Difference between revisions of "Ksmbd-review"

From SambaWiki
m (I don;t know what was going on here)
Line 112: Line 112:
 
Also helpful will be a careful re-review of each of the PDU processing functions, ideally two reviews for each of the below. See below.
 
Also helpful will be a careful re-review of each of the PDU processing functions, ideally two reviews for each of the below. See below.
   
1. smb2 header (Reviewer: )
+
# smb2 header (Reviewer: )
a. structure : smb2_hdr
+
#* structure : smb2_hdr
b. validation function : ksmbd_smb2_check_message()
+
#* validation function : ksmbd_smb2_check_message()
  +
# smb2 negotiate (Reviewer: )
 
  +
#* structure : smb2_negotiate_req
2. smb2 negotiate (Reviewer: )
 
  +
#* validation functioin : smb2_handle_negotiate()
a. structure : smb2_negotiate_req
 
  +
# negotiate context (Reviewer: )
b. validation functioin : smb2_handle_negotiate()
 
  +
#* structure : smb2_neg_context, smb2_preauth_neg_context, smb2_encryption_neg_context, smb2_compression_ctx, smb2_posix_neg_context
 
  +
#* validation function : deassemble_neg_contexts()
3. negotiate context (Reviewer: )
 
  +
# (missing)
a. structure : smb2_neg_context, smb2_preauth_neg_context,
 
  +
# smb2 session setup (Reviewer: )
smb2_encryption_neg_context, smb2_compression_ctx,
 
  +
#* structure : smb2_sess_setup_req
smb2_posix_neg_context
 
b. validation function : deassemble_neg_contexts()
+
#* validation function : smb2_sess_setup()
  +
# smb2 session logoff (Reviewer: )
 
  +
#* struture : smb2_logoff_req
5. smb2 session setup (Reviewer: )
 
  +
#* validation functioin : smb2_session_logoff()
a. structure : smb2_sess_setup_req
 
  +
# smb2 tree connect (Reviewer: )
b. validation function : smb2_sess_setup()
 
  +
#* structure : smb2_tree_connect_req
 
  +
#* validation function : smb2_tree_connect()
6. smb2 session logoff (Reviewer: )
 
  +
# smb2 tree disconnect (Reviewer: )
a. struture : smb2_logoff_req
 
  +
#* structure : smb2_tree_disconnect_req
b. validation functioin : smb2_session_logoff()
 
  +
#* validation function : smb2_tree_disconnect()
 
7. smb2 tree connect (Reviewer: )
+
# smb2 create (Reviewer: )
  +
## smb2 create
a. structure : smb2_tree_connect_req
 
  +
##* structure : smb2_create_req
b. validation function : smb2_tree_connect()
 
  +
##* validation function : smb2_open()
 
  +
## create context
8. smb2 tree disconnect (Reviewer: )
 
  +
##* structure : create_context, create_mxac_req, create_alloc_size_req,create_posix, lease_context, lease_context_v2
a. structure : smb2_tree_disconnect_req
 
b. validation function : smb2_tree_disconnect()
+
##* validation function : smb2_find_context_vals(), smb2_open()
  +
# (missing)
 
9. smb2 create (Reviewer: )
+
# smb2 close (Reviewer: )
  +
##* structure : smb2_close_req
9.1. smb2 create
 
  +
##* validation function : smb2_close()
a. structure : smb2_create_req
 
  +
# smb2 flush (Reviewer: )
b. validation function : smb2_open()
 
  +
##* structure : smb2_flush_req
9.2. create context
 
  +
##* validation function : smb2_flush()
a. structure : create_context, create_mxac_req, create_alloc_size_req,
 
  +
# smb2 read (Reviewer: )
create_posix, lease_context, lease_context_v2
 
  +
##* structure : smb2_read_req
b. validation function : smb2_find_context_vals(), smb2_open()
 
  +
##* validation function : smb2_read()
 
11. smb2 close (Reviewer: )
+
# smb2 write (Reviewer: )
a. structure : smb2_close_req
+
##* structure : smb2_write_req
b. validation function : smb2_close()
+
##* validation function : smb2_write()
  +
# smb2 ioctl (Reviewer: )
 
  +
## FSCTL_VALIDATE_NEGOTIATE_INFO
12. smb2 flush (Reviewer: )
 
  +
##* strcture : validate_negotiate_info_req
a. structure : smb2_flush_req
 
b. validation function : smb2_flush()
+
##* validation function : smb2_ioctl(), fsctl_validate_negotiate_info()
  +
## FSCTL_QUERY_NETWORK_INTERFACE_INFO
 
