[PATCH] smb: client: mask server-provided mode to 07777 in modefromsid

Bjoern Doebel <[email protected]> Thu, 9 Jul 2026 15:54:39 +0000
Newsgroups gmane.linux.kernel.stable,gmane.linux.kernel.cifs,gmane.linux.kernel,gmane.network.samba.internals
Message-ID <[email protected]>
From: Norbert Manthey <[email protected]>

When modefromsid is active, parse_dacl() applies the server-provided
sub_auth[2] value from the NFS mode SID to cf_mode without masking to
07777. Apply the correct masking, same as in the read path.

Fixes: e2f8fbfb8d09c ("cifs: get mode bits from special sid on stat")
Signed-off-by: Norbert Manthey <[email protected]>
Assisted-by: Kiro:claude-opus-4.6
Cc: [email protected]
---
 fs/smb/client/cifsacl.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/smb/client/cifsacl.c b/fs/smb/client/cifsacl.c
index 6d572dd995d79..a0a68404fbff7 100644
--- a/fs/smb/client/cifsacl.c
+++ b/fs/smb/client/cifsacl.c
@@ -962,7 +962,7 @@ static void parse_dacl(struct smb_acl *pdacl, char *end_of_acl,
 				 */
 				fattr->cf_mode &= ~07777;
 				fattr->cf_mode |=
-					le32_to_cpu(ppace[i]->sid.sub_auth[2]);
+					le32_to_cpu(ppace[i]->sid.sub_auth[2]) & 07777;
 				break;
 			} else {
 				if (compare_sids(&(ppace[i]->sid), pownersid) == 0) {
-- 
2.50.1