All of lore.kernel.org
 help / color / mirror / Atom feed
From: Chuck Lever <cel@kernel.org>
To: Jeff Layton <jlayton@kernel.org>, NeilBrown <neil@brown.name>,
	 Olga Kornievskaia <okorniev@redhat.com>,
	Dai Ngo <Dai.Ngo@oracle.com>,  Tom Talpey <tom@talpey.com>,
	Scott Mayhew <smayhew@redhat.com>,
	 Trond Myklebust <trondmy@kernel.org>,
	Anna Schumaker <anna@kernel.org>
Cc: linux-nfs@vger.kernel.org,
	Farhad Alemi <farhad.alemi@berkeley.edu>,
	 Chuck Lever <cel@kernel.org>
Subject: [PATCH v2 0/8] Fix premature completion of rpc_pipefs upcalls
Date: Tue, 01 Sep 2026 16:19:40 -0400	[thread overview]
Message-ID: <20260901-alemi-v2-0-e163f94a3a6e@kernel.org> (raw)

Farhad Alemi's syzkaller run against 7.1-rc5 hit a KASAN
vmalloc-out-of-bounds in rpc_queue_upcall() while NFSD was starting
client tracking:

  https://lore.kernel.org/linux-nfs/CA+0ovCjVF58WLeen2ctdzHyWUASAAW3Y=Yjihyq0pFApYawtDg@mail.gmail.com/

The cld downcall matches a reply to its upcall by xid alone. If a
write arrives before nfsdcld has read the upcall, the waiter returns
while its struct rpc_pipe_msg is still queued, and the pipe is left
holding a list_head into a dead stack frame. The blocklayout device
upcall has the same bug, plus two of its own: the waiter can go to
sleep after the reply has arrived, and a reply left over from a
purged upcall is taken as a fresh one.

Guarding the reply exposes the opposite failure. Once a daemon has
read a whole upcall, rpc_pipe_read() unlinks the message from every
pipe list, so nothing the pipe purges on close can reach it. A
daemon that exits between the read and the write leaves its waiter
sleeping uninterruptibly with no way back. bl_resolve_deviceid()
holds nn->bl_mutex across that wait, so every later device
resolution in the net namespace blocks behind it.

rpc_pipefs pipes are mode 0600, so the writer is a daemon running as
root. These patches guard against a broken or hostile daemon, which
is unlikely. I consider the series as hardening rather than urgent.

The gss and idmap consumers keep their message in an object that
outlives the upcall, and gss also releases what a departing daemon
left behind. Neither has either bug.

The application order of the patches matters, so I'm happy to take
the lot through the NFSD tree. An Acked-by: from the NFS client
maintainers would be great.

Farhad, a run of your reproducer against this series would help.

---
Changes in v2:
- Retire the upcall on accept; drop the racy completion_done() test.
- Retire a purged upcall in bl_pipe_destroy_msg(), not in the waiter.
- New patch 6: set nn->cld_net before the cld pipe can be opened.
- New patch 7: complete a cld upcall when nfsdcld closes the pipe.
- New patch 8: complete a device upcall when blkmapd closes the pipe.
- Link to v1: https://patch.msgid.link/20260830-alemi-v1-0-463f80b9e9a8@kernel.org

---
Chuck Lever (8):
      NFSD: Don't complete a cld upcall the daemon has not read
      NFSD: Move the cld upcall message out of the caller's stack frame
      NFSD: Complete a cld upcall when copying its reply fails
      NFSD: Reject an oversized principal hash from nfsdcld
      pnfs/blocklayout: Complete a device upcall only on its own reply
      NFSD: Set nn->cld_net before registering the cld pipe
      NFSD: Complete a cld upcall when the daemon closes the pipe
      pnfs/blocklayout: Complete a device upcall when the pipe is closed

 fs/nfs/blocklayout/blocklayout.h |  5 ---
 fs/nfs/blocklayout/rpc_pipefs.c  | 79 ++++++++++++++++++++++++----------
 fs/nfs/netns.h                   |  5 ++-
 fs/nfsd/nfs4recover.c            | 91 ++++++++++++++++++++++++++++++++--------
 4 files changed, 135 insertions(+), 45 deletions(-)
---
base-commit: e3c3b1a8188b192b125ae1fc9861d9a5d8d43d85
change-id: 20260830-alemi-d9f420956e8d

Best regards,
--  
Chuck Lever


             reply	other threads:[~2026-09-01 20:19 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-01 20:19 Chuck Lever [this message]
2026-09-01 20:19 ` [PATCH v2 1/8] NFSD: Don't complete a cld upcall the daemon has not read Chuck Lever
2026-09-01 20:19 ` [PATCH v2 2/8] NFSD: Move the cld upcall message out of the caller's stack frame Chuck Lever
2026-09-01 20:19 ` [PATCH v2 3/8] NFSD: Complete a cld upcall when copying its reply fails Chuck Lever
2026-09-01 20:19 ` [PATCH v2 4/8] NFSD: Reject an oversized principal hash from nfsdcld Chuck Lever
2026-09-01 20:19 ` [PATCH v2 5/8] pnfs/blocklayout: Complete a device upcall only on its own reply Chuck Lever
2026-09-01 20:19 ` [PATCH v2 6/8] NFSD: Set nn->cld_net before registering the cld pipe Chuck Lever
2026-09-01 20:19 ` [PATCH v2 7/8] NFSD: Complete a cld upcall when the daemon closes the pipe Chuck Lever
2026-09-01 20:19 ` [PATCH v2 8/8] pnfs/blocklayout: Complete a device upcall when the pipe is closed Chuck Lever

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260901-alemi-v2-0-e163f94a3a6e@kernel.org \
    --to=cel@kernel.org \
    --cc=Dai.Ngo@oracle.com \
    --cc=anna@kernel.org \
    --cc=farhad.alemi@berkeley.edu \
    --cc=jlayton@kernel.org \
    --cc=linux-nfs@vger.kernel.org \
    --cc=neil@brown.name \
    --cc=okorniev@redhat.com \
    --cc=smayhew@redhat.com \
    --cc=tom@talpey.com \
    --cc=trondmy@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.