v3.0.5-experimental — changes since v3.0.4-experimental
Fix: SMB uploads to hardened Windows shares (11 24H2 / Server 2025)
Affects setups where Windows enforces SMB signing per-share or
per-session rather than globally (e.g. RequireSigning on the share, or
24H2-era hardening). Negotiate on those servers still advertises signing as
only enabled, so libsmb2 sent requests unsigned — and on SMB 3.1.1 signs
the tree connect but nothing else, producing a mixed session that hardened
servers reject with STATUS_INVALID_PARAMETER on every CREATE. Symptom:
authentication and share connect succeeded, then all uploads failed.
Diagnosed from a real packet capture; smbclient worked because it signs
by default.
- Adaptive signing: uploads start unsigned as before; on the first
STATUS_INVALID_PARAMETERrejection the connection is rebuilt with
signing forced and the operation retried — matching the mixed-signing
signature exactly (gated to SMB 3.1.1 sessions with credentials). - Learned preference (
s_sign_learned, RAM-only): subsequent sessions
in the same boot connect signed directly; the "Test connection" button
mirrors it. If a learned-signed connect ever fails, it falls back to
unsigned — the preference can never wedge the uploader. - Recovery: after the signed reconnect, the remote directory chain is
rebuilt before retrying (mkdir calls on the rejected session failed
silently). - Guest/no-password sessions are skipped — they have no session key to
sign with. - No vendored libsmb2 changes; uses the existing
smb2_set_sign,
smb2_get_nterror,smb2_get_dialectAPIs. No behavioral change for
servers that accept unsigned requests today, including signing-disabled
NAS/Samba setups.
Verified
- Host libsmb2 client (vendored code, identical sequence) against Samba
4.19.9: full mkdir/open/write/close flow passes at SMB 3.0.2 and 3.1.1
withserver signing = required, and atsigning = autowith forced
client signing — including signed compound Create+Close requests. - 16/16 host tests pass; build clean, ~28% app partition free.
- Note: the "enabled but enforced" server policy is Windows-only behavior
and cannot be emulated on Samba — first real-Windows validation pending.