  +
##* structure : network_interface_info_ioctl_rsp
13. smb2 read (Reviewer: )
 
  +
##* validation functioin : fsctl_query_iface_info_ioctl()
a. structure : smb2_read_req
 
  +
## FSCTL_COPYCHUNK
b. validation function : smb2_read()
 
  +
##* structure : copychunk_ioctl_req
 
  +
##* validation function : smb2_ioctl(), fsctl_copychunk()
14. smb2 write (Reviewer: )
 
  +
## FSCTL_SET_SPARSE
a. structure : smb2_write_req
 
  +
##* structure : file_sparse
b. validation function : smb2_write()
 
  +
##* validation function : smb2_ioctl()
 
  +
## FSCTL_SET_ZERO_DATA
15. smb2 ioctl (Reviewer: )
 
  +
##* structure : file_zero_data_information
15-1. FSCTL_VALIDATE_NEGOTIATE_INFO
 
  +
##* validation function : smb2_ioctl()
a. strcture : validate_negotiate_info_req
 
  +
## FSCTL_REQUEST_RESUME_KEY
b. validation function : smb2_ioctl(), fsctl_validate_negotiate_info()
 
  +
##* structure : resume_key_ioctl_rsp
15-2. FSCTL_QUERY_NETWORK_INTERFACE_INFO
 
  +
##* validation function : smb2_ioctl()
a. structure : network_interface_info_ioctl_rsp
 
  +
## FSCTL_QUERY_ALLOCATED_RANGES
b. validation functioin : fsctl_query_iface_info_ioctl()
 
  +
##* structure : file_allocated_range_buffer
15-3. FSCTL_COPYCHUNK
 
  +
##* validation function : smb2_ioctl()
a. structure : copychunk_ioctl_req
 
  +
## FSCTL_GET_REPARSE_POINT
b. validation function : smb2_ioctl(), fsctl_copychunk()
 
  +
## FSCTL_DUPLICATE_EXTENTS_TO_FILE
15-4. FSCTL_SET_SPARSE
 
a. structure : file_sparse
+
##* structure : duplicate_extents_to_file
b. validation function : smb2_ioctl()
+
##* validation function : smb2_ioctl()
  +
## FSCTL_PIPE_TRANSCEIVE
15-5. FSCTL_SET_ZERO_DATA
 
  +
##* validation function : fsctl_pipe_transceive()
a. structure : file_zero_data_information
 
  +
## FSCTL_CREATE_OR_GET_OBJECT_ID
b. validation function : smb2_ioctl()
 
  +
##* structure : file_object_buf_type1_ioctl_rsp
15-6. FSCTL_REQUEST_RESUME_KEY
 
  +
##* validation function : smb2_ioctl()
a. structure : resume_key_ioctl_rsp
 
  +
# smb2 change notify (Reviewer: )
b. validation function : smb2_ioctl()
 
  +
#* structure : smb2_notify_req
15-7. FSCTL_QUERY_ALLOCATED_RANGES
 
  +
#* validation function : smb2_notify()
a. structure : file_allocated_range_buffer
 
  +
# smb2 lock (Reviewer: )
b. validation function : smb2_ioctl()
 
  +
#* structure : smb2_lock_req
15-8. FSCTL_GET_REPARSE_POINT
 
  +
#* validation functioin : smb2_lock()
15-9. FSCTL_DUPLICATE_EXTENTS_TO_FILE
 
  +
# smb2 echo (Reviewer: )
a. structure : duplicate_extents_to_file
 
  +
#* structure : smb2_echo_req
b. validation function : smb2_ioctl()
 
  +
#* validation function : smb2_echo()
15-10. FSCTL_PIPE_TRANSCEIVE
 
  +
# smb2 query directory (Reviewer: )
a. validation function : fsctl_pipe_transceive()
 
  +
#* smb2_query_directory_req
15-11. FSCTL_CREATE_OR_GET_OBJECT_ID
 
  +
#* validation function : smb2_query_dir()
a. structure : file_object_buf_type1_ioctl_rsp
 
  +
# smb2 query info (Reviewer: )
b. validation function : smb2_ioctl()
 
  +
## SMB2_O_INFO_FILE
 
  +
### FILE_ACCESS_INFORMATION
16. smb2 change notify (Reviewer: )
 
a. structure : smb2_notify_req
+
###* structure : smb2_file_access_info
b. validation function : smb2_notify()
+
###* validation function : get_file_access_info()
  +
### FILE_BASIC_INFORMATION
 
  +
###* structure : smb2_file_all_info
17. smb2 lock (Reviewer: )
 
