Skip to content

F-6.2: NFSv4 Grace Period Blocking

Status: out of scope for nfswolf. This finding was scoped during the design phase but never implemented; with the lock-DoS module and the NLM/NSM clients removed, all of category 6 (denial of service) is out of scope for nfswolf. This write-up is preserved for reference.

Classification

  • Severity: Medium
  • CVSS Vector: Network / Medium Complexity / No Auth Required
  • Affected Versions: NFSv4.0, NFSv4.1, NFSv4.2
  • RFC Reference: RFC 7530 §8.6.2
  • Prerequisite: Ability to trigger server restart or simulate it

Summary

After an NFSv4 server restarts, it enters a grace period during which it rejects all new READ, WRITE, and non-reclaim locking requests with NFS4ERR_GRACE. This is a protocol-mandated recovery mechanism. An attacker who can repeatedly trigger server restarts (or simulate crash/recovery sequences) can maintain continuous service denial — the server spends all its time in grace periods, rejecting legitimate work.

Technical detail

Grace period mechanics

Per RFC 7530 §8.6.2:

"During the grace period, the server must reject READ and WRITE operations and non-reclaim locking requests with an error of NFS4ERR_GRACE."

The grace period typically lasts 90 seconds (configurable). During this window: - All READ/WRITE operations fail - Only lock RECLAIM operations succeed (existing clients recovering state) - New lock requests fail - All new file access is blocked

Attack vectors

Vector 1: Crash trigger

If the attacker can crash the NFS server (via a kernel bug, resource exhaustion, or NLM-related crash on v3-compatible servers), each restart initiates a new grace period.

Vector 2: State destruction via SETCLIENTID

See F-6.3. Destroying client state may trigger reclamation sequences.

Vector 3: Network partition simulation

By blocking traffic between the server and its clients (ARP spoofing, routing manipulation), the server may detect lease expiration and enter a state cleanup cycle.

Impact calculation

If grace period = 90 seconds and attacker can trigger restart every 90 seconds: - 100% service denial maintained indefinitely - All legitimate clients see NFS4ERR_GRACE on every operation - Applications hang or fail

Impact

  • Complete denial of NFS service during grace periods
  • Legitimate client state may be lost if reclaim window expires
  • Applications that don't handle NFS4ERR_GRACE may crash or corrupt data
  • Cascading failures if NFS is used for critical infrastructure (home dirs, web roots)

Detection (nfswolf)

Not implemented. Category 6 (denial of service) is out of scope for nfswolf (see the status banner above); no subcommand detects grace-period behaviour or the NFS4ERR_GRACE error. The check sketched in earlier drafts was never built.

Remediation

  1. Harden the NFS server against crashes (resource limits, watchdog timers)
  2. Shorten the grace period if reclaim traffic is minimal:
    # /etc/nfs.conf
    [nfsd]
    grace-time=15
    
  3. Use NFSv4.1+ session trunking — more resilient to network disruptions
  4. Monitor for repeated restarts — alert on NFS server crash loops
  5. Network segmentation — prevent attacker from reaching NFS infrastructure