Commit 61a09cfc1214 for kernel

commit 61a09cfc121472013f99ae75066676739a5db626
Merge: 0714cf44ac76 4c6320e0ad40
Author: Linus Torvalds <torvalds@linux-foundation.org>
Date:   Sun Aug 23 08:41:36 2026 -0700

    Merge tag 'ksmbd-for-7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/smb

    Pull smb server updates from Namjae Jeon:
     "This contains server updates focused on SMB2 command sequencing, SMB3
      request replay and encryption, Apple Time Machine interoperability,
      protocol-compatibility fixes validated with smbtorture, security
      hardening, SMB Direct transport support, connection reliability, and
      other correctness improvements.

      New features:

       - Implement the SMB2 command sequence window

         Enforce the credit-based MessageId range for each connection,
         rejecting out-of-window, duplicate, and wrapped sequence numbers.
         This prevents invalid requests and same-channel replays from being
         processed

       - Add SMB3 request replay support

         SMB3 clients may resend requests with SMB2_FLAGS_REPLAY_OPERATION
         after a channel disconnect when the original response was lost.
         Track the required channel and open state to safely handle durable
         CREATE replays and make oplock, lease, and lock replays idempotent,
         avoiding duplicate state changes and improving multichannel
         reconnect reliability

       - Add opt-in Apple Time Machine support

         Implement the AAPL negotiation and related Finder, stream,
         COPYCHUNK, sparse-file, CHANGE_NOTIFY, and RPC compatibility
         required for Time Machine shares, allowing macOS backupd to use
         ksmbd for backups

       - Add per-share SMB3 encryption support

         Allow individual shares to require SMB3 encryption by advertising
         SMB2_SHAREFLAG_ENCRYPT_DATA in TREE_CONNECT responses and rejecting
         unencrypted tree connects and plaintext requests for protected
         shares

       - Add SMB Direct RDMA encryption support

         Extend SMB Direct to support SMB3 encrypted payloads over RDMA,
         with transform negotiation and encryption/decryption for RDMA
         READ/WRITE

      Other changes:

       - Parse and retain AppInstanceVersion contexts, enforce version
         ordering, close older active handles for newer takeovers, and
         reject invalid or unversioned opens according to the SMB2 semantics

       - Accept durable reconnect requests that omit VolatileFileId when the
         persistent ID and reconnect context identify the handle, while
         continuing to reject explicit volatile-ID mismatches

       - Fix SMB2/SMB3 protocol validation and security issues, including
         request offsets, file and object IDs, IPC responses, output buffer
         sizes, SMB3.1.1 binding validation, signing-required handling,
         durable handles, ACLs, maximal access, and security information

       - Fix heap out-of-bounds accesses, use-after-free bugs, memory leaks,
         invalid pointer dereferences, and sensitive-data lifetime issues in
         authentication, Kerberos, preauthentication, sessions, connections,
         and module teardown

       - Correct alternate-data-stream and named-stream handling, COPYCHUNK
         behavior, sparse-file and compression attributes, allocated-range
         queries, file trimming, duplicate extents, DOS attributes,
         snapshots, normalized names, and partial information responses

       - Fix locking, lease, oplock, durable reconnect, async request, and
         CHANGE_NOTIFY races, including deferred-lock rollback, parent
         directory lease notifications, and connection teardown lifetime
         bugs

       - Fix SMB3 encryption handling for compressed requests, expired
         encrypted sessions, interim responses, bound multichannel
         connections, and decryption failures

       - Fix SMB3 multichannel session lookup and session state transitions
         so changes are scoped to the correct bound connections and cannot
         revive connections that are already shutting down

       - Fix DACL access checks so ACE walks are bounded by the declared
         DACL size, preventing data beyond the DACL boundary from being
         interpreted during access validation

       - Fix session accounting and lifetime issues, including session
         counter updates during publication and removal, session leaks on
         registration failure, and procfs creation diagnostics

       - Improve TCP connection reliability by enabling TCP keepalive for
         accepted connections and preserving TCP timers for kernel sockets,
         preventing silent peers from holding connections indefinitely

       - Fix smbdirect RDMA cleanup ordering for completion queues, QPs,
         child sockets, and listener locking

       - Improve async response framing, multi-iovec signing, RPC pipe
         status handling, and ksmbd procfs monitoring for server, share,
         connection, session, and open-file state

       - Remove the obsolete DES crypto header and Kconfig dependency now
         that NTLMv1 support has been removed

       - Update the ksmbd repository URL in MAINTAINERS and add an
         additional KSMBD reviewer"

    * tag 'ksmbd-for-7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/smb: (142 commits)
      MAINTAINERS: update ksmbd repository URL
      MAINTAINERS: add myself as KSMBD reviewer
      smb: server: remove unused DES crypto header
      smb: server: Remove obsolete "select CRYPTO_LIB_DES" from Kconfig file
      ksmbd: keep TCP timers alive for kernel sockets
      ksmbd: enable TCP keepalive for accepted connections
      smb/server: fix session counter on session removal
      smb/server: update session counter under sessions table lock
      smb/server: fix session leak in ksmbd_session_register()
      smb/server: warn if ksmbd_proc_create() fails
      ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size
      ksmbd: make RDMA encryption diagnostics conditional
      ksmbd: add SMB Direct RDMA encryption transform
      ksmbd: handle encrypted compressed requests
      ksmbd: decrypt requests from expired encrypted sessions
      ksmbd: disconnect on SMB3 decryption failure
      ksmbd: encrypt interim responses to encrypted requests
      ksmbd: scope session state changes to bound connections
      ksmbd: fix encrypted request lookup on bound channels
      ksmbd: add per-share SMB3 encryption enforcement
      ...