]> git.saurik.com Git - apple/xnu.git/blobdiff - bsd/nfs/nfs4_vnops.c
xnu-7195.101.1.tar.gz
[apple/xnu.git] / bsd / nfs / nfs4_vnops.c
index 85ebceb476cba6a902c701085f9a72775d2d662a..7a5b838d575a66f8317ea4a099e45560b5cf3c24 100644 (file)
@@ -1,8 +1,8 @@
 /*
- * Copyright (c) 2006-2011 Apple Inc. All rights reserved.
+ * Copyright (c) 2006-2020 Apple Inc. All rights reserved.
  *
  * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
- * 
+ *
  * This file contains Original Code and/or Modifications of Original Code
  * as defined in and that are subject to the Apple Public Source License
  * Version 2.0 (the 'License'). You may not use this file except in
  * unlawful or unlicensed copies of an Apple operating system, or to
  * circumvent, violate, or enable the circumvention or violation of, any
  * terms of an Apple operating system software license agreement.
- * 
+ *
  * Please obtain a copy of the License at
  * http://www.opensource.apple.com/apsl/ and read it before using this file.
- * 
+ *
  * The Original Code and all software distributed under the License are
  * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
  * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
  * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
  * Please see the License for the specific language governing rights and
  * limitations under the License.
- * 
+ *
  * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
  */
 
+#include <nfs/nfs_conf.h>
+#if CONFIG_NFS_CLIENT
+
 /*
  * vnode op calls for NFS version 4
  */
@@ -79,8 +82,9 @@
 #include <kern/task.h>
 #include <kern/sched_prim.h>
 
+#if CONFIG_NFS4
 int
-nfs4_access_rpc(nfsnode_t np, u_int32_t *access, vfs_context_t ctx)
+nfs4_access_rpc(nfsnode_t np, u_int32_t *access, int rpcflags, vfs_context_t ctx)
 {
        int error = 0, lockerror = ENOENT, status, numops, slot;
        u_int64_t xid;
@@ -92,8 +96,9 @@ nfs4_access_rpc(nfsnode_t np, u_int32_t *access, vfs_context_t ctx)
        uid_t uid;
        struct nfsreq_secinfo_args si;
 
-       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL)
-               return (0);
+       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL) {
+               return 0;
+       }
 
        NFSREQ_SECINFO_SET(&si, np, NULL, 0, NULL, 0);
        nfsm_chain_null(&nmreq);
@@ -102,7 +107,7 @@ nfs4_access_rpc(nfsnode_t np, u_int32_t *access, vfs_context_t ctx)
        // PUTFH, ACCESS, GETATTR
        numops = 3;
        nfsm_chain_build_alloc_init(error, &nmreq, 17 * NFSX_UNSIGNED);
-       nfsm_chain_add_compound_header(error, &nmreq, "access", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "access", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, nfsvers, np->n_fhp, np->n_fhsize);
@@ -115,10 +120,13 @@ nfs4_access_rpc(nfsnode_t np, u_int32_t *access, vfs_context_t ctx)
        nfsm_chain_build_done(error, &nmreq);
        nfsm_assert(error, (numops == 0), EPROTO);
        nfsmout_if(error);
-       error = nfs_request(np, NULL, &nmreq, NFSPROC4_COMPOUND, ctx, &si, &nmrep, &xid, &status);
+       error = nfs_request2(np, NULL, &nmreq, NFSPROC4_COMPOUND,
+           vfs_context_thread(ctx), vfs_context_ucred(ctx),
+           &si, rpcflags, &nmrep, &xid, &status);
 
-       if ((lockerror = nfs_node_lock(np)))
+       if ((lockerror = nfs_node_lock(np))) {
                error = lockerror;
+       }
        nfsm_chain_skip_tag(error, &nmrep);
        nfsm_chain_get_32(error, &nmrep, numops);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_PUTFH);
@@ -141,21 +149,33 @@ nfs4_access_rpc(nfsnode_t np, u_int32_t *access, vfs_context_t ctx)
        /* ".zfs" subdirectories may erroneously give a denied answer for modify/delete */
        if (nfs_access_dotzfs) {
                vnode_t dvp = NULLVP;
-               if (np->n_flag & NISDOTZFSCHILD) /* may be able to create/delete snapshot dirs */
-                       access_result |= (NFS_ACCESS_MODIFY|NFS_ACCESS_EXTEND|NFS_ACCESS_DELETE);
-               else if (((dvp = vnode_getparent(NFSTOV(np))) != NULLVP) && (VTONFS(dvp)->n_flag & NISDOTZFSCHILD))
+               if (np->n_flag & NISDOTZFSCHILD) /* may be able to create/delete snapshot dirs */
+                       access_result |= (NFS_ACCESS_MODIFY | NFS_ACCESS_EXTEND | NFS_ACCESS_DELETE);
+               } else if (((dvp = vnode_getparent(NFSTOV(np))) != NULLVP) && (VTONFS(dvp)->n_flag & NISDOTZFSCHILD)) {
                        access_result |= NFS_ACCESS_DELETE; /* may be able to delete snapshot dirs */
-               if (dvp != NULLVP)
+               }
+               if (dvp != NULLVP) {
                        vnode_put(dvp);
+               }
        }
        /* Some servers report DELETE support but erroneously give a denied answer. */
-       if (nfs_access_delete && (*access & NFS_ACCESS_DELETE) && !(access_result & NFS_ACCESS_DELETE))
+       if (nfs_access_delete && (*access & NFS_ACCESS_DELETE) && !(access_result & NFS_ACCESS_DELETE)) {
                access_result |= NFS_ACCESS_DELETE;
+       }
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
        nfsm_chain_loadattr(error, &nmrep, np, nfsvers, &xid);
        nfsmout_if(error);
 
-       uid = kauth_cred_getuid(vfs_context_ucred(ctx));
+       if (nfs_mount_gone(nmp)) {
+               error = ENXIO;
+       }
+       nfsmout_if(error);
+
+       if (auth_is_kerberized(np->n_auth) || auth_is_kerberized(nmp->nm_auth)) {
+               uid = nfs_cred_getasid2uid(vfs_context_ucred(ctx));
+       } else {
+               uid = kauth_cred_getuid(vfs_context_ucred(ctx));
+       }
        slot = nfs_node_access_slot(np, uid, 1);
        np->n_accessuid[slot] = uid;
        microuptime(&now);
@@ -165,11 +185,12 @@ nfs4_access_rpc(nfsnode_t np, u_int32_t *access, vfs_context_t ctx)
        /* pass back the access returned with this request */
        *access = np->n_access[slot];
 nfsmout:
-       if (!lockerror)
+       if (!lockerror) {
                nfs_node_unlock(np);
+       }
        nfsm_chain_cleanup(&nmreq);
        nfsm_chain_cleanup(&nmrep);
-       return (error);
+       return error;
 }
 
 int
@@ -189,18 +210,24 @@ nfs4_getattr_rpc(
        struct nfsm_chain nmreq, nmrep;
        struct nfsreq_secinfo_args si;
 
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        nfsvers = nmp->nm_vers;
        acls = (nmp->nm_fsattr.nfsa_flags & NFS_FSFLAG_ACL);
 
        if (np && (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL)) {
                nfs4_default_attrs_for_referral_trigger(VTONFS(np->n_parent), NULL, 0, nvap, NULL);
-               return (0);
+               return 0;
        }
 
-       if (flags & NGA_MONITOR) /* vnode monitor requests should be soft */
+       if (flags & NGA_MONITOR) /* vnode monitor requests should be soft */
                rpcflags = R_RECOVER;
+       }
+
+       if (flags & NGA_SOFT) { /* Return ETIMEDOUT if server not responding */
+               rpcflags |= R_SOFT;
+       }
 
        NFSREQ_SECINFO_SET(&si, np, NULL, 0, NULL, 0);
        nfsm_chain_null(&nmreq);
@@ -209,22 +236,23 @@ nfs4_getattr_rpc(
        // PUTFH, GETATTR
        numops = 2;
        nfsm_chain_build_alloc_init(error, &nmreq, 15 * NFSX_UNSIGNED);
-       nfsm_chain_add_compound_header(error, &nmreq, "getattr", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "getattr", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, nfsvers, fhp, fhsize);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_GETATTR);
        NFS_COPY_ATTRIBUTES(nfs_getattr_bitmap, bitmap);
-       if ((flags & NGA_ACL) && acls)
+       if ((flags & NGA_ACL) && acls) {
                NFS_BITMAP_SET(bitmap, NFS_FATTR_ACL);
+       }
        nfsm_chain_add_bitmap_supported(error, &nmreq, bitmap, nmp, np);
        nfsm_chain_build_done(error, &nmreq);
        nfsm_assert(error, (numops == 0), EPROTO);
        nfsmout_if(error);
-       error = nfs_request2(np, mp, &nmreq, NFSPROC4_COMPOUND, 
-                       vfs_context_thread(ctx), vfs_context_ucred(ctx),
-                       NULL, rpcflags, &nmrep, xidp, &status);
+       error = nfs_request2(np, mp, &nmreq, NFSPROC4_COMPOUND,
+           vfs_context_thread(ctx), vfs_context_ucred(ctx),
+           NULL, rpcflags, &nmrep, xidp, &status);
 
        nfsm_chain_skip_tag(error, &nmrep);
        nfsm_chain_get_32(error, &nmrep, numops);
@@ -241,24 +269,26 @@ nfs4_getattr_rpc(
 nfsmout:
        nfsm_chain_cleanup(&nmreq);
        nfsm_chain_cleanup(&nmrep);
-       return (error);
+       return error;
 }
 
 int
-nfs4_readlink_rpc(nfsnode_t np, char *buf, uint32_t *buflenp, vfs_context_t ctx)
+nfs4_readlink_rpc(nfsnode_t np, char *buf, size_t *buflenp, vfs_context_t ctx)
 {
        struct nfsmount *nmp;
        int error = 0, lockerror = ENOENT, status, numops;
-       uint32_t len = 0;
+       size_t len = 0;
        u_int64_t xid;
        struct nfsm_chain nmreq, nmrep;
        struct nfsreq_secinfo_args si;
 
        nmp = NFSTONMP(np);
-       if (!nmp)
-               return (ENXIO);
-       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL)
-               return (EINVAL);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
+       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL) {
+               return EINVAL;
+       }
        NFSREQ_SECINFO_SET(&si, np, NULL, 0, NULL, 0);
        nfsm_chain_null(&nmreq);
        nfsm_chain_null(&nmrep);
@@ -266,7 +296,7 @@ nfs4_readlink_rpc(nfsnode_t np, char *buf, uint32_t *buflenp, vfs_context_t ctx)
        // PUTFH, GETATTR, READLINK
        numops = 3;
        nfsm_chain_build_alloc_init(error, &nmreq, 16 * NFSX_UNSIGNED);
-       nfsm_chain_add_compound_header(error, &nmreq, "readlink", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "readlink", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, NFS_VER4, np->n_fhp, np->n_fhsize);
@@ -280,8 +310,9 @@ nfs4_readlink_rpc(nfsnode_t np, char *buf, uint32_t *buflenp, vfs_context_t ctx)
        nfsmout_if(error);
        error = nfs_request(np, NULL, &nmreq, NFSPROC4_COMPOUND, ctx, &si, &nmrep, &xid, &status);
 
-       if ((lockerror = nfs_node_lock(np)))
+       if ((lockerror = nfs_node_lock(np))) {
                error = lockerror;
+       }
        nfsm_chain_skip_tag(error, &nmrep);
        nfsm_chain_get_32(error, &nmrep, numops);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_PUTFH);
@@ -291,20 +322,23 @@ nfs4_readlink_rpc(nfsnode_t np, char *buf, uint32_t *buflenp, vfs_context_t ctx)
        nfsm_chain_get_32(error, &nmrep, len);
        nfsmout_if(error);
        if (len >= *buflenp) {
-               if (np->n_size && (np->n_size < *buflenp))
+               if (np->n_size && (np->n_size < *buflenp)) {
                        len = np->n_size;
-               else
+               } else {
                        len = *buflenp - 1;
+               }
        }
        nfsm_chain_get_opaque(error, &nmrep, len, buf);
-       if (!error)
+       if (!error) {
                *buflenp = len;
+       }
 nfsmout:
-       if (!lockerror)
+       if (!lockerror) {
                nfs_node_unlock(np);
+       }
        nfsm_chain_cleanup(&nmreq);
        nfsm_chain_cleanup(&nmrep);
-       return (error);
+       return error;
 }
 
 int
@@ -324,19 +358,21 @@ nfs4_read_rpc_async(
        struct nfsreq_secinfo_args si;
 
        nmp = NFSTONMP(np);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        nfsvers = nmp->nm_vers;
-       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL)
-               return (EINVAL);
+       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL) {
+               return EINVAL;
+       }
 
        NFSREQ_SECINFO_SET(&si, np, NULL, 0, NULL, 0);
        nfsm_chain_null(&nmreq);
 
-       // PUTFH, READ, GETATTR
-       numops = 3;
+       // PUTFH, READ
+       numops = 2;
        nfsm_chain_build_alloc_init(error, &nmreq, 22 * NFSX_UNSIGNED);
-       nfsm_chain_add_compound_header(error, &nmreq, "read", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "read", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, nfsvers, np->n_fhp, np->n_fhsize);
@@ -346,16 +382,13 @@ nfs4_read_rpc_async(
        nfsm_chain_add_stateid(error, &nmreq, &stateid);
        nfsm_chain_add_64(error, &nmreq, offset);
        nfsm_chain_add_32(error, &nmreq, len);
-       numops--;
-       nfsm_chain_add_32(error, &nmreq, NFS_OP_GETATTR);
-       nfsm_chain_add_bitmap_supported(error, &nmreq, nfs_getattr_bitmap, nmp, np);
        nfsm_chain_build_done(error, &nmreq);
        nfsm_assert(error, (numops == 0), EPROTO);
        nfsmout_if(error);
        error = nfs_request_async(np, NULL, &nmreq, NFSPROC4_COMPOUND, thd, cred, &si, 0, cb, reqp);
 nfsmout:
        nfsm_chain_cleanup(&nmreq);
-       return (error);
+       return error;
 }
 
 int
@@ -373,20 +406,22 @@ nfs4_read_rpc_async_finish(
        struct nfsm_chain nmrep;
 
        nmp = NFSTONMP(np);
-       if (!nmp) {
+       if (nfs_mount_gone(nmp)) {
                nfs_request_async_cancel(req);
-               return (ENXIO);
+               return ENXIO;
        }
        nfsvers = nmp->nm_vers;
 
        nfsm_chain_null(&nmrep);
 
        error = nfs_request_async_finish(req, &nmrep, &xid, &status);
-       if (error == EINPROGRESS) /* async request restarted */
-               return (error);
+       if (error == EINPROGRESS) { /* async request restarted */
+               return error;
+       }
 
-       if ((lockerror = nfs_node_lock(np)))
+       if ((lockerror = nfs_node_lock(np))) {
                error = lockerror;
+       }
        nfsm_chain_skip_tag(error, &nmrep);
        nfsm_chain_get_32(error, &nmrep, numops);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_PUTFH);
@@ -397,19 +432,20 @@ nfs4_read_rpc_async_finish(
                *lenp = MIN(retlen, *lenp);
                error = nfsm_chain_get_uio(&nmrep, *lenp, uio);
        }
-       nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
-       nfsm_chain_loadattr(error, &nmrep, np, nfsvers, &xid);
-       if (!lockerror)
+       if (!lockerror) {
                nfs_node_unlock(np);
+       }
        if (eofp) {
-               if (!eof && !retlen)
+               if (!eof && !retlen) {
                        eof = 1;
+               }
                *eofp = eof;
        }
        nfsm_chain_cleanup(&nmrep);
-       if (np->n_vattr.nva_flags & NFS_FFLAG_IS_ATTR)
+       if (np->n_vattr.nva_flags & NFS_FFLAG_IS_ATTR) {
                microuptime(&np->n_lastio);
-       return (error);
+       }
+       return error;
 }
 
 int
@@ -431,16 +467,19 @@ nfs4_write_rpc_async(
        struct nfsreq_secinfo_args si;
 
        nmp = NFSTONMP(np);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        nfsvers = nmp->nm_vers;
-       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL)
-               return (EINVAL);
+       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL) {
+               return EINVAL;
+       }
 
        /* for async mounts, don't bother sending sync write requests */
        if ((iomode != NFS_WRITE_UNSTABLE) && nfs_allow_async &&
-           ((mp = NFSTOMP(np))) && (vfs_flags(mp) & MNT_ASYNC))
+           ((mp = NFSTOMP(np))) && (vfs_flags(mp) & MNT_ASYNC)) {
                iomode = NFS_WRITE_UNSTABLE;
+       }
 
        NFSREQ_SECINFO_SET(&si, np, NULL, 0, NULL, 0);
        nfsm_chain_null(&nmreq);
@@ -448,7 +487,7 @@ nfs4_write_rpc_async(
        // PUTFH, WRITE, GETATTR
        numops = 3;
        nfsm_chain_build_alloc_init(error, &nmreq, 25 * NFSX_UNSIGNED + len);
-       nfsm_chain_add_compound_header(error, &nmreq, "write", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "write", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, nfsvers, np->n_fhp, np->n_fhsize);
@@ -459,11 +498,12 @@ nfs4_write_rpc_async(
        nfsm_chain_add_64(error, &nmreq, uio_offset(uio));
        nfsm_chain_add_32(error, &nmreq, iomode);
        nfsm_chain_add_32(error, &nmreq, len);
-       if (!error)
+       if (!error) {
                error = nfsm_chain_add_uio(&nmreq, uio, len);
+       }
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_GETATTR);
-       nfsm_chain_add_bitmap_supported(error, &nmreq, nfs_getattr_bitmap, nmp, np);
+       nfsm_chain_add_bitmap_supported(error, &nmreq, nfs4_getattr_write_bitmap, nmp, np);
        nfsm_chain_build_done(error, &nmreq);
        nfsm_assert(error, (numops == 0), EPROTO);
        nfsmout_if(error);
@@ -471,7 +511,7 @@ nfs4_write_rpc_async(
        error = nfs_request_async(np, NULL, &nmreq, NFSPROC4_COMPOUND, thd, cred, &si, 0, cb, reqp);
 nfsmout:
        nfsm_chain_cleanup(&nmreq);
-       return (error);
+       return error;
 }
 
 int
@@ -491,22 +531,25 @@ nfs4_write_rpc_async_finish(
        struct nfsm_chain nmrep;
 
        nmp = NFSTONMP(np);
-       if (!nmp) {
+       if (nfs_mount_gone(nmp)) {
                nfs_request_async_cancel(req);
-               return (ENXIO);
+               return ENXIO;
        }
        nfsvers = nmp->nm_vers;
 
        nfsm_chain_null(&nmrep);
 
        error = nfs_request_async_finish(req, &nmrep, &xid, &status);
-       if (error == EINPROGRESS) /* async request restarted */
-               return (error);
+       if (error == EINPROGRESS) { /* async request restarted */
+               return error;
+       }
        nmp = NFSTONMP(np);
-       if (!nmp)
+       if (nfs_mount_gone(nmp)) {
                error = ENXIO;
-       if (!error && (lockerror = nfs_node_lock(np)))
+       }
+       if (!error && (lockerror = nfs_node_lock(np))) {
                error = lockerror;
+       }
        nfsm_chain_skip_tag(error, &nmrep);
        nfsm_chain_get_32(error, &nmrep, numops);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_PUTFH);
@@ -514,13 +557,15 @@ nfs4_write_rpc_async_finish(
        nfsm_chain_get_32(error, &nmrep, rlen);
        nfsmout_if(error);
        *rlenp = rlen;
-       if (rlen <= 0)
+       if (rlen <= 0) {
                error = NFSERR_IO;
+       }
        nfsm_chain_get_32(error, &nmrep, committed);
        nfsm_chain_get_64(error, &nmrep, wverf);
        nfsmout_if(error);
-       if (wverfp)
+       if (wverfp) {
                *wverfp = wverf;
+       }
        lck_mtx_lock(&nmp->nm_lock);
        if (!(nmp->nm_state & NFSSTA_HASWRITEVERF)) {
                nmp->nm_verf = wverf;
@@ -530,18 +575,29 @@ nfs4_write_rpc_async_finish(
        }
        lck_mtx_unlock(&nmp->nm_lock);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
+
+       /*
+        * NFSv4 WRITE RPCs contain partial GETATTR requests - only type, change, size, metadatatime and modifytime are requested.
+        * In such cases,  we do not update the time stamp - but the requested attributes.
+        */
+       np->n_vattr.nva_flags |= NFS_FFLAG_PARTIAL_WRITE;
        nfsm_chain_loadattr(error, &nmrep, np, nfsvers, &xid);
+       np->n_vattr.nva_flags &= ~NFS_FFLAG_PARTIAL_WRITE;
+
 nfsmout:
-       if (!lockerror)
+       if (!lockerror) {
                nfs_node_unlock(np);
+       }
        nfsm_chain_cleanup(&nmrep);
        if ((committed != NFS_WRITE_FILESYNC) && nfs_allow_async &&
-           ((mp = NFSTOMP(np))) && (vfs_flags(mp) & MNT_ASYNC))
+           ((mp = NFSTOMP(np))) && (vfs_flags(mp) & MNT_ASYNC)) {
                committed = NFS_WRITE_FILESYNC;
+       }
        *iomodep = committed;
-       if (np->n_vattr.nva_flags & NFS_FFLAG_IS_ATTR)
+       if (np->n_vattr.nva_flags & NFS_FFLAG_IS_ATTR) {
                microuptime(&np->n_lastio);
-       return (error);
+       }
+       return error;
 }
 
 int
@@ -560,11 +616,13 @@ nfs4_remove_rpc(
        struct nfsreq_secinfo_args si;
 
        nmp = NFSTONMP(dnp);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        nfsvers = nmp->nm_vers;
-       if (dnp->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL)
-               return (EINVAL);
+       if (dnp->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL) {
+               return EINVAL;
+       }
        NFSREQ_SECINFO_SET(&si, dnp, NULL, 0, NULL, 0);
 restart:
        nfsm_chain_null(&nmreq);
@@ -573,7 +631,7 @@ restart:
        // PUTFH, REMOVE, GETATTR
        numops = 3;
        nfsm_chain_build_alloc_init(error, &nmreq, 17 * NFSX_UNSIGNED + namelen);
-       nfsm_chain_add_compound_header(error, &nmreq, "remove", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "remove", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, nfsvers, dnp->n_fhp, dnp->n_fhsize);
@@ -589,8 +647,9 @@ restart:
 
        error = nfs_request2(dnp, NULL, &nmreq, NFSPROC4_COMPOUND, thd, cred, &si, 0, &nmrep, &xid, &status);
 
-       if ((lockerror = nfs_node_lock(dnp)))
+       if ((lockerror = nfs_node_lock(dnp))) {
                error = lockerror;
+       }
        nfsm_chain_skip_tag(error, &nmrep);
        nfsm_chain_get_32(error, &nmrep, numops);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_PUTFH);
@@ -599,8 +658,9 @@ restart:
        nfsm_chain_check_change_info(error, &nmrep, dnp);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
        nfsm_chain_loadattr(error, &nmrep, dnp, nfsvers, &xid);
-       if (error && !lockerror)
+       if (error && !lockerror) {
                NATTRINVALIDATE(dnp);
+       }
 nfsmout:
        nfsm_chain_cleanup(&nmreq);
        nfsm_chain_cleanup(&nmrep);
@@ -610,11 +670,11 @@ nfsmout:
                nfs_node_unlock(dnp);
        }
        if (error == NFSERR_GRACE) {
-               tsleep(&nmp->nm_state, (PZERO-1), "nfsgrace", 2*hz);
+               tsleep(&nmp->nm_state, (PZERO - 1), "nfsgrace", 2 * hz);
                goto restart;
        }
 
-       return (remove_error);
+       return remove_error;
 }
 
 int
@@ -634,13 +694,16 @@ nfs4_rename_rpc(
        struct nfsreq_secinfo_args si;
 
        nmp = NFSTONMP(fdnp);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        nfsvers = nmp->nm_vers;
-       if (fdnp->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL)
-               return (EINVAL);
-       if (tdnp->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL)
-               return (EINVAL);
+       if (fdnp->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL) {
+               return EINVAL;
+       }
+       if (tdnp->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL) {
+               return EINVAL;
+       }
 
        NFSREQ_SECINFO_SET(&si, fdnp, NULL, 0, NULL, 0);
        nfsm_chain_null(&nmreq);
@@ -649,7 +712,7 @@ nfs4_rename_rpc(
        // PUTFH(FROM), SAVEFH, PUTFH(TO), RENAME, GETATTR(TO), RESTOREFH, GETATTR(FROM)
        numops = 7;
        nfsm_chain_build_alloc_init(error, &nmreq, 30 * NFSX_UNSIGNED + fnamelen + tnamelen);
-       nfsm_chain_add_compound_header(error, &nmreq, "rename", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "rename", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, nfsvers, fdnp->n_fhp, fdnp->n_fhsize);
@@ -676,8 +739,9 @@ nfs4_rename_rpc(
 
        error = nfs_request(fdnp, NULL, &nmreq, NFSPROC4_COMPOUND, ctx, &si, &nmrep, &xid, &status);
 
-       if ((lockerror = nfs_node_lock2(fdnp, tdnp)))
+       if ((lockerror = nfs_node_lock2(fdnp, tdnp))) {
                error = lockerror;
+       }
        nfsm_chain_skip_tag(error, &nmrep);
        nfsm_chain_get_32(error, &nmrep, numops);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_PUTFH);
@@ -690,14 +754,16 @@ nfs4_rename_rpc(
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
        savedxid = xid;
        nfsm_chain_loadattr(error, &nmrep, tdnp, nfsvers, &xid);
-       if (error && !lockerror)
+       if (error && !lockerror) {
                NATTRINVALIDATE(tdnp);
+       }
        nfsm_chain_op_check(error, &nmrep, NFS_OP_RESTOREFH);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
        xid = savedxid;
        nfsm_chain_loadattr(error, &nmrep, fdnp, nfsvers, &xid);
-       if (error && !lockerror)
+       if (error && !lockerror) {
                NATTRINVALIDATE(fdnp);
+       }
 nfsmout:
        nfsm_chain_cleanup(&nmreq);
        nfsm_chain_cleanup(&nmrep);
@@ -706,7 +772,7 @@ nfsmout:
                tdnp->n_flag |= NMODIFIED;
                nfs_node_unlock2(fdnp, tdnp);
        }
-       return (error);
+       return error;
 }
 
 /*
@@ -718,31 +784,34 @@ nfs4_readdir_rpc(nfsnode_t dnp, struct nfsbuf *bp, vfs_context_t ctx)
        struct nfsmount *nmp;
        int error = 0, lockerror, nfsvers, namedattr, rdirplus, bigcookies, numops;
        int i, status, more_entries = 1, eof, bp_dropped = 0;
+       uint16_t namlen, reclen;
        uint32_t nmreaddirsize, nmrsize;
-       uint32_t namlen, skiplen, fhlen, xlen, attrlen, reclen, space_free, space_needed;
-       uint64_t cookie, lastcookie, xid, savedxid;
+       uint32_t namlen32, skiplen, fhlen, xlen, attrlen;
+       uint64_t padlen, cookie, lastcookie, xid, savedxid, space_free, space_needed;
        struct nfsm_chain nmreq, nmrep, nmrepsave;
-       fhandle_t fh;
-       struct nfs_vattr nvattr, *nvattrp;
+       fhandle_t *fh;
+       struct nfs_vattr *nvattr, *nvattrp;
        struct nfs_dir_buf_header *ndbhp;
        struct direntry *dp;
-       char *padstart, padlen;
+       char *padstart;
        const char *tag;
        uint32_t entry_attrs[NFS_ATTR_BITMAP_LEN];
        struct timeval now;
        struct nfsreq_secinfo_args si;
 
        nmp = NFSTONMP(dnp);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        nfsvers = nmp->nm_vers;
        nmreaddirsize = nmp->nm_readdirsize;
        nmrsize = nmp->nm_rsize;
        bigcookies = nmp->nm_state & NFSSTA_BIGCOOKIES;
        namedattr = (dnp->n_vattr.nva_flags & NFS_FFLAG_IS_ATTR) ? 1 : 0;
        rdirplus = (NMFLAG(nmp, RDIRPLUS) || namedattr) ? 1 : 0;
-       if (dnp->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL)
-               return (EINVAL);
+       if (dnp->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL) {
+               return EINVAL;
+       }
        NFSREQ_SECINFO_SET(&si, dnp, NULL, 0, NULL, 0);
 
        /*
@@ -764,15 +833,20 @@ nfs4_readdir_rpc(nfsnode_t dnp, struct nfsbuf *bp, vfs_context_t ctx)
        NFS_BITMAP_SET(entry_attrs, NFS_FATTR_RDATTR_ERROR);
 
        /* lock to protect access to cookie verifier */
-       if ((lockerror = nfs_node_lock(dnp)))
-               return (lockerror);
+       if ((lockerror = nfs_node_lock(dnp))) {
+               return lockerror;
+       }
+
+       fh = zalloc(nfs_fhandle_zone);
+       MALLOC(nvattr, struct nfs_vattr *, sizeof(*nvattr), M_TEMP, M_WAITOK);
 
        /* determine cookie to use, and move dp to the right offset */
        ndbhp = (struct nfs_dir_buf_header*)bp->nb_data;
        dp = NFS_DIR_BUF_FIRST_DIRENTRY(bp);
        if (ndbhp->ndbh_count) {
-               for (i=0; i < ndbhp->ndbh_count-1; i++)
+               for (i = 0; i < ndbhp->ndbh_count - 1; i++) {
                        dp = NFS_DIRENTRY_NEXT(dp);
+               }
                cookie = dp->d_seekoff;
                dp = NFS_DIRENTRY_NEXT(dp);
        } else {
@@ -789,16 +863,17 @@ nfs4_readdir_rpc(nfsnode_t dnp, struct nfsbuf *bp, vfs_context_t ctx)
         */
        if (((bp->nb_lblkno == 0) && (ndbhp->ndbh_count == 0)) &&
            !(dnp->n_vattr.nva_flags & NFS_FFLAG_IS_ATTR)) {
-               fh.fh_len = 0;
-               fhlen = rdirplus ? fh.fh_len + 1 : 0;
+               fh->fh_len = 0;
+               fhlen = rdirplus ? fh->fh_len + 1 : 0;
                xlen = rdirplus ? (fhlen + sizeof(time_t)) : 0;
                /* "." */
                namlen = 1;
-               reclen = NFS_DIRENTRY_LEN(namlen + xlen);
-               if (xlen)
-                       bzero(&dp->d_name[namlen+1], xlen);
+               reclen = NFS_DIRENTRY_LEN_16(namlen + xlen);
+               if (xlen) {
+                       bzero(&dp->d_name[namlen + 1], xlen);
+               }
                dp->d_namlen = namlen;
-               strlcpy(dp->d_name, ".", namlen+1);
+               strlcpy(dp->d_name, ".", namlen + 1);
                dp->d_fileno = dnp->n_vattr.nva_fileid;
                dp->d_type = DT_DIR;
                dp->d_reclen = reclen;
@@ -806,32 +881,38 @@ nfs4_readdir_rpc(nfsnode_t dnp, struct nfsbuf *bp, vfs_context_t ctx)
                padstart = dp->d_name + dp->d_namlen + 1 + xlen;
                dp = NFS_DIRENTRY_NEXT(dp);
                padlen = (char*)dp - padstart;
-               if (padlen > 0)
+               if (padlen > 0) {
                        bzero(padstart, padlen);
-               if (rdirplus) /* zero out attributes */
+               }
+               if (rdirplus) { /* zero out attributes */
                        bzero(NFS_DIR_BUF_NVATTR(bp, 0), sizeof(struct nfs_vattr));
+               }
 
                /* ".." */
                namlen = 2;
-               reclen = NFS_DIRENTRY_LEN(namlen + xlen);
-               if (xlen)
-                       bzero(&dp->d_name[namlen+1], xlen);
+               reclen = NFS_DIRENTRY_LEN_16(namlen + xlen);
+               if (xlen) {
+                       bzero(&dp->d_name[namlen + 1], xlen);
+               }
                dp->d_namlen = namlen;
-               strlcpy(dp->d_name, "..", namlen+1);
-               if (dnp->n_parent)
+               strlcpy(dp->d_name, "..", namlen + 1);
+               if (dnp->n_parent) {
                        dp->d_fileno = VTONFS(dnp->n_parent)->n_vattr.nva_fileid;
-               else
+               } else {
                        dp->d_fileno = dnp->n_vattr.nva_fileid;
+               }
                dp->d_type = DT_DIR;
                dp->d_reclen = reclen;
                dp->d_seekoff = 2;
                padstart = dp->d_name + dp->d_namlen + 1 + xlen;
                dp = NFS_DIRENTRY_NEXT(dp);
                padlen = (char*)dp - padstart;
-               if (padlen > 0)
+               if (padlen > 0) {
                        bzero(padstart, padlen);
-               if (rdirplus) /* zero out attributes */
+               }
+               if (rdirplus) { /* zero out attributes */
                        bzero(NFS_DIR_BUF_NVATTR(bp, 1), sizeof(struct nfs_vattr));
+               }
 
                ndbhp->ndbh_entry_end = (char*)dp - bp->nb_data;
                ndbhp->ndbh_count = 2;
@@ -845,11 +926,10 @@ nfs4_readdir_rpc(nfsnode_t dnp, struct nfsbuf *bp, vfs_context_t ctx)
        nfsm_chain_null(&nmreq);
        nfsm_chain_null(&nmrep);
        while (nfs_dir_buf_freespace(bp, rdirplus) && !(ndbhp->ndbh_flags & NDB_FULL)) {
-
                // PUTFH, GETATTR, READDIR
                numops = 3;
                nfsm_chain_build_alloc_init(error, &nmreq, 26 * NFSX_UNSIGNED);
-               nfsm_chain_add_compound_header(error, &nmreq, tag, numops);
+               nfsm_chain_add_compound_header(error, &nmreq, tag, nmp->nm_minor_vers, numops);
                numops--;
                nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
                nfsm_chain_add_fh(error, &nmreq, nfsvers, dnp->n_fhp, dnp->n_fhsize);
@@ -869,8 +949,9 @@ nfs4_readdir_rpc(nfsnode_t dnp, struct nfsbuf *bp, vfs_context_t ctx)
                nfsmout_if(error);
                error = nfs_request(dnp, NULL, &nmreq, NFSPROC4_COMPOUND, ctx, &si, &nmrep, &xid, &status);
 
-               if ((lockerror = nfs_node_lock(dnp)))
+               if ((lockerror = nfs_node_lock(dnp))) {
                        error = lockerror;
+               }
 
                savedxid = xid;
                nfsm_chain_skip_tag(error, &nmrep);
@@ -888,14 +969,24 @@ nfs4_readdir_rpc(nfsnode_t dnp, struct nfsbuf *bp, vfs_context_t ctx)
                }
                nfsmout_if(error);
 
-               if (rdirplus)
+               if (rdirplus) {
                        microuptime(&now);
+                       if (lastcookie == 0) {
+                               dnp->n_rdirplusstamp_sof = now.tv_sec;
+                               dnp->n_rdirplusstamp_eof = 0;
+                       }
+               }
 
                /* loop through the entries packing them into the buffer */
                while (more_entries) {
                        /* Entry: COOKIE, NAME, FATTR */
                        nfsm_chain_get_64(error, &nmrep, cookie);
-                       nfsm_chain_get_32(error, &nmrep, namlen);
+                       nfsm_chain_get_32(error, &nmrep, namlen32);
+                       if (namlen32 > UINT16_MAX) {
+                               error = EBADRPC;
+                               goto nfsmout;
+                       }
+                       namlen = (uint16_t)namlen32;
                        nfsmout_if(error);
                        if (!bigcookies && (cookie >> 32) && (nmp == NFSTONMP(dnp))) {
                                /* we've got a big cookie, make sure flag is set */
@@ -909,7 +1000,7 @@ nfs4_readdir_rpc(nfsnode_t dnp, struct nfsbuf *bp, vfs_context_t ctx)
                                error = EBADRPC;
                                goto nfsmout;
                        }
-                       if (namlen > (sizeof(dp->d_name)-1)) {
+                       if (namlen > (sizeof(dp->d_name) - 1)) {
                                skiplen = namlen - sizeof(dp->d_name) + 1;
                                namlen = sizeof(dp->d_name) - 1;
                        } else {
@@ -919,7 +1010,7 @@ nfs4_readdir_rpc(nfsnode_t dnp, struct nfsbuf *bp, vfs_context_t ctx)
                        fhlen = rdirplus ? (1 + dnp->n_fhsize) : 0;
                        xlen = rdirplus ? (fhlen + sizeof(time_t)) : 0;
                        attrlen = rdirplus ? sizeof(struct nfs_vattr) : 0;
-                       reclen = NFS_DIRENTRY_LEN(namlen + xlen);
+                       reclen = NFS_DIRENTRY_LEN_16(namlen + xlen);
                        space_needed = reclen + attrlen;
                        space_free = nfs_dir_buf_freespace(bp, rdirplus);
                        if (space_needed > space_free) {
@@ -957,12 +1048,13 @@ nextbuffer:
                        nfsm_chain_get_opaque(error, &nmrep, namlen, dp->d_name);
                        nfsmout_if(error);
                        dp->d_name[namlen] = '\0';
-                       if (skiplen)
+                       if (skiplen) {
                                nfsm_chain_adv(error, &nmrep,
-                                       nfsm_rndup(namlen + skiplen) - nfsm_rndup(namlen));
+                                   nfsm_rndup(namlen + skiplen) - nfsm_rndup(namlen));
+                       }
                        nfsmout_if(error);
-                       nvattrp = rdirplus ? NFS_DIR_BUF_NVATTR(bp, ndbhp->ndbh_count) : &nvattr;
-                       error = nfs4_parsefattr(&nmrep, NULL, nvattrp, &fh, NULL, NULL);
+                       nvattrp = rdirplus ? NFS_DIR_BUF_NVATTR(bp, ndbhp->ndbh_count) : nvattr;
+                       error = nfs4_parsefattr(&nmrep, NULL, nvattrp, fh, NULL, NULL);
                        if (!error && NFS_BITMAP_ISSET(nvattrp->nva_bitmap, NFS_FATTR_ACL)) {
                                /* we do NOT want ACLs returned to us here */
                                NFS_BITMAP_CLR(nvattrp->nva_bitmap, NFS_FATTR_ACL);
@@ -975,7 +1067,7 @@ nextbuffer:
                                /* OK, we may not have gotten all of the attributes but we will use what we can. */
                                if ((error == NFSERR_MOVED) || (error == NFSERR_INVAL)) {
                                        /* set this up to look like a referral trigger */
-                                       nfs4_default_attrs_for_referral_trigger(dnp, dp->d_name, namlen, nvattrp, &fh);
+                                       nfs4_default_attrs_for_referral_trigger(dnp, dp->d_name, namlen, nvattrp, fh);
                                }
                                error = 0;
                        }
@@ -991,17 +1083,20 @@ nextbuffer:
                                continue;
                        }
 
-                       if (NFS_BITMAP_ISSET(nvattrp->nva_bitmap, NFS_FATTR_TYPE))
+                       if (NFS_BITMAP_ISSET(nvattrp->nva_bitmap, NFS_FATTR_TYPE)) {
                                dp->d_type = IFTODT(VTTOIF(nvattrp->nva_type));
-                       if (NFS_BITMAP_ISSET(nvattrp->nva_bitmap, NFS_FATTR_FILEID))
+                       }
+                       if (NFS_BITMAP_ISSET(nvattrp->nva_bitmap, NFS_FATTR_FILEID)) {
                                dp->d_fileno = nvattrp->nva_fileid;
+                       }
                        if (rdirplus) {
                                /* fileid is already in d_fileno, so stash xid in attrs */
                                nvattrp->nva_fileid = savedxid;
+                               nvattrp->nva_flags |= NFS_FFLAG_FILEID_CONTAINS_XID;
                                if (NFS_BITMAP_ISSET(nvattrp->nva_bitmap, NFS_FATTR_FILEHANDLE)) {
-                                       fhlen = fh.fh_len + 1;
+                                       fhlen = fh->fh_len + 1;
                                        xlen = fhlen + sizeof(time_t);
-                                       reclen = NFS_DIRENTRY_LEN(namlen + xlen);
+                                       reclen = NFS_DIRENTRY_LEN_16(namlen + xlen);
                                        space_needed = reclen + attrlen;
                                        if (space_needed > space_free) {
                                                /* didn't actually have the room... move on to next buffer */
@@ -1009,18 +1104,19 @@ nextbuffer:
                                                goto nextbuffer;
                                        }
                                        /* pack the file handle into the record */
-                                       dp->d_name[dp->d_namlen+1] = fh.fh_len;
-                                       bcopy(fh.fh_data, &dp->d_name[dp->d_namlen+2], fh.fh_len);
+                                       dp->d_name[dp->d_namlen + 1] = (unsigned char)fh->fh_len; /* No truncation because fh_len's value is checked during nfs4_parsefattr() */
+                                       bcopy(fh->fh_data, &dp->d_name[dp->d_namlen + 2], fh->fh_len);
                                } else {
                                        /* mark the file handle invalid */
-                                       fh.fh_len = 0;
-                                       fhlen = fh.fh_len + 1;
+                                       fh->fh_len = 0;
+                                       fhlen = fh->fh_len + 1;
                                        xlen = fhlen + sizeof(time_t);
-                                       reclen = NFS_DIRENTRY_LEN(namlen + xlen);
-                                       bzero(&dp->d_name[dp->d_namlen+1], fhlen);
+                                       reclen = NFS_DIRENTRY_LEN_16(namlen + xlen);
+                                       bzero(&dp->d_name[dp->d_namlen + 1], fhlen);
                                }
-                               *(time_t*)(&dp->d_name[dp->d_namlen+1+fhlen]) = now.tv_sec;
+                               *(time_t*)(&dp->d_name[dp->d_namlen + 1 + fhlen]) = now.tv_sec;
                                dp->d_reclen = reclen;
+                               nfs_rdirplus_update_node_attrs(dnp, dp, fh, nvattrp, &savedxid);
                        }
                        padstart = dp->d_name + dp->d_namlen + 1 + xlen;
                        ndbhp->ndbh_count++;
@@ -1031,16 +1127,20 @@ nextbuffer:
                        ndbhp->ndbh_entry_end = (char*)dp - bp->nb_data;
                        /* zero out the pad bytes */
                        padlen = (char*)dp - padstart;
-                       if (padlen > 0)
+                       if (padlen > 0) {
                                bzero(padstart, padlen);
+                       }
                }
                /* Finally, get the eof boolean */
                nfsm_chain_get_32(error, &nmrep, eof);
                nfsmout_if(error);
                if (eof) {
-                       ndbhp->ndbh_flags |= (NDB_FULL|NDB_EOF);
+                       ndbhp->ndbh_flags |= (NDB_FULL | NDB_EOF);
                        nfs_node_lock_force(dnp);
                        dnp->n_eofcookie = lastcookie;
+                       if (rdirplus) {
+                               dnp->n_rdirplusstamp_eof = now.tv_sec;
+                       }
                        nfs_node_unlock(dnp);
                } else {
                        more_entries = 1;
@@ -1050,20 +1150,25 @@ nextbuffer:
                        bp = NULL;
                        break;
                }
-               if ((lockerror = nfs_node_lock(dnp)))
+               if ((lockerror = nfs_node_lock(dnp))) {
                        error = lockerror;
+               }
                nfsmout_if(error);
                nfsm_chain_cleanup(&nmrep);
                nfsm_chain_null(&nmreq);
        }
 nfsmout:
-       if (bp_dropped && bp)
+       if (bp_dropped && bp) {
                nfs_buf_release(bp, 0);
-       if (!lockerror)
+       }
+       if (!lockerror) {
                nfs_node_unlock(dnp);
+       }
        nfsm_chain_cleanup(&nmreq);
        nfsm_chain_cleanup(&nmrep);
-       return (bp_dropped ? NFSERR_DIRBUFDROPPED : error);
+       NFS_ZFREE(nfs_fhandle_zone, fh);
+       FREE(nvattr, M_TEMP);
+       return bp_dropped ? NFSERR_DIRBUFDROPPED : error;
 }
 
 int
@@ -1081,11 +1186,13 @@ nfs4_lookup_rpc_async(
        struct nfsreq_secinfo_args si;
 
        nmp = NFSTONMP(dnp);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        nfsvers = nmp->nm_vers;
-       if (dnp->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL)
-               return (EINVAL);
+       if (dnp->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL) {
+               return EINVAL;
+       }
 
        if ((name[0] == '.') && (name[1] == '.') && (namelen == 2)) {
                isdotdot = 1;
@@ -1099,7 +1206,7 @@ nfs4_lookup_rpc_async(
        // PUTFH, GETATTR, LOOKUP(P), GETFH, GETATTR (FH)
        numops = 5;
        nfsm_chain_build_alloc_init(error, &nmreq, 20 * NFSX_UNSIGNED + namelen);
-       nfsm_chain_add_compound_header(error, &nmreq, "lookup", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "lookup", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, nfsvers, dnp->n_fhp, dnp->n_fhsize);
@@ -1119,21 +1226,24 @@ nfs4_lookup_rpc_async(
        nfsm_chain_add_32(error, &nmreq, NFS_OP_GETATTR);
        NFS_COPY_ATTRIBUTES(nfs_getattr_bitmap, bitmap);
        /* some ".zfs" directories can't handle being asked for some attributes */
-       if ((dnp->n_flag & NISDOTZFS) && !isdotdot)
+       if ((dnp->n_flag & NISDOTZFS) && !isdotdot) {
                NFS_BITMAP_CLR(bitmap, NFS_FATTR_NAMED_ATTR);
-       if ((dnp->n_flag & NISDOTZFSCHILD) && isdotdot)
+       }
+       if ((dnp->n_flag & NISDOTZFSCHILD) && isdotdot) {
                NFS_BITMAP_CLR(bitmap, NFS_FATTR_NAMED_ATTR);
-       if (((namelen == 4) && (name[0] == '.') && (name[1] == 'z') && (name[2] == 'f') && (name[3] == 's')))
+       }
+       if (((namelen == 4) && (name[0] == '.') && (name[1] == 'z') && (name[2] == 'f') && (name[3] == 's'))) {
                NFS_BITMAP_CLR(bitmap, NFS_FATTR_NAMED_ATTR);
+       }
        nfsm_chain_add_bitmap_supported(error, &nmreq, bitmap, nmp, NULL);
        nfsm_chain_build_done(error, &nmreq);
        nfsm_assert(error, (numops == 0), EPROTO);
        nfsmout_if(error);
        error = nfs_request_async(dnp, NULL, &nmreq, NFSPROC4_COMPOUND,
-                       vfs_context_thread(ctx), vfs_context_ucred(ctx), &si, 0, NULL, reqp);
+           vfs_context_thread(ctx), vfs_context_ucred(ctx), &si, 0, NULL, reqp);
 nfsmout:
        nfsm_chain_cleanup(&nmreq);
-       return (error);
+       return error;
 }
 
 
@@ -1155,28 +1265,38 @@ nfs4_lookup_rpc_async_finish(
        struct nfsm_chain nmrep;
 
        nmp = NFSTONMP(dnp);
+       if (nmp == NULL) {
+               return ENXIO;
+       }
        nfsvers = nmp->nm_vers;
-       if ((name[0] == '.') && (name[1] == '.') && (namelen == 2))
+       if ((name[0] == '.') && (name[1] == '.') && (namelen == 2)) {
                isdotdot = 1;
+       }
 
        nfsm_chain_null(&nmrep);
 
        error = nfs_request_async_finish(req, &nmrep, &xid, &status);
 
-       if ((lockerror = nfs_node_lock(dnp)))
+       if ((lockerror = nfs_node_lock(dnp))) {
                error = lockerror;
+       }
        nfsm_chain_skip_tag(error, &nmrep);
        nfsm_chain_get_32(error, &nmrep, numops);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_PUTFH);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
-       if (xidp)
+       if (xidp) {
                *xidp = xid;
+       }
        nfsm_chain_loadattr(error, &nmrep, dnp, nfsvers, &xid);
 
        nfsm_chain_op_check(error, &nmrep, (isdotdot ? NFS_OP_LOOKUPP : NFS_OP_LOOKUP));
        nfsmout_if(error || !fhp || !nvap);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETFH);
        nfsm_chain_get_32(error, &nmrep, fhp->fh_len);
+       if (error == 0 && fhp->fh_len > sizeof(fhp->fh_data)) {
+               error = EBADRPC;
+       }
+       nfsmout_if(error);
        nfsm_chain_get_opaque(error, &nmrep, fhp->fh_len, fhp->fh_data);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
        if ((error == NFSERR_MOVED) || (error == NFSERR_INVAL)) {
@@ -1188,8 +1308,9 @@ nfs4_lookup_rpc_async_finish(
                error = nfs4_parsefattr(&nmrep, NULL, nvap, NULL, NULL, NULL);
        }
 nfsmout:
-       if (!lockerror)
+       if (!lockerror) {
                nfs_node_unlock(dnp);
+       }
        nfsm_chain_cleanup(&nmrep);
        if (!error && (op == NFS_OP_LOOKUP) && (nmp->nm_state & NFSSTA_NEEDSECINFO)) {
                /* We still need to get SECINFO to set default for mount. */
@@ -1199,18 +1320,20 @@ nfsmout:
                sec.count = NX_MAX_SEC_FLAVORS;
                error = nfs4_secinfo_rpc(nmp, &req->r_secinfo, vfs_context_ucred(ctx), sec.flavors, &sec.count);
                /* [sigh] some implementations return "illegal" error for unsupported ops */
-               if (error == NFSERR_OP_ILLEGAL)
+               if (error == NFSERR_OP_ILLEGAL) {
                        error = 0;
+               }
                if (!error) {
                        /* set our default security flavor to the first in the list */
                        lck_mtx_lock(&nmp->nm_lock);
-                       if (sec.count)
+                       if (sec.count) {
                                nmp->nm_auth = sec.flavors[0];
+                       }
                        nmp->nm_state &= ~NFSSTA_NEEDSECINFO;
                        lck_mtx_unlock(&nmp->nm_lock);
                }
        }
-       return (error);
+       return error;
 }
 
 int
@@ -1230,18 +1353,17 @@ nfs4_commit_rpc(
 
        nmp = NFSTONMP(np);
        FSDBG(521, np, offset, count, nmp ? nmp->nm_state : 0);
-       if (!nmp)
-               return (ENXIO);
-       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL)
-               return (EINVAL);
-       if (!(nmp->nm_state & NFSSTA_HASWRITEVERF))
-               return (0);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
+       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL) {
+               return EINVAL;
+       }
+       if (!(nmp->nm_state & NFSSTA_HASWRITEVERF)) {
+               return 0;
+       }
        nfsvers = nmp->nm_vers;
-
-       if (count > UINT32_MAX)
-               count32 = 0;
-       else
-               count32 = count;
+       count32 = count > UINT32_MAX ? 0 : (uint32_t)count;
 
        NFSREQ_SECINFO_SET(&si, np, NULL, 0, NULL, 0);
        nfsm_chain_null(&nmreq);
@@ -1250,7 +1372,7 @@ nfs4_commit_rpc(
        // PUTFH, COMMIT, GETATTR
        numops = 3;
        nfsm_chain_build_alloc_init(error, &nmreq, 19 * NFSX_UNSIGNED);
-       nfsm_chain_add_compound_header(error, &nmreq, "commit", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "commit", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, nfsvers, np->n_fhp, np->n_fhsize);
@@ -1265,10 +1387,11 @@ nfs4_commit_rpc(
        nfsm_assert(error, (numops == 0), EPROTO);
        nfsmout_if(error);
        error = nfs_request2(np, NULL, &nmreq, NFSPROC4_COMPOUND,
-                       current_thread(), cred, &si, 0, &nmrep, &xid, &status);
+           current_thread(), cred, &si, 0, &nmrep, &xid, &status);
 
-       if ((lockerror = nfs_node_lock(np)))
+       if ((lockerror = nfs_node_lock(np))) {
                error = lockerror;
+       }
        nfsm_chain_skip_tag(error, &nmrep);
        nfsm_chain_get_32(error, &nmrep, numops);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_PUTFH);
@@ -1276,19 +1399,22 @@ nfs4_commit_rpc(
        nfsm_chain_get_64(error, &nmrep, newwverf);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
        nfsm_chain_loadattr(error, &nmrep, np, nfsvers, &xid);
-       if (!lockerror)
+       if (!lockerror) {
                nfs_node_unlock(np);
+       }
        nfsmout_if(error);
        lck_mtx_lock(&nmp->nm_lock);
-       if (nmp->nm_verf != newwverf)
+       if (nmp->nm_verf != newwverf) {
                nmp->nm_verf = newwverf;
-       if (wverf != newwverf)
+       }
+       if (wverf != newwverf) {
                error = NFSERR_STALEWRITEVERF;
+       }
        lck_mtx_unlock(&nmp->nm_lock);
 nfsmout:
        nfsm_chain_cleanup(&nmreq);
        nfsm_chain_cleanup(&nmrep);
-       return (error);
+       return error;
 }
 
 int
@@ -1302,17 +1428,20 @@ nfs4_pathconf_rpc(
        struct nfsm_chain nmreq, nmrep;
        struct nfsmount *nmp = NFSTONMP(np);
        uint32_t bitmap[NFS_ATTR_BITMAP_LEN];
-       struct nfs_vattr nvattr;
+       struct nfs_vattr *nvattr;
        struct nfsreq_secinfo_args si;
 
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        nfsvers = nmp->nm_vers;
-       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL)
-               return (EINVAL);
+       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL) {
+               return EINVAL;
+       }
 
        NFSREQ_SECINFO_SET(&si, np, NULL, 0, NULL, 0);
-       NVATTR_INIT(&nvattr);
+       MALLOC(nvattr, struct nfs_vattr *, sizeof(*nvattr), M_TEMP, M_WAITOK);
+       NVATTR_INIT(nvattr);
        nfsm_chain_null(&nmreq);
        nfsm_chain_null(&nmrep);
 
@@ -1320,7 +1449,7 @@ nfs4_pathconf_rpc(
        // PUTFH, GETATTR
        numops = 2;
        nfsm_chain_build_alloc_init(error, &nmreq, 16 * NFSX_UNSIGNED);
-       nfsm_chain_add_compound_header(error, &nmreq, "pathconf", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "pathconf", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, nfsvers, np->n_fhp, np->n_fhsize);
@@ -1344,128 +1473,152 @@ nfs4_pathconf_rpc(
        nfsm_chain_op_check(error, &nmrep, NFS_OP_PUTFH);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
        nfsmout_if(error);
-       error = nfs4_parsefattr(&nmrep, nfsap, &nvattr, NULL, NULL, NULL);
+       error = nfs4_parsefattr(&nmrep, nfsap, nvattr, NULL, NULL, NULL);
        nfsmout_if(error);
-       if ((lockerror = nfs_node_lock(np)))
+       if ((lockerror = nfs_node_lock(np))) {
                error = lockerror;
-       if (!error)
-               nfs_loadattrcache(np, &nvattr, &xid, 0);
-       if (!lockerror)
+       }
+       if (!error) {
+               nfs_loadattrcache(np, nvattr, &xid, 0);
+       }
+       if (!lockerror) {
                nfs_node_unlock(np);
+       }
 nfsmout:
-       NVATTR_CLEANUP(&nvattr);
+       NVATTR_CLEANUP(nvattr);
+       FREE(nvattr, M_TEMP);
        nfsm_chain_cleanup(&nmreq);
        nfsm_chain_cleanup(&nmrep);
-       return (error);
+       return error;
 }
 
 int
 nfs4_vnop_getattr(
        struct vnop_getattr_args /* {
-               struct vnodeop_desc *a_desc;
-               vnode_t a_vp;
-               struct vnode_attr *a_vap;
-               vfs_context_t a_context;
-       } */ *ap)
+                                  *  struct vnodeop_desc *a_desc;
+                                  *  vnode_t a_vp;
+                                  *  struct vnode_attr *a_vap;
+                                  *  vfs_context_t a_context;
+                                  *  } */*ap)
 {
        struct vnode_attr *vap = ap->a_vap;
        struct nfsmount *nmp;
-       struct nfs_vattr nva;
+       struct nfs_vattr *nva;
        int error, acls, ngaflags;
 
-       if (!(nmp = VTONMP(ap->a_vp)))
-               return (ENXIO);
+       nmp = VTONMP(ap->a_vp);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        acls = (nmp->nm_fsattr.nfsa_flags & NFS_FSFLAG_ACL);
 
        ngaflags = NGA_CACHED;
-       if (VATTR_IS_ACTIVE(vap, va_acl) && acls)
+       if (VATTR_IS_ACTIVE(vap, va_acl) && acls) {
                ngaflags |= NGA_ACL;
-       error = nfs_getattr(VTONFS(ap->a_vp), &nva, ap->a_context, ngaflags);
-       if (error)
-               return (error);
+       }
+       MALLOC(nva, struct nfs_vattr *, sizeof(*nva), M_TEMP, M_WAITOK);
+       error = nfs_getattr(VTONFS(ap->a_vp), nva, ap->a_context, ngaflags);
+       if (error) {
+               goto out;
+       }
 
        /* copy what we have in nva to *a_vap */
-       if (VATTR_IS_ACTIVE(vap, va_rdev) && NFS_BITMAP_ISSET(nva.nva_bitmap, NFS_FATTR_RAWDEV)) {
-               dev_t rdev = makedev(nva.nva_rawdev.specdata1, nva.nva_rawdev.specdata2);
+       if (VATTR_IS_ACTIVE(vap, va_rdev) && NFS_BITMAP_ISSET(nva->nva_bitmap, NFS_FATTR_RAWDEV)) {
+               dev_t rdev = makedev(nva->nva_rawdev.specdata1, nva->nva_rawdev.specdata2);
                VATTR_RETURN(vap, va_rdev, rdev);
        }
-       if (VATTR_IS_ACTIVE(vap, va_nlink) && NFS_BITMAP_ISSET(nva.nva_bitmap, NFS_FATTR_NUMLINKS))
-               VATTR_RETURN(vap, va_nlink, nva.nva_nlink);
-       if (VATTR_IS_ACTIVE(vap, va_data_size) && NFS_BITMAP_ISSET(nva.nva_bitmap, NFS_FATTR_SIZE))
-               VATTR_RETURN(vap, va_data_size, nva.nva_size);
+       if (VATTR_IS_ACTIVE(vap, va_nlink) && NFS_BITMAP_ISSET(nva->nva_bitmap, NFS_FATTR_NUMLINKS)) {
+               VATTR_RETURN(vap, va_nlink, nva->nva_nlink);
+       }
+       if (VATTR_IS_ACTIVE(vap, va_data_size) && NFS_BITMAP_ISSET(nva->nva_bitmap, NFS_FATTR_SIZE)) {
+               VATTR_RETURN(vap, va_data_size, nva->nva_size);
+       }
        // VATTR_RETURN(vap, va_data_alloc, ???);
        // VATTR_RETURN(vap, va_total_size, ???);
-       if (VATTR_IS_ACTIVE(vap, va_total_alloc) && NFS_BITMAP_ISSET(nva.nva_bitmap, NFS_FATTR_SPACE_USED))
-               VATTR_RETURN(vap, va_total_alloc, nva.nva_bytes);
-       if (VATTR_IS_ACTIVE(vap, va_uid) && NFS_BITMAP_ISSET(nva.nva_bitmap, NFS_FATTR_OWNER))
-               VATTR_RETURN(vap, va_uid, nva.nva_uid);
-       if (VATTR_IS_ACTIVE(vap, va_uuuid) && NFS_BITMAP_ISSET(nva.nva_bitmap, NFS_FATTR_OWNER))
-               VATTR_RETURN(vap, va_uuuid, nva.nva_uuuid);
-       if (VATTR_IS_ACTIVE(vap, va_gid) && NFS_BITMAP_ISSET(nva.nva_bitmap, NFS_FATTR_OWNER_GROUP))
-               VATTR_RETURN(vap, va_gid, nva.nva_gid);
-       if (VATTR_IS_ACTIVE(vap, va_guuid) && NFS_BITMAP_ISSET(nva.nva_bitmap, NFS_FATTR_OWNER_GROUP))
-               VATTR_RETURN(vap, va_guuid, nva.nva_guuid);
+       if (VATTR_IS_ACTIVE(vap, va_total_alloc) && NFS_BITMAP_ISSET(nva->nva_bitmap, NFS_FATTR_SPACE_USED)) {
+               VATTR_RETURN(vap, va_total_alloc, nva->nva_bytes);
+       }
+       if (VATTR_IS_ACTIVE(vap, va_uid) && NFS_BITMAP_ISSET(nva->nva_bitmap, NFS_FATTR_OWNER)) {
+               VATTR_RETURN(vap, va_uid, nva->nva_uid);
+       }
+       if (VATTR_IS_ACTIVE(vap, va_uuuid) && NFS_BITMAP_ISSET(nva->nva_bitmap, NFS_FATTR_OWNER)) {
+               VATTR_RETURN(vap, va_uuuid, nva->nva_uuuid);
+       }
+       if (VATTR_IS_ACTIVE(vap, va_gid) && NFS_BITMAP_ISSET(nva->nva_bitmap, NFS_FATTR_OWNER_GROUP)) {
+               VATTR_RETURN(vap, va_gid, nva->nva_gid);
+       }
+       if (VATTR_IS_ACTIVE(vap, va_guuid) && NFS_BITMAP_ISSET(nva->nva_bitmap, NFS_FATTR_OWNER_GROUP)) {
+               VATTR_RETURN(vap, va_guuid, nva->nva_guuid);
+       }
        if (VATTR_IS_ACTIVE(vap, va_mode)) {
-               if (NMFLAG(nmp, ACLONLY) || !NFS_BITMAP_ISSET(nva.nva_bitmap, NFS_FATTR_MODE))
-                       VATTR_RETURN(vap, va_mode, 0777);
-               else
-                       VATTR_RETURN(vap, va_mode, nva.nva_mode);
+               if (NMFLAG(nmp, ACLONLY) || !NFS_BITMAP_ISSET(nva->nva_bitmap, NFS_FATTR_MODE)) {
+                       VATTR_RETURN(vap, va_mode, ACCESSPERMS);
+               } else {
+                       VATTR_RETURN(vap, va_mode, nva->nva_mode);
+               }
        }
        if (VATTR_IS_ACTIVE(vap, va_flags) &&
-           (NFS_BITMAP_ISSET(nva.nva_bitmap, NFS_FATTR_ARCHIVE) ||
-            NFS_BITMAP_ISSET(nva.nva_bitmap, NFS_FATTR_HIDDEN) ||
-            (nva.nva_flags & NFS_FFLAG_TRIGGER))) {
+           (NFS_BITMAP_ISSET(nva->nva_bitmap, NFS_FATTR_ARCHIVE) ||
+           NFS_BITMAP_ISSET(nva->nva_bitmap, NFS_FATTR_HIDDEN) ||
+           (nva->nva_flags & NFS_FFLAG_TRIGGER))) {
                uint32_t flags = 0;
-               if (NFS_BITMAP_ISSET(nva.nva_bitmap, NFS_FATTR_ARCHIVE) &&
-                   (nva.nva_flags & NFS_FFLAG_ARCHIVED))
+               if (NFS_BITMAP_ISSET(nva->nva_bitmap, NFS_FATTR_ARCHIVE) &&
+                   (nva->nva_flags & NFS_FFLAG_ARCHIVED)) {
                        flags |= SF_ARCHIVED;
-               if (NFS_BITMAP_ISSET(nva.nva_bitmap, NFS_FATTR_HIDDEN) &&
-                   (nva.nva_flags & NFS_FFLAG_HIDDEN))
+               }
+               if (NFS_BITMAP_ISSET(nva->nva_bitmap, NFS_FATTR_HIDDEN) &&
+                   (nva->nva_flags & NFS_FFLAG_HIDDEN)) {
                        flags |= UF_HIDDEN;
+               }
                VATTR_RETURN(vap, va_flags, flags);
        }
-       if (VATTR_IS_ACTIVE(vap, va_create_time) && NFS_BITMAP_ISSET(nva.nva_bitmap, NFS_FATTR_TIME_CREATE)) {
-               vap->va_create_time.tv_sec = nva.nva_timesec[NFSTIME_CREATE];
-               vap->va_create_time.tv_nsec = nva.nva_timensec[NFSTIME_CREATE];
+       if (VATTR_IS_ACTIVE(vap, va_create_time) && NFS_BITMAP_ISSET(nva->nva_bitmap, NFS_FATTR_TIME_CREATE)) {
+               vap->va_create_time.tv_sec = nva->nva_timesec[NFSTIME_CREATE];
+               vap->va_create_time.tv_nsec = nva->nva_timensec[NFSTIME_CREATE];
                VATTR_SET_SUPPORTED(vap, va_create_time);
        }
-       if (VATTR_IS_ACTIVE(vap, va_access_time) && NFS_BITMAP_ISSET(nva.nva_bitmap, NFS_FATTR_TIME_ACCESS)) {
-               vap->va_access_time.tv_sec = nva.nva_timesec[NFSTIME_ACCESS];
-               vap->va_access_time.tv_nsec = nva.nva_timensec[NFSTIME_ACCESS];
+       if (VATTR_IS_ACTIVE(vap, va_access_time) && NFS_BITMAP_ISSET(nva->nva_bitmap, NFS_FATTR_TIME_ACCESS)) {
+               vap->va_access_time.tv_sec = nva->nva_timesec[NFSTIME_ACCESS];
+               vap->va_access_time.tv_nsec = nva->nva_timensec[NFSTIME_ACCESS];
                VATTR_SET_SUPPORTED(vap, va_access_time);
        }
-       if (VATTR_IS_ACTIVE(vap, va_modify_time) && NFS_BITMAP_ISSET(nva.nva_bitmap, NFS_FATTR_TIME_MODIFY)) {
-               vap->va_modify_time.tv_sec = nva.nva_timesec[NFSTIME_MODIFY];
-               vap->va_modify_time.tv_nsec = nva.nva_timensec[NFSTIME_MODIFY];
+       if (VATTR_IS_ACTIVE(vap, va_modify_time) && NFS_BITMAP_ISSET(nva->nva_bitmap, NFS_FATTR_TIME_MODIFY)) {
+               vap->va_modify_time.tv_sec = nva->nva_timesec[NFSTIME_MODIFY];
+               vap->va_modify_time.tv_nsec = nva->nva_timensec[NFSTIME_MODIFY];
                VATTR_SET_SUPPORTED(vap, va_modify_time);
        }
-       if (VATTR_IS_ACTIVE(vap, va_change_time) && NFS_BITMAP_ISSET(nva.nva_bitmap, NFS_FATTR_TIME_METADATA)) {
-               vap->va_change_time.tv_sec = nva.nva_timesec[NFSTIME_CHANGE];
-               vap->va_change_time.tv_nsec = nva.nva_timensec[NFSTIME_CHANGE];
+       if (VATTR_IS_ACTIVE(vap, va_change_time) && NFS_BITMAP_ISSET(nva->nva_bitmap, NFS_FATTR_TIME_METADATA)) {
+               vap->va_change_time.tv_sec = nva->nva_timesec[NFSTIME_CHANGE];
+               vap->va_change_time.tv_nsec = nva->nva_timensec[NFSTIME_CHANGE];
                VATTR_SET_SUPPORTED(vap, va_change_time);
        }
-       if (VATTR_IS_ACTIVE(vap, va_backup_time) && NFS_BITMAP_ISSET(nva.nva_bitmap, NFS_FATTR_TIME_BACKUP)) {
-               vap->va_backup_time.tv_sec = nva.nva_timesec[NFSTIME_BACKUP];
-               vap->va_backup_time.tv_nsec = nva.nva_timensec[NFSTIME_BACKUP];
+       if (VATTR_IS_ACTIVE(vap, va_backup_time) && NFS_BITMAP_ISSET(nva->nva_bitmap, NFS_FATTR_TIME_BACKUP)) {
+               vap->va_backup_time.tv_sec = nva->nva_timesec[NFSTIME_BACKUP];
+               vap->va_backup_time.tv_nsec = nva->nva_timensec[NFSTIME_BACKUP];
                VATTR_SET_SUPPORTED(vap, va_backup_time);
        }
-       if (VATTR_IS_ACTIVE(vap, va_fileid) && NFS_BITMAP_ISSET(nva.nva_bitmap, NFS_FATTR_FILEID))
-               VATTR_RETURN(vap, va_fileid, nva.nva_fileid);
-       if (VATTR_IS_ACTIVE(vap, va_type) && NFS_BITMAP_ISSET(nva.nva_bitmap, NFS_FATTR_TYPE))
-               VATTR_RETURN(vap, va_type, nva.nva_type);
-       if (VATTR_IS_ACTIVE(vap, va_filerev) && NFS_BITMAP_ISSET(nva.nva_bitmap, NFS_FATTR_CHANGE))
-               VATTR_RETURN(vap, va_filerev, nva.nva_change);
+       if (VATTR_IS_ACTIVE(vap, va_fileid) && NFS_BITMAP_ISSET(nva->nva_bitmap, NFS_FATTR_FILEID)) {
+               VATTR_RETURN(vap, va_fileid, nva->nva_fileid);
+       }
+       if (VATTR_IS_ACTIVE(vap, va_type) && NFS_BITMAP_ISSET(nva->nva_bitmap, NFS_FATTR_TYPE)) {
+               VATTR_RETURN(vap, va_type, nva->nva_type);
+       }
+       if (VATTR_IS_ACTIVE(vap, va_filerev) && NFS_BITMAP_ISSET(nva->nva_bitmap, NFS_FATTR_CHANGE)) {
+               VATTR_RETURN(vap, va_filerev, nva->nva_change);
+       }
 
        if (VATTR_IS_ACTIVE(vap, va_acl) && acls) {
-               VATTR_RETURN(vap, va_acl, nva.nva_acl);
-               nva.nva_acl = NULL;
+               VATTR_RETURN(vap, va_acl, nva->nva_acl);
+               nva->nva_acl = NULL;
        }
 
        // other attrs we might support someday:
        // VATTR_RETURN(vap, va_encoding, ??? /* potentially unnormalized UTF-8? */);
 
-       NVATTR_CLEANUP(&nva);
-       return (error);
+       NVATTR_CLEANUP(nva);
+out:
+       FREE(nva, M_TEMP);
+       return error;
 }
 
 int
@@ -1484,35 +1637,43 @@ nfs4_setattr_rpc(
        nfs_stateid stateid;
        struct nfsreq_secinfo_args si;
 
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        nfsvers = nmp->nm_vers;
-       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL)
-               return (EINVAL);
+       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL) {
+               return EINVAL;
+       }
 
-       if (VATTR_IS_ACTIVE(vap, va_flags) && (vap->va_flags & ~(SF_ARCHIVED|UF_HIDDEN))) {
+       if (VATTR_IS_ACTIVE(vap, va_flags) && (vap->va_flags & ~(SF_ARCHIVED | UF_HIDDEN))) {
                /* we don't support setting unsupported flags (duh!) */
-               if (vap->va_active & ~VNODE_ATTR_va_flags)
-                       return (EINVAL);        /* return EINVAL if other attributes also set */
-               else
-                       return (ENOTSUP);       /* return ENOTSUP for chflags(2) */
+               if (vap->va_active & ~VNODE_ATTR_va_flags) {
+                       return EINVAL;        /* return EINVAL if other attributes also set */
+               } else {
+                       return ENOTSUP;       /* return ENOTSUP for chflags(2) */
+               }
        }
 
        /* don't bother requesting some changes if they don't look like they are changing */
-       if (VATTR_IS_ACTIVE(vap, va_uid) && (vap->va_uid == np->n_vattr.nva_uid))
+       if (VATTR_IS_ACTIVE(vap, va_uid) && (vap->va_uid == np->n_vattr.nva_uid)) {
                VATTR_CLEAR_ACTIVE(vap, va_uid);
-       if (VATTR_IS_ACTIVE(vap, va_gid) && (vap->va_gid == np->n_vattr.nva_gid))
+       }
+       if (VATTR_IS_ACTIVE(vap, va_gid) && (vap->va_gid == np->n_vattr.nva_gid)) {
                VATTR_CLEAR_ACTIVE(vap, va_gid);
-       if (VATTR_IS_ACTIVE(vap, va_uuuid) && kauth_guid_equal(&vap->va_uuuid, &np->n_vattr.nva_uuuid))
+       }
+       if (VATTR_IS_ACTIVE(vap, va_uuuid) && kauth_guid_equal(&vap->va_uuuid, &np->n_vattr.nva_uuuid)) {
                VATTR_CLEAR_ACTIVE(vap, va_uuuid);
-       if (VATTR_IS_ACTIVE(vap, va_guuid) && kauth_guid_equal(&vap->va_guuid, &np->n_vattr.nva_guuid))
+       }
+       if (VATTR_IS_ACTIVE(vap, va_guuid) && kauth_guid_equal(&vap->va_guuid, &np->n_vattr.nva_guuid)) {
                VATTR_CLEAR_ACTIVE(vap, va_guuid);
+       }
 
 tryagain:
        /* do nothing if no attributes will be sent */
        nfs_vattr_set_bitmap(nmp, bitmap, vap);
-       if (!bitmap[0] && !bitmap[1])
-               return (0);
+       if (!bitmap[0] && !bitmap[1]) {
+               return 0;
+       }
 
        NFSREQ_SECINFO_SET(&si, np, NULL, 0, NULL, 0);
        nfsm_chain_null(&nmreq);
@@ -1526,24 +1687,26 @@ tryagain:
        NFS_COPY_ATTRIBUTES(nfs_getattr_bitmap, getbitmap);
        if (NFS_BITMAP_ISSET(bitmap, NFS_FATTR_ACL) ||
            NFS_BITMAP_ISSET(bitmap, NFS_FATTR_MODE)) {
-               if (NACLVALID(np))
+               if (NACLVALID(np)) {
                        NFS_BITMAP_SET(getbitmap, NFS_FATTR_ACL);
+               }
                NACLINVALIDATE(np);
        }
 
        // PUTFH, SETATTR, GETATTR
        numops = 3;
        nfsm_chain_build_alloc_init(error, &nmreq, 40 * NFSX_UNSIGNED);
-       nfsm_chain_add_compound_header(error, &nmreq, "setattr", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "setattr", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, nfsvers, np->n_fhp, np->n_fhsize);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_SETATTR);
-       if (VATTR_IS_ACTIVE(vap, va_data_size))
+       if (VATTR_IS_ACTIVE(vap, va_data_size)) {
                nfs_get_stateid(np, vfs_context_thread(ctx), vfs_context_ucred(ctx), &stateid);
-       else
+       } else {
                stateid.seqid = stateid.other[0] = stateid.other[1] = stateid.other[2] = 0;
+       }
        nfsm_chain_add_stateid(error, &nmreq, &stateid);
        nfsm_chain_add_fattr4(error, &nmreq, vap, nmp);
        numops--;
@@ -1554,8 +1717,9 @@ tryagain:
        nfsmout_if(error);
        error = nfs_request(np, NULL, &nmreq, NFSPROC4_COMPOUND, ctx, &si, &nmrep, &xid, &status);
 
-       if ((lockerror = nfs_node_lock(np)))
+       if ((lockerror = nfs_node_lock(np))) {
                error = lockerror;
+       }
        nfsm_chain_skip_tag(error, &nmrep);
        nfsm_chain_get_32(error, &nmrep, numops);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_PUTFH);
@@ -1567,15 +1731,17 @@ tryagain:
        bmlen = NFS_ATTR_BITMAP_LEN;
        nfsm_chain_get_bitmap(error, &nmrep, setbitmap, bmlen);
        if (!error) {
-               if (VATTR_IS_ACTIVE(vap, va_data_size) && (np->n_vattr.nva_flags & NFS_FFLAG_IS_ATTR))
+               if (VATTR_IS_ACTIVE(vap, va_data_size) && (np->n_vattr.nva_flags & NFS_FFLAG_IS_ATTR)) {
                        microuptime(&np->n_lastio);
+               }
                nfs_vattr_set_supported(setbitmap, vap);
                error = setattr_error;
        }
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
        nfsm_chain_loadattr(error, &nmrep, np, nfsvers, &xid);
-       if (error)
+       if (error) {
                NATTRINVALIDATE(np);
+       }
        /*
         * We just changed the attributes and we want to make sure that we
         * see the latest attributes.  Get the next XID.  If it's not the
@@ -1592,8 +1758,9 @@ tryagain:
                NATTRINVALIDATE(np);
        }
 nfsmout:
-       if (!lockerror)
+       if (!lockerror) {
                nfs_node_unlock(np);
+       }
        nfsm_chain_cleanup(&nmreq);
        nfsm_chain_cleanup(&nmrep);
        if ((setattr_error == EINVAL) && VATTR_IS_ACTIVE(vap, va_acl) && VATTR_IS_ACTIVE(vap, va_mode) && !NMFLAG(nmp, ACLONLY)) {
@@ -1604,14 +1771,15 @@ nfsmout:
                 * but mode was already successfully set).
                 */
                if (((bitmap[0] & setbitmap[0]) != bitmap[0]) ||
-                   ((bitmap[1] & (setbitmap[1]|NFS_FATTR_MODE)) != bitmap[1])) {
+                   ((bitmap[1] & (setbitmap[1] | NFS_FATTR_MODE)) != bitmap[1])) {
                        VATTR_CLEAR_ACTIVE(vap, va_mode);
                        error = 0;
                        goto tryagain;
                }
        }
-       return (error);
+       return error;
 }
+#endif /* CONFIG_NFS4 */
 
 /*
  * Wait for any pending recovery to complete.
@@ -1619,20 +1787,21 @@ nfsmout:
 int
 nfs_mount_state_wait_for_recovery(struct nfsmount *nmp)
 {
-       struct timespec ts = { 1, 0 };
+       struct timespec ts = { .tv_sec = 1, .tv_nsec = 0 };
        int error = 0, slpflag = NMFLAG(nmp, INTR) ? PCATCH : 0;
 
        lck_mtx_lock(&nmp->nm_lock);
        while (nmp->nm_state & NFSSTA_RECOVER) {
-               if ((error = nfs_sigintr(nmp, NULL, current_thread(), 1)))
+               if ((error = nfs_sigintr(nmp, NULL, current_thread(), 1))) {
                        break;
+               }
                nfs_mount_sock_thread_wake(nmp);
-               msleep(&nmp->nm_state, &nmp->nm_lock, slpflag|(PZERO-1), "nfsrecoverwait", &ts);
+               msleep(&nmp->nm_state, &nmp->nm_lock, slpflag | (PZERO - 1), "nfsrecoverwait", &ts);
                slpflag = 0;
        }
        lck_mtx_unlock(&nmp->nm_lock);
 
-       return (error);
+       return error;
 }
 
 /*
@@ -1644,28 +1813,31 @@ nfs_mount_state_wait_for_recovery(struct nfsmount *nmp)
 int
 nfs_mount_state_in_use_start(struct nfsmount *nmp, thread_t thd)
 {
-       struct timespec ts = { 1, 0 };
+       struct timespec ts = { .tv_sec = 1, .tv_nsec = 0 };
        int error = 0, slpflag = (NMFLAG(nmp, INTR) && thd) ? PCATCH : 0;
 
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        lck_mtx_lock(&nmp->nm_lock);
-       if (nmp->nm_state & (NFSSTA_FORCE|NFSSTA_DEAD)) {
+       if (nmp->nm_state & (NFSSTA_FORCE | NFSSTA_DEAD)) {
                lck_mtx_unlock(&nmp->nm_lock);
-               return (ENXIO);
+               return ENXIO;
        }
        while (nmp->nm_state & NFSSTA_RECOVER) {
-               if ((error = nfs_sigintr(nmp, NULL, thd, 1)))
+               if ((error = nfs_sigintr(nmp, NULL, thd, 1))) {
                        break;
+               }
                nfs_mount_sock_thread_wake(nmp);
-               msleep(&nmp->nm_state, &nmp->nm_lock, slpflag|(PZERO-1), "nfsrecoverwait", &ts);
+               msleep(&nmp->nm_state, &nmp->nm_lock, slpflag | (PZERO - 1), "nfsrecoverwait", &ts);
                slpflag = 0;
        }
-       if (!error)
+       if (!error) {
                nmp->nm_stateinuse++;
+       }
        lck_mtx_unlock(&nmp->nm_lock);
 
-       return (error);
+       return error;
 }
 
 /*
@@ -1678,25 +1850,29 @@ nfs_mount_state_in_use_end(struct nfsmount *nmp, int error)
 {
        int restart = nfs_mount_state_error_should_restart(error);
 
-       if (!nmp)
-               return (restart);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        lck_mtx_lock(&nmp->nm_lock);
        if (restart && (error != NFSERR_OLD_STATEID) && (error != NFSERR_GRACE)) {
                printf("nfs_mount_state_in_use_end: error %d, initiating recovery for %s, 0x%x\n",
-                       error, vfs_statfs(nmp->nm_mountp)->f_mntfromname, nmp->nm_stategenid);
+                   error, vfs_statfs(nmp->nm_mountp)->f_mntfromname, nmp->nm_stategenid);
                nfs_need_recover(nmp, error);
        }
-       if (nmp->nm_stateinuse > 0)
+       if (nmp->nm_stateinuse > 0) {
                nmp->nm_stateinuse--;
-       else
+       } else {
                panic("NFS mount state in use count underrun");
-       if (!nmp->nm_stateinuse && (nmp->nm_state & NFSSTA_RECOVER))
+       }
+       if (!nmp->nm_stateinuse && (nmp->nm_state & NFSSTA_RECOVER)) {
                wakeup(&nmp->nm_stateinuse);
+       }
        lck_mtx_unlock(&nmp->nm_lock);
-       if (error == NFSERR_GRACE)
-               tsleep(&nmp->nm_state, (PZERO-1), "nfsgrace", 2*hz);
+       if (error == NFSERR_GRACE) {
+               tsleep(&nmp->nm_state, (PZERO - 1), "nfsgrace", 2 * hz);
+       }
 
-       return (restart);
+       return restart;
 }
 
 /*
@@ -1713,9 +1889,9 @@ nfs_mount_state_error_should_restart(int error)
        case NFSERR_OLD_STATEID:
        case NFSERR_BAD_STATEID:
        case NFSERR_GRACE:
-               return (1);
+               return 1;
        }
-       return (0);
+       return 0;
 }
 
 /*
@@ -1726,7 +1902,7 @@ nfs_mount_state_error_should_restart(int error)
 uint
 nfs_mount_state_max_restarts(struct nfsmount *nmp)
 {
-       return (MAX(nmp->nm_fsattr.nfsa_lease, 60));
+       return MAX(nmp->nm_fsattr.nfsa_lease, 60);
 }
 
 /*
@@ -1742,9 +1918,9 @@ nfs_mount_state_error_delegation_lost(int error)
        case NFSERR_OLD_STATEID:
        case NFSERR_BAD_STATEID:
        case NFSERR_GRACE: /* ugh! (stupid) RFC 3530 specifically disallows CLAIM_DELEGATE_CUR during grace period? */
-               return (1);
+               return 1;
        }
-       return (0);
+       return 0;
 }
 
 
@@ -1755,27 +1931,30 @@ int
 nfs_open_state_set_busy(nfsnode_t np, thread_t thd)
 {
        struct nfsmount *nmp;
-       struct timespec ts = {2, 0};
+       struct timespec ts = { .tv_sec = 2, .tv_nsec = 0 };
        int error = 0, slpflag;
 
        nmp = NFSTONMP(np);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        slpflag = (NMFLAG(nmp, INTR) && thd) ? PCATCH : 0;
 
        lck_mtx_lock(&np->n_openlock);
        while (np->n_openflags & N_OPENBUSY) {
-               if ((error = nfs_sigintr(nmp, NULL, thd, 0)))
+               if ((error = nfs_sigintr(nmp, NULL, thd, 0))) {
                        break;
+               }
                np->n_openflags |= N_OPENWANT;
                msleep(&np->n_openflags, &np->n_openlock, slpflag, "nfs_open_state_set_busy", &ts);
                slpflag = 0;
        }
-       if (!error)
+       if (!error) {
                np->n_openflags |= N_OPENBUSY;
+       }
        lck_mtx_unlock(&np->n_openlock);
 
-       return (error);
+       return error;
 }
 
 /*
@@ -1788,13 +1967,15 @@ nfs_open_state_clear_busy(nfsnode_t np)
        int wanted;
 
        lck_mtx_lock(&np->n_openlock);
-       if (!(np->n_openflags & N_OPENBUSY))
+       if (!(np->n_openflags & N_OPENBUSY)) {
                panic("nfs_open_state_clear_busy");
+       }
        wanted = (np->n_openflags & N_OPENWANT);
-       np->n_openflags &= ~(N_OPENBUSY|N_OPENWANT);
+       np->n_openflags &= ~(N_OPENBUSY | N_OPENWANT);
        lck_mtx_unlock(&np->n_openlock);
-       if (wanted)
+       if (wanted) {
                wakeup(&np->n_openflags);
+       }
 }
 
 /*
@@ -1810,17 +1991,19 @@ nfs_open_owner_find(struct nfsmount *nmp, kauth_cred_t cred, int alloc)
 tryagain:
        lck_mtx_lock(&nmp->nm_lock);
        TAILQ_FOREACH(noop, &nmp->nm_open_owners, noo_link) {
-               if (kauth_cred_getuid(noop->noo_cred) == uid)
+               if (kauth_cred_getuid(noop->noo_cred) == uid) {
                        break;
+               }
        }
 
        if (!noop && !newnoop && alloc) {
                lck_mtx_unlock(&nmp->nm_lock);
                MALLOC(newnoop, struct nfs_open_owner *, sizeof(struct nfs_open_owner), M_TEMP, M_WAITOK);
-               if (!newnoop)
-                       return (NULL);
+               if (!newnoop) {
+                       return NULL;
+               }
                bzero(newnoop, sizeof(*newnoop));
-               lck_mtx_init(&newnoop->noo_lock, nfs_open_grp, LCK_ATTR_NULL);
+               lck_mtx_init(&newnoop->noo_lock, &nfs_open_grp, LCK_ATTR_NULL);
                newnoop->noo_mount = nmp;
                kauth_cred_ref(cred);
                newnoop->noo_cred = cred;
@@ -1830,18 +2013,21 @@ tryagain:
        }
        if (!noop && newnoop) {
                newnoop->noo_flags |= NFS_OPEN_OWNER_LINK;
+               os_ref_init(&newnoop->noo_refcnt, NULL);
                TAILQ_INSERT_HEAD(&nmp->nm_open_owners, newnoop, noo_link);
                noop = newnoop;
        }
        lck_mtx_unlock(&nmp->nm_lock);
 
-       if (newnoop && (noop != newnoop))
+       if (newnoop && (noop != newnoop)) {
                nfs_open_owner_destroy(newnoop);
+       }
 
-       if (noop)
+       if (noop) {
                nfs_open_owner_ref(noop);
+       }
 
-       return (noop);
+       return noop;
 }
 
 /*
@@ -1850,9 +2036,10 @@ tryagain:
 void
 nfs_open_owner_destroy(struct nfs_open_owner *noop)
 {
-       if (noop->noo_cred)
+       if (noop->noo_cred) {
                kauth_cred_unref(&noop->noo_cred);
-       lck_mtx_destroy(&noop->noo_lock, nfs_open_grp);
+       }
+       lck_mtx_destroy(&noop->noo_lock, &nfs_open_grp);
        FREE(noop, M_TEMP);
 }
 
@@ -1863,7 +2050,7 @@ void
 nfs_open_owner_ref(struct nfs_open_owner *noop)
 {
        lck_mtx_lock(&noop->noo_lock);
-       noop->noo_refcnt++;
+       os_ref_retain_locked(&noop->noo_refcnt);
        lck_mtx_unlock(&noop->noo_lock);
 }
 
