]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
NFSv4: xattr handlers should check for absent nfs filehandles
authorScott Mayhew <smayhew@redhat.com>
Wed, 16 Apr 2025 15:23:38 +0000 (11:23 -0400)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Sun, 6 Jul 2025 08:57:54 +0000 (10:57 +0200)
[ Upstream commit 6e9a2f8dbe93c8004c2af2c0158888628b7ca034 ]

The nfs inodes for referral anchors that have not yet been followed have
their filehandles zeroed out.

Attempting to call getxattr() on one of these will cause the nfs client
to send a GETATTR to the nfs server with the preceding PUTFH sans
filehandle.  The server will reply NFS4ERR_NOFILEHANDLE, leading to -EIO
being returned to the application.

For example:

$ strace -e trace=getxattr getfattr -n system.nfs4_acl /mnt/t/ref
getxattr("/mnt/t/ref", "system.nfs4_acl", NULL, 0) = -1 EIO (Input/output error)
/mnt/t/ref: system.nfs4_acl: Input/output error
+++ exited with 1 +++

Have the xattr handlers return -ENODATA instead.

Signed-off-by: Scott Mayhew <smayhew@redhat.com>
Signed-off-by: Anna Schumaker <anna.schumaker@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
fs/nfs/nfs4proc.c

index 2d94d1d7b0c629fb27b518e7e37346f4f49c36f6..29f8a2df2c11a784b71aa4aaf916ab2e34eaecc6 100644 (file)
@@ -6065,6 +6065,8 @@ static ssize_t nfs4_proc_get_acl(struct inode *inode, void *buf, size_t buflen,
        struct nfs_server *server = NFS_SERVER(inode);
        int ret;
 
+       if (unlikely(NFS_FH(inode)->size == 0))
+               return -ENODATA;
        if (!nfs4_server_supports_acls(server, type))
                return -EOPNOTSUPP;
        ret = nfs_revalidate_inode(inode, NFS_INO_INVALID_CHANGE);
@@ -6139,6 +6141,9 @@ static int nfs4_proc_set_acl(struct inode *inode, const void *buf,
 {
        struct nfs4_exception exception = { };
        int err;
+
+       if (unlikely(NFS_FH(inode)->size == 0))
+               return -ENODATA;
        do {
                err = __nfs4_proc_set_acl(inode, buf, buflen, type);
                trace_nfs4_set_acl(inode, err);