Linux NFS development
 help / color / mirror / Atom feed
From: Jinpyo Lee <bint4b13@gmail.com>
To: linux-nfs@vger.kernel.org
Cc: Chuck Lever <cel@kernel.org>, Jeff Layton <jlayton@kernel.org>,
	NeilBrown <neil@brown.name>,
	Olga Kornievskaia <okorniev@redhat.com>,
	Dai Ngo <Dai.Ngo@oracle.com>, Tom Talpey <tom@talpey.com>,
	Greg KH <gregkh@linuxfoundation.org>,
	bobtobabz@gmail.com, Jinpyo Lee <bint4b13@gmail.com>
Subject: [PATCH v2] nfsd: hold client reference while reaping async copies
Date: Mon, 28 Sep 2026 17:30:50 +0900	[thread overview]
Message-ID: <20260928083050.642664-1-bint4b13@gmail.com> (raw)

nfsd4_async_copy_reaper() moves expired COPY state from the client list
to a private reap list while holding nn->client_lock, then releases the
lock before destroying the stateid. The detached COPY state retains a
raw sc_client pointer, but does not hold a reference on the associated
nfs4_client.

Client teardown can therefore release the final client reference after
the COPY state is detached and before cleanup_async_copy() releases its
stateid. nfs4_put_stid() then follows sc_client and accesses state in the
freed client. Generic KASAN reported a four-byte use-after-free write in
_raw_spin_lock() through nfs4_put_stid() and
nfsd4_async_copy_reaper().

Add nfsd4_get_client() as the counterpart to nfsd4_put_client(). Take a
client reference while nn->client_lock still protects the detached COPY
state, and release it after cleanup_async_copy() completes. This makes
the client lifetime required by the unlocked cleanup phase explicit and
avoids open-coding the client's internal kref operation at the call site.

On a KASAN- and lockdep-enabled kernel based on nfsd-testing at
cab95e6be3ba, with only this patch applied, the reproducer retained 512
completed NFSv4.2 asynchronous COPY operations. A cleanup kprobe on
nfs4_put_copy() recorded 509 cleanup events, and client expiry completed
without the original KASAN report, an oops, or a panic.

The reproducer uses the administrator client-expiry interface to place
expiry at the affected cleanup boundary. It demonstrates the lifetime
error, but does not establish a reliable remote-only trigger. A source
reproducer and the complete KASAN log are available privately on
request.

Basic NFSv4.2 and NFSv3 read, write, and unmount smoke tests also passed
on a patched KASAN kernel. An x86-64 allmodconfig vmlinux and modules
build completed with CONFIG_WERROR=y, including fs/nfsd/nfsd.ko, without
new warnings.

The vulnerability research and validation were conducted by members of
the Tobabz team as part of the Best of the Best 15th program.

Fixes: ac0514f4d198 ("NFSD: Add a laundromat reaper for async copy state")
Assisted-by: LLM
Signed-off-by: Jinpyo Lee <bint4b13@gmail.com>
---
Changes in v2:

- Add nfsd4_get_client() instead of manipulating the client kref directly.
- Expand the description of the lifetime bug and runtime validation.

 fs/nfsd/nfs4proc.c  | 10 ++++++++++
 fs/nfsd/nfs4state.c |  9 +++++++++
 fs/nfsd/state.h     |  1 +
 3 files changed, 20 insertions(+)

diff --git a/fs/nfsd/nfs4proc.c b/fs/nfsd/nfs4proc.c
index 7df60abfb..2593038fa 100644
--- a/fs/nfsd/nfs4proc.c
+++ b/fs/nfsd/nfs4proc.c
@@ -1608,6 +1608,12 @@ void nfsd4_async_copy_reaper(struct nfsd_net *nn)
 			if (test_bit(NFSD4_COPY_F_OFFLOAD_DONE,
 				     &copy->cp_copy.cp_flags)) {
 				if (!--copy->cp_ttl) {
+					/*
+					 * cleanup_async_copy() drops the stateid's
+					 * final reference after client_lock is
+					 * released. Keep sc_client alive until then.
+					 */
+					nfsd4_get_client(clp);
 					list_del_init(&copy->copies);
 					list_add(&copy->copies, &reaplist);
 				}
@@ -1618,10 +1624,14 @@ void nfsd4_async_copy_reaper(struct nfsd_net *nn)
 	spin_unlock(&nn->client_lock);
 
 	while (!list_empty(&reaplist)) {
+		struct nfs4_client *clp;
+
 		copy = list_first_entry(&reaplist, struct nfsd4_async_copy,
 					copies);
+		clp = copy->cp_stid.sc_client;
 		list_del_init(&copy->copies);
 		cleanup_async_copy(copy);
+		nfsd4_put_client(clp);
 	}
 }
 
diff --git a/fs/nfsd/nfs4state.c b/fs/nfsd/nfs4state.c
index 0f9340eb2..05937a504 100644
--- a/fs/nfsd/nfs4state.c
+++ b/fs/nfsd/nfs4state.c
@@ -2805,6 +2805,15 @@ static void __free_client(struct kref *k)
 	kmem_cache_free(client_slab, clp);
 }
 
+/**
+ * nfsd4_get_client - acquire a reference on an nfs4_client
+ * @clp: the client to be acquired
+ */
+void nfsd4_get_client(struct nfs4_client *clp)
+{
+	kref_get(&clp->cl_nfsdfs.cl_ref);
+}
+
 /**
  * nfsd4_put_client - release a reference on an nfs4_client
  * @clp: the client to be released
diff --git a/fs/nfsd/state.h b/fs/nfsd/state.h
index cd9294f02..2a44ad503 100644
--- a/fs/nfsd/state.h
+++ b/fs/nfsd/state.h
@@ -952,6 +952,7 @@ static inline void nfsd4_try_run_cb(struct nfsd4_callback *cb)
 
 extern void nfsd4_shutdown_callback(struct nfs4_client *);
 extern void nfsd4_shutdown_copy(struct nfs4_client *clp);
+void nfsd4_get_client(struct nfs4_client *clp);
 void nfsd4_put_client(struct nfs4_client *clp);
 void nfsd4_async_copy_reaper(struct nfsd_net *nn);
 bool nfsd4_has_active_async_copies(struct nfs4_client *clp);
-- 
2.50.1 (Apple Git-155)

             reply	other threads:[~2026-09-28  8:31 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28  8:30 Jinpyo Lee [this message]
2026-10-05 15:00 ` [PATCH v2] nfsd: hold client reference while reaping async copies Chuck Lever

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260928083050.642664-1-bint4b13@gmail.com \
    --to=bint4b13@gmail.com \
    --cc=Dai.Ngo@oracle.com \
    --cc=bobtobabz@gmail.com \
    --cc=cel@kernel.org \
    --cc=gregkh@linuxfoundation.org \
    --cc=jlayton@kernel.org \
    --cc=linux-nfs@vger.kernel.org \
    --cc=neil@brown.name \
    --cc=okorniev@redhat.com \
    --cc=tom@talpey.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox