From: Jinpyo Lee <bint4b13@gmail.com>
To: linux-nfs@vger.kernel.org
Cc: Chuck Lever <cel@kernel.org>, Jeff Layton <jlayton@kernel.org>,
NeilBrown <neil@brown.name>,
Olga Kornievskaia <okorniev@redhat.com>,
Dai Ngo <Dai.Ngo@oracle.com>, Tom Talpey <tom@talpey.com>,
Greg KH <gregkh@linuxfoundation.org>,
bobtobabz@gmail.com, Jinpyo Lee <bint4b13@gmail.com>
Subject: [PATCH v2] nfsd: hold client reference while reaping async copies
Date: Mon, 28 Sep 2026 17:30:50 +0900 [thread overview]
Message-ID: <20260928083050.642664-1-bint4b13@gmail.com> (raw)
nfsd4_async_copy_reaper() moves expired COPY state from the client list
to a private reap list while holding nn->client_lock, then releases the
lock before destroying the stateid. The detached COPY state retains a
raw sc_client pointer, but does not hold a reference on the associated
nfs4_client.
Client teardown can therefore release the final client reference after
the COPY state is detached and before cleanup_async_copy() releases its
stateid. nfs4_put_stid() then follows sc_client and accesses state in the
freed client. Generic KASAN reported a four-byte use-after-free write in
_raw_spin_lock() through nfs4_put_stid() and
nfsd4_async_copy_reaper().
Add nfsd4_get_client() as the counterpart to nfsd4_put_client(). Take a
client reference while nn->client_lock still protects the detached COPY
state, and release it after cleanup_async_copy() completes. This makes
the client lifetime required by the unlocked cleanup phase explicit and
avoids open-coding the client's internal kref operation at the call site.
On a KASAN- and lockdep-enabled kernel based on nfsd-testing at
cab95e6be3ba, with only this patch applied, the reproducer retained 512
completed NFSv4.2 asynchronous COPY operations. A cleanup kprobe on
nfs4_put_copy() recorded 509 cleanup events, and client expiry completed
without the original KASAN report, an oops, or a panic.
The reproducer uses the administrator client-expiry interface to place
expiry at the affected cleanup boundary. It demonstrates the lifetime
error, but does not establish a reliable remote-only trigger. A source
reproducer and the complete KASAN log are available privately on
request.
Basic NFSv4.2 and NFSv3 read, write, and unmount smoke tests also passed
on a patched KASAN kernel. An x86-64 allmodconfig vmlinux and modules
build completed with CONFIG_WERROR=y, including fs/nfsd/nfsd.ko, without
new warnings.
The vulnerability research and validation were conducted by members of
the Tobabz team as part of the Best of the Best 15th program.
Fixes: ac0514f4d198 ("NFSD: Add a laundromat reaper for async copy state")
Assisted-by: LLM
Signed-off-by: Jinpyo Lee <bint4b13@gmail.com>
---
Changes in v2:
- Add nfsd4_get_client() instead of manipulating the client kref directly.
- Expand the description of the lifetime bug and runtime validation.
fs/nfsd/nfs4proc.c | 10 ++++++++++
fs/nfsd/nfs4state.c | 9 +++++++++
fs/nfsd/state.h | 1 +
3 files changed, 20 insertions(+)
diff --git a/fs/nfsd/nfs4proc.c b/fs/nfsd/nfs4proc.c
index 7df60abfb..2593038fa 100644
--- a/fs/nfsd/nfs4proc.c
+++ b/fs/nfsd/nfs4proc.c
@@ -1608,6 +1608,12 @@ void nfsd4_async_copy_reaper(struct nfsd_net *nn)
if (test_bit(NFSD4_COPY_F_OFFLOAD_DONE,
©->cp_copy.cp_flags)) {
if (!--copy->cp_ttl) {
+ /*
+ * cleanup_async_copy() drops the stateid's
+ * final reference after client_lock is
+ * released. Keep sc_client alive until then.
+ */
+ nfsd4_get_client(clp);
list_del_init(©->copies);
list_add(©->copies, &reaplist);
}
@@ -1618,10 +1624,14 @@ void nfsd4_async_copy_reaper(struct nfsd_net *nn)
spin_unlock(&nn->client_lock);
while (!list_empty(&reaplist)) {
+ struct nfs4_client *clp;
+
copy = list_first_entry(&reaplist, struct nfsd4_async_copy,
copies);
+ clp = copy->cp_stid.sc_client;
list_del_init(©->copies);
cleanup_async_copy(copy);
+ nfsd4_put_client(clp);
}
}
diff --git a/fs/nfsd/nfs4state.c b/fs/nfsd/nfs4state.c
index 0f9340eb2..05937a504 100644
--- a/fs/nfsd/nfs4state.c
+++ b/fs/nfsd/nfs4state.c
@@ -2805,6 +2805,15 @@ static void __free_client(struct kref *k)
kmem_cache_free(client_slab, clp);
}
+/**
+ * nfsd4_get_client - acquire a reference on an nfs4_client
+ * @clp: the client to be acquired
+ */
+void nfsd4_get_client(struct nfs4_client *clp)
+{
+ kref_get(&clp->cl_nfsdfs.cl_ref);
+}
+
/**
* nfsd4_put_client - release a reference on an nfs4_client
* @clp: the client to be released
diff --git a/fs/nfsd/state.h b/fs/nfsd/state.h
index cd9294f02..2a44ad503 100644
--- a/fs/nfsd/state.h
+++ b/fs/nfsd/state.h
@@ -952,6 +952,7 @@ static inline void nfsd4_try_run_cb(struct nfsd4_callback *cb)
extern void nfsd4_shutdown_callback(struct nfs4_client *);
extern void nfsd4_shutdown_copy(struct nfs4_client *clp);
+void nfsd4_get_client(struct nfs4_client *clp);
void nfsd4_put_client(struct nfs4_client *clp);
void nfsd4_async_copy_reaper(struct nfsd_net *nn);
bool nfsd4_has_active_async_copies(struct nfs4_client *clp);
--
2.50.1 (Apple Git-155)
next reply other threads:[~2026-09-28 8:31 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 8:30 Jinpyo Lee [this message]
2026-10-05 15:00 ` [PATCH v2] nfsd: hold client reference while reaping async copies Chuck Lever
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928083050.642664-1-bint4b13@gmail.com \
--to=bint4b13@gmail.com \
--cc=Dai.Ngo@oracle.com \
--cc=bobtobabz@gmail.com \
--cc=cel@kernel.org \
--cc=gregkh@linuxfoundation.org \
--cc=jlayton@kernel.org \
--cc=linux-nfs@vger.kernel.org \
--cc=neil@brown.name \
--cc=okorniev@redhat.com \
--cc=tom@talpey.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox