Files
Linus Torvalds 61a09cfc12 Merge tag 'ksmbd-for-7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/smb
Pull smb server updates from Namjae Jeon:
 "This contains server updates focused on SMB2 command sequencing, SMB3
  request replay and encryption, Apple Time Machine interoperability,
  protocol-compatibility fixes validated with smbtorture, security
  hardening, SMB Direct transport support, connection reliability, and
  other correctness improvements.

  New features:

   - Implement the SMB2 command sequence window

     Enforce the credit-based MessageId range for each connection,
     rejecting out-of-window, duplicate, and wrapped sequence numbers.
     This prevents invalid requests and same-channel replays from being
     processed

   - Add SMB3 request replay support

     SMB3 clients may resend requests with SMB2_FLAGS_REPLAY_OPERATION
     after a channel disconnect when the original response was lost.
     Track the required channel and open state to safely handle durable
     CREATE replays and make oplock, lease, and lock replays idempotent,
     avoiding duplicate state changes and improving multichannel
     reconnect reliability

   - Add opt-in Apple Time Machine support

     Implement the AAPL negotiation and related Finder, stream,
     COPYCHUNK, sparse-file, CHANGE_NOTIFY, and RPC compatibility
     required for Time Machine shares, allowing macOS backupd to use
     ksmbd for backups

   - Add per-share SMB3 encryption support

     Allow individual shares to require SMB3 encryption by advertising
     SMB2_SHAREFLAG_ENCRYPT_DATA in TREE_CONNECT responses and rejecting
     unencrypted tree connects and plaintext requests for protected
     shares

   - Add SMB Direct RDMA encryption support

     Extend SMB Direct to support SMB3 encrypted payloads over RDMA,
     with transform negotiation and encryption/decryption for RDMA
     READ/WRITE

  Other changes:

   - Parse and retain AppInstanceVersion contexts, enforce version
     ordering, close older active handles for newer takeovers, and
     reject invalid or unversioned opens according to the SMB2 semantics

   - Accept durable reconnect requests that omit VolatileFileId when the
     persistent ID and reconnect context identify the handle, while
     continuing to reject explicit volatile-ID mismatches

   - Fix SMB2/SMB3 protocol validation and security issues, including
     request offsets, file and object IDs, IPC responses, output buffer
     sizes, SMB3.1.1 binding validation, signing-required handling,
     durable handles, ACLs, maximal access, and security information

   - Fix heap out-of-bounds accesses, use-after-free bugs, memory leaks,
     invalid pointer dereferences, and sensitive-data lifetime issues in
     authentication, Kerberos, preauthentication, sessions, connections,
     and module teardown

   - Correct alternate-data-stream and named-stream handling, COPYCHUNK
     behavior, sparse-file and compression attributes, allocated-range
     queries, file trimming, duplicate extents, DOS attributes,
     snapshots, normalized names, and partial information responses

   - Fix locking, lease, oplock, durable reconnect, async request, and
     CHANGE_NOTIFY races, including deferred-lock rollback, parent
     directory lease notifications, and connection teardown lifetime
     bugs

   - Fix SMB3 encryption handling for compressed requests, expired
     encrypted sessions, interim responses, bound multichannel
     connections, and decryption failures

   - Fix SMB3 multichannel session lookup and session state transitions
     so changes are scoped to the correct bound connections and cannot
     revive connections that are already shutting down

   - Fix DACL access checks so ACE walks are bounded by the declared
     DACL size, preventing data beyond the DACL boundary from being
     interpreted during access validation

   - Fix session accounting and lifetime issues, including session
     counter updates during publication and removal, session leaks on
     registration failure, and procfs creation diagnostics

   - Improve TCP connection reliability by enabling TCP keepalive for
     accepted connections and preserving TCP timers for kernel sockets,
     preventing silent peers from holding connections indefinitely

   - Fix smbdirect RDMA cleanup ordering for completion queues, QPs,
     child sockets, and listener locking

   - Improve async response framing, multi-iovec signing, RPC pipe
     status handling, and ksmbd procfs monitoring for server, share,
     connection, session, and open-file state

   - Remove the obsolete DES crypto header and Kconfig dependency now
     that NTLMv1 support has been removed

   - Update the ksmbd repository URL in MAINTAINERS and add an
     additional KSMBD reviewer"

* tag 'ksmbd-for-7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/smb: (142 commits)
  MAINTAINERS: update ksmbd repository URL
  MAINTAINERS: add myself as KSMBD reviewer
  smb: server: remove unused DES crypto header
  smb: server: Remove obsolete "select CRYPTO_LIB_DES" from Kconfig file
  ksmbd: keep TCP timers alive for kernel sockets
  ksmbd: enable TCP keepalive for accepted connections
  smb/server: fix session counter on session removal
  smb/server: update session counter under sessions table lock
  smb/server: fix session leak in ksmbd_session_register()
  smb/server: warn if ksmbd_proc_create() fails
  ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size
  ksmbd: make RDMA encryption diagnostics conditional
  ksmbd: add SMB Direct RDMA encryption transform
  ksmbd: handle encrypted compressed requests
  ksmbd: decrypt requests from expired encrypted sessions
  ksmbd: disconnect on SMB3 decryption failure
  ksmbd: encrypt interim responses to encrypted requests
  ksmbd: scope session state changes to bound connections
  ksmbd: fix encrypted request lookup on bound channels
  ksmbd: add per-share SMB3 encryption enforcement
  ...
2026-08-23 08:41:36 -07:00
..