From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D56E4348C46 for ; Fri, 29 May 2026 18:56:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780080973; cv=none; b=hTEYRXGZ9rh/wwuDXF4G94SGVlLoDgRpuqbtBVi5A/zeroABX31Qj5ZyVNcN0BX2wHIqqCd5A4i3GJaA00UFYs+ejytCZmE+VmRHL7rCiGmeIFtE6oELXSSiYW7Svr6h4ewHMnAjYSm67u9HrO7lUaes1wWqqplwfZHETxN6GcM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780080973; c=relaxed/simple; bh=Eq8v9BDnMGtidgHHv2Zp08P0CNMdC2PQSzOHxPXhKc8=; h=MIME-Version:Date:From:To:Cc:Message-Id:In-Reply-To:References: Subject:Content-Type; b=B8BAqW8bdUqcRC3pUt98rqgSm1yCUgsB7ri+2d1hDxFK+eOKWBeyWarOa/xmqAN6J/MjSCNzgyJYjynkUYpR8+FooBFgOgmNmm2VWy7UuRA4uRY/jO/9WO1cbEOJVKT/3neWQF8KCIaVhUSw95D55o1Tu+aNpZSyNWHlVPjPGiI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=mVHFQShw; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="mVHFQShw" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 245C41F00893; Fri, 29 May 2026 18:56:12 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1780080972; bh=b/kHUiS6zeUE21ZmSwB4Q/Ldq/1CI77vJ/9Gui7oWgs=; h=Date:From:To:Cc:In-Reply-To:References:Subject; b=mVHFQShwSy1Dbn6kR/P83SjXIDffrUvu7o809MAGK+lIYSF5gN+g9PMvctFV8JtQb l7v5aAHu+hm1zFOKWXDM8CoKXhKL+mGrRdLtDp0gLTE4VWluRY8YcKAPrg90P9v8An ZpwzWR5X950ezhLXarM5ZK1jtMWK6eve1/HfiIP56TaXvK1MFb8LzZ5IB6kdS8DPaI U1oviPBBYNB+4MM3Zy9FJj+uOTd+szfzMzrBOQICJUR0LjytS7Kaih4UqwePsermlp xqi+V4A1egq61Wk1lpIn7gs1FcfTvfFhHdDG9bLnJ8owAgSFYZ0boXXeIafo2yNKOD rxD8OXvpqYhDw== Received: from phl-compute-10.internal (phl-compute-10.internal [10.202.2.50]) by mailfauth.phl.internal (Postfix) with ESMTP id 68140F4007D; Fri, 29 May 2026 14:56:11 -0400 (EDT) Received: from phl-imap-15 ([10.202.2.104]) by phl-compute-10.internal (MEProxy); Fri, 29 May 2026 14:56:11 -0400 X-ME-Sender: X-ME-Proxy-Cause: dmFkZTEngVlcI/gU8TDsF8mY2Ph/TO+eQ1kh12hdK/sy0yMtz5mzuu2s2u43n4Bl8ar5Vs CzrUvlegFbVqHbDYUWZUKOWnVGxl7PmkVW/6fteqsdVhVMu4HEWjy47lrdQbUTQe12hHpr 64yO3tAdrDoPw1yFEadxVbElsDUc8QvKpTTK7kHBSq5FYD8kfgk3OxTdjS4R2593np9nL1 PAmU5K/UYC37/cYL0EwoiDbOectNa8olFEeCIQHbEu7K02Q7F8DVT1u51bnVew4vSSI/61 HvVgIcZQTjJ+YdmyQkPKe79LTBz6yEtJxG1iTZclwsMzSto07K0x5Yx6knXRp9ARy0qsb1 WNKWuolac/z/qZzQhM6MzrC7iwfFEYSeaR2Yt0LaKeoderSQfv2rYlbbT1ZnnLEQ2/WEVF 2nuSih8CyBDpf1ebJRZJEB7Yh75iMkyl12/7RJ5RP+rPMH/BJql5CRr88I8g+lwvY6hLKK naH5h2Cfp+YWszxBBHAYrLB8ofhpa9ajTIktPT3vcscaRfWnzEiibMqHDPqnQJo7awbTfn 9/TQ7ppXHkn4jwQUVR4l8e1GAZ0oNvw/acr/UwmoXK4MMvMkOxT2qu+1iy01cUdjsowmoy kfSlzqIhDh+VDmrcN1+L99/j+yViruR11axdRo3Z/aQyDSCezQFuubqZjsyw X-ME-Proxy: Feedback-ID: ifa6e4810:Fastmail Received: by mailuser.phl.internal (Postfix, from userid 501) id 3D59678008F; Fri, 29 May 2026 14:56:11 -0400 (EDT) X-Mailer: MessagingEngine.com Webmail Interface Precedence: bulk X-Mailing-List: linux-nfs@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-ThreadId: A-9Yz8QMcdKk Date: Fri, 29 May 2026 14:55:51 -0400 From: "Chuck Lever" To: "Jeff Layton" , "Chuck Lever" , NeilBrown , "Olga Kornievskaia" , "Dai Ngo" , "Tom Talpey" , "J. Bruce Fields" , "Scott Mayhew" , "Trond Myklebust" , "Andreas Gruenbacher" , "Mike Snitzer" , "Rick Macklem" Cc: "Chris Mason" , linux-nfs@vger.kernel.org, linux-kernel@vger.kernel.org Message-Id: In-Reply-To: <20260528-nfsd-fixes-v1-10-e78708eff77d@kernel.org> References: <20260528-nfsd-fixes-v1-0-e78708eff77d@kernel.org> <20260528-nfsd-fixes-v1-10-e78708eff77d@kernel.org> Subject: Re: [PATCH 10/10] nfsd: validate symlink target length in NFSv4 CREATE Content-Type: text/plain Content-Transfer-Encoding: 7bit On Thu, May 28, 2026, at 5:55 PM, Jeff Layton wrote: > nfsd4_decode_create() accepts an unbounded cr_datalen from the wire for > NF4LNK symlink targets, allowing a client to force a kmalloc of up to > the RPC-max size (~1 MiB) per COMPOUND op that persists until compound > teardown. The VFS rejects oversized targets with ENAMETOOLONG, but the > allocation has already occurred. > > Reject cr_datalen == 0 or cr_datalen >= PATH_MAX early with > nfserr_nametoolong to bound the allocation. > > Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") > Assisted-by: kres:claude-opus-4-7 > Signed-off-by: Jeff Layton > --- > fs/nfsd/nfs4xdr.c | 4 ++++ > 1 file changed, 4 insertions(+) > > diff --git a/fs/nfsd/nfs4xdr.c b/fs/nfsd/nfs4xdr.c > index 5469c6c207ba..1f5e49f50f3a 100644 > --- a/fs/nfsd/nfs4xdr.c > +++ b/fs/nfsd/nfs4xdr.c > @@ -957,6 +957,10 @@ nfsd4_decode_create(struct nfsd4_compoundargs > *argp, union nfsd4_op_u *u) > case NF4LNK: > if (xdr_stream_decode_u32(argp->xdr, &create->cr_datalen) < 0) > return nfserr_bad_xdr; > + if (create->cr_datalen == 0) > + return nfserr_inval; > + if (create->cr_datalen >= PATH_MAX) > + return nfserr_nametoolong; Nit: The protocol already has NFS4_MAXPATHLEN defined to PATH_MAX. The v3 decoder uses its analog NFS3_MAXPATHLEN. Using NFS4_MAXPATHLEN here expresses the protocol-layer intent and matches the cross-version idiom. The new boundary condition differs from v2/v3. v3 uses "tlen > NFS3_MAXPATHLEN", accepting a target of exactly PATH_MAX bytes; this uses ">= PATH_MAX", rejecting it. Switching to "> NFS4_MAXPATHLEN" both adopts the named constant and realigns the maximum accepted length with v2/v3. > p = xdr_inline_decode(argp->xdr, create->cr_datalen); > if (!p) > return nfserr_bad_xdr; > > -- > 2.54.0 -- Chuck Lever