NFS Server Subsystem Details
Overview
NFSD (fs/nfsd/) implements the Linux NFS server with support for NFSv2, NFSv3, and NFSv4.x protocols. The subsystem is actively migrating NFSv3 XDR handling to auto-generated code (xdrgen). Code is generally well-structured but complex state management and reference counting require careful review.
NFSD-Specific Patterns [NFSD]
Detailed review patterns are organized by topic. Load the relevant pattern files based on what code areas are being modified:
Input validation and protocol handling:
- NFSD-001: XDR input trust boundaries
- NFSD-005: NFS error code mapping
- NFSD-007: XDR encode/decode failure handling
Resource management:
- NFSD-002: Reference counting balance
- NFSD-003: File handle lifecycle
- NFSD-004: NFSv4 stateid lifecycle
Concurrency and state:
- NFSD-006: Locking correctness
- NFSD-008: Client state transitions
- NFSD-013: Session slot state and SEQUENCE operations
Security:
- NFSD-009: User namespace conversion
- NFSD-010: Security-critical input validation
Advanced features:
- NFSD-011: NFSv4 callback client operations
Quick Checks
Code style (required for NFSD):
- Automatic variables in reverse-christmas tree order
- Line length ≤ 68 characters in commit messages
Common operations:
- cpu_to_be32/be32_to_cpu for byte order conversions
- dget/dput pairs for dentry references
- Permission checks via fh_verify() before operations
- nfs_ok (0) returned on success
- nfserr_* constants returned on error
XDR migration (ongoing):
- NFSv3 procedures being migrated to use nfs3xdr_gen.c
- New code should use generated encode/decode functions
- Generated functions prefixed with nfs_svc_decode_* and nfs_svc_encode_*
- Check pc_decode/pc_encode in svc_procedure arrays
Recent Bug Classes (Oct-Nov 2025)
These represent real vulnerabilities found recently - scrutinize similar patterns:
Refcount leak from early assignment (b3da9b141578)
- Location: nfsd_set_fh_dentry()
- Pattern: Assigning resource before error checks complete
Missing bounds check in hot path (7ac3be9e56d8)
- Location: nfsd_iter_read()
- Pattern: Loop count from network not validated
XDR buffer space not reserved (38dd5c11ff52)
- Location: nfsd_splice_read()
- Pattern: xdr_reserve_space_vec() called after encoding
Encode failure causing state corruption (27f9ab3c7674)
- Location: nfsd4_close()
- Pattern: State change committed despite encoding failure
Protocol violation in caching (48990a0923a7)
- Location: nfsd4_sequence()
- Pattern: Cached response when RFC requires fresh generation
Security Focus Areas
Highest priority for security review:
Untrusted input handling:
- All data from XDR decode is untrusted
- String lengths, array counts, offsets must be validated
- File handles must be verified before use
Trust boundaries:
- Client callbacks (nfs4callback.c)
- Userspace control interface (nfsctl.c)
- Export table updates
Permission enforcement:
- fh_verify() with appropriate MAY_* flags
- Export access control (export.c)
- File type restrictions (e.g., no symlink operations)
State consistency:
- Stateid validation for NFSv4 operations
- Proper locking around state changes
- Reference counting prevents use-after-free
Review Workflow Recommendations
- Identify changed files - Check risk level above
- Understand change type:
- New feature? Full security review required
- Bug fix? Verify fix is complete and doesn't introduce new bugs
- Refactor? Check reference counting and locking unchanged
- XDR migration? Verify generated functions used correctly
- Apply relevant patterns - Load and apply patterns matching the change type
- Check error paths - Most bugs are in error handling
- Verify cleanup - All acquired resources freed?
- Consider performance - Does change affect hot paths?