[PATCH] nfsd: use xdr_encode_opaque_fixed for all GETXATTR fragments
From: Aldo Ariel Panzardo
Date: Tue Sep 15 2026 - 15:02:23 EST
nfsd4_vbuf_to_stream() already uses xdr_encode_opaque_fixed() when the
final fragment is shorter than a page, but the preceding memcpy() in the
loop body does not clear XDR padding.
When the last fragment happens to be exactly PAGE_SIZE the short-fragment
branch is never entered, and the loop exits through the normal buflen
path. If that final page-sized reservation is not word-aligned within
the XDR stream, its padding bytes are left stale.
Convert the loop memcpy to xdr_encode_opaque_fixed() and drop the now
redundant short-fragment padding block, matching the first-fragment fix.
Suggested-by: Jeff Layton <jlayton@xxxxxxxxxx>
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@xxxxxxxxx>
---
fs/nfsd/nfs4xdr.c | 10 +---------
1 file changed, 1 insertion(+), 9 deletions(-)
diff --git a/fs/nfsd/nfs4xdr.c b/fs/nfsd/nfs4xdr.c
index XXXXXXX..XXXXXXX 100644
--- a/fs/nfsd/nfs4xdr.c
+++ b/fs/nfsd/nfs4xdr.c
@@ -5963,15 +5963,7 @@ nfsd4_vbuf_to_stream(struct xdr_stream *xdr, char *buf, u32 buflen)
if (!p)
return nfserr_resource;
- memcpy(p, buf, cplen);
-
- if (cplen < PAGE_SIZE) {
- /*
- * We're done, with a length that wasn't page
- * aligned, so possibly not word aligned. Pad
- * any trailing bytes with 0.
- */
- xdr_encode_opaque_fixed(p, NULL, cplen);
- break;
- }
+ xdr_encode_opaque_fixed(p, buf, cplen);
+ if (cplen < PAGE_SIZE)
+ break;
buflen -= PAGE_SIZE;
buf += PAGE_SIZE;
--
2.43.0