F-6.2: NFSv4 Grace Period Blocking¶
Status: out of scope for nfswolf. This finding was scoped during the design phase but never implemented; with the lock-DoS module and the NLM/NSM clients removed, all of category 6 (denial of service) is out of scope for nfswolf. This write-up is preserved for reference.
Classification¶
- Severity: Medium
- CVSS Vector: Network / Medium Complexity / No Auth Required
- Affected Versions: NFSv4.0, NFSv4.1, NFSv4.2
- RFC Reference: RFC 7530 §8.6.2
- Prerequisite: Ability to trigger server restart or simulate it
Summary¶
After an NFSv4 server restarts, it enters a grace period during which it rejects all new READ, WRITE, and non-reclaim locking requests with NFS4ERR_GRACE. This is a protocol-mandated recovery mechanism. An attacker who can repeatedly trigger server restarts (or simulate crash/recovery sequences) can maintain continuous service denial — the server spends all its time in grace periods, rejecting legitimate work.
Technical detail¶
Grace period mechanics¶
Per RFC 7530 §8.6.2:
"During the grace period, the server must reject READ and WRITE operations and non-reclaim locking requests with an error of NFS4ERR_GRACE."
The grace period typically lasts 90 seconds (configurable). During this window: - All READ/WRITE operations fail - Only lock RECLAIM operations succeed (existing clients recovering state) - New lock requests fail - All new file access is blocked
Attack vectors¶
Vector 1: Crash trigger¶
If the attacker can crash the NFS server (via a kernel bug, resource exhaustion, or NLM-related crash on v3-compatible servers), each restart initiates a new grace period.
Vector 2: State destruction via SETCLIENTID¶
See F-6.3. Destroying client state may trigger reclamation sequences.
Vector 3: Network partition simulation¶
By blocking traffic between the server and its clients (ARP spoofing, routing manipulation), the server may detect lease expiration and enter a state cleanup cycle.
Impact calculation¶
If grace period = 90 seconds and attacker can trigger restart every 90 seconds: - 100% service denial maintained indefinitely - All legitimate clients see NFS4ERR_GRACE on every operation - Applications hang or fail
Impact¶
- Complete denial of NFS service during grace periods
- Legitimate client state may be lost if reclaim window expires
- Applications that don't handle NFS4ERR_GRACE may crash or corrupt data
- Cascading failures if NFS is used for critical infrastructure (home dirs, web roots)
Detection (nfswolf)¶
Not implemented. Category 6 (denial of service) is out of scope for nfswolf (see the status banner above); no subcommand detects grace-period behaviour or the NFS4ERR_GRACE error. The check sketched in earlier drafts was never built.
Remediation¶
- Harden the NFS server against crashes (resource limits, watchdog timers)
- Shorten the grace period if reclaim traffic is minimal:
- Use NFSv4.1+ session trunking — more resilient to network disruptions
- Monitor for repeated restarts — alert on NFS server crash loops
- Network segmentation — prevent attacker from reaching NFS infrastructure