* [PATCH] NFSD: Fix CB_GETATTR status fix
@ 2025-02-10 16:43 cel
2025-02-10 16:48 ` Jeff Layton
0 siblings, 1 reply; 2+ messages in thread
From: cel @ 2025-02-10 16:43 UTC (permalink / raw)
To: Neil Brown, Jeff Layton, Olga Kornievskaia, Dai Ngo, Tom Talpey
Cc: linux-nfs, Chuck Lever
From: Chuck Lever <chuck.lever@oracle.com>
Jeff says:
Now that I look, 1b3e26a5ccbf is wrong. The patch on the ml was correct, but
the one that got committed is different. It should be:
status = decode_cb_op_status(xdr, OP_CB_GETATTR, &cb->cb_status);
if (unlikely(status || cb->cb_status))
If "status" is non-zero, decoding failed (usu. BADXDR), but we also want to
bail out and not decode the rest of the call if the decoded cb_status is
non-zero. That's not happening here, cb_seq_status has already been checked and
is non-zero, so this ends up trying to decode the rest of the CB_GETATTR reply
when it doesn't exist.
Reported-by: Jeff Layton: <jlayton@kernel.org>
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=219737
Fixes: 1b3e26a5ccbf ("NFSD: fix decoding in nfs4_xdr_dec_cb_getattr")
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
---
fs/nfsd/nfs4callback.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/nfsd/nfs4callback.c b/fs/nfsd/nfs4callback.c
index cf6d29828f4e..484077200c5d 100644
--- a/fs/nfsd/nfs4callback.c
+++ b/fs/nfsd/nfs4callback.c
@@ -679,7 +679,7 @@ static int nfs4_xdr_dec_cb_getattr(struct rpc_rqst *rqstp,
return status;
status = decode_cb_op_status(xdr, OP_CB_GETATTR, &cb->cb_status);
- if (unlikely(status || cb->cb_seq_status))
+ if (unlikely(status || cb->cb_status))
return status;
if (xdr_stream_decode_uint32_array(xdr, bitmap, 3) < 0)
return -NFSERR_BAD_XDR;
--
2.47.0
^ permalink raw reply related [flat|nested] 2+ messages in thread* Re: [PATCH] NFSD: Fix CB_GETATTR status fix
2025-02-10 16:43 [PATCH] NFSD: Fix CB_GETATTR status fix cel
@ 2025-02-10 16:48 ` Jeff Layton
0 siblings, 0 replies; 2+ messages in thread
From: Jeff Layton @ 2025-02-10 16:48 UTC (permalink / raw)
To: cel, Neil Brown, Olga Kornievskaia, Dai Ngo, Tom Talpey
Cc: linux-nfs, Chuck Lever
On Mon, 2025-02-10 at 11:43 -0500, cel@kernel.org wrote:
> From: Chuck Lever <chuck.lever@oracle.com>
>
> Jeff says:
>
> Now that I look, 1b3e26a5ccbf is wrong. The patch on the ml was correct, but
> the one that got committed is different. It should be:
>
> status = decode_cb_op_status(xdr, OP_CB_GETATTR, &cb->cb_status);
> if (unlikely(status || cb->cb_status))
>
> If "status" is non-zero, decoding failed (usu. BADXDR), but we also want to
> bail out and not decode the rest of the call if the decoded cb_status is
> non-zero. That's not happening here, cb_seq_status has already been checked and
> is non-zero, so this ends up trying to decode the rest of the CB_GETATTR reply
> when it doesn't exist.
>
> Reported-by: Jeff Layton: <jlayton@kernel.org>
> Closes: https://bugzilla.kernel.org/show_bug.cgi?id=219737
> Fixes: 1b3e26a5ccbf ("NFSD: fix decoding in nfs4_xdr_dec_cb_getattr")
> Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
> ---
> fs/nfsd/nfs4callback.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/fs/nfsd/nfs4callback.c b/fs/nfsd/nfs4callback.c
> index cf6d29828f4e..484077200c5d 100644
> --- a/fs/nfsd/nfs4callback.c
> +++ b/fs/nfsd/nfs4callback.c
> @@ -679,7 +679,7 @@ static int nfs4_xdr_dec_cb_getattr(struct rpc_rqst *rqstp,
> return status;
>
> status = decode_cb_op_status(xdr, OP_CB_GETATTR, &cb->cb_status);
> - if (unlikely(status || cb->cb_seq_status))
> + if (unlikely(status || cb->cb_status))
> return status;
> if (xdr_stream_decode_uint32_array(xdr, bitmap, 3) < 0)
> return -NFSERR_BAD_XDR;
Reviewed-by: Jeff Layton <jlayton@kernel.org>
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2025-02-10 16:48 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-02-10 16:43 [PATCH] NFSD: Fix CB_GETATTR status fix cel
2025-02-10 16:48 ` Jeff Layton
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox