| From f1442d6349a2e7bb7a6134791bdc26cb776c79af Mon Sep 17 00:00:00 2001 |
| From: Daniel Kobras <kobras@puzzle-itc.de> |
| Date: Sat, 27 Feb 2021 00:04:37 +0100 |
| Subject: sunrpc: fix refcount leak for rpc auth modules |
| |
| From: Daniel Kobras <kobras@puzzle-itc.de> |
| |
| commit f1442d6349a2e7bb7a6134791bdc26cb776c79af upstream. |
| |
| If an auth module's accept op returns SVC_CLOSE, svc_process_common() |
| enters a call path that does not call svc_authorise() before leaving the |
| function, and thus leaks a reference on the auth module's refcount. Hence, |
| make sure calls to svc_authenticate() and svc_authorise() are paired for |
| all call paths, to make sure rpc auth modules can be unloaded. |
| |
| Signed-off-by: Daniel Kobras <kobras@puzzle-itc.de> |
| Fixes: 4d712ef1db05 ("svcauth_gss: Close connection when dropping an incoming message") |
| Link: https://lore.kernel.org/linux-nfs/3F1B347F-B809-478F-A1E9-0BE98E22B0F0@oracle.com/T/#t |
| Signed-off-by: Chuck Lever <chuck.lever@oracle.com> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| --- |
| net/sunrpc/svc.c | 6 ++++-- |
| 1 file changed, 4 insertions(+), 2 deletions(-) |
| |
| --- a/net/sunrpc/svc.c |
| +++ b/net/sunrpc/svc.c |
| @@ -1330,7 +1330,7 @@ svc_process_common(struct svc_rqst *rqst |
| |
| sendit: |
| if (svc_authorise(rqstp)) |
| - goto close; |
| + goto close_xprt; |
| return 1; /* Caller can now send it */ |
| |
| dropit: |
| @@ -1339,6 +1339,8 @@ svc_process_common(struct svc_rqst *rqst |
| return 0; |
| |
| close: |
| + svc_authorise(rqstp); |
| +close_xprt: |
| if (rqstp->rq_xprt && test_bit(XPT_TEMP, &rqstp->rq_xprt->xpt_flags)) |
| svc_close_xprt(rqstp->rq_xprt); |
| dprintk("svc: svc_process close\n"); |
| @@ -1347,7 +1349,7 @@ svc_process_common(struct svc_rqst *rqst |
| err_short_len: |
| svc_printk(rqstp, "short len %zd, dropping request\n", |
| argv->iov_len); |
| - goto close; |
| + goto close_xprt; |
| |
| err_bad_rpc: |
| serv->sv_stats->rpcbadfmt++; |