From: Shashank Mohan Jain <jain.sm@gmail.com>
To: Trond Myklebust <trondmy@kernel.org>, Anna Schumaker <anna@kernel.org>
Cc: linux-nfs@vger.kernel.org, linux-kernel@vger.kernel.org,
Andrew Morton <akpm@linux-foundation.org>
Subject: [PATCH] NFSv4: use match_uint() for ids in the legacy idmapper upcall
Date: Sun, 27 Sep 2026 10:47:07 +0530 [thread overview]
Message-ID: <20260927051707.71187-1-jain.sm@gmail.com> (raw)
For an id to name lookup, nfs_idmap_lookup_name() prints the __u32 id
with "%u" and requests the key "user:<id>" or "group:<id>". If the
legacy idmapper is used, nfs_idmap_prepare_message() parses the id back
into the __u32 im_id with match_int(), which parses a signed int.
Since commit 77dd3b0bd17a ("lib/parser.c: avoid overflow in
match_number()"), match_int() returns -ERANGE on 64-bit for values
above INT_MAX, so the upcall fails for every uid and gid of 2^31 or
above. nfs_map_uid_to_name() and nfs_map_gid_to_group() then send
the numeric id instead of a name. A server that requires names, for
example Linux nfsd with Kerberos (it never accepts numeric ids from
RPCSEC_GSS clients), rejects it with NFS4ERR_BADOWNER, so
chown() and chgrp() to such an id fail with -EINVAL. On 32-bit these
ids happen to work, because match_int() does not detect the overflow
there and the wrapped int converts back to the same __u32.
The signed parser has been used for the __u32 im_id since commit
57e62324e469 ("NFS: Store the legacy idmapper result in the keyring"),
which added this code; it only started to fail when match_int() gained
its range check.
The client only maps ids to names when it does not send numeric ids,
that is with Kerberos or with nfs.nfs4_disable_idmapping=0. It uses the
legacy idmapper (an upcall to rpc.idmapd) when the request-key upcall
fails, for example when nfsidmap is not configured, and always when the
NFS client was created from a user namespace other than init_user_ns.
Use match_uint(), which parses a decimal unsigned int with kstrtouint().
The id is always printed by the kernel in decimal, so every __u32 is now
accepted on all architectures. The type of im_id now also matches the
parser.
Fixes: 57e62324e469 ("NFS: Store the legacy idmapper result in the keyring")
Cc: stable@vger.kernel.org # 5.12.x: needs match_uint()
Assisted-by: LLM
Signed-off-by: Shashank Mohan Jain <jain.sm@gmail.com>
---
This patch was prepared with Claude Code (Anthropic), model Claude Opus 5.5
(claude-opus-5-5): the analysis, the fix, the changelog and the throwaway
test described below. The trailer only says "Assisted-by: LLM", as
Documentation/process/coding-assistants.rst describes.
Dependencies: none. The patch is correct on its own on current mainline.
It is related to "lib: parser: reject out-of-range values in
match_number()", sent to Andrew Morton:
https://lore.kernel.org/r/20260926012718.15675-1-jain.sm@gmail.com
On 32-bit, that patch makes match_int() reject these ids as well, so this
patch should be merged before it or together with it.
Testing done:
- W=1 build of fs/nfs/nfs4idmap.o with allmodconfig for x86_64 and i386:
no warnings.
- A throwaway KUnit test (not part of this patch) called
nfs_idmap_prepare_message() under UML (x86_64 and i386 subarch) with
"user:<id>" and "group:<id>"
built the way nfs_idmap_lookup_name() builds them, for ids 0, 1000,
65534, 2^31 - 1, 2^31, 3000000000, 2^32 - 2 and 2^32 - 1.
x86_64: without the patch every id >= 2^31 fails with -ERANGE; with it
all ids parse to the right value. i386: passes with and without the
patch; with the parser patch above applied it fails without this patch
and passes with it.
Not tested: a real NFSv4 mount using rpc.idmapd (legacy upcall), and the
resulting chown() failure against a Kerberos export. That effect comes
from reading nfs_map_uid_to_name() and fs/nfsd/nfs4idmap.c.
fs/nfs/nfs4idmap.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/nfs/nfs4idmap.c b/fs/nfs/nfs4idmap.c
index bc397110d977..c7a20286d0ee 100644
--- a/fs/nfs/nfs4idmap.c
+++ b/fs/nfs/nfs4idmap.c
@@ -519,7 +519,7 @@ static int nfs_idmap_prepare_message(char *desc, struct idmap *idmap,
fallthrough;
case Opt_find_group:
im->im_conv = IDMAP_CONV_IDTONAME;
- ret = match_int(&substr, &im->im_id);
+ ret = match_uint(&substr, &im->im_id);
if (ret)
goto out;
break;
--
2.43.0
reply other threads:[~2026-09-27 5:17 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260927051707.71187-1-jain.sm@gmail.com \
--to=jain.sm@gmail.com \
--cc=akpm@linux-foundation.org \
--cc=anna@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-nfs@vger.kernel.org \
--cc=trondmy@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®