]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
NFSv4: ensure the open stateid seqid doesn't go backwards
authorScott Mayhew <smayhew@redhat.com>
Mon, 3 Nov 2025 15:44:15 +0000 (10:44 -0500)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Sat, 17 Jan 2026 15:31:19 +0000 (16:31 +0100)
[ Upstream commit 2e47c3cc64b44b0b06cd68c2801db92ff143f2b2 ]

We have observed an NFSv4 client receiving a LOCK reply with a status of
NFS4ERR_OLD_STATEID and subsequently retrying the LOCK request with an
earlier seqid value in the stateid.  As this was for a new lockowner,
that would imply that nfs_set_open_stateid_locked() had updated the open
stateid seqid with an earlier value.

Looking at nfs_set_open_stateid_locked(), if the incoming seqid is out
of sequence, the task will sleep on the state->waitq for up to 5
seconds.  If the task waits for the full 5 seconds, then after finishing
the wait it'll update the open stateid seqid with whatever value the
incoming seqid has.  If there are multiple waiters in this scenario,
then the last one to perform said update may not be the one with the
highest seqid.

Add a check to ensure that the seqid can only be incremented, and add a
tracepoint to indicate when old seqids are skipped.

Signed-off-by: Scott Mayhew <smayhew@redhat.com>
Reviewed-by: Benjamin Coddington <bcodding@hammerspace.com>
Signed-off-by: Trond Myklebust <trond.myklebust@hammerspace.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
fs/nfs/nfs4proc.c
fs/nfs/nfs4trace.h

index 172ff213b50b6553cf49f0288c07b3f80817f889..89f779f16f0dcbad22b8c46a755bf2da58cadf5b 100644 (file)
@@ -1753,8 +1753,17 @@ static void nfs_set_open_stateid_locked(struct nfs4_state *state,
                if (nfs_stateid_is_sequential(state, stateid))
                        break;
 
-               if (status)
-                       break;
+               if (status) {
+                       if (nfs4_stateid_match_other(stateid, &state->open_stateid) &&
+                           !nfs4_stateid_is_newer(stateid, &state->open_stateid)) {
+                               trace_nfs4_open_stateid_update_skip(state->inode,
+                                                                   stateid, status);
+                               return;
+                       } else {
+                               break;
+                       }
+               }
+
                /* Rely on seqids for serialisation with NFSv4.0 */
                if (!nfs4_has_session(NFS_SERVER(state->inode)->nfs_client))
                        break;
index 22c973316f0bdd83bddf324e9a78bdfab76c5847..9a38a5d3bf51258d3d07dccd1f75b4188e9d1c43 100644 (file)
@@ -1278,6 +1278,7 @@ DEFINE_NFS4_INODE_STATEID_EVENT(nfs4_setattr);
 DEFINE_NFS4_INODE_STATEID_EVENT(nfs4_delegreturn);
 DEFINE_NFS4_INODE_STATEID_EVENT(nfs4_open_stateid_update);
 DEFINE_NFS4_INODE_STATEID_EVENT(nfs4_open_stateid_update_wait);
+DEFINE_NFS4_INODE_STATEID_EVENT(nfs4_open_stateid_update_skip);
 DEFINE_NFS4_INODE_STATEID_EVENT(nfs4_close_stateid_update_wait);
 
 DECLARE_EVENT_CLASS(nfs4_getattr_event,