All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Chuck Lever" <cel@kernel.org>
To: "Jeff Layton" <jlayton@kernel.org>, NeilBrown <neil@brown.name>,
	"Olga Kornievskaia" <okorniev@redhat.com>,
	"Dai Ngo" <Dai.Ngo@oracle.com>, "Tom Talpey" <tom@talpey.com>
Cc: linux-nfs@vger.kernel.org, linux-kernel@vger.kernel.org,
	"kernel test robot" <lkp@intel.com>
Subject: Re: [PATCH 1/2] nfsd: fix type mismatch and explain host-endian xdr buffer usage
Date: Mon, 03 Aug 2026 12:04:19 -0400	[thread overview]
Message-ID: <c018418c-4f4e-4984-8312-c082509090cd@app.fastmail.com> (raw)
In-Reply-To: <b8a7379cf6e8e73a0e994937a6b738757a8be744.camel@kernel.org>



On Mon, Aug 3, 2026, at 11:43 AM, Jeff Layton wrote:
> On Mon, 2026-08-03 at 11:32 -0400, Chuck Lever wrote:
>> 
>> On Mon, Aug 3, 2026, at 10:49 AM, Jeff Layton wrote:
>> > sparse flagged this type mismatch. Also the xdr buffer usage is a bit
>> > non-standard, so explain what we're doing and why.
>> > 
>> > Fixes: 4b64b811f368 ("nfsd: add notification handlers for dir events")
>> > Reported-by: kernel test robot <lkp@intel.com>
>> > Closes: 
>> > https://lore.kernel.org/oe-kbuild-all/202607310455.AT0GoC5j-lkp@intel.com/
>> > Signed-off-by: Jeff Layton <jlayton@kernel.org>
>> > ---
>> >  fs/nfsd/nfs4xdr.c | 11 ++++++++---
>> >  1 file changed, 8 insertions(+), 3 deletions(-)
>> > 
>> > diff --git a/fs/nfsd/nfs4xdr.c b/fs/nfsd/nfs4xdr.c
>> > index a47eb544b99f..5cbb4a415384 100644
>> > --- a/fs/nfsd/nfs4xdr.c
>> > +++ b/fs/nfsd/nfs4xdr.c
>> > @@ -4383,13 +4383,18 @@ nfsd4_setup_notify_entry4(struct notify_entry4 
>> > *ne, struct xdr_stream *xdr,
>> >  	struct path path = nf->nf_file->f_path;
>> >  	struct nfsd4_fattr_args args = { };
>> >  	const u32 *reqmask;
>> > -	uint32_t *attrmask;
>> > +	u32 *attrmask;
>> >  	__be32 status;
>> >  	bool parent;
>> >  	int ret;
>> > 
>> > -	/* Reserve space for attrmask */
>> > -	attrmask = xdr_reserve_space(xdr, 3 * sizeof(uint32_t));
>> > +	/*
>> > +	 * attrmask is the host-order bmval[3] that nfsd4_encode_attr_vals()
>> > +	 * consumes and that ne_attrs.attrmask.element points at. It must
>> > +	 * outlive this call, so steal a few words from the xdr stream to hold
>> > +	 * it.
>> > +	 */
>> > +	attrmask = (u32 *)xdr_reserve_space(xdr, 3 * sizeof(*attrmask));
>> >  	if (!attrmask)
>> >  		return false;
>> 
>> I still don't understand what's going on. "Steal a few words to hold it"
>> sounds like you're trying to avoid a kmalloc call. Is this code reserving
>> space in the XDR stream, or isn't it? If it is, then accessing those bytes
>> has to be done with a big-endian pointer, the same way it is done at every
>> other xdr_reserve_space() call site. Storing host-order bytes that are not
>> part of an opaque into an XDR stream is just... wrong.
>> 
>> If you're doing the usual "reserve and backfill the encoded data later"
>> dance, then spell it the way everyone else does so us poor human readers
>> can recognize that's what's going on.
>
> It's using a small piece of the xdr buffer (3 32-bit words) to hold the
> host-endian bitmap fields that will later be encoded into the stream
> when the encoding is actually done.
>
> This piece is not accessed by anything else and there is plenty of room
> in the buffer, so I don't see the issue here. Can you elaborate on why
> you feel that this is a problem?

Well A-number-1 is that it's a hack and technical debt. It just
isn't obvious what's going on, it needs a four-line comment to
explain it, and it opens the door to people copy-pasting it to
other encoders.

Number 2 is that the XDR stream buffer is ephemeral. There are
conditions that callers must stick to to keep that pointer valid
for the lifetime of the xdr_stream.

Number 3: Yes, we have a sordid history of grabbing a piece of
the xdr_buf's tail iov for temporary storage. That doesn't make
it wise to do, and assumes behavior about that buffer that is
not guaranteed by sunrpc's API contracts. That makes life hard
when future changes need to change that buffer to, say, a page
rather than kmalloc'd memory. Or when I want to convert this
code to use xdrgen instead of hand-rolled encoding.

So what you've done is fine for operational prototype code, but
not something we can carry forward as production code. The sparse
warning is a canary, it's not the actual structural problem.


> Certainly we could do this with yet another set of separate
> allocations, but I'm not clear on how we'd track them to free them.
> Each notify_entry4 gets a separate bitmap, so we'd need more than one.

The server has a chain of temporary allocations that are freed
after the COMPOUND is released. Could do something similar for
the server's callback client.


-- 
Chuck Lever

  reply	other threads:[~2026-08-03 16:04 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-03 14:49 [PATCH 0/2] nfsd: fix up some sparse warnings Jeff Layton
2026-08-03 14:49 ` [PATCH 1/2] nfsd: fix type mismatch and explain host-endian xdr buffer usage Jeff Layton
2026-08-03 15:32   ` Chuck Lever
2026-08-03 15:43     ` Jeff Layton
2026-08-03 16:04       ` Chuck Lever [this message]
2026-08-03 16:23         ` Jeff Layton
2026-08-03 18:33           ` Chuck Lever
2026-08-03 18:58             ` Jeff Layton
2026-08-04 13:23             ` Jeff Layton
2026-08-03 14:49 ` [PATCH 2/2] nfsd: fix nfserr type in nfsd_lookup_dentry() Jeff Layton
2026-08-03 15:16   ` Chuck Lever

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=c018418c-4f4e-4984-8312-c082509090cd@app.fastmail.com \
    --to=cel@kernel.org \
    --cc=Dai.Ngo@oracle.com \
    --cc=jlayton@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-nfs@vger.kernel.org \
    --cc=lkp@intel.com \
    --cc=neil@brown.name \
    --cc=okorniev@redhat.com \
    --cc=tom@talpey.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.