[PATCH openEuler-1.0-LTS] NFSD: Prevent client use-after-free during delegation revoke
From: Chuck Lever <cel@kernel.org> mainline inclusion from mainline-v7.3-rc1 commit 4683ca76b3b7e5808338491c6eb3c20e6b4894d5 category: bugfix bugzilla: https://atomgit.com/src-openeuler/kernel/issues/18928 CVE: CVE-2026-89659 Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=... -------------------------------- A delegation stateid holds only a bare pointer to its owning nfs4_client and does not keep it alive. The client survives its stateids only because __destroy_client() drains cl_delegations and cl_revoked before free_client() runs. nfs4_laundromat() breaks that invariant: it unhashes an expired delegation from cl_delegations, drops deleg_lock, then revoke_delegation() relinks it onto cl_revoked under cl_lock. In that window the delegation is on neither list, so client_has_state() can report no remaining state. Every teardown path first requires cl_rpc_users to be zero, but the laundromat holds no such reference. A client whose recalled delegation has just timed out can therefore reach free_client() while revoke_delegation() is still about to dereference cl_lock, a use-after-free. Pin the client with cl_rpc_users across the revoke so teardown blocks until it completes, then reap the delegation from cl_revoked. A client already expiring reaps its own, so skip it and leave the delegation on del_recall_lru. Fixes: 3bd64a5ba171 ("nfsd4: implement SEQ4_STATUS_RECALLABLE_STATE_REVOKED") Cc: stable@vger.kernel.org Reviewed-by: NeilBrown <neil@brown.name> Reviewed-by: Jeff Layton <jlayton@kernel.org> Link: https://patch.msgid.link/20260709-cel-v4-2-1d519d9be0cb@kernel.org Signed-off-by: Chuck Lever <cel@kernel.org> Conflicts: fs/nfsd/nfs4state.c [Commit 4683ca76b3b7 pins the client with cl_rpc_users (guarded by a dedicated deleg_lock, waking expiry_wq on release). This tree has neither cl_rpc_users nor deleg_lock nor expiry_wq; it guards client expiry with cl_refcount (checked by mark_client_expired_locked) and protects del_recall_lru with state_lock. So the backport pins the client with atomic_inc(&clp->cl_refcount) under client_lock (taken before state_lock, matching the existing client_lock->state_lock ordering in nfsd_find_all_delegations) and unpins with a plain atomic_dec after revoke_delegation(), skipping the wake_up_all(&expiry_wq) that has no target here. The netns.h comment-only change advertising deleg_lock was dropped since that lock does not exist in this tree.] Co-authored-by: BackportAgent@deepseek-v4-flash Signed-off-by: Gaosheng Cui <cuigaosheng1@huawei.com> --- fs/nfsd/nfs4state.c | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/fs/nfsd/nfs4state.c b/fs/nfsd/nfs4state.c index d07e620fe72d..972a9127fc26 100644 --- a/fs/nfsd/nfs4state.c +++ b/fs/nfsd/nfs4state.c @@ -4825,6 +4825,7 @@ nfs4_laundromat(struct nfsd_net *nn) list_del_init(&clp->cl_lru); expire_client(clp); } + spin_lock(&nn->client_lock); spin_lock(&state_lock); list_for_each_safe(pos, next, &nn->del_recall_lru) { dp = list_entry (pos, struct nfs4_delegation, dl_recall_lru); @@ -4833,15 +4834,27 @@ nfs4_laundromat(struct nfsd_net *nn) new_timeo = min(new_timeo, t); break; } + clp = dp->dl_stid.sc_client; + if (is_client_expired(clp)) + continue; + /* + * Pin the client so it cannot be torn down and freed + * while revoke_delegation() reaps this delegation below. + */ + atomic_inc(&clp->cl_refcount); WARN_ON(!unhash_delegation_locked(dp)); list_add(&dp->dl_recall_lru, &reaplist); } spin_unlock(&state_lock); + spin_unlock(&nn->client_lock); while (!list_empty(&reaplist)) { dp = list_first_entry(&reaplist, struct nfs4_delegation, dl_recall_lru); + clp = dp->dl_stid.sc_client; list_del_init(&dp->dl_recall_lru); revoke_delegation(dp); + /* Unpin without renewing the reaped client's lease. */ + atomic_dec(&clp->cl_refcount); } spin_lock(&nn->client_lock); -- 2.43.0
反馈: 您发送到kernel@openeuler.org的补丁/补丁集,已成功转换为PR! PR链接地址: https://gitcode.com/openeuler/kernel/merge_requests/29145 邮件列表地址:https://mailweb.openeuler.org/archives/list/kernel@openeuler.org/message/BPR... FeedBack: The patch(es) which you have sent to kernel@openeuler.org mailing list has been converted to a pull request successfully! Pull request link: https://gitcode.com/openeuler/kernel/merge_requests/29145 Mailing list address: https://mailweb.openeuler.org/archives/list/kernel@openeuler.org/message/BPR...
participants (2)
-
Gaosheng Cui -
patchwork bot