NFSv4.1: Fix a protocol issue with CLOSE stateids

commit 4a1e2fe upstream.

According to RFC5661 Section 18.2.4, CLOSE is supposed to return
the zero stateid. This means that nfs_clear_open_stateid_locked()
cannot assume that the result stateid will always match the 'other'
field of the existing open stateid when trying to determine a race
with a parallel OPEN.

Instead, we look at the argument, and check for matches.

Signed-off-by: Trond Myklebust <>
Signed-off-by: Greg Kroah-Hartman <>
trondmypd authored and gregkh committed Aug 31, 2015
1 parent f638419 commit 3d5c6b90ed90eadcd9c66951877697d848e63ac1
Showing with 10 additions and 5 deletions.
  1. +10 −5 fs/nfs/nfs4proc.c
@@ -1216,6 +1216,7 @@ static void nfs_resync_open_stateid_locked(struct nfs4_state *state)

static void nfs_clear_open_stateid_locked(struct nfs4_state *state,
nfs4_stateid *arg_stateid,
nfs4_stateid *stateid, fmode_t fmode)
clear_bit(NFS_O_RDWR_STATE, &state->flags);
@@ -1234,8 +1235,9 @@ static void nfs_clear_open_stateid_locked(struct nfs4_state *state,
if (stateid == NULL)
/* Handle races with OPEN */
if (!nfs4_stateid_match_other(stateid, &state->open_stateid) ||
!nfs4_stateid_is_newer(stateid, &state->open_stateid)) {
if (!nfs4_stateid_match_other(arg_stateid, &state->open_stateid) ||
(nfs4_stateid_match_other(stateid, &state->open_stateid) &&
!nfs4_stateid_is_newer(stateid, &state->open_stateid))) {
@@ -1244,10 +1246,12 @@ static void nfs_clear_open_stateid_locked(struct nfs4_state *state,
nfs4_stateid_copy(&state->open_stateid, stateid);

static void nfs_clear_open_stateid(struct nfs4_state *state, nfs4_stateid *stateid, fmode_t fmode)
static void nfs_clear_open_stateid(struct nfs4_state *state,
nfs4_stateid *arg_stateid,
nfs4_stateid *stateid, fmode_t fmode)
nfs_clear_open_stateid_locked(state, stateid, fmode);
nfs_clear_open_stateid_locked(state, arg_stateid, stateid, fmode);
if (test_bit(NFS_STATE_RECLAIM_NOGRACE, &state->flags))
@@ -2672,7 +2676,8 @@ static void nfs4_close_done(struct rpc_task *task, void *data)
goto out_release;
nfs_clear_open_stateid(state, res_stateid, calldata->arg.fmode);
nfs_clear_open_stateid(state, &calldata->arg.stateid,
res_stateid, calldata->arg.fmode);
nfs_refresh_inode(calldata->inode, calldata->res.fattr);