  +
###* validation function : get_file_basic_info()
a. structure : smb2_lock_req
 
  +
### FILE_STANDARD_INFORMATION
b. validation functioin : smb2_lock()
 
  +
###* structure : smb2_file_standard_info
 
  +
###* validation function : get_file_standard_info()
18. smb2 echo (Reviewer: )
 
  +
### FILE_ALIGNMENT_INFORMATION
a. structure : smb2_echo_req
 
  +
###* structure : smb2_file_alignment_info
b. validation function : smb2_echo()
 
  +
###* validation function : get_file_alignment_info()
 
  +
### FILE_ALL_INFORMATION
19. smb2 query directory (Reviewer: )
 
  +
###* structure : smb2_file_all_info
a. smb2_query_directory_req
 
b. validation function : smb2_query_dir()
+
###* validation function : get_file_all_info()
  +
### FILE_ALTERNATE_NAME_INFORMATION
 
  +
###* structure : smb2_file_alt_name_info
20. smb2 query info (Reviewer: )
 
  +
###* validation function : get_file_alternate_info()
20.1. SMB2_O_INFO_FILE
 
  +
### FILE_STREAM_INFORMATION
20.1.1. FILE_ACCESS_INFORMATION
 
a. structure : smb2_file_access_info
+
###* structure : smb2_file_stream_info
b. validation function : get_file_access_info()
+
###* validation function : get_file_stream_info()
  +
### FILE_INTERNAL_INFORMATION
20.1.2. FILE_BASIC_INFORMATION
 
a. structure : smb2_file_all_info
+
###* structure : smb2_file_internal_info
b. validation function : get_file_basic_info()
+
###* validation function : get_file_internal_info()
  +
### FILE_NETWORK_OPEN_INFORMATION
20.1.3. FILE_STANDARD_INFORMATION
 
a. structure : smb2_file_standard_info
+
###* structure : smb2_file_ntwrk_info
b. validation function : get_file_standard_info()
+
###* validation function : get_file_network_open_info()
  +
### FILE_EA_INFORMATION
20.1.4. FILE_ALIGNMENT_INFORMATION
 
a. structure : smb2_file_alignment_info
+
###* structure : smb2_file_ea_info
b. validation function : get_file_alignment_info()
+
###* validation function : get_file_ea_info()
  +
### FILE_FULL_EA_INFORMATION
20.1.5. FILE_ALL_INFORMATION
 
a. structure : smb2_file_all_info
+
###* structure : smb2_ea_info
b. validation function : get_file_all_info()
+
###* validation function : smb2_get_ea()
  +
### FILE_POSITION_INFORMATION
20.1.6. FILE_ALTERNATE_NAME_INFORMATION
 
a. structure : smb2_file_alt_name_info
+
###* structure : smb2_file_pos_info
b. validation function : get_file_alternate_info()
+
###* validation function : get_file_position_info()
  +
### FILE_MODE_INFORMATION
20.1.7. FILE_STREAM_INFORMATION
 
a. structure : smb2_file_stream_info
+
###* structure : smb2_file_mode_info
b. validation function : get_file_stream_info()
+
###* validation function : get_file_mode_info()
  +
### FILE_POSITION_INFORMATION
20.1.8. FILE_INTERNAL_INFORMATION
 
a. structure : smb2_file_internal_info
+
###* structure : smb2_file_pos_info
b. validation function : get_file_internal_info()
+
###* validation function : get_file_position_info()
  +
### FILE_MODE_INFORMATION
20.1.9. FILE_NETWORK_OPEN_INFORMATION
 
a. structure : smb2_file_ntwrk_info
+
###* structure : smb2_file_mode_info
b. validation function : get_file_network_open_info()
+
###* validation function : get_file_mode_info()
  +
### FILE_COMPRESSION_INFORMATION
20.1.10. FILE_EA_INFORMATION
 
a. structure : smb2_file_ea_info
+
###* structure : smb2_file_comp_info
b. validation function : get_file_ea_info()
+
###* validation function : get_file_compression_info()
  +
### FILE_ATTRIBUTE_TAG_INFORMATION
20.1.11. FILE_FULL_EA_INFORMATION
 
a. structure : smb2_ea_info
+
###* structure : smb2_file_attr_tag_info
b. validation function : smb2_get_ea()
+
###* validation function : get_file_attribute_tag_info()
  +
### SMB_FIND_FILE_POSIX_INFO
20.1.12. FILE_POSITION_INFORMATION
 
a. structure : smb2_file_pos_info
+
###* structure : smb311_posix_qinfo
b. validation function : get_file_position_info()
+
###* validation function : find_file_posix_info()
  +
## SMB2_O_INFO_FILESYSTEM
20.1.13. FILE_MODE_INFORMATION
 
  +
### FS_DEVICE_INFORMATION
a. structure : smb2_file_mode_info
 
  +
###* structure : filesystem_device_info
b. validation function : get_file_mode_info()
 
  +
###* validation function : smb2_get_info_filesystem()
20.1.14. FILE_POSITION_INFORMATION
 
  +
### FS_ATTRIBUTE_INFORMATION
a. structure : smb2_file_pos_info
 
  +
###* structure : filesystem_attribute_info
b. validation function : get_file_position_info()
 
  +
###* validation function : smb2_get_info_filesystem()
20.1.15. FILE_MODE_INFORMATION
 
  +
### FS_VOLUME_INFORMATION
a. structure : smb2_file_mode_info
 
  +
###* structure : filesystem_vol_info
b. validation function : get_file_mode_info()
 
  +
###* validation function : smb2_get_info_filesystem()
20.1.16. FILE_COMPRESSION_INFORMATION
 
  +
### FS_SIZE_INFORMATION
a. structure : smb2_file_comp_info
 
  +
###* structure : filesystem_info
b. validation function : get_file_compression_info()
 
  +
###* validation function : smb2_get_info_filesystem()
20.1.17. FILE_ATTRIBUTE_TAG_INFORMATION
 
  +
### FS_FULL_SIZE_INFORMATION
a. structure : smb2_file_attr_tag_info
 
  +
###* structure : smb2_fs_full_size_info
b. validation function : get_file_attribute_tag_info()
 
  +
###* validation function : smb2_get_info_filesystem()
20.1.18. SMB_FIND_FILE_POSIX_INFO
 
  +
### FS_OBJECT_ID_INFORMATION
a. structure : smb311_posix_qinfo
 
  +
###* structure : object_id_info
b. validation function : find_file_posix_info()
 
  +
###* validation function : smb2_get_info_filesystem()
 
  +
### FS_SECTOR_SIZE_INFORMATION
20.2. SMB2_O_INFO_FILESYSTEM
 
  +
###* structure : smb3_fs_ss_info
20.2.1. FS_DEVICE_INFORMATION
 
  +
###* validation function : smb2_get_info_filesystem()
a. structure : filesystem_device_info
 
  +
### FS_CONTROL_INFORMATION
b. validation function : smb2_get_info_filesystem()
 
  +
###* structure : smb2_fs_control_info
20.2.2. FS_ATTRIBUTE_INFORMATION
 
  +
###* validation function : smb2_get_info_filesystem()
a. structure : filesystem_attribute_info
 
  +
### FS_POSIX_INFORMATION
b. validation function : smb2_get_info_filesystem()
 
  +
###* structure : filesystem_posix_info
20.2.3. FS_VOLUME_INFORMATION
 
  +
###* validation function : smb2_get_info_filesystem()
a. structure : filesystem_vol_info
 
  +
## SMB2_O_INFO_SECURITY
b. validation function : smb2_get_info_filesystem()
 
  +
##* structure : smb_ntsd, smb_acl, smb_ace, smb_sid
20.2.4. FS_SIZE_INFORMATION
 
  +
##* validation function : build_sec_desc()
a. structure : filesystem_info
 
  +
# smb2 set info (Reviewer: )
b. validation function : smb2_get_info_filesystem()
 
  +
## SMB2_O_INFO_FILE
20.2.5. FS_FULL_SIZE_INFORMATION
 
  +
### FILE_BASIC_INFORMATION
a. structure : smb2_fs_full_size_info
 
  +
###* structure : smb2_file_basic_info
b. validation function : smb2_get_info_filesystem()
 
  +
###* validation functioin : smb2_set_info_file()
20.2.6. FS_OBJECT_ID_INFORMATION
 
  +
### FILE_ALLOCATION_INFORMATION
a. structure : object_id_info
 
  +
###* structure : smb2_file_alloc_info
b. validation function : smb2_get_info_filesystem()
 
  +
###* validation functioin : smb2_set_info_file()
20.2.7. FS_SECTOR_SIZE_INFORMATION
 
  +
### FILE_END_OF_FILE_INFORMATION
a. structure : smb3_fs_ss_info
 
  +
###* structure : smb2_file_eof_info
b. validation function : smb2_get_info_filesystem()
 
  +
###* validation functioin : smb2_set_info_file()
20.2.8. FS_CONTROL_INFORMATION
 
  +
### FILE_RENAME_INFORMATION
a. structure : smb2_fs_control_info
 
  +
###* structure : smb2_file_rename_info
b. validation function : smb2_get_info_filesystem()
 
  +
###* validation functioin : smb2_set_info_file(), set_rename_info()
20.2.9. FS_POSIX_INFORMATION
 
  +
### FILE_LINK_INFORMATION
a. structure : filesystem_posix_info
 
  +
###* structure : smb2_file_link_info
b. validation function : smb2_get_info_filesystem()
 
  +
###* validation functioin : smb2_create_link()
 
  +
### FILE_DISPOSITION_INFORMATION
20.2. SMB2_O_INFO_SECURITY
 
a. structure : smb_ntsd, smb_acl, smb_ace, smb_sid
+
###* structure : smb2_file_disposition_info
b. validation function : build_sec_desc()
+
###* validation functioin : smb2_set_info_file()
  +
### FILE_FULL_EA_INFORMATION
 
  +
### structure : smb2_ea_info
21. smb2 set info (Reviewer: )
 
  +
### validation functioin : smb2_set_info_file(), smb2_set_ea
21.1. SMB2_O_INFO_FILE
 
  +
### FILE_POSITION_INFORMATION
21.1.1 FILE_BASIC_INFORMATION
 
a. structure : smb2_file_basic_info
+
###* structure : smb2_file_pos_info
b. validation functioin : smb2_set_info_file()
+
###* validation functioin : smb2_set_info_file()
  +
### FILE_MODE_INFORMATION
21.1.2 FILE_ALLOCATION_INFORMATION
 
a. structure : smb2_file_alloc_info
+
###* structure : smb2_file_mode_info
b. validation functioin : smb2_set_info_file()
+
###* validation functioin : smb2_set_info_file()
  +
## SMB2_O_INFO_SECURITY
21.1.3 FILE_END_OF_FILE_INFORMATION
 
a. structure : smb2_file_eof_info
+
##* structure : smb_ntsd, smb_acl, smb_ace, smb_sid
b. validation functioin : smb2_set_info_file()
+
##* validation function : parse_sec_desc()
  +
# smb2 oplock break ack (Reviewer: )
21.1.4 FILE_RENAME_INFORMATION
 
a. structure : smb2_file_rename_info
+
#* structure : smb2_oplock_break
b. validation functioin : smb2_set_info_file(), set_rename_info()
+
#* validation function : smb20_oplock_break_ack()
  +
# smb2 lease break ack (Reviewer: )
21.1.5 FILE_LINK_INFORMATION
 
a. structure : smb2_file_link_info
+
#* structure : smb2_lease_ack
b. validation functioin : smb2_create_link()
+
#* validation function : smb21_lease_break_ack()
21.1.6 FILE_DISPOSITION_INFORMATION
 
a. structure : smb2_file_disposition_info
 
b. validation functioin : smb2_set_info_file()
 
21.1.7 FILE_FULL_EA_INFORMATION
 
a. structure : smb2_ea_info
 
b. validation functioin : smb2_set_info_file(), smb2_set_ea
 
21.1.8 FILE_POSITION_INFORMATION
 
a. structure : smb2_file_pos_info
 
b. validation functioin : smb2_set_info_file()
 
21.1.9 FILE_MODE_INFORMATION
 
a. structure : smb2_file_mode_info
 
b. validation functioin : smb2_set_info_file()
 
 
22.1 SMB2_O_INFO_SECURITY
 
a. structure : smb_ntsd, smb_acl, smb_ace, smb_sid
 
b. validation function : parse_sec_desc()
 
 
22. smb2 oplock break ack (Reviewer: )
 
a. structure : smb2_oplock_break
 
b. validation function : smb20_oplock_break_ack()
 
 
23. smb2 lease break ack (Reviewer: )
 
a. structure : smb2_lease_ack
 
b. validation function : smb21_lease_break_ack()
 

Revision as of 13:22, 21 September 2021

There are various checks that are especially important for SMB3 servers. They fall into multiple categories:

  • packet processing checks to make sure buffers do not overflow, allowing access to data outside the SMB request
  • path processing checks to make sure access to files outside the share is not permitted, these include checks for ".." or "../.." to make sure they do not go outside the share, and checks for symlinks in paths and checks to ensure paths do not allow a processed path e.g. with "\" or "/" to go outside the share. These primarily impact three operations (open, query directory and rename) as unlike SMB1 most SMB2/SMB3 operations are handle based, not path based.
  • denial of service and resource checks (e.g. ensure that no single client can exhaust the server by opening millions of files, or use so many credits that they submit thousands of simultaneous requests starving other clients)

In addition, it is important that servers only implement reasonably secure dialects and authentication mechanisms by default. For example SMB2.1 or later supports protection against "man in the middle" attacks, and should be the minimum version supported by default. In addition, NTLMv1 authentication should be disabled (NTLMv2 can be allowed, although 8 character and longer passwords may be a good minimum to require by default). Kerberos authentication should also be supported. In the longer run, especially to support Macs (which allow at least two additional peer-to-peer authentication mechanisms which look promising) we can consider adding additional mechanisms, but currently NTLMv2 (encapsulated in NTLMSSP during negotiation) is for "peer to peer" use cases, and Kerberos for domain joined cases.

SMB3.1.1 supports very strong signing and encryption options (e.g. GCM256 encryption), and it may be helpful to ensure that users know about the advantages of using current SMB3.1.1 so they don't choose less secure options.

Packet processing checks in ksmbd
Type of check Status (submitted, reviewed) Function(s) including the check (and patch name if not included yet) Additional work if any
SMB3 header validation Already implemented See ksmbd_smb2_check_message function in smb2misc.c and ksmbd_verify_smb_message
StructureSize field check for all 19 SMB3 commands Already implemented See smb2_get_data_area_len function and smb2_req_struct_sizes in smb2misc.c
check for overflow of SET_INFO command patches submitted, partially reviewed "ksmbd: add request buffer validation in smb2_set_info"
check for overflow of FSCTL command patch submitted, partially reviewed "ksmbd: add validation in smb2_ioctl", smb2pdu.c
Generic check for packet overflow Already implmented See ksmb2_check_message and smb2_calc_size functions
Packet Signing Check (for packet corruption and man-in-the-middle attacks) Already implemented check_sign_req function in smb2pdu.c
Check for open context overflow patch submitted, partially reviewed See "ksmbd: add buffer validation for SMB2_CREATE_CONTEXT", oplock.c smb2pdu.c
Check for overflow of ACL patch submitted, partially reviewed See "ksmbd: add buffer validation for SMB2_CREATE_CONTEXT", smbacl.c (parse_dacl and parse_sec_desc functions)
Check for negotiate context overflow Already implemented See deassemble_neg_contexts function (in smb2pdu.c) and also decode_encrypt_context and decode_sign_cap_ctxt Some contexts (such as compression context) are ignored (set to none) and may need additional checks in future when implemented
Path processing checks in ksmbd
Type of check Status (submitted, reviewed) Function(s) including the check (and patch name if not included yet) Additional work if any
checks for .. escaping the share patch submitted, reviewed, tested multiple ways (libsmb2, smbclient) "ksmbd: prevent out of share access" (see ksmbd_conv_path_to_unix function in misc.c and its use in smb2pdu.c)
checks for symlinks in path components patch submitted, partially reviewed "ksmbd: use LOOKUP_NO_SYMLINKS flags for default lookup" See smb2_open, and ksmbd_vfs_create, ksmbd_vfs_mkdir, ksmb_vfs_link and ksmbd_remove_file and ksmbd_vfs_fp_rename
checks for resolved path never being / or \ (outside the share) (also see additional restrictions made possible by ksmbd_share_veto_filename function in mgmt/share_config.c, and ksmbd_validate_filename in misc.c)


Denial of Service checks
Type of check Status (submitted, reviewed) Function(s) including the check (and patch name if not included yet) Additional work if any
checks for opening too many files Would additional checks be helpful e.g. see smb2_open in smb2pdu.c and ksmbd_open_fd in vfs_cache.c?
checks for allowing too many requests (crediting) See smb2_set_rsp_credits and conn->max_credits field, and conn->total_credits in smb2_consume_credit_charge to investigate this

Also helpful will be a careful re-review of each of the PDU processing functions, ideally two reviews for each of the below. See below.

  1. smb2 header (Reviewer: )
    • structure : smb2_hdr
    • validation function : ksmbd_smb2_check_message()
  2. smb2 negotiate (Reviewer: )
    • structure : smb2_negotiate_req
    • validation functioin : smb2_handle_negotiate()
  3. negotiate context (Reviewer: )
    • structure : smb2_neg_context, smb2_preauth_neg_context, smb2_encryption_neg_context, smb2_compression_ctx, smb2_posix_neg_context
    • validation function : deassemble_neg_contexts()
  4. (missing)
  5. smb2 session setup (Reviewer: )
    • structure : smb2_sess_setup_req
    • validation function : smb2_sess_setup()
  6. smb2 session logoff (Reviewer: )
    • struture : smb2_logoff_req
    • validation functioin : smb2_session_logoff()
  7. smb2 tree connect (Reviewer: )
    • structure : smb2_tree_connect_req
    • validation function : smb2_tree_connect()
  8. smb2 tree disconnect (Reviewer: )
    • structure : smb2_tree_disconnect_req
    • validation function : smb2_tree_disconnect()
  9. smb2 create (Reviewer: )
    1. smb2 create
      • structure : smb2_create_req
      • validation function : smb2_open()
    2. create context
      • structure : create_context, create_mxac_req, create_alloc_size_req,create_posix, lease_context, lease_context_v2
      • validation function : smb2_find_context_vals(), smb2_open()
  10. (missing)
  11. smb2 close (Reviewer: )
      • structure : smb2_close_req
      • validation function : smb2_close()
  12. smb2 flush (Reviewer: )
      • structure : smb2_flush_req
      • validation function : smb2_flush()
  13. smb2 read (Reviewer: )
      • structure : smb2_read_req
      • validation function : smb2_read()
  14. smb2 write (Reviewer: )
      • structure : smb2_write_req
      • validation function : smb2_write()
  15. smb2 ioctl (Reviewer: )
    1. FSCTL_VALIDATE_NEGOTIATE_INFO
      • strcture : validate_negotiate_info_req
      • validation function : smb2_ioctl(), fsctl_validate_negotiate_info()
    2. FSCTL_QUERY_NETWORK_INTERFACE_INFO
      • structure : network_interface_info_ioctl_rsp
      • validation functioin : fsctl_query_iface_info_ioctl()
    3. FSCTL_COPYCHUNK
      • structure : copychunk_ioctl_req
      • validation function : smb2_ioctl(), fsctl_copychunk()
    4. FSCTL_SET_SPARSE
      • structure : file_sparse
      • validation function : smb2_ioctl()
    5. FSCTL_SET_ZERO_DATA
      • structure : file_zero_data_information
      • validation function : smb2_ioctl()
    6. FSCTL_REQUEST_RESUME_KEY
      • structure : resume_key_ioctl_rsp
      • validation function : smb2_ioctl()
    7. FSCTL_QUERY_ALLOCATED_RANGES
      • structure : file_allocated_range_buffer
      • validation function : smb2_ioctl()
    8. FSCTL_GET_REPARSE_POINT
    9. FSCTL_DUPLICATE_EXTENTS_TO_FILE
      • structure : duplicate_extents_to_file
      • validation function : smb2_ioctl()
    10. FSCTL_PIPE_TRANSCEIVE
      • validation function : fsctl_pipe_transceive()
    11. FSCTL_CREATE_OR_GET_OBJECT_ID
      • structure : file_object_buf_type1_ioctl_rsp
      • validation function : smb2_ioctl()
  16. smb2 change notify (Reviewer: )
    • structure : smb2_notify_req
    • validation function : smb2_notify()
  17. smb2 lock (Reviewer: )
    • structure : smb2_lock_req
    • validation functioin : smb2_lock()
  18. smb2 echo (Reviewer: )
    • structure : smb2_echo_req
    • validation function : smb2_echo()
  19. smb2 query directory (Reviewer: )
    • smb2_query_directory_req
    • validation function : smb2_query_dir()
  20. smb2 query info (Reviewer: )
    1. SMB2_O_INFO_FILE
      1. FILE_ACCESS_INFORMATION
        • structure : smb2_file_access_info
        • validation function : get_file_access_info()
      2. FILE_BASIC_INFORMATION
        • structure : smb2_file_all_info
        • validation function : get_file_basic_info()
      3. FILE_STANDARD_INFORMATION
        • structure : smb2_file_standard_info
        • validation function : get_file_standard_info()
      4. FILE_ALIGNMENT_INFORMATION
        • structure : smb2_file_alignment_info
        • validation function : get_file_alignment_info()
      5. FILE_ALL_INFORMATION
        • structure : smb2_file_all_info
        • validation function : get_file_all_info()
      6. FILE_ALTERNATE_NAME_INFORMATION
        • structure : smb2_file_alt_name_info
        • validation function : get_file_alternate_info()
      7. FILE_STREAM_INFORMATION
        • structure : smb2_file_stream_info
        • validation function : get_file_stream_info()
      8. FILE_INTERNAL_INFORMATION
        • structure : smb2_file_internal_info
        • validation function : get_file_internal_info()
      9. FILE_NETWORK_OPEN_INFORMATION
        • structure : smb2_file_ntwrk_info
        • validation function : get_file_network_open_info()
      10. FILE_EA_INFORMATION
        • structure : smb2_file_ea_info
        • validation function : get_file_ea_info()
      11. FILE_FULL_EA_INFORMATION
        • structure : smb2_ea_info
        • validation function : smb2_get_ea()
      12. FILE_POSITION_INFORMATION
        • structure : smb2_file_pos_info
        • validation function : get_file_position_info()
      13. FILE_MODE_INFORMATION
        • structure : smb2_file_mode_info
        • validation function : get_file_mode_info()
      14. FILE_POSITION_INFORMATION
        • structure : smb2_file_pos_info
        • validation function : get_file_position_info()
      15. FILE_MODE_INFORMATION
        • structure : smb2_file_mode_info
        • validation function : get_file_mode_info()
      16. FILE_COMPRESSION_INFORMATION
        • structure : smb2_file_comp_info
        • validation function : get_file_compression_info()
      17. FILE_ATTRIBUTE_TAG_INFORMATION
        • structure : smb2_file_attr_tag_info
        • validation function : get_file_attribute_tag_info()
      18. SMB_FIND_FILE_POSIX_INFO
        • structure : smb311_posix_qinfo
        • validation function : find_file_posix_info()
    2. SMB2_O_INFO_FILESYSTEM
      1. FS_DEVICE_INFORMATION
        • structure : filesystem_device_info
        • validation function : smb2_get_info_filesystem()
      2. FS_ATTRIBUTE_INFORMATION
        • structure : filesystem_attribute_info
        • validation function : smb2_get_info_filesystem()
      3. FS_VOLUME_INFORMATION
        • structure : filesystem_vol_info
        • validation function : smb2_get_info_filesystem()
      4. FS_SIZE_INFORMATION
        • structure : filesystem_info
        • validation function : smb2_get_info_filesystem()
      5. FS_FULL_SIZE_INFORMATION
        • structure : smb2_fs_full_size_info
        • validation function : smb2_get_info_filesystem()
      6. FS_OBJECT_ID_INFORMATION
        • structure : object_id_info
        • validation function : smb2_get_info_filesystem()
      7. FS_SECTOR_SIZE_INFORMATION
        • structure : smb3_fs_ss_info
        • validation function : smb2_get_info_filesystem()
      8. FS_CONTROL_INFORMATION
        • structure : smb2_fs_control_info
        • validation function : smb2_get_info_filesystem()
      9. FS_POSIX_INFORMATION
        • structure : filesystem_posix_info
        • validation function : smb2_get_info_filesystem()
    3. SMB2_O_INFO_SECURITY
      • structure : smb_ntsd, smb_acl, smb_ace, smb_sid
      • validation function : build_sec_desc()
  21. smb2 set info (Reviewer: )
    1. SMB2_O_INFO_FILE
      1. FILE_BASIC_INFORMATION
        • structure : smb2_file_basic_info
        • validation functioin : smb2_set_info_file()
      2. FILE_ALLOCATION_INFORMATION
        • structure : smb2_file_alloc_info
        • validation functioin : smb2_set_info_file()
      3. FILE_END_OF_FILE_INFORMATION
        • structure : smb2_file_eof_info
        • validation functioin : smb2_set_info_file()
      4. FILE_RENAME_INFORMATION
        • structure : smb2_file_rename_info
        • validation functioin : smb2_set_info_file(), set_rename_info()
      5. FILE_LINK_INFORMATION
        • structure : smb2_file_link_info
        • validation functioin : smb2_create_link()
      6. FILE_DISPOSITION_INFORMATION
        • structure : smb2_file_disposition_info
        • validation functioin : smb2_set_info_file()
      7. FILE_FULL_EA_INFORMATION
      8. structure : smb2_ea_info
      9. validation functioin : smb2_set_info_file(), smb2_set_ea
      10. FILE_POSITION_INFORMATION
        • structure : smb2_file_pos_info
        • validation functioin : smb2_set_info_file()
      11. FILE_MODE_INFORMATION
        • structure : smb2_file_mode_info
        • validation functioin : smb2_set_info_file()
    2. SMB2_O_INFO_SECURITY
      • structure : smb_ntsd, smb_acl, smb_ace, smb_sid
      • validation function : parse_sec_desc()
  22. smb2 oplock break ack (Reviewer: )
    • structure : smb2_oplock_break
    • validation function : smb20_oplock_break_ack()
  23. smb2 lease break ack (Reviewer: )
    • structure : smb2_lease_ack
    • validation function : smb21_lease_break_ack()