Linux CIFS filesystem development
 help / color / mirror / Atom feed
From: Jeff Layton <jlayton@kernel.org>
To: NeilBrown <neil@brown.name>,
	Alexander Viro <viro@zeniv.linux.org.uk>,
	 Christian Brauner <brauner@kernel.org>,
	Chuck Lever <cel@kernel.org>, Jori Koolstra <jkoolstra@xs4all.nl>,
	Mateusz Guzik <mjguzik@gmail.com>,
	Dorjoy Chowdhury <dorjoychy111@gmail.com>
Cc: Trond Myklebust <trondmy@kernel.org>,
	Anna Schumaker <anna@kernel.org>,
	 Andreas Gruenbacher	 <agruenba@redhat.com>,
	gfs2@lists.linux.dev, Ilya Dryomov <idryomov@gmail.com>,
	 Alex Markuze <amarkuze@redhat.com>,
	Viacheslav Dubeyko <slava@dubeyko.com>,
	ceph-devel@vger.kernel.org,  Paulo Alcantara	 <pc@manguebit.org>,
	Namjae Jeon <linkinjeon@kernel.org>,
	 linux-cifs@vger.kernel.org, linux-fsdevel@vger.kernel.org,
	 linux-nfs@vger.kernel.org
Subject: Re: [PATCH v2 11/14] nfsd: check for mountpoints after non-creating open.
Date: Thu, 24 Sep 2026 09:03:55 -0400	[thread overview]
Message-ID: <2a78884377a5e537dab390788d66b10fbf2b2726.camel@kernel.org> (raw)
In-Reply-To: <20260919022441.3305170-12-neilb@ownmail.net>

LLM review:

> diff --git a/fs/nfsd/nfs4proc.c b/fs/nfsd/nfs4proc.c
> index 6e443503d0b7..3d37754f787b 100644
> --- a/fs/nfsd/nfs4proc.c
> +++ b/fs/nfsd/nfs4proc.c

[ ... ]

> @@ -466,6 +454,14 @@ nfsd4_create_file(struct svc_rqst *rqstp, struct svc_fh *fhp,
>  			status = nfserr_exist;
>  			goto out;
>  		}
> +		/* We opened an existing file, it might be a junction. */
> +		if (unlikely(nfsd_mountpoint(child, fhp->fh_export) == 1)) {
> +			dget(child);
> +			nfsd_filp_close(open->op_filp);
> +			open->op_filp = NULL;
> +			goto do_cross_mnt;
> +		}
> +

[ ... ]

> @@ -511,6 +507,21 @@ nfsd4_create_file(struct svc_rqst *rqstp, struct svc_fh *fhp,
>  out:
>  	nfsd_attrs_free(&attrs);
>  	return status;
> +
> +do_cross_mnt:
> +	exp = exp_get(fhp->fh_export);
> +
> +	status = nfsd_cross_mnt(rqstp, &child, &exp);
> +	if (status == nfs_ok)
> +		status = fh_compose(resfhp, exp,
> +				    child, fhp);

When the new junction check triggers, resfhp was already composed
earlier in nfsd4_create_file(), so the fh_compose() in do_cross_mnt
runs a second time on the same handle:

fs/nfsd/nfsfh.c:fh_compose() {
	...
	if (fhp->fh_dentry) {
		printk(KERN_ERR "fh_compose: fh %pd2 not initialized!\n",
		       dentry);
	}
	...
	fhp->fh_dentry = dget(dentry); /* our internal copy */
	fhp->fh_export = exp_get(exp);
	...
}

The first composed dentry and export references are overwritten
without being released. Should resfhp be released before crossing,
or the mountpoint check done before the first compose?

-- 
Jeff Layton <jlayton@kernel.org>

  reply	other threads:[~2026-09-24 13:04 UTC|newest]

Thread overview: 48+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-19  2:06 [PATCH v2 01/14] fixes for vfs_lookup_open, and integration with nfsd NeilBrown
2026-09-19  2:06 ` [PATCH v2 01/14] VFS: revise and expand documentation for atomic_open NeilBrown
2026-09-24 12:25   ` Jeff Layton
2026-09-19  2:06 ` [PATCH v2 02/14] nfs: correctly handle NFS4ERR_WRONG_TYPE from v4 OPEN request NeilBrown
2026-09-24 12:55   ` Jeff Layton
2026-09-24 13:01   ` Jeff Layton
2026-09-19  2:06 ` [PATCH v2 03/14] gfs2: simplify atomic_open handling NeilBrown
2026-09-19 16:49   ` Andreas Gruenbacher
2026-09-19 22:22     ` NeilBrown
2026-09-20 16:31       ` Andreas Gruenbacher
2026-09-22 21:16         ` NeilBrown
2026-09-19  2:06 ` [PATCH v2 04/14] ceph: simplify atomic_open to use finish_no_open() NeilBrown
2026-09-24 13:02   ` Jeff Layton
2026-09-25 21:49     ` NeilBrown
2026-09-26 11:48       ` Jeff Layton
2026-09-19  2:06 ` [PATCH v2 05/14] cifs: allow -EISDIR precedence over -EFTYPE in __cifs_do_create() NeilBrown
2026-09-23  5:54   ` Namjae Jeon
2026-09-23  6:50     ` NeilBrown
2026-09-23  7:52       ` Namjae Jeon
2026-09-23  8:13   ` Namjae Jeon
2026-09-19  2:06 ` [PATCH v2 06/14] vfs: add some allowed open flags to vfs_lookup_open() NeilBrown
2026-09-24 12:54   ` Jeff Layton
2026-09-29 15:18   ` Jori Koolstra
2026-09-29 22:04     ` NeilBrown
2026-09-19  2:06 ` [PATCH v2 07/14] vfs: O_NONBLOCK|O_CREAT open shouldn't wait for directory delegation NeilBrown
2026-09-24 12:51   ` Jeff Layton
2026-09-19  2:06 ` [PATCH v2 08/14] vfs: don't return -ENODEV from vfs_lookup_open() NeilBrown
2026-09-24 13:07   ` Jeff Layton
2026-09-19  2:06 ` [PATCH v2 09/14] vfs: change vfs_lookup_open() to use do_open(), not vfs_open() NeilBrown
2026-09-24 13:13   ` Jeff Layton
2026-09-19  2:06 ` [PATCH v2 10/14] nfsd: make EEXIST checks in nfsd4_create_file() more consistent NeilBrown
2026-09-24 13:23   ` Jeff Layton
2026-09-25 21:57     ` NeilBrown
2026-09-19  2:06 ` [PATCH v2 11/14] nfsd: check for mountpoints after non-creating open NeilBrown
2026-09-24 13:03   ` Jeff Layton [this message]
2026-09-25 22:14     ` NeilBrown
2026-09-19  2:06 ` [PATCH v2 12/14] nfsd: switch NFS4 OPEN to use vfs_lookup_open() NeilBrown
2026-09-20 17:10   ` Chuck Lever
2026-09-22 21:55     ` NeilBrown
2026-09-23  4:07       ` NeilBrown
2026-09-19  2:06 ` [PATCH v2 13/14] nfsd: change nfsd_check_obj_isreg() to use nfs error codes NeilBrown
2026-09-24 13:25   ` Jeff Layton
2026-09-19  2:06 ` [PATCH v2 14/14] nfsd: use vfs_lookup_open() for non-creating open requests too NeilBrown
2026-09-20 17:13   ` Chuck Lever
2026-09-25 22:26     ` NeilBrown
2026-09-25 16:04 ` [PATCH v2 01/14] fixes for vfs_lookup_open, and integration with nfsd Christian Brauner
2026-09-25 16:56   ` Chuck Lever
  -- strict thread matches above, loose matches on Subject: below --
2026-09-20 17:08 [PATCH v2 11/14] nfsd: check for mountpoints after non-creating open Chuck Lever

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2a78884377a5e537dab390788d66b10fbf2b2726.camel@kernel.org \
    --to=jlayton@kernel.org \
    --cc=agruenba@redhat.com \
    --cc=amarkuze@redhat.com \
    --cc=anna@kernel.org \
    --cc=brauner@kernel.org \
    --cc=cel@kernel.org \
    --cc=ceph-devel@vger.kernel.org \
    --cc=dorjoychy111@gmail.com \
    --cc=gfs2@lists.linux.dev \
    --cc=idryomov@gmail.com \
    --cc=jkoolstra@xs4all.nl \
    --cc=linkinjeon@kernel.org \
    --cc=linux-cifs@vger.kernel.org \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-nfs@vger.kernel.org \
    --cc=mjguzik@gmail.com \
    --cc=neil@brown.name \
    --cc=pc@manguebit.org \
    --cc=slava@dubeyko.com \
    --cc=trondmy@kernel.org \
    --cc=viro@zeniv.linux.org.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox