* [PATCH v1 1/2] NFSD: map fh_verify() status codes for NFS_ACLv2 replies
@ 2026-09-16 0:42 Chuck Lever
2026-09-16 0:42 ` [PATCH v1 2/2] NFSD: map fh_verify() status codes for NFS_ACLv3 replies Chuck Lever
0 siblings, 1 reply; 4+ messages in thread
From: Chuck Lever @ 2026-09-16 0:42 UTC (permalink / raw)
To: NeilBrown, Jeff Layton, Olga Kornievskaia, Dai Ngo, Tom Talpey; +Cc: linux-nfs
The NFS_ACL v2 protocol shares its status code space with NFSv2,
which has no NFSERR_BADHANDLE and no NFSERR_NOFILEHANDLE. An
NFS_ACLv2 GETACL, SETACL, GETATTR, or ACCESS request that carries a
malformed or empty file handle gets a reply with status 10001 or
10020, values the client cannot interpret.
Commit 1459ad57673b ("nfsd: Move error code mapping to per-version
proc code.") removed the version check from fh_verify() that turned
those codes into NFSERR_STALE for any version 2 program. The NFSv2
procedures gained nfsd_map_status() in exchange, but the NFS_ACL v2
procedures did not, so the unmapped status reaches the encoder.
Add the same mapping to the NFS_ACL v2 procedures.
Fixes: 1459ad57673b ("nfsd: Move error code mapping to per-version proc code.")
Signed-off-by: Chuck Lever <cel@kernel.org>
---
fs/nfsd/nfs2acl.c | 18 ++++++++++++++++++
1 file changed, 18 insertions(+)
diff --git a/fs/nfsd/nfs2acl.c b/fs/nfsd/nfs2acl.c
index 0a5c444fef99..0673e83b6666 100644
--- a/fs/nfsd/nfs2acl.c
+++ b/fs/nfsd/nfs2acl.c
@@ -59,6 +59,20 @@ static const struct nfsd_access_maps nfsd2_access_maps = {
.other = nfsd2_otheraccess,
};
+static __be32 nfsacld_map_status(__be32 status)
+{
+ switch (status) {
+ case nfserr_nofilehandle:
+ case nfserr_badhandle:
+ status = nfserr_stale;
+ break;
+ case nfserr_wrongsec:
+ status = nfserr_acces;
+ break;
+ }
+ return status;
+}
+
/*
* NULL call.
*/
@@ -123,6 +137,7 @@ static __be32 nfsacld_proc_getacl(struct svc_rqst *rqstp)
/* resp->acl_{access,default} are released in nfssvc_release_getacl. */
out:
+ resp->status = nfsacld_map_status(resp->status);
return rpc_success;
fail:
@@ -181,6 +196,7 @@ static __be32 nfsacld_proc_setacl(struct svc_rqst *rqstp)
out:
/* argp->acl_{access,default} are released in nfsaclsvc_release_setacl. */
+ resp->status = nfsacld_map_status(resp->status);
return rpc_success;
out_drop_lock:
@@ -207,6 +223,7 @@ static __be32 nfsacld_proc_getattr(struct svc_rqst *rqstp)
goto out;
resp->status = fh_getattr(&resp->fh, &resp->stat);
out:
+ resp->status = nfsacld_map_status(resp->status);
return rpc_success;
}
@@ -231,6 +248,7 @@ static __be32 nfsacld_proc_access(struct svc_rqst *rqstp)
goto out;
resp->status = fh_getattr(&resp->fh, &resp->stat);
out:
+ resp->status = nfsacld_map_status(resp->status);
return rpc_success;
}
--
2.55.0
^ permalink raw reply related [flat|nested] 4+ messages in thread* [PATCH v1 2/2] NFSD: map fh_verify() status codes for NFS_ACLv3 replies
2026-09-16 0:42 [PATCH v1 1/2] NFSD: map fh_verify() status codes for NFS_ACLv2 replies Chuck Lever
@ 2026-09-16 0:42 ` Chuck Lever
0 siblings, 0 replies; 4+ messages in thread
From: Chuck Lever @ 2026-09-16 0:42 UTC (permalink / raw)
To: NeilBrown, Jeff Layton, Olga Kornievskaia, Dai Ngo, Tom Talpey; +Cc: linux-nfs
The NFS_ACLv3 protocol shares its status code space with NFSv3,
which has NFS3ERR_BADHANDLE but no NFSERR_NOFILEHANDLE. An
NFS_ACLv3 GETACL or SETACL request that carries an empty file
handle gets a reply with status 10020, a value the client cannot
interpret.
Commit 1459ad57673b ("nfsd: Move error code mapping to per-version
proc code.") made fh_verify() return nfserr_nofilehandle for an
empty handle regardless of protocol version. The NFSv3 procedures
gained nfsd3_map_status() in exchange, but the NFS_ACLv3 procedures
did not, so the unmapped status reaches the encoder.
Add the same mapping to the NFS_ACLv3 procedures.
Fixes: 1459ad57673b ("nfsd: Move error code mapping to per-version proc code.")
Signed-off-by: Chuck Lever <cel@kernel.org>
---
fs/nfsd/nfs3acl.c | 15 +++++++++++++++
1 file changed, 15 insertions(+)
diff --git a/fs/nfsd/nfs3acl.c b/fs/nfsd/nfs3acl.c
index 7183995182ab..5219ec634587 100644
--- a/fs/nfsd/nfs3acl.c
+++ b/fs/nfsd/nfs3acl.c
@@ -14,6 +14,19 @@
#include "xdr3.h"
#include "vfs.h"
+static __be32 nfsd3_map_status(__be32 status)
+{
+ switch (status) {
+ case nfserr_nofilehandle:
+ status = nfserr_badhandle;
+ break;
+ case nfserr_wrongsec:
+ status = nfserr_acces;
+ break;
+ }
+ return status;
+}
+
/*
* NULL call.
*/
@@ -72,6 +85,7 @@ static __be32 nfsd3_proc_getacl(struct svc_rqst *rqstp)
/* resp->acl_{access,default} are released in nfs3svc_release_getacl. */
out:
+ resp->status = nfsd3_map_status(resp->status);
return rpc_success;
fail:
@@ -125,6 +139,7 @@ static __be32 nfsd3_proc_setacl(struct svc_rqst *rqstp)
resp->status = nfserrno(error);
out:
/* argp->acl_{access,default} are released in nfs3svc_release_setacl. */
+ resp->status = nfsd3_map_status(resp->status);
return rpc_success;
}
--
2.55.0
^ permalink raw reply related [flat|nested] 4+ messages in thread
* [PATCH v1 00/27] Convert server-side NFSv2 XDR to use xdrgen
@ 2026-09-16 16:28 Chuck Lever
2026-09-16 16:28 ` [PATCH v1 2/2] NFSD: map fh_verify() status codes for NFS_ACLv3 replies Chuck Lever
0 siblings, 1 reply; 4+ messages in thread
From: Chuck Lever @ 2026-09-16 16:28 UTC (permalink / raw)
To: NeilBrown, Jeff Layton, Olga Kornievskaia, Dai Ngo, Tom Talpey; +Cc: linux-nfs
Replace NFSD's NFSv2 XDR encoders and decoders with code that is
mechanically generated directly from the NFSv2 RPC language
specification.
The benefits for NFSv2 are marginal. When we eventually convert
newer NFS versions to use xdrgen, I expect a reduction in human
coding errors, improved spec compliance, and better memory safety
for those more complex NFS programs.
These patches have been lightly tested with fstests run against an
xfs export.
Chuck Lever (27):
Documentation: Add the RPC language description of NFSv2
NFSD: Add infrastructure for generating NFSv2 XDR encoders and
decoders
NFSD: Use xdrgen-generated NFSv2 protocol definitions
NFSD: Remove '#include "xdr.h"' from fs/nfsd/xdr3.h
NFSD: Relocate the NFSv2 XDR storage union into nfsproc.c
NFSD: Use xdrgen XDR functions for the NFSv2 NULL procedure
NFSD: Use xdrgen XDR functions for NFSv2 GETATTR procedure
NFSD: Use xdrgen XDR functions for NFSv2 SETATTR procedure
NFSD: Use xdrgen XDR functions for the NFSv2 ROOT procedure
NFSD: Use xdrgen XDR functions for the NFSv2 LOOKUP procedure
NFSD: Use xdrgen XDR functions for NFSv2 READLINK procedure
NFSD: Use xdrgen XDR functions for NFSv2 READ procedure
NFSD: Use xdrgen XDR functions for the NFSv2 WRITECACHE procedure
NFSD: Use xdrgen XDR functions for NFSv2 WRITE procedure
NFSD: Refactor nfsd_proc_create()
NFSD: Use xdrgen XDR functions for NFSv2 CREATE procedure
NFSD: Use xdrgen XDR functions for the NFSv2 REMOVE procedure
NFSD: Use xdrgen XDR functions for the NFSv2 RENAME procedure
NFSD: Use xdrgen XDR functions for the NFSv2 LINK procedure
NFSD: Use xdrgen XDR functions for NFSv2 SYMLINK procedure
NFSD: Use xdrgen XDR functions for NFSv2 MKDIR procedure
NFSD: Use xdrgen XDR functions for NFSv2 RMDIR procedure
NFSD: Use xdrgen XDR functions for the NFSv2 STATFS procedure
NFSD: Use xdrgen XDR functions for NFSv2 READDIR arguments
NFSD: Add a streaming directory reader
NFSD: Refactor NFSv2 directory cookie encoding
NFSD: Use xdrgen XDR functions for NFSv2 READDIR results
Documentation/sunrpc/xdr/nfs2.x | 254 +++++
fs/nfs_common/common.c | 5 +-
fs/nfsd/Makefile | 15 +-
fs/nfsd/nfs2acl.c | 2 +-
fs/nfsd/nfs2xdr_gen.c | 1079 +++++++++++++++++++
fs/nfsd/nfs2xdr_gen.h | 46 +
fs/nfsd/nfs3xdr.c | 2 +
fs/nfsd/nfsd.h | 2 -
fs/nfsd/nfserr.h | 2 +-
fs/nfsd/nfsfh.h | 5 +
fs/nfsd/nfsproc.c | 1574 +++++++++++++++++++---------
fs/nfsd/nfsxdr.c | 605 +++--------
fs/nfsd/vfs.c | 239 +++--
fs/nfsd/vfs.h | 40 +
fs/nfsd/xdr.h | 167 +--
fs/nfsd/xdr3.h | 3 +-
include/linux/nfs_common.h | 4 +-
include/linux/sunrpc/xdrgen/nfs2.h | 298 ++++++
18 files changed, 3121 insertions(+), 1221 deletions(-)
create mode 100644 Documentation/sunrpc/xdr/nfs2.x
create mode 100644 fs/nfsd/nfs2xdr_gen.c
create mode 100644 fs/nfsd/nfs2xdr_gen.h
create mode 100644 include/linux/sunrpc/xdrgen/nfs2.h
--
2.55.0
^ permalink raw reply [flat|nested] 4+ messages in thread* [PATCH v1 2/2] NFSD: map fh_verify() status codes for NFS_ACLv3 replies
2026-09-16 16:28 [PATCH v1 00/27] Convert server-side NFSv2 XDR to use xdrgen Chuck Lever
@ 2026-09-16 16:28 ` Chuck Lever
2026-09-17 11:57 ` Jeff Layton
0 siblings, 1 reply; 4+ messages in thread
From: Chuck Lever @ 2026-09-16 16:28 UTC (permalink / raw)
To: NeilBrown, Jeff Layton, Olga Kornievskaia, Dai Ngo, Tom Talpey; +Cc: linux-nfs
The NFS_ACLv3 protocol shares its status code space with NFSv3,
which has NFS3ERR_BADHANDLE but no NFSERR_NOFILEHANDLE. An
NFS_ACLv3 GETACL or SETACL request that carries an empty file
handle gets a reply with status 10020, a value the client cannot
interpret.
Commit 1459ad57673b ("nfsd: Move error code mapping to per-version
proc code.") made fh_verify() return nfserr_nofilehandle for an
empty handle regardless of protocol version. The NFSv3 procedures
gained nfsd3_map_status() in exchange, but the NFS_ACLv3 procedures
did not, so the unmapped status reaches the encoder.
Add the same mapping to the NFS_ACLv3 procedures.
Fixes: 1459ad57673b ("nfsd: Move error code mapping to per-version proc code.")
Signed-off-by: Chuck Lever <cel@kernel.org>
---
fs/nfsd/nfs3acl.c | 15 +++++++++++++++
1 file changed, 15 insertions(+)
diff --git a/fs/nfsd/nfs3acl.c b/fs/nfsd/nfs3acl.c
index 7183995182ab..5219ec634587 100644
--- a/fs/nfsd/nfs3acl.c
+++ b/fs/nfsd/nfs3acl.c
@@ -14,6 +14,19 @@
#include "xdr3.h"
#include "vfs.h"
+static __be32 nfsd3_map_status(__be32 status)
+{
+ switch (status) {
+ case nfserr_nofilehandle:
+ status = nfserr_badhandle;
+ break;
+ case nfserr_wrongsec:
+ status = nfserr_acces;
+ break;
+ }
+ return status;
+}
+
/*
* NULL call.
*/
@@ -72,6 +85,7 @@ static __be32 nfsd3_proc_getacl(struct svc_rqst *rqstp)
/* resp->acl_{access,default} are released in nfs3svc_release_getacl. */
out:
+ resp->status = nfsd3_map_status(resp->status);
return rpc_success;
fail:
@@ -125,6 +139,7 @@ static __be32 nfsd3_proc_setacl(struct svc_rqst *rqstp)
resp->status = nfserrno(error);
out:
/* argp->acl_{access,default} are released in nfs3svc_release_setacl. */
+ resp->status = nfsd3_map_status(resp->status);
return rpc_success;
}
--
2.55.0
^ permalink raw reply related [flat|nested] 4+ messages in thread* Re: [PATCH v1 2/2] NFSD: map fh_verify() status codes for NFS_ACLv3 replies
2026-09-16 16:28 ` [PATCH v1 2/2] NFSD: map fh_verify() status codes for NFS_ACLv3 replies Chuck Lever
@ 2026-09-17 11:57 ` Jeff Layton
0 siblings, 0 replies; 4+ messages in thread
From: Jeff Layton @ 2026-09-17 11:57 UTC (permalink / raw)
To: Chuck Lever, NeilBrown, Olga Kornievskaia, Dai Ngo, Tom Talpey; +Cc: linux-nfs
On Wed, 2026-09-16 at 12:28 -0400, Chuck Lever wrote:
> The NFS_ACLv3 protocol shares its status code space with NFSv3,
> which has NFS3ERR_BADHANDLE but no NFSERR_NOFILEHANDLE. An
> NFS_ACLv3 GETACL or SETACL request that carries an empty file
> handle gets a reply with status 10020, a value the client cannot
> interpret.
>
> Commit 1459ad57673b ("nfsd: Move error code mapping to per-version
> proc code.") made fh_verify() return nfserr_nofilehandle for an
> empty handle regardless of protocol version. The NFSv3 procedures
> gained nfsd3_map_status() in exchange, but the NFS_ACLv3 procedures
> did not, so the unmapped status reaches the encoder.
>
> Add the same mapping to the NFS_ACLv3 procedures.
>
> Fixes: 1459ad57673b ("nfsd: Move error code mapping to per-version proc code.")
> Signed-off-by: Chuck Lever <cel@kernel.org>
> ---
> fs/nfsd/nfs3acl.c | 15 +++++++++++++++
> 1 file changed, 15 insertions(+)
>
> diff --git a/fs/nfsd/nfs3acl.c b/fs/nfsd/nfs3acl.c
> index 7183995182ab..5219ec634587 100644
> --- a/fs/nfsd/nfs3acl.c
> +++ b/fs/nfsd/nfs3acl.c
> @@ -14,6 +14,19 @@
> #include "xdr3.h"
> #include "vfs.h"
>
> +static __be32 nfsd3_map_status(__be32 status)
> +{
> + switch (status) {
> + case nfserr_nofilehandle:
> + status = nfserr_badhandle;
> + break;
> + case nfserr_wrongsec:
> + status = nfserr_acces;
> + break;
> + }
> + return status;
> +}
> +
> /*
> * NULL call.
> */
> @@ -72,6 +85,7 @@ static __be32 nfsd3_proc_getacl(struct svc_rqst *rqstp)
>
> /* resp->acl_{access,default} are released in nfs3svc_release_getacl. */
> out:
> + resp->status = nfsd3_map_status(resp->status);
> return rpc_success;
>
> fail:
> @@ -125,6 +139,7 @@ static __be32 nfsd3_proc_setacl(struct svc_rqst *rqstp)
> resp->status = nfserrno(error);
> out:
> /* argp->acl_{access,default} are released in nfs3svc_release_setacl. */
> + resp->status = nfsd3_map_status(resp->status);
> return rpc_success;
> }
>
Reviewed-by: Jeff Layton <jlayton@kernel.org>
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-09-17 11:57 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-16 0:42 [PATCH v1 1/2] NFSD: map fh_verify() status codes for NFS_ACLv2 replies Chuck Lever
2026-09-16 0:42 ` [PATCH v1 2/2] NFSD: map fh_verify() status codes for NFS_ACLv3 replies Chuck Lever
-- strict thread matches above, loose matches on Subject: below --
2026-09-16 16:28 [PATCH v1 00/27] Convert server-side NFSv2 XDR to use xdrgen Chuck Lever
2026-09-16 16:28 ` [PATCH v1 2/2] NFSD: map fh_verify() status codes for NFS_ACLv3 replies Chuck Lever
2026-09-17 11:57 ` Jeff Layton
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox