linux-fsdevel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Amir Goldstein <amir73il@gmail.com>
To: "J. Bruce Fields" <bfields@redhat.com>
Cc: Al Viro <viro@zeniv.linux.org.uk>,
	linux-fsdevel <linux-fsdevel@vger.kernel.org>,
	Christoph Hellwig <hch@lst.de>
Subject: Re: [PATCH] exportfs: fix handling of rename race in reconnect_one()
Date: Mon, 27 Jan 2020 20:38:00 +0200	[thread overview]
Message-ID: <CAOQ4uxhqO5DtSwAtO950oGcnWVaVG+Vcdu6TYDfUKawVNGWEiA@mail.gmail.com> (raw)
In-Reply-To: <20200127173002.GD115624@pick.fieldses.org>

On Mon, Jan 27, 2020 at 7:30 PM J. Bruce Fields <bfields@redhat.com> wrote:
>
> Thanks for spotting this!
>
> On Mon, Jan 27, 2020 at 12:08:00AM +0200, Amir Goldstein wrote:
> > If a disconnected dentry gets looked up and renamed between the
> > call to exportfs_get_name() and lookup_one_len_unlocked(), and if also
> > lookup_one_len_unlocked() returns ERR_PTR(-ENOENT), maybe because old
> > parent was deleted, we return an error, although dentry may be connected.
>
> A comment that -ENOENT means the parent's gone might be helpful.

It doesn't have to mean that, but that's the most obvious case.

>
> But are we sure -ENOENT is what every filesystem returns in the case the
> parent was deleted?

No, it's what __lookup_slow() returns if parent is dead.
Most filesystems do not return -ENOENT for lookup, but a negative
dentry on NULL. I am not sure which filesystems return -ENOENT.
A short survey of NFS exporting fs I didn't find any.

> And are we sure there aren't other cases that
> should be handled similarly to -ENOENT?
>

Not sure, but ENOENT is the most obvious one for rename race.

> > Commit 909e22e05353 ("exportfs: fix 'passing zero to ERR_PTR()'
> > warning") changes this behavior from always returning success,
> > regardless if dentry was reconnected by somoe other task, to always
> > returning a failure.
>
> I wonder whether it might be safest to take the out_reconnected case on
> any error, not just -ENOENT.
>

I wondered that as well, but preferred to follow the precedent.

> Looking further back through the history....  Looks like the missing
> PTR_ERR(tmp) was just a mistake, introduced in 2013 by my bbf7a8a3562f
> "exportfs: move most of reconnect_path to helper function".  So the
> historical behavior was always to bail on error.
>
> The old code still did a DCACHE_DISCONNECTED check on the target dentry
> in that case and returned success if it found that already cleared, but
> we can't necessarily rely on DCACHE_DISCONNECTED being cleared
> immediately, so the old code was probably still vulnerable to the race
> you saw.
>

Yeh, I started to try and document history, but since there seemed to be
no point where behavior looked sane I gave up.

> There's not much value in preserving the error as exportfs_decode_fh()
> ends up turning everything into ENOMEM or ESTALE for some reason.
>

You signed up on this reason...

Thanks,
Amir.

commit 09bb8bfffd29c3dffb72bc2c69a062dfb1ae624c
Author: NeilBrown <neilb@suse.com>
Date:   Thu Aug 4 10:19:06 2016 +1000

    exportfs: be careful to only return expected errors.

    When nfsd calls fh_to_dentry, it expect ESTALE or ENOMEM as errors.
    In particular it can be tempting to return ENOENT, but this is not
    handled well by nfsd.

    Rather than requiring strict adherence to error code code filesystems,
    treat all unexpected error codes the same as ESTALE.  This is safest.

    Signed-off-by: NeilBrown <neilb@suse.com>
    Signed-off-by: J. Bruce Fields <bfields@redhat.com>

  reply	other threads:[~2020-01-27 18:38 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-01-26 22:08 [PATCH] exportfs: fix handling of rename race in reconnect_one() Amir Goldstein
2020-01-27  8:04 ` Christoph Hellwig
2020-01-27 17:30 ` J. Bruce Fields
2020-01-27 18:38   ` Amir Goldstein [this message]
2020-01-27 21:17     ` J. Bruce Fields
2020-02-06 20:22       ` Amir Goldstein
2020-02-06 21:10         ` J. Bruce Fields
2020-02-06 21:45 ` Al Viro
2020-02-07  6:26   ` Amir Goldstein
2020-03-13 14:33     ` Amir Goldstein

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=CAOQ4uxhqO5DtSwAtO950oGcnWVaVG+Vcdu6TYDfUKawVNGWEiA@mail.gmail.com \
    --to=amir73il@gmail.com \
    --cc=bfields@redhat.com \
    --cc=hch@lst.de \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=viro@zeniv.linux.org.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).