration. ksmbd does
not currently provide a share option or filter inaccessible directory
entries.

Add a hide-unreadable share flag and advertise
SMB2_SHAREFLAG_ACCESS_BASED_DIRECTORY_ENUM when it is enabled. During
QUERY_DIRECTORY, omit entries unless the connected user has
FILE_READ_DATA, FILE_READ_EA, and FILE_READ_ATTRIBUTES access according
to the Windows ACL.

Keep the existing implicit access allowances for normal CREATE
permission checks while using strict access-mask matching for directory
enumeration.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:29 +09:00
Namjae Jeon
cc2f133e80 ksmbd: fix maximum allowed access checks
The DACL permission check looks for an ACE matching the current user and
falls back to the Everyone ACE. It does not consider an Authenticated
Users ACE, even though an authenticated session is a member of that
well-known group.

As a result, opening a file whose access is granted through S-1-5-11 can
incorrectly fail with STATUS_ACCESS_DENIED. Treat an Authenticated Users
ACE as a fallback entry alongside Everyone.

The maximal access calculation also combines access masks from every ACE,
regardless of whether its SID applies to the current user. This can grant
rights belonging to an unrelated principal. Process only ACEs applying to
the user, Everyone, or Authenticated Users, and accumulate allowed and
denied masks in ACL order. Preserve explicitly requested access bits so
they are validated against the resulting maximal mask.

When ACCESS_SYSTEM_SECURITY is denied, report STATUS_PRIVILEGE_NOT_HELD
instead of the generic STATUS_ACCESS_DENIED. Access to the system ACL
requires a security privilege that ksmbd does not grant.

For regular files, include FILE_EXECUTE in maximal access when the client
requested GENERIC_EXECUTE and the DACL grants the complete file-read set.
Keep a direct FILE_EXECUTE request subject to the explicit DACL bit. This
matches the POSIX file ACL mapping without broadening specific execute
requests.

Do not replace rights from an applicable NT ACE with a POSIX ACL entry.
The POSIX ACL is only a fallback when no user, Everyone, or Authenticated
Users ACE applies; otherwise it can incorrectly broaden the stored DACL.

This fixes smb2.maximum_allowed.maximum_allowed.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:28 +09:00
Namjae Jeon
df35438ba9 ksmbd: validate SMB2 write offsets
An SMB2 WRITE request with a negative offset returns -EINVAL directly
from smb2_write(). This bypasses the common error response path, leaving
the client waiting until the request times out.

ksmbd also allows nonempty writes at or beyond MAXFILESIZE as defined by
[MS-FSA]. Writes beyond the limit must fail with
STATUS_INVALID_PARAMETER. Writes ending at the limit fail with
STATUS_DISK_FULL, while a zero-length write remains valid.

Route negative offsets through the common error path and validate the end
offset of nonempty writes against MAXFILESIZE.

This fixes smb2.rw.invalid.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:28 +09:00
Namjae Jeon
7019a11f79 ksmbd: reject SMB3.1.1 binding with mismatched cipher
SMB3.1.1 multichannel connections belonging to the same session must use
the same negotiated encryption cipher.

ksmbd validates the dialect and client GUID during session binding, but
does not compare the cipher negotiated by the new connection with the
cipher used by the existing session channels. This allows a channel
negotiated with AES-128-CCM to bind to a session using AES-128-GCM.

Compare the new connection's cipher with an existing session channel and
return STATUS_INVALID_PARAMETER when they differ.

This fixes smb2.session.bind_negative_smb3encGtoCs.

Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
2026-08-17 15:00:28 +09:00
Linus Torvalds
8d3ae59288 Linux 7.2 2026-08-16 14:32:26 -07:00
Linus Torvalds
fd923b32d7 - Make sure a delayed sched entity's runtime stats are updated at the right
time so that it receives the proper lag compensation
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEzv7L6UO9uDPlPSfHEsHwGGHeVUoFAmqB/CQACgkQEsHwGGHe
 VUq4Eg//ZeldqtFqUxohjcy5ZrgJ9dhdxwRfqZgYhZCSqTJHVLqAxWVAHnJZWfiz
 Vh63rnt78rIPpVX6E/lZLnYm2VwhEO6P6piMzG4CVlh2pMySjhoRIQ3ufNAQRt0o
 P79Y29rLhDhHkOaL+jjgSr+ePiDzerrkBfYHK0wJ+BAjphjWxML1wYyCGwhWk/Lu
 KuXN/jzbEbAn2QWEwEy9KyxztzJlTYTE+l8jiGfRywAeZOBo8HaXg0HhuCwLnaXb
 yPmarhof2/7XUdW/CBGYggLaXF+mW6VeMaiqdhxSKl48KMpIfPnBC99/YCJy6vmQ
 pD+kOiysGSFy+3vMbTvjwOYV8T3g7LOpeVkY8KkVmAHUFVF9wBSyPULyooNuxGS9
 2pBv6Uz2ojm3wMVk+gggt2VU5uVNLsn9IKpNObyuBRDkt3My4Jej3cQ89LeqyS8Z
 q49JbAhEwCRfGpxq92WW6izMWjOnduhiTd9TXF/WoXVtcT9ZSbyxJ3sCxbTBrJxd
 na7xln2xsR8w9+G91DmmNPRnBtBkBOJ6xRGacKDeV8dcfKcZGGH6/sRMN9mIhP8v
 huCVazSwNCVWDaHn8o/ORBJ0dEJ/536a806ysYfB6MdNzZYtU8iepCj5Lr+uAG/Q
 W49ftqYFst9o22wT2i4ZdTfrDrkbekVU67BLv9yu8VcmoQJgt90=
 =bK3W
 -----END PGP SIGNATURE-----

Merge tag 'sched_urgent_for_v7.2' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull scheduler fix from Borislav Petkov:

 - Make sure a delayed sched entity's runtime stats are updated at the
   right time so that it receives the proper lag compensation

* tag 'sched_urgent_for_v7.2' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  sched: Update time before requeueing delayed entities
2026-08-16 11:15:23 -07:00
Linus Torvalds
240de1acf3 - Detect a broken EL2 virtual timer in the bcm2712 SoC boards (RPi5) and
fallback to the physical one instead
 
 - Fix a build error with ARM rpc_defconfig and function tracer enabled
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEzv7L6UO9uDPlPSfHEsHwGGHeVUoFAmqB+qQACgkQEsHwGGHe
 VUr7zQ//d2p80ASoa/3p6qzDs5FiySg2tWEfdRp6PoWDeonu5xVcXHs4GJyFFunP
 X7pu4kZ+gXq5RoWuk/ClFschaakeij0XtNCjMrpA7ZZpqwBwx387nv3v/9KecU3n
 IGqS6bz22d/99te9cMo+1vj3gm/PBIE3SOEnwQQ7oD2pAc2TzdLeoXo554EE5zZu
 tBpgdCz4fDcvmpr9sXzw9fDjgJgPjlVJYq/+juCtxXAWQtGJnHWCqGdMxbOtzHHo
 E2lLQhZNgC3Vi+jbTYB7mpa70R9iS8TmjuosjKpan3uxakQZnE/+pqN6xFpDh3Ho
 090dtBFOUYxx7LDcX6RjXrbddIaHwZNCP1W6OB0EKPUntcpD6MMo4GMBURUxJ4mO
 TT0gCtd1bsgYhNwZDVBUxhwoqM1e+EtL44ndT26E0HnIIT0gqr4QE6ODvFpeUQmj
 2sNdnBSslrLYeHYypBFRRo3aiDmfYCrML2z/OWEdRmAOYvUssJP4euXrBbInobd5
 VtBxjjQmBCSiV7nD0vor9eU5kJ4y6VNfiDDBuByNBzIWliMznLNgN92zAGPn7uwR
 IZ1wBWSbMYoc2C8h0CIPax1J+S517G17WVhMbJnYNlg9SzMAxttBWoHHvrdGMfW8
 Nua9plybvDVa+SRgCgJl7fiY19/UtXh/9NxHFQtcJnqR0eQfxJs=
 =IlDf
 -----END PGP SIGNATURE-----

Merge tag 'timers_urgent_for_v7.2' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull timer fixes from Borislav Petkov:

 - Detect a broken EL2 virtual timer in the bcm2712 SoC boards (RPi5)
   and fallback to the physical one instead

 - Fix a build error with ARM rpc_defconfig and function tracer enabled

* tag 'timers_urgent_for_v7.2' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  clocksource/drivers/arm_arch_timer: Workaround bcm2712 broken EL2 virtual timer
  tick: Include ktime.h and jiffies.h in linux/tick.h
2026-08-16 11:12:13 -07:00
Linus Torvalds
7820dd4a12 - Prevent a lockup when rseq grants a timeslice extension
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEzv7L6UO9uDPlPSfHEsHwGGHeVUoFAmqB+IQACgkQEsHwGGHe
 VUoLoA//UiK75T3O49g7pPmQh3lOqoadcvFduoGPVulWr9MqMYb9la+XRAPTO2aX
 lMldJhHoQBdL4chQU/2r1LgcM9i2GF753ssqO+MhAQHrDUMhZD87fRkQt+0e1jEc
 iAfjQCWVV7+abzsgKbZOlvXeYBFY6Bcy/EwGr9OhNPn1Zg6yGT73gV/ihgc1KYtj
 gyUCNjgu5n5UWLZOsAfy0JpSxdeHqCaydYKRRIWbQrbjlp+fauRPtbyOXua3mwNt
 gCnBpXnB3rD3R98KGr9C1GHg4DhwTSWZIQj67KMSnEKLco3fzhzq1PW1GwY3UFqn
 81OKGIqKHP+VDJTNsk4F0zrXLqG3NWaKwCu9jLV5yhA1z3/4GXNAE3iOT8DT3lmp
 upDnQ85aNkPSruF/ZjFxeNT3qrPOLCyMz0p/6qhZN7A3V/4R+B9vRYpvWZunvzvC
 k5hqeV1NyeRSoqvEp8ySH++v7Ifny2LbltIcuL+9wWUvRCb45ACQTgsjfIIRrm8F
 5mGBRyZs53lU7NthyE1FScNrVUFw7HaWAIapzaZPZIqhNh2+MAOODclTggYp0Y2A
 tIEGLohrsuEiPDA3xwa+6a+826M7Uan0lfIVV39BwTM2axuMOuapn/Ou5GmPSvx6
 guE0WRugo7TN5st8e+Go0ZrUMXzcQ61G3fdNJOR7UIbQROmrgEo=
 =7htY
 -----END PGP SIGNATURE-----

Merge tag 'core_urgent_for_v7.2' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull rseq fix from Borislav Petkov:

 - Prevent a lockup when rseq grants a timeslice extension

* tag 'core_urgent_for_v7.2' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  rseq: Prevent hard lockup on granted time slice extension
2026-08-16 11:09:37 -07:00
Charlie-cy Wu
d6e7d57ed9 wifi: mt76: mt7921: refactor regd update to fix recursive mutex deadlock
Split mt7921_mcu_regd_update() into two functions to prevent recursive
mutex acquisition. Introduce __mt7921_mcu_regd_update() as the internal
implementation that assumes the mutex is already held by the caller,
while mt7921_mcu_regd_update() remains as the external interface that
handles mutex acquisition and release.

This fixes a deadlock issue when mt7921_regd_set_6ghz_power_type() is
called with the device mutex already held. Without this change, calling
mt7921_mcu_regd_update() would attempt to acquire the same mutex again,
causing a recursive lock deadlock.

The __mt7921_mcu_regd_update() function can be safely called when the
caller has already acquired the device mutex, avoiding the deadlock
while maintaining proper synchronization for regulatory domain updates.

Fixes: dc2608cf5224 ("wifi: mt76: mt7921: refactor regulatory notifier flow")
Signed-off-by: Charlie-cy Wu <Charlie-cy.Wu@mediatek.com>
Tested-by: Mikhail Gavrilov <mikhail.v.gavrilov@gmail.com>
Tested-by: Devin Wittmayer <lucid_duck@justthetip.ca>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2026-08-16 11:07:18 -07:00
Linus Torvalds
d5b95e612c Revert "i2c: designware: defer probe if child GpioInt controllers are not bound"
This reverts commit 0a4bb2abc3.

This was reported to break the touchpad on at least some Thinkpads, and
while the revert has hit the i2c tree, it hasn't hit mine.  So I'm
reverting it directly just to have this resolved for the imminent 7.2
release.

Reported-by: Thorsten Leemhuis <linux@leemhuis.info>
Link: https://lore.kernel.org/all/b4a4eadb-282f-464c-843a-19d415a34d0c@leemhuis.info/
Cc: Mario Limonciello <mario.limonciello@amd.com>
CC: Hardik Prakash <hardikprakash.official@gmail.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2026-08-16 10:40:14 -07:00
Linus Torvalds
9da3fc37f5 - Prevent the use of exited events as group leaders
- Avoid use-after-free of an event's group leader by promoting detached
   sibling events to standalone entities and correct related accounting and
   state transitions
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEzv7L6UO9uDPlPSfHEsHwGGHeVUoFAmqB6xQACgkQEsHwGGHe
 VUpWFQ/+KyU6R2DC48ifpChzgTFmQ2gmIjy1IIsWSGmdSbyD5CEWar8hHDRq1X9r
 peuQizTXTQ2Ze75atTMIBExR6eUFYb2sKA1HpobcGnB96cpK8e2vmxhvXoHgB3IZ
 TYDXQ1RMPnbyTn2rCQwr5cgSq2Qe7w2tMXMQKzfmDxP1r7cE81zJVFAsRdVVZP75
 kvlcCL43pIwzxzP7sDb9bU9lTkW2Sw83dLIp3jBd3iiUpIQpwqV+UG3/fkInV58n
 L56cYFsovLbvWdxq4oj6cFwRBmvyrYKV0zkT+zW0SO2AzlVhfwCD/o74hxLwrN//
 Gas0d51uQfWt+5M7s6T0KFQYBfClG4uoIi2yh7zXxWEXyhcNuvmAVrY3xiQxReIi
 m88+ByWHfBc/mYTHKWJAqb8sHhJiktU52T55ktOJaPNGczA5+O/4alnOg3Kxvw7d
 CXp1raxJLqDxvd7Ubu/LVjWY96ds+fAaC15ydC6Lh08b9LPhA8rRCavf7NeSOzOD
 E1NA3QLS3TwbrTboaGqLMmzOLPkBBZ+28PUASg1ZpyfGnw91Ggv/gOVNUgr5PvMU
 D/gzRCwEYfDdhOrIHzGrfJ1fwj4qFsZ6HSge3sHDj8/BCcQYj/zmlTKe0CHKbaiy
 D7bkLNwdBc0z+eh5T7UfCYodUu0qiiek5Y0G3q8FVad0mFDYtUA=
 =moR8
 -----END PGP SIGNATURE-----

Merge tag 'perf_urgent_for_v7.2' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull perf fixes from Borislav Petkov:

 - Prevent the use of exited events as group leaders

 - Avoid use-after-free of an event's group leader by promoting detached
   sibling events to standalone entities and correct related accounting
   and state transitions

* tag 'perf_urgent_for_v7.2' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  perf/core: Fix group leader use-after-free after sibling detach
  perf: Reject exited events as group leaders
2026-08-16 10:31:05 -07:00
Linus Torvalds
16429bb371 - Add a proper kernel cmdline option to control the TLB invalidation method on
x86 prompted mainly by a recent finding on AMD related to INVLPGB/TYLBSYNC
   invalidations. Having the command line option is simply another way to
   alleviate the situation short-term
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEzv7L6UO9uDPlPSfHEsHwGGHeVUoFAmqB44wACgkQEsHwGGHe
 VUqKSRAAgQKrFw3mH29qsNGjS0GH1m1B6DShBB6/BwJb716gGNfFV/EmYrcwRM4+
 GTSA+LGLkKrb45gR+PkKkyoiXDPB/OzfmSlNvD+VCt1t78RdHCXLByye7SxxFjV/
 smboswwphQJPLJ8iTeJn+I1jbfC45Wla1hlMgCdHC7tTyyBOPfg32JdQ37cnd2PE
 8igsVVhMbEvszhbDrjVAWWUUjlWEjax8ix4rEKMV9J9zETgurK6Vy/G4QNTePSQU
 cc31FFUp+z+iBNWjCv1jhsuxUbxsH4u7SM3x18cTmgfKz03DQwVnCafkGPy8Rs2o
 nIdgojAnDginPQ0CsGvB1la7zHQ2MFtBRbNabW+m6WGs2OdwHs1+ATcm0/bFuQBh
 UqXic8fZ9jYsoGwRfqy/Nsg1ywkrm+IJ5RxSD1+wreGgYPPpEk5tzs5tx4vPFemX
 dm2ZizKr+kDxZThdTutwV0WY1A/xaix8M5y2poXb929zMy6E+sMwe7fjdnFSZph4
 I84PzW4vlH5BTnEK96ROl+ZB4tTMLGBGM/3ymtlmeXAkLiyrj10f+QdKCF1GPHsO
 Ljv0LVtVL6h4/AJzoV6mYNLCOQUmooMkwwvTYWoHZ3yoqjHGWjGlWDyx7b5uL6BY
 mFv81rxp0TWcFKLxv8g737NLKH95JAbP9/bKbldc9rmMl/tBOKE=
 =1btz
 -----END PGP SIGNATURE-----

Merge tag 'x86_urgent_for_v7.2' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull x86 fix from Borislav Petkov:

 - Add a proper kernel cmdline option to control the TLB invalidation
   method on x86 prompted mainly by a recent finding on AMD related to
   INVLPGB/TYLBSYNC invalidations.

   Having the command line option is simply another way to alleviate
   the situation short-term

* tag 'x86_urgent_for_v7.2' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  x86/CPU: Add a tlbi= cmdline switch
2026-08-16 10:28:31 -07:00
Linus Torvalds
dcb68831ea block-7.2-20260815
-----BEGIN PGP SIGNATURE-----
 
 iQJEBAABCAAuFiEEwPw5LcreJtl1+l5K99NY+ylx4KYFAmqBJfoQHGF4Ym9lQGtl
 cm5lbC5kawAKCRD301j7KXHgpnZvEAC5y7aQuMkr++q00K/+gkRF2mef/kZPyySR
 N7alVJW69FgAluun+2MD9Sg1SXNXKlJ+8WAouKwhwbo/LuzzxdrJhJ8FO+94JTqn
 Dnf01ZCsbSU2KU1/D5Nk81vJTJMHTAmaefvejdJ1X0R8arBNLJ+8TZRRtuxixyez
 6kt5HZTEY4n7WtkJs1sDUrbUCYt3jGXRz+sE+bNSzNFOCaTDBqCEquucZpa5QGRl
 Z7uVdHmpl8aQBCPNJq3H9l3HCav3FYCP8j+6DOzw8wNamlFdBj7ALldEz6uX1Kr9
 EySUjW5MT9WwkN6dbSGOmF5bNQYuO8Umv0VsWTnIxXmEb34Jsz7PwVKZ+lJydsp5
 Lm1JN9qT0uvN0CHyAL4ni3FnsTZnWDiTozBrZ4+vEPO8jRhTHg52eWtF4kfpaMxJ
 h2gw0MmPW+TaMQ13EiJ6fqppm/BrqtsX7WBKyKyflZIDXTy+KOoXxaiMO/IDMV0i
 ttS3yc6qLtvTR9BacLKlGc6YkiP4R9/1xSLWpOjNh18qljzgFFYjxOuszbcCE0/p
 vrefCd8J14HcCt5Qlw2XGYBptowbsNkEJ/k6L8Og36RAnyYzE84kbfVpiWddk0EU
 WqwAFWKc1J+1Ujf0TvmiprU1OfCPPeNp2xbDMMCGMRgLb6WSDUgUwBTiM9Hl2TmN
 N59eL2LfxA==
 =jmZj
 -----END PGP SIGNATURE-----

Merge tag 'block-7.2-20260815' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux

Pull block fix from Jens Axboe:
 "A single fix for a regression in this cycle, where drbd would leak
  shared secrets over netlink. This restores the behavior to match
  what we had before"

* tag 'block-7.2-20260815' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux:
  drbd: don't leak the shared secret to unprivileged netlink dumps
2026-08-16 07:00:40 -07:00
Linus Torvalds
0bae94aab8 io_uring-7.2-20260815
-----BEGIN PGP SIGNATURE-----
 
 iQJEBAABCAAuFiEEwPw5LcreJtl1+l5K99NY+ylx4KYFAmqA/oQQHGF4Ym9lQGtl
 cm5lbC5kawAKCRD301j7KXHgpj4ND/9OYcaM9+R/w7sv5+gefzm0omHhlLeg1nZ9
 RCUKvG86yq2PaNQfL4Tu+xJAiAMoW1maL0BIhLITzB4Q7X+L6MA6ddEi7180YvoH
 J3vimltNwJRdwRwQVFgjMI+L5DpBbM864s8Uk53Dj8nYl6pNh/0rcVxxjEfy/6Mz
 XyT5lijBXSHieL5qynLxPnHyz5jLq0Y/Y9uVWhPxRuYYwrOjWNVPugsnrg17vNpC
 3m9OwDzYldsAvoJehd8d6jrDGU/yxRynvP9NV8UfMnwg9k3F+C1f0PdbUrVwQlHh
 KqmpGluSpYyPuoyL82nS3WUpZ3iTpCvzPEl6g3HpKK3xo2DutaohrqLFt0q/oJd0
 B1LoMuIs7nO486ZoodtyvzWWevkEFbKtYlOleLYhYX9N+oOPRczsO64ZL3lyT2MG
 FsNWaiyN6F5VlI4UAZyxg1PNqtTFutcU6WZjrsWVhOOEvq+rf5on1RgXH/i6LR4n
 DxEBTXeVrBUWOT0+Y2txxHz6T1UbcWkqdpk781dOZY+HCTg1MVCha20x3YttASBd
 9JY03+JSolbBFzocaFXF/mWR1MGJdATWu3mutrdNoboeUiy5R/Kb3E81+a0CCR2K
 fI0TQ9RhQ+UxI8XW7IkxlTK/6bSyxiEIudgv0sYmKEZgH9O8SNY6ZTD8MeuA1fVN
 YgbVYoS8eA==
 =vArh
 -----END PGP SIGNATURE-----

Merge tag 'io_uring-7.2-20260815' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux

Pull io_uring fix from Jens Axboe:
 "Just a single fix for a potential issue on 32-bit x86 with PAE"

* tag 'io_uring-7.2-20260815' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux:
  io_uring/rsrc: reject overflowing regvec bvec byte counts
2026-08-16 06:58:27 -07:00