mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-31 08:15:07 -04:00
nfsd: guard nfsd_serv deref in nfsd_file_net_dispose
nfsd_file_net_dispose() is the consumer side of l->freeme: the nfsd
service thread loop calls it to drain entries that the filecache
garbage collector and shrinker append via
nfsd_file_dispose_list_delayed(). During per-net teardown,
nn->nfsd_serv is cleared before the filecache laundrette is shut
down, so the service thread can still run a dispose pass that finds
more than eight entries on l->freeme and dereferences a NULL
svc_serv:
nfsd service thread loop
nfsd_file_net_dispose(nn)
if (!list_empty(&l->freeme)) {
...
svc_wake_up(nn->nfsd_serv); /* nn->nfsd_serv == NULL */
}
The sibling helper nfsd_file_dispose_list_delayed() already documents
this ordering and caches nn->nfsd_serv into a local before testing it
for NULL. nfsd_file_net_dispose() was introduced with the same raw
svc_wake_up(nn->nfsd_serv) call and never picked up the guard.
Fix by loading nn->nfsd_serv into a local svc_serv pointer and only
calling svc_wake_up() when it is non-NULL, matching the pattern in
nfsd_file_dispose_list_delayed().
Fixes: ffb4025961 ("nfsd: Don't leave work of closing files to a work queue")
Cc: stable@vger.kernel.org
Assisted-by: kres:claude-opus-4-7
Signed-off-by: Chris Mason <clm@meta.com>
Link: https://patch.msgid.link/20260602-nfsd-testing-v2-4-e4ea62e3cd5c@kernel.org
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
This commit is contained in:
@@ -471,11 +471,20 @@ void nfsd_file_net_dispose(struct nfsd_net *nn)
|
||||
for (i = 0; i < 8 && !list_empty(&l->freeme); i++)
|
||||
list_move(l->freeme.next, &dispose);
|
||||
spin_unlock(&l->lock);
|
||||
if (!list_empty(&l->freeme))
|
||||
/* Wake up another thread to share the work
|
||||
if (!list_empty(&l->freeme)) {
|
||||
/*
|
||||
* Wake up another thread to share the work
|
||||
* *before* doing any actual disposing.
|
||||
*
|
||||
* The filecache laundrette is shut down after
|
||||
* the nn->nfsd_serv pointer is cleared, but
|
||||
* before the svc_serv is freed.
|
||||
*/
|
||||
svc_wake_up(nn->nfsd_serv);
|
||||
struct svc_serv *serv = nn->nfsd_serv;
|
||||
|
||||
if (serv)
|
||||
svc_wake_up(serv);
|
||||
}
|
||||
nfsd_file_dispose_list(&dispose);
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user