]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
NFSD: Fix last write offset handling in layoutcommit
authorSergey Bashirov <sergeybashirov@gmail.com>
Mon, 20 Oct 2025 12:56:56 +0000 (08:56 -0400)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 29 Oct 2025 13:01:23 +0000 (14:01 +0100)
[ Upstream commit d68886bae76a4b9b3484d23e5b7df086f940fa38 ]

The data type of loca_last_write_offset is newoffset4 and is switched
on a boolean value, no_newoffset, that indicates if a previous write
occurred or not. If no_newoffset is FALSE, an offset is not given.
This means that client does not try to update the file size. Thus,
server should not try to calculate new file size and check if it fits
into the segment range. See RFC 8881, section 12.5.4.2.

Sometimes the current incorrect logic may cause clients to hang when
trying to sync an inode. If layoutcommit fails, the client marks the
inode as dirty again.

Fixes: 9cf514ccfacb ("nfsd: implement pNFS operations")
Cc: stable@vger.kernel.org
Co-developed-by: Konstantin Evtushenko <koevtushenko@yandex.com>
Signed-off-by: Konstantin Evtushenko <koevtushenko@yandex.com>
Signed-off-by: Sergey Bashirov <sergeybashirov@gmail.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
[ removed rqstp parameter from proc_layoutcommit ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
fs/nfsd/blocklayout.c
fs/nfsd/nfs4proc.c

index d91a686d2f3131ff947438e7457323bf8babd8c6..aa9b7ae59a076820006dfabb9572ef4c64207596 100644 (file)
@@ -121,7 +121,6 @@ static __be32
 nfsd4_block_commit_blocks(struct inode *inode, struct nfsd4_layoutcommit *lcp,
                struct iomap *iomaps, int nr_iomaps)
 {
-       loff_t new_size = lcp->lc_last_wr + 1;
        struct iattr iattr = { .ia_valid = 0 };
        int error;
 
@@ -131,9 +130,9 @@ nfsd4_block_commit_blocks(struct inode *inode, struct nfsd4_layoutcommit *lcp,
        iattr.ia_valid |= ATTR_ATIME | ATTR_CTIME | ATTR_MTIME;
        iattr.ia_atime = iattr.ia_ctime = iattr.ia_mtime = lcp->lc_mtime;
 
-       if (new_size > i_size_read(inode)) {
+       if (lcp->lc_size_chg) {
                iattr.ia_valid |= ATTR_SIZE;
-               iattr.ia_size = new_size;
+               iattr.ia_size = lcp->lc_newsize;
        }
 
        error = inode->i_sb->s_export_op->commit_blocks(inode, iomaps,
index dab23132db9e8eb49281f4cf27b2aea52cc0ca82..67dd77017e3ce3dc2d8257b174d287c2f957c7ec 100644 (file)
@@ -2262,7 +2262,6 @@ nfsd4_layoutcommit(struct svc_rqst *rqstp,
        const struct nfsd4_layout_seg *seg = &lcp->lc_seg;
        struct svc_fh *current_fh = &cstate->current_fh;
        const struct nfsd4_layout_ops *ops;
-       loff_t new_size = lcp->lc_last_wr + 1;
        struct inode *inode;
        struct nfs4_layout_stateid *ls;
        __be32 nfserr;
@@ -2277,13 +2276,21 @@ nfsd4_layoutcommit(struct svc_rqst *rqstp,
                goto out;
        inode = d_inode(current_fh->fh_dentry);
 
-       nfserr = nfserr_inval;
-       if (new_size <= seg->offset)
-               goto out;
-       if (new_size > seg->offset + seg->length)
-               goto out;
-       if (!lcp->lc_newoffset && new_size > i_size_read(inode))
-               goto out;
+       lcp->lc_size_chg = false;
+       if (lcp->lc_newoffset) {
+               loff_t new_size = lcp->lc_last_wr + 1;
+
+               nfserr = nfserr_inval;
+               if (new_size <= seg->offset)
+                       goto out;
+               if (new_size > seg->offset + seg->length)
+                       goto out;
+
+               if (new_size > i_size_read(inode)) {
+                       lcp->lc_size_chg = true;
+                       lcp->lc_newsize = new_size;
+               }
+       }
 
        nfserr = nfsd4_preprocess_layout_stateid(rqstp, cstate, &lcp->lc_sid,
                                                false, lcp->lc_layout_type,
@@ -2299,13 +2306,6 @@ nfsd4_layoutcommit(struct svc_rqst *rqstp,
        /* LAYOUTCOMMIT does not require any serialization */
        mutex_unlock(&ls->ls_mutex);
 
-       if (new_size > i_size_read(inode)) {
-               lcp->lc_size_chg = 1;
-               lcp->lc_newsize = new_size;
-       } else {
-               lcp->lc_size_chg = 0;
-       }
-
        nfserr = ops->proc_layoutcommit(inode, lcp);
        nfs4_put_stid(&ls->ls_stid);
 out: