Linux NFS development
 help / color / mirror / Atom feed
* [PATCH v2] nfsd: hold client reference while reaping async copies
@ 2026-09-28  8:30 Jinpyo Lee
  2026-10-05 15:00 ` Chuck Lever
  0 siblings, 1 reply; 2+ messages in thread
From: Jinpyo Lee @ 2026-09-28  8:30 UTC (permalink / raw)
  To: linux-nfs
  Cc: Chuck Lever, Jeff Layton, NeilBrown, Olga Kornievskaia, Dai Ngo,
	Tom Talpey, Greg KH, bobtobabz, Jinpyo Lee

nfsd4_async_copy_reaper() moves expired COPY state from the client list
to a private reap list while holding nn->client_lock, then releases the
lock before destroying the stateid. The detached COPY state retains a
raw sc_client pointer, but does not hold a reference on the associated
nfs4_client.

Client teardown can therefore release the final client reference after
the COPY state is detached and before cleanup_async_copy() releases its
stateid. nfs4_put_stid() then follows sc_client and accesses state in the
freed client. Generic KASAN reported a four-byte use-after-free write in
_raw_spin_lock() through nfs4_put_stid() and
nfsd4_async_copy_reaper().

Add nfsd4_get_client() as the counterpart to nfsd4_put_client(). Take a
client reference while nn->client_lock still protects the detached COPY
state, and release it after cleanup_async_copy() completes. This makes
the client lifetime required by the unlocked cleanup phase explicit and
avoids open-coding the client's internal kref operation at the call site.

On a KASAN- and lockdep-enabled kernel based on nfsd-testing at
cab95e6be3ba, with only this patch applied, the reproducer retained 512
completed NFSv4.2 asynchronous COPY operations. A cleanup kprobe on
nfs4_put_copy() recorded 509 cleanup events, and client expiry completed
without the original KASAN report, an oops, or a panic.

The reproducer uses the administrator client-expiry interface to place
expiry at the affected cleanup boundary. It demonstrates the lifetime
error, but does not establish a reliable remote-only trigger. A source
reproducer and the complete KASAN log are available privately on
request.

Basic NFSv4.2 and NFSv3 read, write, and unmount smoke tests also passed
on a patched KASAN kernel. An x86-64 allmodconfig vmlinux and modules
build completed with CONFIG_WERROR=y, including fs/nfsd/nfsd.ko, without
new warnings.

The vulnerability research and validation were conducted by members of
the Tobabz team as part of the Best of the Best 15th program.

Fixes: ac0514f4d198 ("NFSD: Add a laundromat reaper for async copy state")
Assisted-by: LLM
Signed-off-by: Jinpyo Lee <bint4b13@gmail.com>
---
Changes in v2:

- Add nfsd4_get_client() instead of manipulating the client kref directly.
- Expand the description of the lifetime bug and runtime validation.

 fs/nfsd/nfs4proc.c  | 10 ++++++++++
 fs/nfsd/nfs4state.c |  9 +++++++++
 fs/nfsd/state.h     |  1 +
 3 files changed, 20 insertions(+)

diff --git a/fs/nfsd/nfs4proc.c b/fs/nfsd/nfs4proc.c
index 7df60abfb..2593038fa 100644
--- a/fs/nfsd/nfs4proc.c
+++ b/fs/nfsd/nfs4proc.c
@@ -1608,6 +1608,12 @@ void nfsd4_async_copy_reaper(struct nfsd_net *nn)
 			if (test_bit(NFSD4_COPY_F_OFFLOAD_DONE,
 				     &copy->cp_copy.cp_flags)) {
 				if (!--copy->cp_ttl) {
+					/*
+					 * cleanup_async_copy() drops the stateid's
+					 * final reference after client_lock is
+					 * released. Keep sc_client alive until then.
+					 */
+					nfsd4_get_client(clp);
 					list_del_init(&copy->copies);
 					list_add(&copy->copies, &reaplist);
 				}
@@ -1618,10 +1624,14 @@ void nfsd4_async_copy_reaper(struct nfsd_net *nn)
 	spin_unlock(&nn->client_lock);
 
 	while (!list_empty(&reaplist)) {
+		struct nfs4_client *clp;
+
 		copy = list_first_entry(&reaplist, struct nfsd4_async_copy,
 					copies);
+		clp = copy->cp_stid.sc_client;
 		list_del_init(&copy->copies);
 		cleanup_async_copy(copy);
+		nfsd4_put_client(clp);
 	}
 }
 
diff --git a/fs/nfsd/nfs4state.c b/fs/nfsd/nfs4state.c
index 0f9340eb2..05937a504 100644
--- a/fs/nfsd/nfs4state.c
+++ b/fs/nfsd/nfs4state.c
@@ -2805,6 +2805,15 @@ static void __free_client(struct kref *k)
 	kmem_cache_free(client_slab, clp);
 }
 
+/**
+ * nfsd4_get_client - acquire a reference on an nfs4_client
+ * @clp: the client to be acquired
+ */
+void nfsd4_get_client(struct nfs4_client *clp)
+{
+	kref_get(&clp->cl_nfsdfs.cl_ref);
+}
+
 /**
  * nfsd4_put_client - release a reference on an nfs4_client
  * @clp: the client to be released
diff --git a/fs/nfsd/state.h b/fs/nfsd/state.h
index cd9294f02..2a44ad503 100644
--- a/fs/nfsd/state.h
+++ b/fs/nfsd/state.h
@@ -952,6 +952,7 @@ static inline void nfsd4_try_run_cb(struct nfsd4_callback *cb)
 
 extern void nfsd4_shutdown_callback(struct nfs4_client *);
 extern void nfsd4_shutdown_copy(struct nfs4_client *clp);
+void nfsd4_get_client(struct nfs4_client *clp);
 void nfsd4_put_client(struct nfs4_client *clp);
 void nfsd4_async_copy_reaper(struct nfsd_net *nn);
 bool nfsd4_has_active_async_copies(struct nfs4_client *clp);
-- 
2.50.1 (Apple Git-155)

^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH v2] nfsd: hold client reference while reaping async copies
  2026-09-28  8:30 [PATCH v2] nfsd: hold client reference while reaping async copies Jinpyo Lee
@ 2026-10-05 15:00 ` Chuck Lever
  0 siblings, 0 replies; 2+ messages in thread
From: Chuck Lever @ 2026-10-05 15:00 UTC (permalink / raw)
  To: linux-nfs, Jinpyo Lee
  Cc: Jeff Layton, NeilBrown, Olga Kornievskaia, Dai Ngo, Tom Talpey,
	Greg KH, bobtobabz


On Mon, 28 Sep 2026 17:30:50 +0900, Jinpyo Lee wrote:
> nfsd4_async_copy_reaper() moves expired COPY state from the client list
> to a private reap list while holding nn->client_lock, then releases the
> lock before destroying the stateid. The detached COPY state retains a
> raw sc_client pointer, but does not hold a reference on the associated
> nfs4_client.
> 
> Client teardown can therefore release the final client reference after
> the COPY state is detached and before cleanup_async_copy() releases its
> stateid. nfs4_put_stid() then follows sc_client and accesses state in the
> freed client. Generic KASAN reported a four-byte use-after-free write in
> _raw_spin_lock() through nfs4_put_stid() and
> nfsd4_async_copy_reaper().
> 
> [...]

Applied, thanks!

[1/1] nfsd: hold client reference while reaping async copies
      commit: 719ce5204fcfb98daf1656fd85c76ba2f5369f8d

Best regards,
-- 
Chuck Lever <cel@kernel.org>

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-10-05 15:00 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-28  8:30 [PATCH v2] nfsd: hold client reference while reaping async copies Jinpyo Lee
2026-10-05 15:00 ` Chuck Lever

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox