From: Chuck Lever <cel@kernel.org>
To: NeilBrown <neil@brown.name>, Jeff Layton <jlayton@kernel.org>,
Olga Kornievskaia <okorniev@redhat.com>,
Dai Ngo <dai.ngo@oracle.com>, Tom Talpey <tom@talpey.com>
Cc: <linux-nfs@vger.kernel.org>
Subject: [PATCH v1 6/7] sunrpc: preserve rq_daddrlen across request deferral
Date: Sun, 4 Oct 2026 15:40:28 -0400 [thread overview]
Message-ID: <20261004194029.10714-7-cel@kernel.org> (raw)
In-Reply-To: <20261004194029.10714-1-cel@kernel.org>
svc_defer() saves rq_daddr in the svc_deferred_req but not
rq_daddrlen, and svc_deferred_recv() restores only the address. The
thread that replays a deferred request keeps the rq_daddrlen of the
last request it processed. A newly created thread has a length of
zero.
gen_callback() and nlmsvc_lookup_host() copy rq_daddrlen bytes of
rq_daddr to form the source address of an NFSv4.0 or NLM callback
transport. When a new thread replays a deferred SETCLIENTID that
arrived over IPv6, the copy is empty and the source address is left
as AF_UNSPEC. xs_bind() then fails with -EAFNOSUPPORT, and the
callback transport never connects. A length left over from an IPv4
request copies only part of an IPv6 address. Found by code
inspection.
Record rq_daddrlen in the existing daddrlen field of struct
svc_deferred_req when the request is first deferred, and restore it
in svc_deferred_recv().
Fixes: 849a1cf13d43 ("SUNRPC: Replace svc_addr_u by sockaddr_storage")
Signed-off-by: Chuck Lever <cel@kernel.org>
---
net/sunrpc/svc_xprt.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/net/sunrpc/svc_xprt.c b/net/sunrpc/svc_xprt.c
index bf5b2cdad35e..031cbac2a612 100644
--- a/net/sunrpc/svc_xprt.c
+++ b/net/sunrpc/svc_xprt.c
@@ -1343,6 +1343,7 @@ static struct cache_deferred_req *svc_defer(struct cache_req *req)
memcpy(&dr->addr, &rqstp->rq_addr, rqstp->rq_addrlen);
dr->addrlen = rqstp->rq_addrlen;
dr->daddr = rqstp->rq_daddr;
+ dr->daddrlen = rqstp->rq_daddrlen;
dr->secure = test_bit(RQ_SECURE, &rqstp->rq_flags);
dr->argslen = rqstp->rq_arg.len >> 2;
@@ -1377,6 +1378,7 @@ static noinline int svc_deferred_recv(struct svc_rqst *rqstp)
memcpy(&rqstp->rq_addr, &dr->addr, dr->addrlen);
rqstp->rq_addrlen = dr->addrlen;
rqstp->rq_daddr = dr->daddr;
+ rqstp->rq_daddrlen = dr->daddrlen;
rqstp->rq_xprt_ctxt = dr->xprt_ctxt;
/*
* ->xpo_recvfrom() is bypassed for a deferred request, so the
--
2.55.0
next prev parent reply other threads:[~2026-10-04 19:40 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-04 19:40 [PATCH v1 0/7] NFSD short subjects Chuck Lever
2026-10-04 19:40 ` [PATCH v1 1/7] nfsd: use direct I/O only for the last operation in a COMPOUND Chuck Lever
2026-10-04 19:40 ` [PATCH v1 2/7] nfsd: account for page_base when advancing rq_next_page Chuck Lever
2026-10-04 19:40 ` [PATCH v1 3/7] nfsd: locate the READ sink page from the reply buffer Chuck Lever
2026-10-04 19:40 ` [PATCH v1 4/7] nfsd: keep spliced pages below rq_next_page when a READ fails Chuck Lever
2026-10-04 19:40 ` [PATCH v1 5/7] nfsd: remove unreachable cancel of the layout fence work Chuck Lever
2026-10-04 19:40 ` Chuck Lever [this message]
2026-10-04 19:40 ` [PATCH v1 7/7] sunrpc: assign RQ_LOCAL from the transport on every receive Chuck Lever
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261004194029.10714-7-cel@kernel.org \
--to=cel@kernel.org \
--cc=dai.ngo@oracle.com \
--cc=jlayton@kernel.org \
--cc=linux-nfs@vger.kernel.org \
--cc=neil@brown.name \
--cc=okorniev@redhat.com \
--cc=tom@talpey.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox