Linux NFS development
 help / color / mirror / Atom feed
From: Jeff Layton <jlayton@kernel.org>
To: Chuck Lever <cel@kernel.org>, NeilBrown <neilb@ownmail.net>,
	Olga Kornievskaia <okorniev@redhat.com>,
	Dai Ngo <dai.ngo@oracle.com>, Tom Talpey <tom@talpey.com>,
	Benjamin Coddington <bcodding@hammerspace.com>
Cc: linux-nfs@vger.kernel.org, Chuck Lever <chuck.lever@oracle.com>
Subject: Re: [PATCH v2 05/42] NFS: Use nlmclnt_rpc_clnt() helper to retrieve nlm_host's rpc_clnt
Date: Fri, 23 Jan 2026 16:30:03 -0500	[thread overview]
Message-ID: <5c7126f0ace2874ceb2af74726962875e647256d.camel@kernel.org> (raw)
In-Reply-To: <8f13122c-66eb-4c54-a767-c152cc3db04d@kernel.org>

On Fri, 2026-01-23 at 15:44 -0500, Chuck Lever wrote:
> On 1/23/26 3:23 PM, Jeff Layton wrote:
> > On Fri, 2026-01-23 at 13:52 -0500, Chuck Lever wrote:
> > > From: Chuck Lever <chuck.lever@oracle.com>
> > > 
> > > The external API definitions for lockd reside in linux/lockd/bind.h.
> > > Because "struct nlm_host" is an internal lockd structure, bind.h
> > > does not include a definition of it. Dereferencing that structure
> > > outside of lockd violates the layering boundary between NFS and
> > > lockd.
> > > 
> > > The proper approach is to use the nlmclnt_rpc_clnt() helper function
> > > already provided in lockd/bind.h, which retrieves the NLM host's
> > > struct rpc_clnt without exposing internal lockd structures. This
> > > maintains clean separation between the NFS client and lockd
> > > internals.
> > > 
> > > Note that the nlm_host's h_rpcclnt field can be NULL during
> > > initialization (host.c:141) or after cleanup (host.c:629). Add a
> > > NULL check before calling shutdown_client() to prevent a potential
> > > NULL pointer dereference in the sysfs shutdown path.
> > > 
> > > Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
> > > ---
> > >  fs/nfs/sysfs.c | 10 +++++++---
> > >  1 file changed, 7 insertions(+), 3 deletions(-)
> > > 
> > > diff --git a/fs/nfs/sysfs.c b/fs/nfs/sysfs.c
> > > index ea6e6168092b..186b29de0129 100644
> > > --- a/fs/nfs/sysfs.c
> > > +++ b/fs/nfs/sysfs.c
> > > @@ -12,7 +12,7 @@
> > >  #include <linux/string.h>
> > >  #include <linux/nfs_fs.h>
> > >  #include <linux/rcupdate.h>
> > > -#include <linux/lockd/lockd.h>
> > > +#include <linux/lockd/bind.h>
> > >  
> > >  #include "internal.h"
> > >  #include "nfs4_fs.h"
> > > @@ -284,8 +284,12 @@ shutdown_store(struct kobject *kobj, struct kobj_attribute *attr,
> > >  	if (!IS_ERR(server->client_acl))
> > >  		shutdown_client(server->client_acl);
> > >  
> > > -	if (server->nlm_host)
> > > -		shutdown_client(server->nlm_host->h_rpcclnt);
> > > +	if (server->nlm_host) {
> > > +		struct rpc_clnt *nlm_clnt = nlmclnt_rpc_clnt(server->nlm_host);
> > > +
> > > +		if (nlm_clnt)
> > > +			shutdown_client(nlm_clnt);
> > 
> > I don't see any locking here. Soon after this thing goes NULL, the
> > nlm_clnt can be freed. ISTM that this ought to take a reference to
> > nlm_clnt and put it afterward.
> 
> So there is no locking here before the patch is applied. The patch does
> not change that. Do you mean that the patch should add the additional
> reference count bump (and document that fix in the commit message) ?
> 
> Mason's prompts did not call this out, so I assumed there wasn't an
> obvious UAF possible in this path.
> 

(Adding Ben since he wrote this originally...)

Sorry, I didn't make it clear. This is (possibly) an existing bug and
not something that is changed by your patches.

If that value can go NULL and be freed (and it looks like it can in
nlm_shutdown_hosts_net()) then I think that could race with someone
writing to the "shutdown" file. OTOH, maybe that can't happen because
the sysfs file gets removed before lockd_down() runs? I'm not sure.

The safest thing might be to take and hold the (global) nlm_host_mutex
around the NLM parts of shutdown_store(). Maybe we could add a helper
to the nlm public interface that does that so we don't need to expose
that mutex outside of NLM?

> 
> > 
> > > +	}
> > >  out:
> > >  	shutdown_nfs_client(server->nfs_client);
> > >  	return count;
> > 
> 

-- 
Jeff Layton <jlayton@kernel.org>

  reply	other threads:[~2026-01-23 21:30 UTC|newest]

Thread overview: 53+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-01-23 18:52 [PATCH v2 00/42] Clarify module API boundaries Chuck Lever
2026-01-23 18:52 ` [PATCH v2 01/42] lockd: Simplify cast_status() in svcproc.c Chuck Lever
2026-01-23 18:52 ` [PATCH v2 02/42] lockd: Introduce nlm__int__deadlock Chuck Lever
2026-01-26 12:34   ` Jeff Layton
2026-01-26 14:36     ` Chuck Lever
2026-01-23 18:52 ` [PATCH v2 03/42] lockd: Have nlm_fopen() return errno values Chuck Lever
2026-01-23 18:52 ` [PATCH v2 04/42] lockd: Relocate nlmsvc_unlock API declarations Chuck Lever
2026-01-23 18:52 ` [PATCH v2 05/42] NFS: Use nlmclnt_rpc_clnt() helper to retrieve nlm_host's rpc_clnt Chuck Lever
2026-01-23 20:23   ` Jeff Layton
2026-01-23 20:44     ` Chuck Lever
2026-01-23 21:30       ` Jeff Layton [this message]
2026-01-23 21:37         ` Chuck Lever
2026-01-23 18:52 ` [PATCH v2 06/42] lockd: Move xdr4.h from include/linux/lockd/ to fs/lockd/ Chuck Lever
2026-01-23 18:52 ` [PATCH v2 07/42] lockd: Move share.h " Chuck Lever
2026-01-23 18:52 ` [PATCH v2 08/42] lockd: Relocate include/linux/lockd/lockd.h Chuck Lever
2026-01-23 18:52 ` [PATCH v2 09/42] lockd: Remove lockd/debug.h Chuck Lever
2026-01-23 18:52 ` [PATCH v2 10/42] lockd: Move xdr.h from include/linux/lockd/ to fs/lockd/ Chuck Lever
2026-01-24  1:20   ` kernel test robot
2026-01-24  2:57   ` kernel test robot
2026-01-23 18:52 ` [PATCH v2 11/42] lockd: Make linux/lockd/nlm.h an internal header Chuck Lever
2026-01-23 18:52 ` [PATCH v2 12/42] lockd: Move nlm4svc_set_file_lock_range() Chuck Lever
2026-01-23 18:52 ` [PATCH v2 13/42] lockd: Relocate svc_version definitions to XDR layer Chuck Lever
2026-01-23 18:52 ` [PATCH v2 14/42] Documentation: Add the RPC language description of NLM version 4 Chuck Lever
2026-01-23 18:52 ` [PATCH v2 15/42] lockd: Use xdrgen XDR functions for the NLMv4 NULL procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 16/42] lockd: Use xdrgen XDR functions for the NLMv4 TEST procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 17/42] lockd: Use xdrgen XDR functions for the NLMv4 LOCK procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 18/42] lockd: Use xdrgen XDR functions for the NLMv4 CANCEL procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 19/42] lockd: Use xdrgen XDR functions for the NLMv4 UNLOCK procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 20/42] lockd: Use xdrgen XDR functions for the NLMv4 GRANTED procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 21/42] lockd: Refactor nlm4svc_callback() Chuck Lever
2026-01-23 18:52 ` [PATCH v2 22/42] lockd: Use xdrgen XDR functions for the NLMv4 TEST_MSG procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 23/42] lockd: Use xdrgen XDR functions for the NLMv4 LOCK_MSG procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 24/42] lockd: Use xdrgen XDR functions for the NLMv4 CANCEL_MSG procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 25/42] lockd: Use xdrgen XDR functions for the NLMv4 UNLOCK_MSG procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 26/42] lockd: Use xdrgen XDR functions for the NLMv4 GRANTED_MSG procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 27/42] lockd: Use xdrgen XDR functions for the NLMv4 TEST_RES procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 28/42] lockd: Use xdrgen XDR functions for the NLMv4 LOCK_RES procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 29/42] lockd: Use xdrgen XDR functions for the NLMv4 CANCEL_RES procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 30/42] lockd: Use xdrgen XDR functions for the NLMv4 UNLOCK_RES procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 31/42] lockd: Use xdrgen XDR functions for the NLMv4 GRANTED_RES procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 32/42] lockd: Use xdrgen XDR functions for the NLMv4 SM_NOTIFY procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 33/42] lockd: Convert server-side undefined procedures to xdrgen Chuck Lever
2026-01-23 18:52 ` [PATCH v2 34/42] lockd: Hoist file_lock init out of nlm4svc_decode_shareargs() Chuck Lever
2026-01-23 18:52 ` [PATCH v2 35/42] lockd: Prepare share helpers for xdrgen conversion Chuck Lever
2026-01-23 18:52 ` [PATCH v2 36/42] lockd: Use xdrgen XDR functions for the NLMv4 SHARE procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 37/42] lockd: Use xdrgen XDR functions for the NLMv4 UNSHARE procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 38/42] lockd: Use xdrgen XDR functions for the NLMv4 NM_LOCK procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 39/42] lockd: Use xdrgen XDR functions for the NLMv4 FREE_ALL procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 40/42] lockd: Add LOCKD_SHARE_SVID constant for DOS sharing mode Chuck Lever
2026-01-23 18:52 ` [PATCH v2 41/42] lockd: Remove C macros that are no longer used Chuck Lever
2026-01-23 18:52 ` [PATCH v2 42/42] lockd: Remove dead code from fs/lockd/xdr4.c Chuck Lever
2026-01-26 12:51 ` [PATCH v2 00/42] Clarify module API boundaries Jeff Layton
2026-01-26 14:35   ` Chuck Lever

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=5c7126f0ace2874ceb2af74726962875e647256d.camel@kernel.org \
    --to=jlayton@kernel.org \
    --cc=bcodding@hammerspace.com \
    --cc=cel@kernel.org \
    --cc=chuck.lever@oracle.com \
    --cc=dai.ngo@oracle.com \
    --cc=linux-nfs@vger.kernel.org \
    --cc=neilb@ownmail.net \
    --cc=okorniev@redhat.com \
    --cc=tom@talpey.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox