From nobody Mon Sep 28 22:31:46 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B433038C42F; Sun, 16 Aug 2026 08:01:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786867293; cv=none; b=jqYM/kN2fdQ+j4jvQfJfNy2TQYrt1hK5ew8vbRdLkDGeIPZ8LDi6kCT1ScOVq3O0VwiafWoXjC+Sulu21ZBv1EsMCd2G4xfeDIUVq520LPtAGXZviQmPNt2BZX72FGEoilexSqOwpScUn83p0SdZo6XmM+6oaG/CbKCcbohzbTg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786867293; c=relaxed/simple; bh=lpo4I0txAlV3EWqxLW3j0hiSsXefJAiYqgAbCg2N2gQ=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=IamlE7qzaewC8ONoyuwGA68ZFouB4SFv54KyVUgGTVzTxERzTus9gy4wWRPmvH7cfZvA8kgdmRW/1kkTmWdaaE5t5fDz6jzmeF1uX0IaGYNsP8ytVMjqHCHOfwfhZy2NY5nIH6PFoJAD10rcLKoUclNxd0TW+H9ZekYoKHBHv0g= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=NYuZJj5w; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="NYuZJj5w" Received: by smtp.kernel.org (Postfix) with ESMTPS id 7136BC2BCC7; Sun, 16 Aug 2026 08:01:33 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1786867293; bh=lpo4I0txAlV3EWqxLW3j0hiSsXefJAiYqgAbCg2N2gQ=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=NYuZJj5wwzhJGg+wTgACotem3IGWCrb11xVyZvmRFo/ndyj4zAu0yceO2xpTy/asm 2f/ePcOktySEkLNRfXn9NsNgF9R1UV5r24WqePEeWIIwaoKEautv1u396uhwuaz/Cy DzjgoLHERtBrqARBkGq21/ZFtT3JF3bi1roMyRyod5oPmyW4vVqSlBzctht04zHDmn n4rrq/jDWlQ8LvgP7AWhelzdcEJNhwFJqwNUaTXWDexiXwrvaogFf+/0+zxlz0mtXO pn+2jkm3gO9Eb7Z5bYbAo0cGojCFNXFp+709CARs9p4e3rHcxWS4eNJ6J9sJ9Ux6Ef R+y/caO/0nTvw== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 52642C5DF6D; Sun, 16 Aug 2026 08:01:33 +0000 (UTC) From: Junrui Luo via B4 Relay Date: Sun, 16 Aug 2026 16:01:27 +0800 Subject: [PATCH 1/3] NFSv4.2: fix LAYOUTSTATS send buffer exhaustion Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260816-nfs4-fixes-v1-1-a810f21729ab@outlook.com> References: <20260816-nfs4-fixes-v1-0-a810f21729ab@outlook.com> In-Reply-To: <20260816-nfs4-fixes-v1-0-a810f21729ab@outlook.com> To: Trond Myklebust , Anna Schumaker , Peng Tao , Jeff Layton , Tao Peng , Weston Andros Adamson , Tom Haynes Cc: Trond Myklebust , linux-nfs@vger.kernel.org, linux-kernel@vger.kernel.org, Trond Myklebust , Junrui Luo , Yuhao Jiang , stable@vger.kernel.org X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=openpgp-sha256; l=1940; i=moonafterrain@outlook.com; h=from:subject:message-id; bh=4WLBba8p7bwGAneqhTqmcyaXp3xOnrgg5APLE5Akwfw=; b=owJ4nJvAy8zAJVb4wiKgu++DA+NptSSGrMa8aObCHElOMalOsUVr5u+QsLd4nMyhIbP2U+Py5 HpGx23vvnWUsjCIcTHIiimyHC+49M3Cd4vuFp8tyTBzWJlAhjBwcQrAROrOMDI8jQl5MC0yeea8 nCvKP36oM3qn7Z0fX7guZU/wJdFC63nmjAx/mjvautqNKhb8WXr/t8L+1y0TlslUcy6aYTlVuGF +qSofACusSMo= X-Developer-Key: i=moonafterrain@outlook.com; a=openpgp; fpr=C770D2F6384DB42DB44CB46371E838508B8EF040 X-Endpoint-Received: by B4 Relay for moonafterrain@outlook.com/default with auth_id=909 X-Original-From: Junrui Luo Reply-To: moonafterrain@outlook.com From: Junrui Luo encode_layoutstats_maxsz budgets XDR_QUADLEN(PNFS_LAYOUTSTATS_MAXSIZE), i.e. 256 bytes, for the layoutupdate4 body written by the layout driver. The flexfiles record can exceed that. ff_layout_encode_ff_layoutupdate() emits, per data server, a netaddr4, an nfs_fh4, two ff_io_latency4, an nfstime4 and a bool. A data server whose filehandle is NFS_MAXFHSIZE bytes long already accounts for 132 of those bytes, and the two ff_io_latency4 at 64 bytes each, the nfstime4 and the bool add a further 144, so the body passes 256 bytes before the netaddr4 is encoded at all. encode_layoutstats() additionally writes the deviceid4 and the layoutupdate4 lou_type word, neither of which the macro accounts for. The filehandle and the address are both chosen by the server, through LAYOUTGET and GETDEVICEINFO, so it can drive the encoder past the end of the send buffer. xdr_reserve_space() returns NULL once that happens, and the two ff_layout_encode_io_latency() calls run with dss_info->mirror->lock held, so a NULL return there leaves the lock permanently held. Raise PNFS_LAYOUTSTATS_MAXSIZE to 384 so that the record fits inside the reservation. Fixes: 27c430644369 ("pnfs/flexfiles: encode LAYOUTSTATS flexfiles specific= data") Reported-by: Yuhao Jiang Assisted-by: Claude:claude-opus-5 Cc: stable@vger.kernel.org Signed-off-by: Junrui Luo --- include/linux/nfs_xdr.h | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/include/linux/nfs_xdr.h b/include/linux/nfs_xdr.h index 11c5b31cfc7d..e8144048cd0e 100644 --- a/include/linux/nfs_xdr.h +++ b/include/linux/nfs_xdr.h @@ -354,7 +354,7 @@ struct nfs4_layoutreturn { struct nfs4_xdr_opaque_data ld_private; }; =20 -#define PNFS_LAYOUTSTATS_MAXSIZE 256 +#define PNFS_LAYOUTSTATS_MAXSIZE 384 =20 struct nfs42_layoutstat_args; struct nfs42_layoutstat_devinfo; --=20 2.51.2 From nobody Mon Sep 28 22:31:46 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C053538E100; Sun, 16 Aug 2026 08:01:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786867293; cv=none; b=SQFUR2Wp0CXcSGl55PG4KXnnIgzbi6A4U0F2mwqQS1gaFmugr4Dh2PIpD97Tys+FkYcWjVXmc70iRzYlw+IzBL2BNNgWpfBH10iGEcl/RQRqD8MIBy7zyfl7fROeg13uk4Eh9VwndGUerXAdS+QL6ykgn68BWkjxsKmPyfyYouk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786867293; c=relaxed/simple; bh=LA6r3YMDN8e3rQCpTzUWwK2+WYrCHzvRORnV5+xfikQ=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=KSekJoRm+9dkemxWrIbdRAjYX9yTbnwqgTwUKERz42eHrnNBtV833CdzHk53rJoCYY30us+1gMmzAOlHHeMe6Q19faFH7LfVaM3MVUF5dibbiNDdLaJ2H2wWMAiJzRd4uZRFBjlIMiOsnoZ0w3StLQ2kNxn6OmNKpbORhUQilqY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=L6b2CAzs; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="L6b2CAzs" Received: by smtp.kernel.org (Postfix) with ESMTPS id 802F3C2BCFB; Sun, 16 Aug 2026 08:01:33 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1786867293; bh=LA6r3YMDN8e3rQCpTzUWwK2+WYrCHzvRORnV5+xfikQ=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=L6b2CAzsIdzd/cy29MjnTu58OcOSO3l1qcltFa9N7xX6DZzvc6LB8pXJuEPvKFB/f G1vUAOQhEXh/omIYYNGHhrjXyY9nw99D0KvERC29mYjsdfr7H+H/b7bq6dvXJ7cK2R 2LneRCz4H1V+OIf7CBrJG3hVUqkvhApV2R/KmVNHlrjJES2wIXEJ8XvvlDA6PNCQyG xcPl0sHBJNnbP09ohqd/Q3KeeZ+iM6ds4HyWsmtZinoNSiCOvH3J9FjN5n3TDRj4UV AepEM6rJkn8Jh15tSS+czk2n0H2UOkdV3Z1TamFZgQ8zwsjMm2ThQbX4LjgbCy6EdO GeSgCQ9w2cEeA== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 620B8C5DF66; Sun, 16 Aug 2026 08:01:33 +0000 (UTC) From: Junrui Luo via B4 Relay Date: Sun, 16 Aug 2026 16:01:28 +0800 Subject: [PATCH 2/3] NFSv4/pnfs: key the data server cache on the NFS version Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260816-nfs4-fixes-v1-2-a810f21729ab@outlook.com> References: <20260816-nfs4-fixes-v1-0-a810f21729ab@outlook.com> In-Reply-To: <20260816-nfs4-fixes-v1-0-a810f21729ab@outlook.com> To: Trond Myklebust , Anna Schumaker , Peng Tao , Jeff Layton , Tao Peng , Weston Andros Adamson , Tom Haynes Cc: Trond Myklebust , linux-nfs@vger.kernel.org, linux-kernel@vger.kernel.org, Trond Myklebust , Junrui Luo , Yuhao Jiang , stable@vger.kernel.org X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=openpgp-sha256; l=5932; i=moonafterrain@outlook.com; h=from:subject:message-id; bh=VFSoisGY6SsoJBTL8kcnEnZhI63PwDw+LG5KbdMIJjA=; b=owJ4nJvAy8zAJVb4wiKgu++DA+NptSSGrMa86GdGT5eu/zL1/YVPUU8yRb9Om+DE12D/sv0oS 09668WFNZM6SlkYxLgYZMUUWY4XXPpm4btFd4vPlmSYOaxMIEMYuDgFYCLVbIwMNxWvll14mthd mbhTm1dk08uTun9ebWdn+XXkz4tlwdO272b4xby/d+N2s+DF7ySd+mYGVRnMflTp9HO/2AqXut9 c0qJbOAF7Ck+K X-Developer-Key: i=moonafterrain@outlook.com; a=openpgp; fpr=C770D2F6384DB42DB44CB46371E838508B8EF040 X-Endpoint-Received: by B4 Relay for moonafterrain@outlook.com/default with auth_id=909 X-Original-From: Junrui Luo Reply-To: moonafterrain@outlook.com From: Junrui Luo nfs4_pnfs_ds_add() keys the per-net data server cache on the multipath address set alone, and struct nfs4_pnfs_ds records no version. That suffices for the files layout driver, which always connects with version 4, but flexfiles takes its version tuple from GETDEVICEINFO per device, and one address can legitimately serve both NFSv3 and NFSv4. Two deviceids on one address with different ds_versions[0].version therefore share a single nfs4_pnfs_ds, and whichever mirror connects first pins ds_clp to its own version. The other one is handed that client anyway, so it selects rpc_call_ops for a version the connection does not speak, and the mismatched sequence-slot handling dereferences NULL. Add the version to the cache key so the two cannot alias, giving each version its own nfs4_pnfs_ds and connection while both mirrors stay usable. Only the major version is compared, since that is what selects rpc_call_ops and rpc_ops; v4.0 and v4.1 keep sharing a client. The files layout driver passes the 4 it already hardcodes at connect time. Fixes: d67ae825a59d ("pnfs/flexfiles: Add the FlexFile Layout Driver") Reported-by: Yuhao Jiang Assisted-by: Claude:claude-opus-5 Cc: stable@vger.kernel.org Signed-off-by: Junrui Luo --- fs/nfs/filelayout/filelayoutdev.c | 3 ++- fs/nfs/flexfilelayout/flexfilelayoutdev.c | 3 ++- fs/nfs/pnfs.h | 3 ++- fs/nfs/pnfs_nfs.c | 14 +++++++++----- 4 files changed, 15 insertions(+), 8 deletions(-) diff --git a/fs/nfs/filelayout/filelayoutdev.c b/fs/nfs/filelayout/filelayo= utdev.c index 7226989ee4d5..9ddcaf86fcef 100644 --- a/fs/nfs/filelayout/filelayoutdev.c +++ b/fs/nfs/filelayout/filelayoutdev.c @@ -170,7 +170,8 @@ nfs4_fl_alloc_deviceid_node(struct nfs_server *server, = struct pnfs_device *pdev, goto out_err_free_deviceid; } =20 - dsaddr->ds_list[i] =3D nfs4_pnfs_ds_add(net, &dsaddrs, gfp_flags); + dsaddr->ds_list[i] =3D nfs4_pnfs_ds_add(net, &dsaddrs, 4, + gfp_flags); if (!dsaddr->ds_list[i]) goto out_err_drain_dsaddrs; trace_fl_getdevinfo(server, &pdev->dev_id, dsaddr->ds_list[i]->ds_remote= str); diff --git a/fs/nfs/flexfilelayout/flexfilelayoutdev.c b/fs/nfs/flexfilelay= out/flexfilelayoutdev.c index 1109462a9699..c716fd99e8ef 100644 --- a/fs/nfs/flexfilelayout/flexfilelayoutdev.c +++ b/fs/nfs/flexfilelayout/flexfilelayoutdev.c @@ -153,7 +153,8 @@ nfs4_ff_alloc_deviceid_node(struct nfs_server *server, = struct pnfs_device *pdev, new_ds->ds_versions =3D ds_versions; new_ds->ds_versions_cnt =3D version_count; =20 - new_ds->ds =3D nfs4_pnfs_ds_add(net, &dsaddrs, gfp_flags); + new_ds->ds =3D nfs4_pnfs_ds_add(net, &dsaddrs, ds_versions[0].version, + gfp_flags); if (!new_ds->ds) goto out_err_drain_dsaddrs; =20 diff --git a/fs/nfs/pnfs.h b/fs/nfs/pnfs.h index eb39859c216c..f06a03ac4fa3 100644 --- a/fs/nfs/pnfs.h +++ b/fs/nfs/pnfs.h @@ -63,6 +63,7 @@ struct nfs4_pnfs_ds { const struct net *ds_net; struct nfs_client *ds_clp; refcount_t ds_count; + u32 ds_version; /* cache key, with ds_addrs */ unsigned long ds_state; #define NFS4DS_CONNECTING 0 /* ds is establishing connection */ }; @@ -417,7 +418,7 @@ void pnfs_generic_write_commit_done(struct rpc_task *ta= sk, void *data); void nfs4_pnfs_ds_put(struct nfs4_pnfs_ds *ds); struct nfs4_pnfs_ds *nfs4_pnfs_ds_add(const struct net *net, struct list_head *dsaddrs, - gfp_t gfp_flags); + u32 version, gfp_t gfp_flags); void nfs4_pnfs_v3_ds_connect_unload(void); int nfs4_pnfs_ds_connect(struct nfs_server *mds_srv, struct nfs4_pnfs_ds *= ds, struct nfs4_deviceid_node *devid, unsigned int timeo, diff --git a/fs/nfs/pnfs_nfs.c b/fs/nfs/pnfs_nfs.c index 648c95b78eea..49c621cde43a 100644 --- a/fs/nfs/pnfs_nfs.c +++ b/fs/nfs/pnfs_nfs.c @@ -603,15 +603,17 @@ _same_data_server_addrs_locked(const struct list_head= *dsaddrs1, } =20 /* - * Lookup DS by addresses. nfs4_ds_cache_lock is held + * Lookup DS by addresses and NFS version. nfs4_ds_cache_lock is held */ static struct nfs4_pnfs_ds * -_data_server_lookup_locked(const struct nfs_net *nn, const struct list_hea= d *dsaddrs) +_data_server_lookup_locked(const struct nfs_net *nn, + const struct list_head *dsaddrs, u32 version) { struct nfs4_pnfs_ds *ds; =20 list_for_each_entry(ds, &nn->nfs4_data_server_cache, ds_node) - if (_same_data_server_addrs_locked(&ds->ds_addrs, dsaddrs)) + if (ds->ds_version =3D=3D version && + _same_data_server_addrs_locked(&ds->ds_addrs, dsaddrs)) return ds; return NULL; } @@ -719,7 +721,8 @@ nfs4_pnfs_remotestr(struct list_head *dsaddrs, gfp_t gf= p_flags) * uncached and return cached struct nfs4_pnfs_ds. */ struct nfs4_pnfs_ds * -nfs4_pnfs_ds_add(const struct net *net, struct list_head *dsaddrs, gfp_t g= fp_flags) +nfs4_pnfs_ds_add(const struct net *net, struct list_head *dsaddrs, u32 ver= sion, + gfp_t gfp_flags) { struct nfs_net *nn =3D net_generic(net, nfs_net_id); struct nfs4_pnfs_ds *tmp_ds, *ds =3D NULL; @@ -738,7 +741,7 @@ nfs4_pnfs_ds_add(const struct net *net, struct list_hea= d *dsaddrs, gfp_t gfp_fla remotestr =3D nfs4_pnfs_remotestr(dsaddrs, gfp_flags); =20 spin_lock(&nn->nfs4_data_server_lock); - tmp_ds =3D _data_server_lookup_locked(nn, dsaddrs); + tmp_ds =3D _data_server_lookup_locked(nn, dsaddrs, version); if (tmp_ds =3D=3D NULL) { INIT_LIST_HEAD(&ds->ds_addrs); list_splice_init(dsaddrs, &ds->ds_addrs); @@ -747,6 +750,7 @@ nfs4_pnfs_ds_add(const struct net *net, struct list_hea= d *dsaddrs, gfp_t gfp_fla INIT_LIST_HEAD(&ds->ds_node); ds->ds_net =3D net; ds->ds_clp =3D NULL; + ds->ds_version =3D version; list_add(&ds->ds_node, &nn->nfs4_data_server_cache); dprintk("%s add new data server %s\n", __func__, ds->ds_remotestr); --=20 2.51.2 From nobody Mon Sep 28 22:31:46 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BB7E238DC65; Sun, 16 Aug 2026 08:01:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786867293; cv=none; b=YCNgJrQsW3x+HiNfD/3Au92zYvakr8BLIXHT9fnZK63DocdbT8OMAr2qciBR8jlaw7Q4TGu5xzo94ygtBS8gs/gUcbWbbGs/kScKqHCX9UE+2/G/kWBRyg883wWT1Fhr6wnKeLIV/9gLx9VSLG/w+Ahh5OZMdsSjX1s/ISDVXW0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786867293; c=relaxed/simple; bh=V08XHTzDmd0zndE2k1uFguiKVcMiev5gvp2O0PzV+2k=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=n7kHaOoHaXHJyM7+AYAdykn6y4ma76xBhrE9KVL+QwXmvDLBf667g26+Xr92dfuywWGNGl6BAlwg2//k8G0HazHVTbrAPEEsgkaytwCPTof1sbDhmCZmX7cjrJ7Sp8en04N1i0Cs80SPyF1jitshcVaQr/rOdQlMS2SiJgMgJwc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Fd0J6vm+; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Fd0J6vm+" Received: by smtp.kernel.org (Postfix) with ESMTPS id 86C03C2BCFD; Sun, 16 Aug 2026 08:01:33 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1786867293; bh=V08XHTzDmd0zndE2k1uFguiKVcMiev5gvp2O0PzV+2k=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=Fd0J6vm+ujC8N5O5tZcPkJgrYq7jPAG6+tFOPw2R0JkZzBAxhIsNkK+kzEDIjh1o0 zgDoKtwjJirab5p9f3yQwdXKcDFH/J/ND+JaRy/e39aAOh+9e0+lQwSSCYAR0du559 B1RFO/K0Zl6AooU2ilxIiwZt7Gzs+HwkeAx3RJTZvh68nj/4HdWxX51G56yiURcM/v 9qXXV9f1jc+X+rZDgMPYOz2mfMgt/aPqhWNRLIF/Kio5zmDDxux7cufcZWDx1xaN/F xOKE7CZFnAfO4NOYw8TKqTOgaq7FKgB/pWYhbdgnQqEO2LsJq5kvJwUJrqFi7yeJ3/ FEjrpATPhjLkw== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 739ABC5DF76; Sun, 16 Aug 2026 08:01:33 +0000 (UTC) From: Junrui Luo via B4 Relay Date: Sun, 16 Aug 2026 16:01:29 +0800 Subject: [PATCH 3/3] NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260816-nfs4-fixes-v1-3-a810f21729ab@outlook.com> References: <20260816-nfs4-fixes-v1-0-a810f21729ab@outlook.com> In-Reply-To: <20260816-nfs4-fixes-v1-0-a810f21729ab@outlook.com> To: Trond Myklebust , Anna Schumaker , Peng Tao , Jeff Layton , Tao Peng , Weston Andros Adamson , Tom Haynes Cc: Trond Myklebust , linux-nfs@vger.kernel.org, linux-kernel@vger.kernel.org, Trond Myklebust , Junrui Luo , Yuhao Jiang , stable@vger.kernel.org X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=openpgp-sha256; l=1716; i=moonafterrain@outlook.com; h=from:subject:message-id; bh=D7n3g4lGtcu9wd31yKYC70rrbF3Z2OQe2hWQ9E6cyoE=; b=owJ4nJvAy8zAJVb4wiKgu++DA+NptSSGrMa8aCsPPc09OY/XHnCMW8+2K/SJ5kWFCefeN3Dfe GT7r/uC2NSOUhYGMS4GWTFFluMFl75Z+G7R3eKzJRlmDisTyBAGLk4BmMidbIb/CQrbXQ4lT5Jm 3/R91rknK8vSd72ZvWHFlX0zPC9v2SF0fjcjw6Wt1x9c9agWLMj8Vbr8AM+kaWn5LOwFl+TdNq/ suLCPgxEApqFPaA== X-Developer-Key: i=moonafterrain@outlook.com; a=openpgp; fpr=C770D2F6384DB42DB44CB46371E838508B8EF040 X-Endpoint-Received: by B4 Relay for moonafterrain@outlook.com/default with auth_id=909 X-Original-From: Junrui Luo Reply-To: moonafterrain@outlook.com From: Junrui Luo When the server returns a new layout stateid while a valid one is still held, pnfs_layout_process() calls pnfs_mark_matching_lsegs_return() on the on-stack free_me list and jumps to out_forget. Segments whose reference count drops to zero are unlinked from lo->plh_segs and moved to free_me by mark_lseg_invalid(); for an idle cached segment the layout header holds the only reference, so this happens on the first decrement. out_forget never drains free_me -- only the success path calls pnfs_free_lseg_list(). Commit 814b84971388 ("pNFS/NFSv4: Fix a layout segment leak in pnfs_layout_process()") added the drain; commit 08bd8dbe8882 ("pNFS/NFSv4: Try to return invalid layout in pnfs_layout_process()") removed it while switching the destination to lo->plh_return_segs, which is drained elsewhere. Commit fb700ef02676 ("NFSv4.1: Simplify layout return in pnfs_layout_process()") switched the destination back to free_me without restoring the drain. Restore the pnfs_free_lseg_list() call. Fixes: fb700ef02676 ("NFSv4.1: Simplify layout return in pnfs_layout_proces= s()") Reported-by: Yuhao Jiang Assisted-by: Claude:claude-opus-5 Cc: stable@vger.kernel.org Signed-off-by: Junrui Luo --- fs/nfs/pnfs.c | 1 + 1 file changed, 1 insertion(+) diff --git a/fs/nfs/pnfs.c b/fs/nfs/pnfs.c index 7715e2bd5871..a3d2ffc9daa5 100644 --- a/fs/nfs/pnfs.c +++ b/fs/nfs/pnfs.c @@ -2643,6 +2643,7 @@ pnfs_layout_process(struct nfs4_layoutget *lgp) spin_unlock(&ino->i_lock); lseg->pls_layout =3D lo; NFS_SERVER(ino)->pnfs_curr_ld->free_lseg(lseg); + pnfs_free_lseg_list(&free_me); return ERR_PTR(-EAGAIN); } =20 --=20 2.51.2