]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
NFSD: detect mismatch of file handle and delegation stateid in OPEN op
authorDai Ngo <dai.ngo@oracle.com>
Tue, 10 Jun 2025 15:35:28 +0000 (08:35 -0700)
committerChuck Lever <chuck.lever@oracle.com>
Mon, 14 Jul 2025 16:46:40 +0000 (12:46 -0400)
When the client sends an OPEN with claim type CLAIM_DELEG_CUR_FH or
CLAIM_DELEGATION_CUR, the delegation stateid and the file handle
must belong to the same file, otherwise return NFS4ERR_INVAL.

Note that RFC8881, section 8.2.4, mandates the server to return
NFS4ERR_BAD_STATEID if the selected table entry does not match the
current filehandle. However returning NFS4ERR_BAD_STATEID in the
OPEN causes the client to retry the operation and therefor get the
client into a loop. To avoid this situation we return NFS4ERR_INVAL
instead.

Reported-by: Petro Pavlov <petro.pavlov@vastdata.com>
Fixes: c44c5eeb2c02 ("[PATCH] nfsd4: add open state code for CLAIM_DELEGATE_CUR")
Cc: stable@vger.kernel.org
Signed-off-by: Dai Ngo <dai.ngo@oracle.com>
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
fs/nfsd/nfs4state.c

index 95d88555648d61d1053ade40f628b25c005531be..f46d0814d20643d45760104420cadb0cd1352ba2 100644 (file)
@@ -6361,6 +6361,20 @@ nfsd4_process_open2(struct svc_rqst *rqstp, struct svc_fh *current_fh, struct nf
                status = nfs4_check_deleg(cl, open, &dp);
                if (status)
                        goto out;
+               if (dp && nfsd4_is_deleg_cur(open) &&
+                               (dp->dl_stid.sc_file != fp)) {
+                       /*
+                        * RFC8881 section 8.2.4 mandates the server to return
+                        * NFS4ERR_BAD_STATEID if the selected table entry does
+                        * not match the current filehandle. However returning
+                        * NFS4ERR_BAD_STATEID in the OPEN can cause the client
+                        * to repeatedly retry the operation with the same
+                        * stateid, since the stateid itself is valid. To avoid
+                        * this situation NFSD returns NFS4ERR_INVAL instead.
+                        */
+                       status = nfserr_inval;
+                       goto out;
+               }
                stp = nfsd4_find_and_lock_existing_open(fp, open);
        } else {
                open->op_file = NULL;