Re: [PATCH] smb: client: set SB_I_NODEV to prevent device node injection
Steve French <[email protected]> Thu, 9 Jul 2026 12:20:33 -0500
| Newsgroups | gmane.linux.file-systems,gmane.linux.kernel.cifs,gmane.linux.kernel,gmane.network.samba.internals,gmane.linux.kernel.stable |
|---|---|
| Message-ID | <CAH2r5msvEGdEJvyV5sWcZjQ0SjMOwXP_Ad4eKN7etHtXS1vwbA@mail.gmail.com> |
Setting SB_I_NODEV is apparently not done for any remote filesystems, and AI search confirmed that it probably isn't a good idea to set it for remote fs. It is more of a thing in pseudofilesystems and not needed for network filesystems. e.g. "Is there any benefit to setting SB_I_NODEV? Today, probably not.If you grep the kernel, you'll find SB_I_NODEV is used in only a handful of places, and those places generally involve pseudo-filesystems or internal VFS assumptions rather than remote storage. Setting it on CIFS or NFS is unlikely to change behavior, because those filesystems have worked correctly for decades without it. Most remote filesystems don't set s_iflags because almost none of the SB_I_* flags are intended as generic filesystem capability flags. They're mostly internal VFS state, and SB_I_NODEV in particular has a very specific purpose. SB_I_NODEV does not mean "this filesystem contains no device nodes." It means something closer to: This superblock is not associated with a block device. or more precisely: The VFS should not expect a backing struct block_device for this superblock." Has something changed? How did this question about SB_I_NODEV come up? On Thu, Jul 9, 2026 at 11:05=E2=80=AFAM Bjoern Doebel <[email protected]> wr= ote: > > From: Norbert Manthey <[email protected]> > > Set SB_I_NODEV on the superblock by default for CIFS mounts. This is > consistent with how other filesystems handle untrusted remote content > and prevents the server side from injecting device nodes on the client. > > Fixes: 2e4564b31b645 ("smb3: add support for stat of WSL reparse points f= or special file types") > Signed-off-by: Norbert Manthey <[email protected]> > Assisted-by: Kiro:claude-opus-4.6 > Cc: [email protected] > --- > fs/smb/client/cifsfs.c | 3 +++ > 1 file changed, 3 insertions(+) > > diff --git a/fs/smb/client/cifsfs.c b/fs/smb/client/cifsfs.c > index ea4fc0fa68cac..35eee2f9899d5 100644 > --- a/fs/smb/client/cifsfs.c > +++ b/fs/smb/client/cifsfs.c > @@ -208,6 +208,9 @@ cifs_read_super(struct super_block *sb) > if (sbflags & CIFS_MOUNT_POSIXACL) > sb->s_flags |=3D SB_POSIXACL; > > + /* Prevent device node opens from remote filesystem by default */ > + sb->s_iflags |=3D SB_I_NODEV; > + > if (tcon->snapshot_time) > sb->s_flags |=3D SB_RDONLY; > > -- > 2.50.1 > > --=20 Thanks, Steve