From: NeilBrown <neilb@ownmail.net>
To: Trond Myklebust <trondmy@kernel.org>,
Anna Schumaker <anna@kernel.org>,
Alexander Viro <viro@zeniv.linux.org.uk>,
Christian Brauner <brauner@kernel.org>
Cc: Jeff Layton <jlayton@kernel.org>, Jan Kara <jack@suse.cz>,
linux-fsdevel@vger.kernel.org, linux-nfs@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: [PATCH v2 2/9] nfs: fix nfs_call_unlink()
Date: Tue, 29 Sep 2026 12:21:12 +1000 [thread overview]
Message-ID: <20260929022547.1428036-3-neilb@ownmail.net> (raw)
In-Reply-To: <20260929022547.1428036-1-neilb@ownmail.net>
From: NeilBrown <neil@brown.name>
nfs_call_unlink() calls d_alloc_parallel() on a dentry which has not had
the d_hash calculated. d_alloc_parallel() assume this is calculated and
doesn't calculate it itself.
So this will never find an existing dentry and so will not detect
the races it aims to detect.
This dentry ("alias") is never hashed so there is no lasting
inconsistency in the dcache.
Fixes: 565277f63c61 ("NFS: Fix a race in sillyrename")
Signed-off-by: NeilBrown <neil@brown.name>
---
fs/nfs/unlink.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/fs/nfs/unlink.c b/fs/nfs/unlink.c
index c8d712204e64..11a46a993e11 100644
--- a/fs/nfs/unlink.c
+++ b/fs/nfs/unlink.c
@@ -125,6 +125,9 @@ static int nfs_call_unlink(struct dentry *dentry, struct inode *inode, struct nf
struct dentry *alias;
down_read_non_owner(&NFS_I(dir)->rmdir_sem);
+ data->args.name.hash = full_name_hash(dentry->d_parent,
+ data->args.name.name,
+ data->args.name.len);
alias = d_alloc_parallel(dentry->d_parent, &data->args.name);
if (IS_ERR(alias)) {
up_read_non_owner(&NFS_I(dir)->rmdir_sem);
--
2.50.0.107.gf914562f5916.dirty
next prev parent reply other threads:[~2026-09-29 2:26 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 2:21 [PATCH v2 0/9] nfs: prepare for VFS locking changes NeilBrown
2026-09-29 2:21 ` [PATCH v2 1/9] nfs: fix open-blocking with d_fsdata NeilBrown
2026-09-29 2:21 ` NeilBrown [this message]
2026-09-29 2:21 ` [PATCH v2 3/9] nfs: remove d_drop()/d_alloc_parallel() from nfs_atomic_open() NeilBrown
2026-09-30 14:32 ` John Stoffel
2026-09-30 21:17 ` NeilBrown
2026-10-01 19:43 ` John Stoffel
2026-09-29 2:21 ` [PATCH v2 4/9] nfs: use d_splice_alias() in nfs_link() NeilBrown
2026-09-29 2:21 ` [PATCH v2 5/9] nfs: don't d_drop() before d_splice_alias() NeilBrown
2026-09-29 2:21 ` [PATCH v2 6/9] nfs: don't d_drop() before d_splice_alias() in atomic_create NeilBrown
2026-09-29 2:21 ` [PATCH v2 7/9] nfs: Use d_alloc_trylock() in nfs_prime_dcache() NeilBrown
2026-09-29 2:21 ` [PATCH v2 8/9] nfs: use d_alloc_trylock() in silly-rename NeilBrown
2026-09-29 2:21 ` [PATCH v2 9/9] nfs: use d_duplicate() NeilBrown
2026-09-29 21:24 ` [PATCH v2 0/9] nfs: prepare for VFS locking changes Anna Schumaker
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929022547.1428036-3-neilb@ownmail.net \
--to=neilb@ownmail.net \
--cc=anna@kernel.org \
--cc=brauner@kernel.org \
--cc=jack@suse.cz \
--cc=jlayton@kernel.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-nfs@vger.kernel.org \
--cc=neil@brown.name \
--cc=trondmy@kernel.org \
--cc=viro@zeniv.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox