* [PATCH] nfsd: update existing connection flags under client lock
@ 2026-10-01 4:14 Jiwoong Wi
2026-10-05 15:05 ` Chuck Lever
0 siblings, 1 reply; 2+ messages in thread
From: Jiwoong Wi @ 2026-10-01 4:14 UTC (permalink / raw)
To: linux-nfs
Cc: Chuck Lever, Jeff Layton, NeilBrown, Olga Kornievskaia, Dai Ngo,
Tom Talpey, bobtobabz, Jiwoong Wi
nfsd4_match_existing_connection() searches the session connection list
while holding clp->cl_lock, but returns the matching nfsd4_conn after
releasing the lock. nfsd4_bind_conn_to_session() then updates
conn->cn_flags. Concurrent transport loss can remove and free the
connection in nfsd4_conn_lost() between the unlock and the update,
leading to a use-after-free read-modify-write of cn_flags.
Update cn_flags before releasing clp->cl_lock and stop returning the raw
connection pointer to the caller.
A natural reproducer pipelined 16 BIND_CONN_TO_SESSION requests and reset
the connection after receiving the first reply. On a Generic KASAN kernel
at v7.3-rc4-606-gfd179f8a05be, it triggered three reports in 1,000
attempts. All attempts completed, covering 55,494 BIND operations and
6,494 processed pipelined BIND requests.
With this change applied to nfsd-testing at 32eb1a60b456, the same
reproducer completed 1,000 attempts with no harness error or KASAN
report. A 750 ms post-unlock timing-aid control also completed without a
KASAN report. Basic NFSv4.2 and NFSv3 read/write/unmount smoke tests
passed, and fs/nfsd built with GCC 12.2 without a new warning.
The vulnerability research and validation were conducted by members of
the Tobabz team as part of the Best of the Best 15th program.
Fixes: 02579b2ff8b0 ("nfsd: back channel stuck in SEQ4_STATUS_CB_PATH_DOWN")
Assisted-by: LLM
Signed-off-by: Jiwoong Wi <dwdnlzj@gmail.com>
---
fs/nfsd/nfs4state.c | 13 +++++--------
1 file changed, 5 insertions(+), 8 deletions(-)
diff --git a/fs/nfsd/nfs4state.c b/fs/nfsd/nfs4state.c
index bbc16dd2294d..6b445c5d4eb3 100644
--- a/fs/nfsd/nfs4state.c
+++ b/fs/nfsd/nfs4state.c
@@ -4810,7 +4810,7 @@ static struct nfsd4_conn *__nfsd4_find_conn(struct svc_xprt *xpt, struct nfsd4_s
}
static __be32 nfsd4_match_existing_connection(struct svc_rqst *rqst,
- struct nfsd4_session *session, u32 req, struct nfsd4_conn **conn)
+ struct nfsd4_session *session, u32 req)
{
struct nfs4_client *clp = session->se_client;
struct svc_xprt *xpt = rqst->rq_xprt;
@@ -4832,9 +4832,10 @@ static __be32 nfsd4_match_existing_connection(struct svc_rqst *rqst,
status = nfs_ok;
else
status = nfserr_inval;
+ if (status == nfs_ok &&
+ (req == NFS4_CDFC4_FORE_OR_BOTH || req == NFS4_CDFC4_BACK))
+ c->cn_flags |= NFS4_CDFC4_BACK;
spin_unlock(&clp->cl_lock);
- if (status == nfs_ok && conn)
- *conn = c;
return status;
}
@@ -4859,12 +4860,8 @@ __be32 nfsd4_bind_conn_to_session(struct svc_rqst *rqstp,
status = nfserr_wrong_cred;
if (!nfsd4_mach_creds_match(session->se_client, rqstp))
goto out;
- status = nfsd4_match_existing_connection(rqstp, session,
- bcts->dir, &conn);
+ status = nfsd4_match_existing_connection(rqstp, session, bcts->dir);
if (status == nfs_ok) {
- if (bcts->dir == NFS4_CDFC4_FORE_OR_BOTH ||
- bcts->dir == NFS4_CDFC4_BACK)
- conn->cn_flags |= NFS4_CDFC4_BACK;
nfsd4_probe_callback(session->se_client);
goto out;
}
base-commit: 32eb1a60b456980761cf7a9cee8f907fdc08afb8
--
2.50.1 (Apple Git-155)
^ permalink raw reply related [flat|nested] 2+ messages in thread* Re: [PATCH] nfsd: update existing connection flags under client lock
2026-10-01 4:14 [PATCH] nfsd: update existing connection flags under client lock Jiwoong Wi
@ 2026-10-05 15:05 ` Chuck Lever
0 siblings, 0 replies; 2+ messages in thread
From: Chuck Lever @ 2026-10-05 15:05 UTC (permalink / raw)
To: linux-nfs, Jiwoong Wi
Cc: Jeff Layton, NeilBrown, Olga Kornievskaia, Dai Ngo, Tom Talpey,
bobtobabz
On Thu, 01 Oct 2026 13:14:33 +0900, Jiwoong Wi wrote:
> nfsd4_match_existing_connection() searches the session connection list
> while holding clp->cl_lock, but returns the matching nfsd4_conn after
> releasing the lock. nfsd4_bind_conn_to_session() then updates
> conn->cn_flags. Concurrent transport loss can remove and free the
> connection in nfsd4_conn_lost() between the unlock and the update,
> leading to a use-after-free read-modify-write of cn_flags.
>
> [...]
Applied, thanks!
[1/1] nfsd: update existing connection flags under client lock
commit: bd9ebf4b2a0e95ee71b5a0d232fbd2e332b001bb
Best regards,
--
Chuck Lever <cel@kernel.org>
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-05 15:05 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-01 4:14 [PATCH] nfsd: update existing connection flags under client lock Jiwoong Wi
2026-10-05 15:05 ` Chuck Lever
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox