• C
    NFS: Fix an LOCK/OPEN race when unlinking an open file · 11476e9d
    Chuck Lever 提交于
    At Connectathon 2016, we found that recent upstream Linux clients
    would occasionally send a LOCK operation with a zero stateid. This
    appeared to happen in close proximity to another thread returning
    a delegation before unlinking the same file while it remained open.
    
    Earlier, the client received a write delegation on this file and
    returned the open stateid. Now, as it is getting ready to unlink the
    file, it returns the write delegation. But there is still an open
    file descriptor on that file, so the client must OPEN the file
    again before it returns the delegation.
    
    Since commit 24311f88 ('NFSv4: Recovery of recalled read
    delegations is broken'), nfs_open_delegation_recall() clears the
    NFS_DELEGATED_STATE flag _before_ it sends the OPEN. This allows a
    racing LOCK on the same inode to be put on the wire before the OPEN
    operation has returned a valid open stateid.
    
    To eliminate this race, serialize delegation return with the
    acquisition of a file lock on the same file. Adopt the same approach
    as is used in the unlock path.
    
    This patch also eliminates a similar race seen when sending a LOCK
    operation at the same time as returning a delegation on the same file.
    
    Fixes: 24311f88 ('NFSv4: Recovery of recalled read ... ')
    Signed-off-by: NChuck Lever <chuck.lever@oracle.com>
    [Anna: Add sentence about LOCK / delegation race]
    Signed-off-by: NAnna Schumaker <Anna.Schumaker@Netapp.com>
    11476e9d
nfs4proc.c 239.5 KB