fs/nfs/nfs42proc.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-)
The NFS server can clear setuid and setgid bits when CLONE modifies the
destination. The client currently omits mode from the post-operation
attributes, so the cached mode can retain setid bits after the server has
removed them. A local process can then execute the file using those stale
privilege bits.
Request mode in the CLONE compound's GETATTR. This lets the ordered
post-operation update install the server's mode before CLONE returns.
Fixes: e5341f3a5762 ("nfs42: add CLONE proc functions")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5
Signed-off-by: Felix Hoffmann <f3lix.dev@gmx.de>
---
Tested on x86-64 using an NFSv4.2 loopback mount with Linux NFSD and a
Btrfs export:
- before this change, the client retained mode 04775 while the server
stored mode 0775, and the privilege transition reproduced in 10/10
non-debug runs
- with this change, both client and server reported mode 0775 and no
privilege transition occurred in 10/10 non-debug runs or 3/3 KASAN
runs
The reproducer requires write authorization to the destination; NFSD
rejected the same operation against a non-writable 04755 file with EACCES.
A working reproducer is available privately on request.
fs/nfs/nfs42proc.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fs/nfs/nfs42proc.c b/fs/nfs/nfs42proc.c
index ab86246fc364..35a4909d51b7 100644
--- a/fs/nfs/nfs42proc.c
+++ b/fs/nfs/nfs42proc.c
@@ -1302,7 +1302,8 @@ static int _nfs42_proc_clone(struct rpc_message *msg, struct file *src_f,
return -ENOMEM;
nfs4_bitmask_set(dst_bitmask, server->cache_consistency_bitmask,
- dst_inode, NFS_INO_INVALID_BLOCKS);
+ dst_inode,
+ NFS_INO_INVALID_BLOCKS | NFS_INO_INVALID_MODE);
status = nfs4_call_sync(server->client, server, msg,
&args.seq_args, &res.seq_res, 0);
--
2.43.0
On Sun, 2 Aug 2026 at 21:58, Felix Hoffmann <f3lix.dev@gmx.de> wrote:
>
> The NFS server can clear setuid and setgid bits when CLONE modifies the
> destination. The client currently omits mode from the post-operation
> attributes, so the cached mode can retain setid bits after the server has
> removed them. A local process can then execute the file using those stale
> privilege bits.
>
> Request mode in the CLONE compound's GETATTR. This lets the ordered
> post-operation update install the server's mode before CLONE returns.
>
> Fixes: e5341f3a5762 ("nfs42: add CLONE proc functions")
> Cc: stable@vger.kernel.org
> Assisted-by: Codex:gpt-5
> Signed-off-by: Felix Hoffmann <f3lix.dev@gmx.de>
> ---
> Tested on x86-64 using an NFSv4.2 loopback mount with Linux NFSD and a
> Btrfs export:
>
> - before this change, the client retained mode 04775 while the server
> stored mode 0775, and the privilege transition reproduced in 10/10
> non-debug runs
> - with this change, both client and server reported mode 0775 and no
> privilege transition occurred in 10/10 non-debug runs or 3/3 KASAN
> runs
>
> The reproducer requires write authorization to the destination; NFSD
> rejected the same operation against a non-writable 04755 file with EACCES.
> A working reproducer is available privately on request.
>
> fs/nfs/nfs42proc.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
>
> diff --git a/fs/nfs/nfs42proc.c b/fs/nfs/nfs42proc.c
> index ab86246fc364..35a4909d51b7 100644
> --- a/fs/nfs/nfs42proc.c
> +++ b/fs/nfs/nfs42proc.c
> @@ -1302,7 +1302,8 @@ static int _nfs42_proc_clone(struct rpc_message *msg, struct file *src_f,
> return -ENOMEM;
>
> nfs4_bitmask_set(dst_bitmask, server->cache_consistency_bitmask,
> - dst_inode, NFS_INO_INVALID_BLOCKS);
> + dst_inode,
> + NFS_INO_INVALID_BLOCKS | NFS_INO_INVALID_MODE);
>
> status = nfs4_call_sync(server->client, server, msg,
> &args.seq_args, &res.seq_res, 0);
Chuck, what do you think? Does this apply only to NFS CLONE, or to NFS COPY too?
Ced
--
Cedric Blancher <cedric.blancher@gmail.com>
[https://plus.google.com/u/0/+CedricBlancher/]
Institute Pasteur
© 2016 - 2026 Red Hat, Inc.