From nobody Fri Oct 2 06:58:48 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 85C7143747B; Tue, 4 Aug 2026 10:55:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785840927; cv=none; b=Jr3iBfZhYniZic0x/yW8e5prTfrUg+Xy/dBKwM8LZ7Dst1nul9BtTC8Rn5xeY10beFI56LRUoLCCdyTzIXE92/bF/2yr4g7scnyAEBXrf944h0jiKedAHAMRxzjUhuJyRHvIaM9KHFfawhss1sF9XX4z6ugFqM9ygWs5rSmddKw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785840927; c=relaxed/simple; bh=/zX1dK5pUUwfUUMgp/WjTg2pjQrJvqcIYBJwxISBk4k=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=skLjRqGKWXsKciYkJfFRBHSj6/ccv4sWekGHcGigHjhJ/xrblUHXpOBjat/3aNcCscYtBPnucmxUNc4rUtPDXP7K9dE7v/W3/9EK9obrZs+IIO7kvSjY7gTRg3q37IkCevNfftEvoif5sLEeb9vniXmzWHYMmZRnb4v6a7uHCS4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=XtYgSNmU; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="XtYgSNmU" Received: by smtp.kernel.org (Postfix) with ESMTPS id A442BC2BCF6; Tue, 4 Aug 2026 10:55:26 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1785840926; bh=/zX1dK5pUUwfUUMgp/WjTg2pjQrJvqcIYBJwxISBk4k=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=XtYgSNmUw1N+43MoNDdnc670SG/gZcUOVmDEZbWK86886C6R9Jnyf9zb+KpvFS/Tn Esm3aKpvH65qCy2M8MxcUtFKENfax4G1ZuSyHIunQDLNvTrUYljqPOiiuYy0CJxKYd FPIKVRNA9csszA6MKZCVKx4AHtyN6LwOFv3UTsd3xHRSP1gfzNigD0HDQFqQZp2Roc 4CiHLIjBmMb69c4AvHFIA/t+9lgfE2gE+GIbaXXNnPQX9Eqxux9v8CzsuwZvtuM1mE fB7FhdokQavUVoOfUJjh0lMwCmHjIUC571Jrum5IxWNZbdGMb0frEbVbUuA+tLkDWO dsRdIrDuKW6bQ== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 86D27C55ABA; Tue, 4 Aug 2026 10:55:26 +0000 (UTC) From: Junrui Luo via B4 Relay Date: Tue, 04 Aug 2026 18:55:01 +0800 Subject: [PATCH 1/5] NFSv4/flexfiles: bound the multipath address count Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260804-nfs-fixes-v1-1-1544df970e7c@outlook.com> References: <20260804-nfs-fixes-v1-0-1544df970e7c@outlook.com> In-Reply-To: <20260804-nfs-fixes-v1-0-1544df970e7c@outlook.com> To: Trond Myklebust , Anna Schumaker Cc: linux-nfs@vger.kernel.org, linux-kernel@vger.kernel.org, Jonathan Curley , Michael Bommarito , Junrui Luo , Yuhao Jiang , stable@vger.kernel.org X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=openpgp-sha256; l=2777; i=moonafterrain@outlook.com; h=from:subject:message-id; bh=P//3MuVFQOmbnVMiCO1Tok8Ub0duINavLD89ty/UirE=; b=owJ4nJvAy8zAJVb4wiKgu++DA+NptSSGrMKj0lencjE0C4WblrXsYp/Rcy7yYd609HPb7srF/ 35Tdbbv/5SOUhYGMS4GWTFFluMFl75Z+G7R3eKzJRlmDisTyBAGLk4BmIjITEaG/62+nILezh4n b73SZ3V7GplUd21nJJNFl9W1uQsfpMunMDKc0uSRMly77kPLkY416VHr48LebK71n2K0O8fjxgz W6VN5AaIpShg= X-Developer-Key: i=moonafterrain@outlook.com; a=openpgp; fpr=C770D2F6384DB42DB44CB46371E838508B8EF040 X-Endpoint-Received: by B4 Relay for moonafterrain@outlook.com/default with auth_id=909 X-Original-From: Junrui Luo Reply-To: moonafterrain@outlook.com From: Junrui Luo nfs4_ff_alloc_deviceid_node() decodes the multipath address list of a flexfiles device from the GETDEVICEINFO reply body. mp_count is taken straight off the wire and used as the loop bound for the nfs4_decode_mp_ds_addr() calls. nfs4_get_device_info() bounds pdev->pglen but not the counts encoded inside it, so a server can advertise up to 2^32 - 1 addresses in a body that holds none of them. Once the xdr_stream is exhausted the loop stops making progress: xdr_stream_decode_string_dup() fails in xdr_stream_decode_opaque_inline() , so nfs4_decode_mp_ds_addr() returns NULL without consuming a byte and every remaining iteration re-fails at the same offset. With mp_count set to 0xffffffff this spins for roughly 2^32 iterations with no rescheduling point, potentially tripping the soft lockup watchdog and the RCU stall detector on non-preemptible kernels. The list_empty(&dsaddrs) check below the loop only runs once the loop has finished. Reject implausible counts up front, as ff_layout_alloc_lseg() already does for mirror_array_cnt and dss_count. Fixes: d67ae825a59d ("pnfs/flexfiles: Add the FlexFile Layout Driver") Reported-by: Yuhao Jiang Assisted-by: Claude:claude-opus-5 Cc: stable@vger.kernel.org Signed-off-by: Junrui Luo --- fs/nfs/flexfilelayout/flexfilelayout.h | 4 ++++ fs/nfs/flexfilelayout/flexfilelayoutdev.c | 5 +++++ 2 files changed, 9 insertions(+) diff --git a/fs/nfs/flexfilelayout/flexfilelayout.h b/fs/nfs/flexfilelayout= /flexfilelayout.h index a5bd00f69e82..d024b8db4ce0 100644 --- a/fs/nfs/flexfilelayout/flexfilelayout.h +++ b/fs/nfs/flexfilelayout/flexfilelayout.h @@ -23,6 +23,10 @@ =20 #define NFS4_FLEXFILE_LAYOUT_MAX_STRIPE_CNT 4096 =20 +/* Filter out insanely large multipath address counts, which would + * otherwise let a server spin the GETDEVICEINFO decode loop. */ +#define NFS4_FLEXFILE_LAYOUT_MAX_MULTIPATH_CNT 4096 + /* LAYOUTSTATS report interval in ms */ #define FF_LAYOUTSTATS_REPORT_INTERVAL (60000L) #define FF_LAYOUTSTATS_MAXDEV 4 diff --git a/fs/nfs/flexfilelayout/flexfilelayoutdev.c b/fs/nfs/flexfilelay= out/flexfilelayoutdev.c index 1109462a9699..659a2bf7b502 100644 --- a/fs/nfs/flexfilelayout/flexfilelayoutdev.c +++ b/fs/nfs/flexfilelayout/flexfilelayoutdev.c @@ -79,6 +79,11 @@ nfs4_ff_alloc_deviceid_node(struct nfs_server *server, s= truct pnfs_device *pdev, mp_count =3D be32_to_cpup(p); dprintk("%s: multipath ds count %d\n", __func__, mp_count); =20 + if (mp_count > NFS4_FLEXFILE_LAYOUT_MAX_MULTIPATH_CNT) { + ret =3D -EINVAL; + goto out_err_drain_dsaddrs; + } + for (i =3D 0; i < mp_count; i++) { /* multipath ds */ da =3D nfs4_decode_mp_ds_addr(net, &stream, gfp_flags); --=20 2.51.2 From nobody Fri Oct 2 06:58:48 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3A1E84570FC; Tue, 4 Aug 2026 10:55:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785840928; cv=none; b=qVW4t9dV1b5QZ6tSbNPo61eNl6JNaw7GojlUgJIHFOqwuHGaBjJEyQljx+Dmz0Ca7wgtuxRzxxBsPKd+YpkscJfodjPeH8RpvEpnhCSEyUMZ4yhabFAEfzfWWsqyenYXOLRI1PHiCn9+Worefd4qeDLKgZ8VHdLJ9MIUdL5zFEs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785840928; c=relaxed/simple; bh=F5f9S39Wy5yR44QpT3JsOfQLfBe7Y4KOQV1Mv0uzWcc=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=lYosmiWHKgf2zlEyKJ9+jWBxf5Gay+K4wG5slD4ecC1xdRXNm/R2rToG2QePwWkvmg0BmUywaJPJE9e1OjCZiUkMcNMFAdRjoQJ4X81bO/ng+N/cCrCMTC1xfQjWlFRKdJ9pLnsrkD9Ycz1SMDdfzDqJwZqqc89OtdGB9lDmrv0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Pxj1O5m4; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Pxj1O5m4" Received: by smtp.kernel.org (Postfix) with ESMTPS id B7347C2BCF7; Tue, 4 Aug 2026 10:55:26 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1785840926; bh=F5f9S39Wy5yR44QpT3JsOfQLfBe7Y4KOQV1Mv0uzWcc=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=Pxj1O5m4o+B+CZ8KocW19ZBCc9n2vT0kdfG+JX65kafkEJc526R7zM5XPVgySQldy 7j5YT/eGufVNM2yrW3/jW5cCZv8bZn/cUoYd6p+No/pmrUvFva71C3hb8wpTLZ8oE0 3NLxILT0h0H+CF8/d6ny/R6PDS5TfmCbSmfWjicYXghV5y9nD/Z1t7qOhkqwgLTvHp JbcEV9wenRx+tEcHBfvBRV52MXRUozNjjjR5LJWnGgV4CHEpQk3DLG/ivGdhiG9IM4 7NgoJ38R0qaPTxbc8ihP1cEdb2rUnZ5s+XFy6IQMJAoVAy069eMg5YQtifR81FDu3J Mv2rxc+nGCuaQ== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 96AC1C5518F; Tue, 4 Aug 2026 10:55:26 +0000 (UTC) From: Junrui Luo via B4 Relay Date: Tue, 04 Aug 2026 18:55:02 +0800 Subject: [PATCH 2/5] NFSv4/flexfiles: fix da_netid leak in nfs4_ff_alloc_deviceid_node() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260804-nfs-fixes-v1-2-1544df970e7c@outlook.com> References: <20260804-nfs-fixes-v1-0-1544df970e7c@outlook.com> In-Reply-To: <20260804-nfs-fixes-v1-0-1544df970e7c@outlook.com> To: Trond Myklebust , Anna Schumaker Cc: linux-nfs@vger.kernel.org, linux-kernel@vger.kernel.org, Jonathan Curley , Michael Bommarito , Junrui Luo , Yuhao Jiang X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=openpgp-sha256; l=1642; i=moonafterrain@outlook.com; h=from:subject:message-id; bh=Js0koCYPuEad0TbgAqXuAe69HQlQTlIjrIH4OepFPu4=; b=owJ4nJvAy8zAJVb4wiKgu++DA+NptSSGrMKjMoU1QradKx7FHXlzc98DHi5PE/8DPLd2b5I5u EvuYavDy+cdpSwMYlwMsmKKLMcLLn2z8N2iu8VnSzLMHFYmkCEMXJwCMBHPRQz/Yy69X7nKIUnY 1NOx8lB74sJl29VirrOmOjo8K3FIq/L9wMhw7NK72JU+4Y+nFXX7807bvO3EGYdp0978vyrlezt ZSJeTBwBJH0zC X-Developer-Key: i=moonafterrain@outlook.com; a=openpgp; fpr=C770D2F6384DB42DB44CB46371E838508B8EF040 X-Endpoint-Received: by B4 Relay for moonafterrain@outlook.com/default with auth_id=909 X-Original-From: Junrui Luo Reply-To: moonafterrain@outlook.com From: Junrui Luo nfs4_decode_mp_ds_addr() allocates the r_netid string and hands ownership to the nfs4_pnfs_ds_addr it returns. Both loops in nfs4_ff_alloc_deviceid_node() that drain the local dsaddrs list free only da_remotestr and the da itself, so the netid is leaked. The success-path loop runs when nfs4_pnfs_ds_add() finds an equivalent data server already cached and leaves the caller's list intact; the out_err_drain_dsaddrs loop runs on every late failure in the function. da_remotestr and da_netid are the only heap pointers in the structure, so free both, as nfs4_pnfs_ds_addr_free() does. Fixes: 4be78d26810b ("NFSv4/pNFS: Store the transport type in struct nfs4_p= nfs_ds_addr") Reported-by: Yuhao Jiang Assisted-by: Claude:claude-opus-5 Signed-off-by: Junrui Luo --- fs/nfs/flexfilelayout/flexfilelayoutdev.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/fs/nfs/flexfilelayout/flexfilelayoutdev.c b/fs/nfs/flexfilelay= out/flexfilelayoutdev.c index 659a2bf7b502..98d464f402d5 100644 --- a/fs/nfs/flexfilelayout/flexfilelayoutdev.c +++ b/fs/nfs/flexfilelayout/flexfilelayoutdev.c @@ -169,6 +169,7 @@ nfs4_ff_alloc_deviceid_node(struct nfs_server *server, = struct pnfs_device *pdev, da_node); list_del_init(&da->da_node); kfree(da->da_remotestr); + kfree(da->da_netid); kfree(da); } =20 @@ -181,6 +182,7 @@ nfs4_ff_alloc_deviceid_node(struct nfs_server *server, = struct pnfs_device *pdev, da_node); list_del_init(&da->da_node); kfree(da->da_remotestr); + kfree(da->da_netid); kfree(da); } =20 --=20 2.51.2 From nobody Fri Oct 2 06:58:48 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8639F456E0C; Tue, 4 Aug 2026 10:55:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785840927; cv=none; b=VdRCAR2YPxQ6QrgQ+pATvbAkEVf9slyRIP2tmg/PT4UFsyyusNCnSm+INfs+n+MEyebMJfjTF36+0hWNUVm7tyGT/+BYIAZHR+/5lJj+ansaASTqqZNs4YW9LzbyqLl1fXIcqx93jDPVaOOvdI/EhE9iq2FHPLwvHQXwMAvxX2Y= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785840927; c=relaxed/simple; bh=L4HfWEiYw6glmwU2i2GuDQ80x6FTEYKOYzeaisiQX2U=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=BxG8EhvSB57pkFDW49Bm1VPeHqkkpMIZ7lf2JVKAsWd2k1DIhVH3twWi47blyywJxHgRNGszFprXVmqP9WLKBS7h6xQGxFsD/tpY7YA3dm5491vWJX9NP6shnw3ylBHckm2YQaczFJM6+Jl2AN75YJ1AmQRZPTuEJM0Bfo+xjp0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=EyPAmK8e; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="EyPAmK8e" Received: by smtp.kernel.org (Postfix) with ESMTPS id C2F87C2BCFD; Tue, 4 Aug 2026 10:55:26 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1785840926; bh=L4HfWEiYw6glmwU2i2GuDQ80x6FTEYKOYzeaisiQX2U=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=EyPAmK8eXdtdHciBsJAQG9q5jSfFQ9doJ0O+LQG0lWiF7/VwOcEe35aY6psxvpFNS FTKSvlpyIjp3mvg4PuqQ9NoDuSNtXRlhZmuiNbuIvVT+oy4eAgYcd7fjjJuVZQmMMZ FPKz9u+oiie5aUyJKy4DOWQXCS1veMsAT/UstMejwU4euji0wEY3yjzK+9v6FV+3ho 7C+k+PVbsa3qFtuB+22e8P731IlaS6tefyztB3M6rybyXraZUmPtSu7+XEKLNmshXC lFWO/rzQPno82gU7HZGPz0Us9gqvbZq2V63yiQTuVQfbDSsv/0RVbx/kJhzlycZZWe 5HVvhr8qWx1sQ== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A7408C561E6; Tue, 4 Aug 2026 10:55:26 +0000 (UTC) From: Junrui Luo via B4 Relay Date: Tue, 04 Aug 2026 18:55:03 +0800 Subject: [PATCH 3/5] NFSv4/pNFS: check the sscanf return in nfs4_decode_mp_ds_addr Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260804-nfs-fixes-v1-3-1544df970e7c@outlook.com> References: <20260804-nfs-fixes-v1-0-1544df970e7c@outlook.com> In-Reply-To: <20260804-nfs-fixes-v1-0-1544df970e7c@outlook.com> To: Trond Myklebust , Anna Schumaker Cc: linux-nfs@vger.kernel.org, linux-kernel@vger.kernel.org, Jonathan Curley , Michael Bommarito , Junrui Luo , Yuhao Jiang , stable@vger.kernel.org X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=openpgp-sha256; l=1786; i=moonafterrain@outlook.com; h=from:subject:message-id; bh=NlRN6hKnIpiIx0oge92JnJ9wPbGlz66/OhgU3FbRdvI=; b=owJ4nJvAy8zAJVb4wiKgu++DA+NptSSGrMKjMt+v1r9OV1p6mvu5FF/T4rC/618WR2rcd1F2a Gjckr66VLmjlIVBjItBVkyR5XjBpW8Wvlt0t/hsSYaZw8oEMoSBi1MAJnJ6A8MfzskVJ5uLgl1y txy+vDVi0yrfuc8yjlREuG76+qGny6/LnOGvvLaV/rnNN3velCcuCf7Wtl32dHyWlMy77IT5x7c y+d7lAACChE6c X-Developer-Key: i=moonafterrain@outlook.com; a=openpgp; fpr=C770D2F6384DB42DB44CB46371E838508B8EF040 X-Endpoint-Received: by B4 Relay for moonafterrain@outlook.com/default with auth_id=909 X-Original-From: Junrui Luo Reply-To: moonafterrain@outlook.com From: Junrui Luo nfs4_decode_mp_ds_addr() splits the r_addr opaque of a netaddr4 into an address part and a trailing ".ABC.DEF" port pair using two strrchr() passes. The address part is validated by rpc_pton(), which is passed an explicit length of portstr - buf and never inspects the port octets. The port octets are converted with sscanf(portstr, "%d-%d", &tmp[0], &tmp[1]) and the return value is discarded. tmp[] is uninitialised and nothing constrains the characters after the last two dots, so an r_addr such as "192.168.1.1.x.y" leaves both elements unwritten. The stale stack contents then become the destination port of the data server connection and are rendered into da_remotestr, potentially leaking client stack memory to the metadata server. Fix by requiring both conversions to succeed and rejecting the address otherwise via the existing out_free_da path, matching the port octet validation in rpc_uaddr2sockaddr(). Fixes: 16b374ca439f ("NFSv4.1: pnfs: filelayout: add driver's LAYOUTGET and= GETDEVICEINFO infrastructure") Reported-by: Yuhao Jiang Assisted-by: Claude:claude-opus-5 Cc: stable@vger.kernel.org Signed-off-by: Junrui Luo --- fs/nfs/pnfs_nfs.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/fs/nfs/pnfs_nfs.c b/fs/nfs/pnfs_nfs.c index 648c95b78eea..63fb3695fdb9 100644 --- a/fs/nfs/pnfs_nfs.c +++ b/fs/nfs/pnfs_nfs.c @@ -1114,7 +1114,8 @@ nfs4_decode_mp_ds_addr(struct net *net, struct xdr_st= ream *xdr, gfp_t gfp_flags) } =20 portstr++; - sscanf(portstr, "%d-%d", &tmp[0], &tmp[1]); + if (sscanf(portstr, "%d-%d", &tmp[0], &tmp[1]) !=3D 2) + goto out_free_da; port =3D htons((tmp[0] << 8) | (tmp[1])); =20 switch (da->da_addr.ss_family) { --=20 2.51.2 From nobody Fri Oct 2 06:58:48 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F1BF7456DE4; Tue, 4 Aug 2026 10:55:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785840928; cv=none; b=HVoFiRV/PpIHQtvdtWoEVV8GZXsnfjJtElVU6P1LLKosMm+19tTDEhnfFe9Kk2FWj3xmdMXGQo5YA3funlVsSVcwUkPvSgNv0qtiEc9cZG6mbwjuI9/h8Sj+g6ts3jKWsegEPwAgCW+q2oEm7jNu2xHfeMvU0BdGzVBO8MqsHUI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785840928; c=relaxed/simple; bh=SHVtQ9W5JkS7JTpSO3lIycMZ8tLRLS4IEpYSXs1pusQ=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=q7hbCp+jO4RehdwiGM4DUCDi2Z2nFQi4J0aRriKZe/ph/06CwSVv8uMcl5RHJTzMVVulCMjJaq39iaE0fKtyuVwqfdQih4sW03zNasYYKP/cnf4RYsAv+bkeukpfXJJbjJEvkSnI9CfWXvHax/OpuOYAYD01zBofaq55dggDepk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=NKVAIFKk; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="NKVAIFKk" Received: by smtp.kernel.org (Postfix) with ESMTPS id C9AFBC2BD00; Tue, 4 Aug 2026 10:55:26 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1785840926; bh=SHVtQ9W5JkS7JTpSO3lIycMZ8tLRLS4IEpYSXs1pusQ=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=NKVAIFKkDilH64pGd2pG6ArMAAGjK9DXFNqKJrOqzps9zQ5CvCVIdBNh1UoTQJzgu ktm1MDDvlXU7qq3ciJbyCavacFm4UUnuVNN0TKKc1ccRfLOUGtRJuFC3iSWr5IJDWS brheYMDcENq1OpPB7s5fR29hfjUXT/4QoRqA4UG27uBtVFuN6De0tfgdhTwrqkmhI5 I/ntLBIm4wxSjP8+98mO7sgtJHyI6LfiVpaCn2juOYAbMmEmGcmxp5kCV7Zrb+IHk3 1w3hRDMzW9GSAOp/OWfkA+WITzWQNhRBlLWw6J/mempKN1++574YLiEgmaYnGGVRgs ZkYzEziNpIYqA== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B8B36C55ABF; Tue, 4 Aug 2026 10:55:26 +0000 (UTC) From: Junrui Luo via B4 Relay Date: Tue, 04 Aug 2026 18:55:04 +0800 Subject: [PATCH 4/5] NFSv4/flexfiles: bound the filehandle version count Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260804-nfs-fixes-v1-4-1544df970e7c@outlook.com> References: <20260804-nfs-fixes-v1-0-1544df970e7c@outlook.com> In-Reply-To: <20260804-nfs-fixes-v1-0-1544df970e7c@outlook.com> To: Trond Myklebust , Anna Schumaker Cc: linux-nfs@vger.kernel.org, linux-kernel@vger.kernel.org, Jonathan Curley , Michael Bommarito , Junrui Luo , Yuhao Jiang , stable@vger.kernel.org X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=openpgp-sha256; l=2341; i=moonafterrain@outlook.com; h=from:subject:message-id; bh=HE7wEMko3m9Jwve0mVBI8y2cKV7TCTLF5kvH7eM8vzw=; b=owJ4nJvAy8zAJVb4wiKgu++DA+NptSSGrMKjMvsSGH+qKbNxX43ZtLXX5UhjmVqNyvttU35Fa B39u/rkmeiOUhYGMS4GWTFFluMFl75Z+G7R3eKzJRlmDisTyBAGLk4BmMi6Lwz/qzh4D77LeWte 4Pj6daWfS19iZs7s3sklr4WLumyO8TIoMPxPeeF5w+afVU9VnuP9TpEe7pevLl5mzj7VuM5i07q zGuGcABtXTSg= X-Developer-Key: i=moonafterrain@outlook.com; a=openpgp; fpr=C770D2F6384DB42DB44CB46371E838508B8EF040 X-Endpoint-Received: by B4 Relay for moonafterrain@outlook.com/default with auth_id=909 X-Original-From: Junrui Luo Reply-To: moonafterrain@outlook.com From: Junrui Luo ff_layout_alloc_lseg() decodes fh_count from the flexfiles LAYOUTGET body and passes it directly to kzalloc_objs() to size the dss_info->fh_versions array. Commit 2c6bb3c40bc2 ("NFSv4/flexfiles: reject zero filehandle version count") rejected a zero count, but unlike the neighbouring mirror_array_cnt and dss_count the value remains unbounded from above. sizeof(struct nfs_fh) is 130, so an fh_count of 32264 or more pushes get_order() past MAX_PAGE_ORDER and trips the page allocator's WARN_ON_ONCE_GFP(). Reject implausible counts up front, as this function already does for mirror_array_cnt and dss_count, and as filelayout_decode_layout() does for the equivalent num_fh field. Fixes: d67ae825a59d ("pnfs/flexfiles: Add the FlexFile Layout Driver") Reported-by: Yuhao Jiang Assisted-by: Claude:claude-opus-5 Cc: stable@vger.kernel.org Signed-off-by: Junrui Luo --- fs/nfs/flexfilelayout/flexfilelayout.c | 3 ++- fs/nfs/flexfilelayout/flexfilelayout.h | 5 +++++ 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/fs/nfs/flexfilelayout/flexfilelayout.c b/fs/nfs/flexfilelayout= /flexfilelayout.c index c4aa995026f6..bdc4b960eeb7 100644 --- a/fs/nfs/flexfilelayout/flexfilelayout.c +++ b/fs/nfs/flexfilelayout/flexfilelayout.c @@ -551,7 +551,8 @@ ff_layout_alloc_lseg(struct pnfs_layout_hdr *lh, if (!p) goto out_err_free; fh_count =3D be32_to_cpup(p); - if (fh_count =3D=3D 0) { + if (fh_count =3D=3D 0 || + fh_count > NFS4_FLEXFILE_LAYOUT_MAX_FH_CNT) { rc =3D -EINVAL; goto out_err_free; } diff --git a/fs/nfs/flexfilelayout/flexfilelayout.h b/fs/nfs/flexfilelayout= /flexfilelayout.h index d024b8db4ce0..a4c7f9040084 100644 --- a/fs/nfs/flexfilelayout/flexfilelayout.h +++ b/fs/nfs/flexfilelayout/flexfilelayout.h @@ -27,6 +27,11 @@ * otherwise let a server spin the GETDEVICEINFO decode loop. */ #define NFS4_FLEXFILE_LAYOUT_MAX_MULTIPATH_CNT 4096 =20 +/* Filter out insanely large filehandle version counts, which would + * otherwise let a server size a kernel allocation from the LAYOUTGET + * body. */ +#define NFS4_FLEXFILE_LAYOUT_MAX_FH_CNT 4096 + /* LAYOUTSTATS report interval in ms */ #define FF_LAYOUTSTATS_REPORT_INTERVAL (60000L) #define FF_LAYOUTSTATS_MAXDEV 4 --=20 2.51.2 From nobody Fri Oct 2 06:58:48 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3A0204570DF; Tue, 4 Aug 2026 10:55:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785840928; cv=none; b=aG92TpeTXdo1+rirWqT7WM0c+KqhMGxolF84N2ejgvQgxIXvOXu9czIxzMNT0JGgmuR12l8xsKHth48brdcBzngiW64NqCipTz1BORPYSG6Y4QDjjYQrad4BkaWxQAQHlI5wplLAPFFterU2uuzbNnCr7mwqZNk8VG1L/bOlRpM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785840928; c=relaxed/simple; bh=jW0DiRUPYl5iBDHQr7MOt5leAF4efNYBlOuPNdThPQI=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=e/WtNOtR7e+WqU4GnXFNqhYq2o4Ty9AYZ+f/bZyZ4J1X5lUx5rded48TI68I8hQRUYg4DD1CdQZ3kvvj+YGfFJmV2GZa6r3KSFmsUWWB7xdsbbCIdNX114DzVY1CQlik2Ne+4arSqLWP4Sx2etAsQlxy6yi1m32oh/8wVMZNhPE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=es1n8Ger; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="es1n8Ger" Received: by smtp.kernel.org (Postfix) with ESMTPS id DA50AC2BCFC; Tue, 4 Aug 2026 10:55:26 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1785840926; bh=jW0DiRUPYl5iBDHQr7MOt5leAF4efNYBlOuPNdThPQI=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=es1n8Gerjiqr6e/UTc0DFiI+q7907uXlGjg8S5A/4Z3QLGu7qcXVp83oKlLP/mHYR TfyDUhNaC0XRGmdTY0LRKv0oOofoMLO/uIpGiclXRD6vv5etP/E8oFZ7Dd0/4/SwRq +/NcI3m0P5Jx94vobIpKQ3et5g1md48+dN86qfAxpxm1y1BK6uW3TexyC8srOGFsXY lEQb7yvfKt7/L+C/Wlb/K8lfh8tJ1OlDMiZeF4r7B4BwXIRF77GDfhVdHBjpmsZA9r un4M3wd5L9xAxrEzm3jgWoG2c0ZOkDwhVnSBxRWQTbrAlY1/ILZb8MhIXqvWJbNCpR j7mXP5+S1MrRw== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C97FDC561F8; Tue, 4 Aug 2026 10:55:26 +0000 (UTC) From: Junrui Luo via B4 Relay Date: Tue, 04 Aug 2026 18:55:05 +0800 Subject: [PATCH 5/5] NFSv4/flexfiles: bound stripe_unit to 32 bits Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260804-nfs-fixes-v1-5-1544df970e7c@outlook.com> References: <20260804-nfs-fixes-v1-0-1544df970e7c@outlook.com> In-Reply-To: <20260804-nfs-fixes-v1-0-1544df970e7c@outlook.com> To: Trond Myklebust , Anna Schumaker Cc: linux-nfs@vger.kernel.org, linux-kernel@vger.kernel.org, Jonathan Curley , Michael Bommarito , Junrui Luo , Yuhao Jiang , stable@vger.kernel.org X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=openpgp-sha256; l=1936; i=moonafterrain@outlook.com; h=from:subject:message-id; bh=gwCePfOLU7Ur1xZ+XPeOVksWgOrn9f4Gb+eoyLnBV3c=; b=kA0DAAoWceg4UIuO8EAByyZiAGpxxRzIk0abGAjx0LSUqTnsDzjv8iOA4XR6S1QCHe7MarJf2 Ih1BAAWCgAdFiEEx3DS9jhNtC20TLRjceg4UIuO8EAFAmpxxRwACgkQceg4UIuO8EDN2AD9ES3i sjhlNcAyA9pPJbc6SPzfh5lFny7McKbAjBbP3S4A/3o7xhRHRHkUIcXalxGoviYkPXHHom/utYl 13jQ1NbgI X-Developer-Key: i=moonafterrain@outlook.com; a=openpgp; fpr=C770D2F6384DB42DB44CB46371E838508B8EF040 X-Endpoint-Received: by B4 Relay for moonafterrain@outlook.com/default with auth_id=909 X-Original-From: Junrui Luo Reply-To: moonafterrain@outlook.com From: Junrui Luo ff_layout_alloc_lseg() decodes stripe_unit from the flexfiles LAYOUTGET body as a 64-bit value and validates it as one: if (dss_count > 1 && stripe_unit =3D=3D 0) goto out_err_free; but every consumer divides by only its low 32 bits. ff_layout_pg_test() narrows it explicitly: u32 stripe_unit =3D FF_LAYOUT_LSEG(pgio->pg_lseg)->stripe_unit; ... do_div(p_stripe, stripe_unit); and nfs4_ff_layout_calc_dss_id() passes the u64 straight to do_div(), which narrows the divisor itself. A server-supplied non-zero multiple of 2^32 such as 0x100000000 therefore passes the check and reaches both dividers as a zero divisor, so the first read or write through the layout takes a divide error and panics the client. The same narrowing silently turns any other value above U32_MAX into an unrelated stripe size. Values that do not fit in 32 bits are not representable by the arithmetic this driver performs on stripe_unit, so reject them at decode time rather than truncating them. Fixes: 20b1d75fb840 ("NFSv4/flexfiles: Add support for striped layouts") Reported-by: Yuhao Jiang Assisted-by: Claude:claude-opus-5 Cc: stable@vger.kernel.org Signed-off-by: Junrui Luo --- fs/nfs/flexfilelayout/flexfilelayout.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/fs/nfs/flexfilelayout/flexfilelayout.c b/fs/nfs/flexfilelayout= /flexfilelayout.c index bdc4b960eeb7..63391f48c5d9 100644 --- a/fs/nfs/flexfilelayout/flexfilelayout.c +++ b/fs/nfs/flexfilelayout/flexfilelayout.c @@ -515,7 +515,8 @@ ff_layout_alloc_lseg(struct pnfs_layout_hdr *lh, dss_count =3D=3D 0) goto out_err_free; =20 - if (dss_count > 1 && stripe_unit =3D=3D 0) + if (dss_count > 1 && + (stripe_unit =3D=3D 0 || stripe_unit > U32_MAX)) goto out_err_free; =20 fls->mirror_array[i] =3D ff_layout_alloc_mirror(dss_count, gfp_flags); --=20 2.51.2