* [PATCH v2] nfsd: hold client reference while reaping async copies
@ 2026-09-28 8:30 Jinpyo Lee
2026-10-05 15:00 ` Chuck Lever
0 siblings, 1 reply; 2+ messages in thread
From: Jinpyo Lee @ 2026-09-28 8:30 UTC (permalink / raw)
To: linux-nfs
Cc: Chuck Lever, Jeff Layton, NeilBrown, Olga Kornievskaia, Dai Ngo,
Tom Talpey, Greg KH, bobtobabz, Jinpyo Lee
nfsd4_async_copy_reaper() moves expired COPY state from the client list
to a private reap list while holding nn->client_lock, then releases the
lock before destroying the stateid. The detached COPY state retains a
raw sc_client pointer, but does not hold a reference on the associated
nfs4_client.
Client teardown can therefore release the final client reference after
the COPY state is detached and before cleanup_async_copy() releases its
stateid. nfs4_put_stid() then follows sc_client and accesses state in the
freed client. Generic KASAN reported a four-byte use-after-free write in
_raw_spin_lock() through nfs4_put_stid() and
nfsd4_async_copy_reaper().
Add nfsd4_get_client() as the counterpart to nfsd4_put_client(). Take a
client reference while nn->client_lock still protects the detached COPY
state, and release it after cleanup_async_copy() completes. This makes
the client lifetime required by the unlocked cleanup phase explicit and
avoids open-coding the client's internal kref operation at the call site.
On a KASAN- and lockdep-enabled kernel based on nfsd-testing at
cab95e6be3ba, with only this patch applied, the reproducer retained 512
completed NFSv4.2 asynchronous COPY operations. A cleanup kprobe on
nfs4_put_copy() recorded 509 cleanup events, and client expiry completed
without the original KASAN report, an oops, or a panic.
The reproducer uses the administrator client-expiry interface to place
expiry at the affected cleanup boundary. It demonstrates the lifetime
error, but does not establish a reliable remote-only trigger. A source
reproducer and the complete KASAN log are available privately on
request.
Basic NFSv4.2 and NFSv3 read, write, and unmount smoke tests also passed
on a patched KASAN kernel. An x86-64 allmodconfig vmlinux and modules
build completed with CONFIG_WERROR=y, including fs/nfsd/nfsd.ko, without
new warnings.
The vulnerability research and validation were conducted by members of
the Tobabz team as part of the Best of the Best 15th program.
Fixes: ac0514f4d198 ("NFSD: Add a laundromat reaper for async copy state")
Assisted-by: LLM
Signed-off-by: Jinpyo Lee <bint4b13@gmail.com>
---
Changes in v2:
- Add nfsd4_get_client() instead of manipulating the client kref directly.
- Expand the description of the lifetime bug and runtime validation.
fs/nfsd/nfs4proc.c | 10 ++++++++++
fs/nfsd/nfs4state.c | 9 +++++++++
fs/nfsd/state.h | 1 +
3 files changed, 20 insertions(+)
diff --git a/fs/nfsd/nfs4proc.c b/fs/nfsd/nfs4proc.c
index 7df60abfb..2593038fa 100644
--- a/fs/nfsd/nfs4proc.c
+++ b/fs/nfsd/nfs4proc.c
@@ -1608,6 +1608,12 @@ void nfsd4_async_copy_reaper(struct nfsd_net *nn)
if (test_bit(NFSD4_COPY_F_OFFLOAD_DONE,
©->cp_copy.cp_flags)) {
if (!--copy->cp_ttl) {
+ /*
+ * cleanup_async_copy() drops the stateid's
+ * final reference after client_lock is
+ * released. Keep sc_client alive until then.
+ */
+ nfsd4_get_client(clp);
list_del_init(©->copies);
list_add(©->copies, &reaplist);
}
@@ -1618,10 +1624,14 @@ void nfsd4_async_copy_reaper(struct nfsd_net *nn)
spin_unlock(&nn->client_lock);
while (!list_empty(&reaplist)) {
+ struct nfs4_client *clp;
+
copy = list_first_entry(&reaplist, struct nfsd4_async_copy,
copies);
+ clp = copy->cp_stid.sc_client;
list_del_init(©->copies);
cleanup_async_copy(copy);
+ nfsd4_put_client(clp);
}
}
diff --git a/fs/nfsd/nfs4state.c b/fs/nfsd/nfs4state.c
index 0f9340eb2..05937a504 100644
--- a/fs/nfsd/nfs4state.c
+++ b/fs/nfsd/nfs4state.c
@@ -2805,6 +2805,15 @@ static void __free_client(struct kref *k)
kmem_cache_free(client_slab, clp);
}
+/**
+ * nfsd4_get_client - acquire a reference on an nfs4_client
+ * @clp: the client to be acquired
+ */
+void nfsd4_get_client(struct nfs4_client *clp)
+{
+ kref_get(&clp->cl_nfsdfs.cl_ref);
+}
+
/**
* nfsd4_put_client - release a reference on an nfs4_client
* @clp: the client to be released
diff --git a/fs/nfsd/state.h b/fs/nfsd/state.h
index cd9294f02..2a44ad503 100644
--- a/fs/nfsd/state.h
+++ b/fs/nfsd/state.h
@@ -952,6 +952,7 @@ static inline void nfsd4_try_run_cb(struct nfsd4_callback *cb)
extern void nfsd4_shutdown_callback(struct nfs4_client *);
extern void nfsd4_shutdown_copy(struct nfs4_client *clp);
+void nfsd4_get_client(struct nfs4_client *clp);
void nfsd4_put_client(struct nfs4_client *clp);
void nfsd4_async_copy_reaper(struct nfsd_net *nn);
bool nfsd4_has_active_async_copies(struct nfs4_client *clp);
--
2.50.1 (Apple Git-155)
^ permalink raw reply related [flat|nested] 2+ messages in thread* Re: [PATCH v2] nfsd: hold client reference while reaping async copies
2026-09-28 8:30 [PATCH v2] nfsd: hold client reference while reaping async copies Jinpyo Lee
@ 2026-10-05 15:00 ` Chuck Lever
0 siblings, 0 replies; 2+ messages in thread
From: Chuck Lever @ 2026-10-05 15:00 UTC (permalink / raw)
To: linux-nfs, Jinpyo Lee
Cc: Jeff Layton, NeilBrown, Olga Kornievskaia, Dai Ngo, Tom Talpey,
Greg KH, bobtobabz
On Mon, 28 Sep 2026 17:30:50 +0900, Jinpyo Lee wrote:
> nfsd4_async_copy_reaper() moves expired COPY state from the client list
> to a private reap list while holding nn->client_lock, then releases the
> lock before destroying the stateid. The detached COPY state retains a
> raw sc_client pointer, but does not hold a reference on the associated
> nfs4_client.
>
> Client teardown can therefore release the final client reference after
> the COPY state is detached and before cleanup_async_copy() releases its
> stateid. nfs4_put_stid() then follows sc_client and accesses state in the
> freed client. Generic KASAN reported a four-byte use-after-free write in
> _raw_spin_lock() through nfs4_put_stid() and
> nfsd4_async_copy_reaper().
>
> [...]
Applied, thanks!
[1/1] nfsd: hold client reference while reaping async copies
commit: 719ce5204fcfb98daf1656fd85c76ba2f5369f8d
Best regards,
--
Chuck Lever <cel@kernel.org>
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-05 15:00 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-28 8:30 [PATCH v2] nfsd: hold client reference while reaping async copies Jinpyo Lee
2026-10-05 15:00 ` Chuck Lever
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox