android_kernel_xiaomi_sm8350/fs/smbfs
Jeff Layton ce88cc5ed8 smbfs: fix calculation of kernel_recvmsg size parameter in smb_receive()
smb_receive calls kernel_recvmsg with a size that's the minimum of the
amount of buffer space in the kvec passed in or req->rq_rlen (which
represents the length of the response).  This does not take into account
any data that was read in a request earlier pass through smb_receive.

If the first pass through smb_receive receives some but not all of the
response, then the next pass can call kernel_recvmsg with a size field
that's too big.  kernel_recvmsg can overrun into the next response,
throwing off the alignment and making it unrecognizable.

This causes messages like this to pop up in the ring buffer:

smb_get_length: Invalid NBT packet, code=69

as well as other errors indicating that the response is unrecognizable.
Typically this is seen on a smbfs mount under heavy I/O.

This patch changes the code to use (req->rq_rlen - req->rq_bytes_recvd)
instead instead of just req->rq_rlen, since that should represent the
amount of unread data in the response.

I think this is correct, but an ACK or NACK from someone more familiar
with this code would be appreciated...

Signed-off-by: Jeff Layton <jlayton@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2008-02-06 10:41:02 -08:00
..
cache.c
dir.c
file.c smbfs: fix debug builds 2007-11-14 18:45:43 -08:00
getopt.c
getopt.h
inode.c deprecate smbfs in favour of cifs 2008-02-05 14:37:15 -08:00
ioctl.c
Makefile FS: Remove dead code 2008-01-28 23:14:37 +01:00
proc.c smbfs: fix debug builds 2007-11-14 18:45:43 -08:00
proto.h
request.c Remove commented-out code copied from NFS 2007-12-06 17:40:31 -05:00
request.h
smb_debug.h
smbiod.c smbfs: fix debug builds 2007-11-14 18:45:43 -08:00
sock.c smbfs: fix calculation of kernel_recvmsg size parameter in smb_receive() 2008-02-06 10:41:02 -08:00
symlink.c