From: "Chuck Lever" <cel@kernel.org>
To: "Jeff Layton" <jlayton@kernel.org>, NeilBrown <neilb@ownmail.net>,
"Olga Kornievskaia" <okorniev@redhat.com>,
"Dai Ngo" <dai.ngo@oracle.com>, "Tom Talpey" <tom@talpey.com>,
"Benjamin Coddington" <bcodding@hammerspace.com>
Cc: linux-nfs@vger.kernel.org, "Chuck Lever" <chuck.lever@oracle.com>
Subject: Re: [PATCH v2 05/42] NFS: Use nlmclnt_rpc_clnt() helper to retrieve nlm_host's rpc_clnt
Date: Fri, 23 Jan 2026 16:37:35 -0500 [thread overview]
Message-ID: <8131fa88-2f62-4724-97d1-25615b2de7d3@app.fastmail.com> (raw)
In-Reply-To: <5c7126f0ace2874ceb2af74726962875e647256d.camel@kernel.org>
On Fri, Jan 23, 2026, at 4:30 PM, Jeff Layton wrote:
> On Fri, 2026-01-23 at 15:44 -0500, Chuck Lever wrote:
>> On 1/23/26 3:23 PM, Jeff Layton wrote:
>> > On Fri, 2026-01-23 at 13:52 -0500, Chuck Lever wrote:
>> > > From: Chuck Lever <chuck.lever@oracle.com>
>> > >
>> > > The external API definitions for lockd reside in linux/lockd/bind.h.
>> > > Because "struct nlm_host" is an internal lockd structure, bind.h
>> > > does not include a definition of it. Dereferencing that structure
>> > > outside of lockd violates the layering boundary between NFS and
>> > > lockd.
>> > >
>> > > The proper approach is to use the nlmclnt_rpc_clnt() helper function
>> > > already provided in lockd/bind.h, which retrieves the NLM host's
>> > > struct rpc_clnt without exposing internal lockd structures. This
>> > > maintains clean separation between the NFS client and lockd
>> > > internals.
>> > >
>> > > Note that the nlm_host's h_rpcclnt field can be NULL during
>> > > initialization (host.c:141) or after cleanup (host.c:629). Add a
>> > > NULL check before calling shutdown_client() to prevent a potential
>> > > NULL pointer dereference in the sysfs shutdown path.
>> > >
>> > > Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
>> > > ---
>> > > fs/nfs/sysfs.c | 10 +++++++---
>> > > 1 file changed, 7 insertions(+), 3 deletions(-)
>> > >
>> > > diff --git a/fs/nfs/sysfs.c b/fs/nfs/sysfs.c
>> > > index ea6e6168092b..186b29de0129 100644
>> > > --- a/fs/nfs/sysfs.c
>> > > +++ b/fs/nfs/sysfs.c
>> > > @@ -12,7 +12,7 @@
>> > > #include <linux/string.h>
>> > > #include <linux/nfs_fs.h>
>> > > #include <linux/rcupdate.h>
>> > > -#include <linux/lockd/lockd.h>
>> > > +#include <linux/lockd/bind.h>
>> > >
>> > > #include "internal.h"
>> > > #include "nfs4_fs.h"
>> > > @@ -284,8 +284,12 @@ shutdown_store(struct kobject *kobj, struct kobj_attribute *attr,
>> > > if (!IS_ERR(server->client_acl))
>> > > shutdown_client(server->client_acl);
>> > >
>> > > - if (server->nlm_host)
>> > > - shutdown_client(server->nlm_host->h_rpcclnt);
>> > > + if (server->nlm_host) {
>> > > + struct rpc_clnt *nlm_clnt = nlmclnt_rpc_clnt(server->nlm_host);
>> > > +
>> > > + if (nlm_clnt)
>> > > + shutdown_client(nlm_clnt);
>> >
>> > I don't see any locking here. Soon after this thing goes NULL, the
>> > nlm_clnt can be freed. ISTM that this ought to take a reference to
>> > nlm_clnt and put it afterward.
>>
>> So there is no locking here before the patch is applied. The patch does
>> not change that. Do you mean that the patch should add the additional
>> reference count bump (and document that fix in the commit message) ?
>>
>> Mason's prompts did not call this out, so I assumed there wasn't an
>> obvious UAF possible in this path.
>>
>
> (Adding Ben since he wrote this originally...)
>
> Sorry, I didn't make it clear. This is (possibly) an existing bug and
> not something that is changed by your patches.
>
> If that value can go NULL and be freed (and it looks like it can in
> nlm_shutdown_hosts_net()) then I think that could race with someone
> writing to the "shutdown" file. OTOH, maybe that can't happen because
> the sysfs file gets removed before lockd_down() runs? I'm not sure.
>
> The safest thing might be to take and hold the (global) nlm_host_mutex
> around the NLM parts of shutdown_store(). Maybe we could add a helper
> to the nlm public interface that does that so we don't need to expose
> that mutex outside of NLM?
I asked Claude specifically to look for races, and he agrees there
is a pre-existing synchronization issue in here. Certainly could
be addressed via a pre-requisite patch to 05/42.
--
Chuck Lever
next prev parent reply other threads:[~2026-01-23 21:38 UTC|newest]
Thread overview: 53+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-01-23 18:52 [PATCH v2 00/42] Clarify module API boundaries Chuck Lever
2026-01-23 18:52 ` [PATCH v2 01/42] lockd: Simplify cast_status() in svcproc.c Chuck Lever
2026-01-23 18:52 ` [PATCH v2 02/42] lockd: Introduce nlm__int__deadlock Chuck Lever
2026-01-26 12:34 ` Jeff Layton
2026-01-26 14:36 ` Chuck Lever
2026-01-23 18:52 ` [PATCH v2 03/42] lockd: Have nlm_fopen() return errno values Chuck Lever
2026-01-23 18:52 ` [PATCH v2 04/42] lockd: Relocate nlmsvc_unlock API declarations Chuck Lever
2026-01-23 18:52 ` [PATCH v2 05/42] NFS: Use nlmclnt_rpc_clnt() helper to retrieve nlm_host's rpc_clnt Chuck Lever
2026-01-23 20:23 ` Jeff Layton
2026-01-23 20:44 ` Chuck Lever
2026-01-23 21:30 ` Jeff Layton
2026-01-23 21:37 ` Chuck Lever [this message]
2026-01-23 18:52 ` [PATCH v2 06/42] lockd: Move xdr4.h from include/linux/lockd/ to fs/lockd/ Chuck Lever
2026-01-23 18:52 ` [PATCH v2 07/42] lockd: Move share.h " Chuck Lever
2026-01-23 18:52 ` [PATCH v2 08/42] lockd: Relocate include/linux/lockd/lockd.h Chuck Lever
2026-01-23 18:52 ` [PATCH v2 09/42] lockd: Remove lockd/debug.h Chuck Lever
2026-01-23 18:52 ` [PATCH v2 10/42] lockd: Move xdr.h from include/linux/lockd/ to fs/lockd/ Chuck Lever
2026-01-24 1:20 ` kernel test robot
2026-01-24 2:57 ` kernel test robot
2026-01-23 18:52 ` [PATCH v2 11/42] lockd: Make linux/lockd/nlm.h an internal header Chuck Lever
2026-01-23 18:52 ` [PATCH v2 12/42] lockd: Move nlm4svc_set_file_lock_range() Chuck Lever
2026-01-23 18:52 ` [PATCH v2 13/42] lockd: Relocate svc_version definitions to XDR layer Chuck Lever
2026-01-23 18:52 ` [PATCH v2 14/42] Documentation: Add the RPC language description of NLM version 4 Chuck Lever
2026-01-23 18:52 ` [PATCH v2 15/42] lockd: Use xdrgen XDR functions for the NLMv4 NULL procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 16/42] lockd: Use xdrgen XDR functions for the NLMv4 TEST procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 17/42] lockd: Use xdrgen XDR functions for the NLMv4 LOCK procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 18/42] lockd: Use xdrgen XDR functions for the NLMv4 CANCEL procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 19/42] lockd: Use xdrgen XDR functions for the NLMv4 UNLOCK procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 20/42] lockd: Use xdrgen XDR functions for the NLMv4 GRANTED procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 21/42] lockd: Refactor nlm4svc_callback() Chuck Lever
2026-01-23 18:52 ` [PATCH v2 22/42] lockd: Use xdrgen XDR functions for the NLMv4 TEST_MSG procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 23/42] lockd: Use xdrgen XDR functions for the NLMv4 LOCK_MSG procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 24/42] lockd: Use xdrgen XDR functions for the NLMv4 CANCEL_MSG procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 25/42] lockd: Use xdrgen XDR functions for the NLMv4 UNLOCK_MSG procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 26/42] lockd: Use xdrgen XDR functions for the NLMv4 GRANTED_MSG procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 27/42] lockd: Use xdrgen XDR functions for the NLMv4 TEST_RES procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 28/42] lockd: Use xdrgen XDR functions for the NLMv4 LOCK_RES procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 29/42] lockd: Use xdrgen XDR functions for the NLMv4 CANCEL_RES procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 30/42] lockd: Use xdrgen XDR functions for the NLMv4 UNLOCK_RES procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 31/42] lockd: Use xdrgen XDR functions for the NLMv4 GRANTED_RES procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 32/42] lockd: Use xdrgen XDR functions for the NLMv4 SM_NOTIFY procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 33/42] lockd: Convert server-side undefined procedures to xdrgen Chuck Lever
2026-01-23 18:52 ` [PATCH v2 34/42] lockd: Hoist file_lock init out of nlm4svc_decode_shareargs() Chuck Lever
2026-01-23 18:52 ` [PATCH v2 35/42] lockd: Prepare share helpers for xdrgen conversion Chuck Lever
2026-01-23 18:52 ` [PATCH v2 36/42] lockd: Use xdrgen XDR functions for the NLMv4 SHARE procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 37/42] lockd: Use xdrgen XDR functions for the NLMv4 UNSHARE procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 38/42] lockd: Use xdrgen XDR functions for the NLMv4 NM_LOCK procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 39/42] lockd: Use xdrgen XDR functions for the NLMv4 FREE_ALL procedure Chuck Lever
2026-01-23 18:52 ` [PATCH v2 40/42] lockd: Add LOCKD_SHARE_SVID constant for DOS sharing mode Chuck Lever
2026-01-23 18:52 ` [PATCH v2 41/42] lockd: Remove C macros that are no longer used Chuck Lever
2026-01-23 18:52 ` [PATCH v2 42/42] lockd: Remove dead code from fs/lockd/xdr4.c Chuck Lever
2026-01-26 12:51 ` [PATCH v2 00/42] Clarify module API boundaries Jeff Layton
2026-01-26 14:35 ` Chuck Lever
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=8131fa88-2f62-4724-97d1-25615b2de7d3@app.fastmail.com \
--to=cel@kernel.org \
--cc=bcodding@hammerspace.com \
--cc=chuck.lever@oracle.com \
--cc=dai.ngo@oracle.com \
--cc=jlayton@kernel.org \
--cc=linux-nfs@vger.kernel.org \
--cc=neilb@ownmail.net \
--cc=okorniev@redhat.com \
--cc=tom@talpey.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox