Skip to content

Commit 4584229

Browse files
daimngogregkh
authored andcommitted
NFSD: fix nfs4_file access extra count in nfsd4_add_rdaccess_to_wrdeleg
[ Upstream commit b48f44f ] In nfsd4_add_rdaccess_to_wrdeleg, if fp->fi_fds[O_RDONLY] is already set by another thread, __nfs4_file_get_access should not be called to increment the nfs4_file access count since that was already done by the thread that added READ access to the file. The extra fi_access count in nfs4_file can prevent the corresponding nfsd_file from being freed. When stopping nfs-server service, these extra access counts trigger a BUG in kmem_cache_destroy() that shows nfsd_file object remaining on __kmem_cache_shutdown. This problem can be reproduced by running the Git project's test suite over NFS. Fixes: 8072e34 ("nfsd: fix nfsd_file reference leak in nfsd4_add_rdaccess_to_wrdeleg()") Signed-off-by: Dai Ngo <dai.ngo@oracle.com> Reviewed-by: Jeff Layton <jlayton@kernel.org> Signed-off-by: Chuck Lever <chuck.lever@oracle.com> Signed-off-by: Sasha Levin <sashal@kernel.org>
1 parent 248e4b9 commit 4584229

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

fs/nfsd/nfs4state.c

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6255,12 +6255,12 @@ nfsd4_add_rdaccess_to_wrdeleg(struct svc_rqst *rqstp, struct nfsd4_open *open,
62556255
return (false);
62566256
fp = stp->st_stid.sc_file;
62576257
spin_lock(&fp->fi_lock);
6258-
__nfs4_file_get_access(fp, NFS4_SHARE_ACCESS_READ);
62596258
if (!fp->fi_fds[O_RDONLY]) {
6259+
__nfs4_file_get_access(fp, NFS4_SHARE_ACCESS_READ);
62606260
fp->fi_fds[O_RDONLY] = nf;
6261+
fp->fi_rdeleg_file = nfsd_file_get(fp->fi_fds[O_RDONLY]);
62616262
nf = NULL;
62626263
}
6263-
fp->fi_rdeleg_file = nfsd_file_get(fp->fi_fds[O_RDONLY]);
62646264
spin_unlock(&fp->fi_lock);
62656265
if (nf)
62666266
nfsd_file_put(nf);

0 commit comments

Comments
 (0)