Linux NFS development
 help / color / mirror / Atom feed
* [PATCH] SUNRPC: account for reply size in TCP backchannel allocation
@ 2026-10-01 14:49 Jiwoong Wi
  0 siblings, 0 replies; only message in thread
From: Jiwoong Wi @ 2026-10-01 14:49 UTC (permalink / raw)
  To: Trond Myklebust, Anna Schumaker, Chuck Lever, Jeff Layton
  Cc: NeilBrown, Olga Kornievskaia, Dai Ngo, Tom Talpey, linux-nfs,
	bobtobabz

The TCP backchannel allocator places an RPC call and its reply in a
single page after struct rpc_buffer. bc_malloc() bounds rq_callsize but
then positions rq_rbuffer at the end of the call without checking whether
rq_rcvsize still fits.

AUTH_SYS reply verifier learning can increase au_rslack and therefore
rq_rcvsize. For CB_NOTIFY, a 3,648-byte call reservation and a 504-byte
reply reservation require 4,160 bytes including struct rpc_buffer, 64
bytes more than a 4 KiB page. receive_cb_reply() accepts the advertised
reply size and copies beyond the page before decoding the reply.

The TCP backchannel allocator is intentionally limited to one page. Check
rq_callsize first, then reject rq_rcvsize when it exceeds the remaining
capacity. Keeping the checks separate avoids arithmetic overflow and
avoids using the existing warning for a reply size that can be influenced
by a peer.

On the current nfsd-testing tree, a crafted AUTH_SYS/CB_NOTIFY reply
reproduced a 504-byte copy that extended 64 bytes beyond the allocated
page under KASAN before this change. With this change, the oversized
callback reservation was rejected before the final callback and no KASAN
report or warning was observed. A 424-byte boundary control callback
completed before and after the change.

A source reproducer and the complete KASAN log are available privately on
request.

NFSv4.2 and NFSv3 read/write/unmount smoke tests passed. A clean bzImage
and modules build completed without new warnings.

The vulnerability research and validation were conducted by members of
the Tobabz team as part of the Best of the Best 15th program.

Fixes: 5fe6eaa1f9a0 ("SUNRPC: Generalize the RPC buffer allocation API")
Assisted-by: LLM
Signed-off-by: Jiwoong Wi <dwdnlzj@gmail.com>
---
 net/sunrpc/xprtsock.c | 8 +++++---
 1 file changed, 5 insertions(+), 3 deletions(-)

diff --git a/net/sunrpc/xprtsock.c b/net/sunrpc/xprtsock.c
index 7f60723fa..6018064ca 100644
--- a/net/sunrpc/xprtsock.c
+++ b/net/sunrpc/xprtsock.c
@@ -2969,15 +2969,17 @@ static void xs_tcp_print_stats(struct rpc_xprt *xprt, struct seq_file *seq)
 static int bc_malloc(struct rpc_task *task)
 {
 	struct rpc_rqst *rqst = task->tk_rqstp;
-	size_t size = rqst->rq_callsize;
+	size_t capacity = PAGE_SIZE - sizeof(struct rpc_buffer);
 	struct page *page;
 	struct rpc_buffer *buf;
 
-	if (size > PAGE_SIZE - sizeof(struct rpc_buffer)) {
+	if (rqst->rq_callsize > capacity) {
 		WARN_ONCE(1, "xprtsock: large bc buffer request (size %zu)\n",
-			  size);
+			  rqst->rq_callsize);
 		return -EINVAL;
 	}
+	if (rqst->rq_rcvsize > capacity - rqst->rq_callsize)
+		return -EINVAL;
 
 	page = alloc_page(GFP_KERNEL | __GFP_NORETRY | __GFP_NOWARN);
 	if (!page)

base-commit: 32eb1a60b456980761cf7a9cee8f907fdc08afb8
-- 
2.43.0

^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-10-01 14:50 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-01 14:49 [PATCH] SUNRPC: account for reply size in TCP backchannel allocation Jiwoong Wi

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox