[PATCH] ksmbd: zero the object ID before filling FS_OBJECT_ID_INFORMATION

Aleksandr Khromov <[email protected]>
Newsgroups org.kernel.vger.linux-cifs,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
FS_OBJECT_ID_INFORMATION reports 64 bytes to the client, so all 16 bytes
of object_id_info::objid are sent.  When the volume UUID is not available
only sizeof(stfs.f_fsid) (8 bytes) is copied, and the remaining 8 bytes
are whatever the response buffer holds.

The response buffer is zeroed on allocation (kzalloc()/kvzalloc()), so
for a standalone request the tail is zero.  In a compound request it need
not be: the offset of the next response is advanced by the length pinned
for the previous one, so if a preceding command wrote its reply into the
buffer and then failed, smb2_set_err_rsp() pins only the short error
response and the next reply lands inside the area already written.  Only
the header is cleared there:

	memset((char *)rsp_hdr, 0, sizeof(struct smb2_hdr) + 2);

Clear the field before filling it in.

Fixes: 3a64125730ca ("ksmbd: use volume UUID in FS_OBJECT_ID_INFORMATION")
Cc: [email protected]
Signed-off-by: Aleksandr Khromov <[email protected]>
---
 fs/smb/server/smb2pdu.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index 76f63f9adc72..6f5f4a399bde 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -6093,6 +6093,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
 
 		info = (struct object_id_info *)(rsp->Buffer);
 
+		memset(info->objid, 0, sizeof(info->objid));
 		if (path.mnt->mnt_sb->s_uuid_len == 16)
 			memcpy(info->objid, path.mnt->mnt_sb->s_uuid.b,
 					path.mnt->mnt_sb->s_uuid_len);
-- 
2.48.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.