@@ -1874,14 +2061,18 @@ nfs_open_owner_ref(struct nfs_open_owner *noop)
 void
 nfs_open_owner_rele(struct nfs_open_owner *noop)
 {
+       os_ref_count_t newcount;
+
        lck_mtx_lock(&noop->noo_lock);
-       if (noop->noo_refcnt < 1)
+       if (os_ref_get_count(&noop->noo_refcnt) < 1) {
                panic("nfs_open_owner_rele: no refcnt");
-       noop->noo_refcnt--;
-       if (!noop->noo_refcnt && (noop->noo_flags & NFS_OPEN_OWNER_BUSY))
+       }
+       newcount = os_ref_release_locked(&noop->noo_refcnt);
+       if (!newcount && (noop->noo_flags & NFS_OPEN_OWNER_BUSY)) {
                panic("nfs_open_owner_rele: busy");
+       }
        /* XXX we may potentially want to clean up idle/unused open owner structures */
-       if (noop->noo_refcnt || (noop->noo_flags & NFS_OPEN_OWNER_LINK)) {
+       if (newcount || (noop->noo_flags & NFS_OPEN_OWNER_LINK)) {
                lck_mtx_unlock(&noop->noo_lock);
                return;
        }
@@ -1898,27 +2089,30 @@ int
 nfs_open_owner_set_busy(struct nfs_open_owner *noop, thread_t thd)
 {
        struct nfsmount *nmp;
-       struct timespec ts = {2, 0};
+       struct timespec ts = { .tv_sec = 2, .tv_nsec = 0 };
        int error = 0, slpflag;
 
        nmp = noop->noo_mount;
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        slpflag = (NMFLAG(nmp, INTR) && thd) ? PCATCH : 0;
 
        lck_mtx_lock(&noop->noo_lock);
        while (noop->noo_flags & NFS_OPEN_OWNER_BUSY) {
-               if ((error = nfs_sigintr(nmp, NULL, thd, 0)))
+               if ((error = nfs_sigintr(nmp, NULL, thd, 0))) {
                        break;
+               }
                noop->noo_flags |= NFS_OPEN_OWNER_WANT;
                msleep(noop, &noop->noo_lock, slpflag, "nfs_open_owner_set_busy", &ts);
                slpflag = 0;
        }
-       if (!error)
+       if (!error) {
                noop->noo_flags |= NFS_OPEN_OWNER_BUSY;
+       }
        lck_mtx_unlock(&noop->noo_lock);
 
-       return (error);
+       return error;
 }
 
 /*
@@ -1931,13 +2125,15 @@ nfs_open_owner_clear_busy(struct nfs_open_owner *noop)
        int wanted;
 
        lck_mtx_lock(&noop->noo_lock);
-       if (!(noop->noo_flags & NFS_OPEN_OWNER_BUSY))
+       if (!(noop->noo_flags & NFS_OPEN_OWNER_BUSY)) {
                panic("nfs_open_owner_clear_busy");
+       }
        wanted = (noop->noo_flags & NFS_OPEN_OWNER_WANT);
-       noop->noo_flags &= ~(NFS_OPEN_OWNER_BUSY|NFS_OPEN_OWNER_WANT);
+       noop->noo_flags &= ~(NFS_OPEN_OWNER_BUSY | NFS_OPEN_OWNER_WANT);
        lck_mtx_unlock(&noop->noo_lock);
-       if (wanted)
+       if (wanted) {
                wakeup(noop);
+       }
 }
 
 /*
@@ -1959,10 +2155,12 @@ nfs_owner_seqid_increment(struct nfs_open_owner *noop, struct nfs_lock_owner *nl
                /* do not increment the open seqid on these errors */
                return;
        }
-       if (noop)
+       if (noop) {
                noop->noo_seqid++;
-       if (nlop)
+       }
+       if (nlop) {
                nlop->nlo_seqid++;
+       }
 }
 
 /*
@@ -1999,20 +2197,22 @@ nfs_open_file_find_internal(
 {
        struct nfs_open_file *nofp = NULL, *nofp2, *newnofp = NULL;
 
-       if (!np)
+       if (!np) {
                goto alloc;
+       }
 tryagain:
        lck_mtx_lock(&np->n_openlock);
        TAILQ_FOREACH(nofp2, &np->n_opens, nof_link) {
                if (nofp2->nof_owner == noop) {
                        nofp = nofp2;
-                       if (!accessMode)
+                       if (!accessMode) {
                                break;
+                       }
                }
                if ((accessMode & nofp2->nof_deny) || (denyMode & nofp2->nof_access)) {
                        /* This request conflicts with an existing open on this client. */
                        lck_mtx_unlock(&np->n_openlock);
-                       return (EACCES);
+                       return EACCES;
                }
        }
 
@@ -2024,18 +2224,20 @@ tryagain:
                lck_mtx_unlock(&np->n_openlock);
 alloc:
                MALLOC(newnofp, struct nfs_open_file *, sizeof(struct nfs_open_file), M_TEMP, M_WAITOK);
-               if (!newnofp)
-                       return (ENOMEM);
+               if (!newnofp) {
+                       return ENOMEM;
+               }
                bzero(newnofp, sizeof(*newnofp));
-               lck_mtx_init(&newnofp->nof_lock, nfs_open_grp, LCK_ATTR_NULL);
+               lck_mtx_init(&newnofp->nof_lock, &nfs_open_grp, LCK_ATTR_NULL);
                newnofp->nof_owner = noop;
                nfs_open_owner_ref(noop);
                newnofp->nof_np = np;
                lck_mtx_lock(&noop->noo_lock);
                TAILQ_INSERT_HEAD(&noop->noo_opens, newnofp, nof_oolink);
                lck_mtx_unlock(&noop->noo_lock);
-               if (np)
+               if (np) {
                        goto tryagain;
+               }
        }
        if (!nofp) {
                if (*nofpp) {
@@ -2044,17 +2246,20 @@ alloc:
                } else {
                        nofp = newnofp;
                }
-               if (nofp && np)
+               if (nofp && np) {
                        TAILQ_INSERT_HEAD(&np->n_opens, nofp, nof_link);
+               }
        }
-       if (np)
+       if (np) {
                lck_mtx_unlock(&np->n_openlock);
+       }
 
-       if (alloc && newnofp && (nofp != newnofp))
+       if (alloc && newnofp && (nofp != newnofp)) {
                nfs_open_file_destroy(newnofp);
+       }
 
        *nofpp = nofp;
-       return (nofp ? 0 : ESRCH);
+       return nofp ? 0 : ESRCH;
 }
 
 /*
@@ -2067,7 +2272,7 @@ nfs_open_file_destroy(struct nfs_open_file *nofp)
        TAILQ_REMOVE(&nofp->nof_owner->noo_opens, nofp, nof_oolink);
        lck_mtx_unlock(&nofp->nof_owner->noo_lock);
        nfs_open_owner_rele(nofp->nof_owner);
-       lck_mtx_destroy(&nofp->nof_lock, nfs_open_grp);
+       lck_mtx_destroy(&nofp->nof_lock, &nfs_open_grp);
        FREE(nofp, M_TEMP);
 }
 
@@ -2079,27 +2284,30 @@ int
 nfs_open_file_set_busy(struct nfs_open_file *nofp, thread_t thd)
 {
        struct nfsmount *nmp;
-       struct timespec ts = {2, 0};
+       struct timespec ts = { .tv_sec = 2, .tv_nsec = 0 };
        int error = 0, slpflag;
 
        nmp = nofp->nof_owner->noo_mount;
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        slpflag = (NMFLAG(nmp, INTR) && thd) ? PCATCH : 0;
 
        lck_mtx_lock(&nofp->nof_lock);
        while (nofp->nof_flags & NFS_OPEN_FILE_BUSY) {
-               if ((error = nfs_sigintr(nmp, NULL, thd, 0)))
+               if ((error = nfs_sigintr(nmp, NULL, thd, 0))) {
                        break;
+               }
                nofp->nof_flags |= NFS_OPEN_FILE_WANT;
                msleep(nofp, &nofp->nof_lock, slpflag, "nfs_open_file_set_busy", &ts);
                slpflag = 0;
        }
-       if (!error)
+       if (!error) {
                nofp->nof_flags |= NFS_OPEN_FILE_BUSY;
+       }
        lck_mtx_unlock(&nofp->nof_lock);
 
-       return (error);
+       return error;
 }
 
 /*
@@ -2112,13 +2320,15 @@ nfs_open_file_clear_busy(struct nfs_open_file *nofp)
        int wanted;
 
        lck_mtx_lock(&nofp->nof_lock);
-       if (!(nofp->nof_flags & NFS_OPEN_FILE_BUSY))
+       if (!(nofp->nof_flags & NFS_OPEN_FILE_BUSY)) {
                panic("nfs_open_file_clear_busy");
+       }
        wanted = (nofp->nof_flags & NFS_OPEN_FILE_WANT);
-       nofp->nof_flags &= ~(NFS_OPEN_FILE_BUSY|NFS_OPEN_FILE_WANT);
+       nofp->nof_flags &= ~(NFS_OPEN_FILE_BUSY | NFS_OPEN_FILE_WANT);
        lck_mtx_unlock(&nofp->nof_lock);
-       if (wanted)
+       if (wanted) {
                wakeup(nofp);
+       }
 }
 
 /*
@@ -2133,49 +2343,55 @@ nfs_open_file_add_open(struct nfs_open_file *nofp, uint32_t accessMode, uint32_t
 
        if (delegated) {
                if (denyMode == NFS_OPEN_SHARE_DENY_NONE) {
-                       if (accessMode == NFS_OPEN_SHARE_ACCESS_READ)
+                       if (accessMode == NFS_OPEN_SHARE_ACCESS_READ) {
                                nofp->nof_d_r++;
-                       else if (accessMode == NFS_OPEN_SHARE_ACCESS_WRITE)
+                       } else if (accessMode == NFS_OPEN_SHARE_ACCESS_WRITE) {
                                nofp->nof_d_w++;
-                       else if (accessMode == NFS_OPEN_SHARE_ACCESS_BOTH)
+                       } else if (accessMode == NFS_OPEN_SHARE_ACCESS_BOTH) {
                                nofp->nof_d_rw++;
+                       }
                } else if (denyMode == NFS_OPEN_SHARE_DENY_WRITE) {
-                       if (accessMode == NFS_OPEN_SHARE_ACCESS_READ)
+                       if (accessMode == NFS_OPEN_SHARE_ACCESS_READ) {
                                nofp->nof_d_r_dw++;
-                       else if (accessMode == NFS_OPEN_SHARE_ACCESS_WRITE)
+                       } else if (accessMode == NFS_OPEN_SHARE_ACCESS_WRITE) {
                                nofp->nof_d_w_dw++;
-                       else if (accessMode == NFS_OPEN_SHARE_ACCESS_BOTH)
+                       } else if (accessMode == NFS_OPEN_SHARE_ACCESS_BOTH) {
                                nofp->nof_d_rw_dw++;
+                       }
                } else { /* NFS_OPEN_SHARE_DENY_BOTH */
-                       if (accessMode == NFS_OPEN_SHARE_ACCESS_READ)
+                       if (accessMode == NFS_OPEN_SHARE_ACCESS_READ) {
                                nofp->nof_d_r_drw++;
-                       else if (accessMode == NFS_OPEN_SHARE_ACCESS_WRITE)
+                       } else if (accessMode == NFS_OPEN_SHARE_ACCESS_WRITE) {
                                nofp->nof_d_w_drw++;
-                       else if (accessMode == NFS_OPEN_SHARE_ACCESS_BOTH)
+                       } else if (accessMode == NFS_OPEN_SHARE_ACCESS_BOTH) {
                                nofp->nof_d_rw_drw++;
+                       }
                }
        } else {
                if (denyMode == NFS_OPEN_SHARE_DENY_NONE) {
-                       if (accessMode == NFS_OPEN_SHARE_ACCESS_READ)
+                       if (accessMode == NFS_OPEN_SHARE_ACCESS_READ) {
                                nofp->nof_r++;
-                       else if (accessMode == NFS_OPEN_SHARE_ACCESS_WRITE)
+                       } else if (accessMode == NFS_OPEN_SHARE_ACCESS_WRITE) {
                                nofp->nof_w++;
-                       else if (accessMode == NFS_OPEN_SHARE_ACCESS_BOTH)
+                       } else if (accessMode == NFS_OPEN_SHARE_ACCESS_BOTH) {
                                nofp->nof_rw++;
+                       }
                } else if (denyMode == NFS_OPEN_SHARE_DENY_WRITE) {
-                       if (accessMode == NFS_OPEN_SHARE_ACCESS_READ)
+                       if (accessMode == NFS_OPEN_SHARE_ACCESS_READ) {
                                nofp->nof_r_dw++;
-                       else if (accessMode == NFS_OPEN_SHARE_ACCESS_WRITE)
+                       } else if (accessMode == NFS_OPEN_SHARE_ACCESS_WRITE) {
                                nofp->nof_w_dw++;
-                       else if (accessMode == NFS_OPEN_SHARE_ACCESS_BOTH)
+                       } else if (accessMode == NFS_OPEN_SHARE_ACCESS_BOTH) {
                                nofp->nof_rw_dw++;
+                       }
                } else { /* NFS_OPEN_SHARE_DENY_BOTH */
-                       if (accessMode == NFS_OPEN_SHARE_ACCESS_READ)
+                       if (accessMode == NFS_OPEN_SHARE_ACCESS_READ) {
                                nofp->nof_r_drw++;
-                       else if (accessMode == NFS_OPEN_SHARE_ACCESS_WRITE)
+                       } else if (accessMode == NFS_OPEN_SHARE_ACCESS_WRITE) {
                                nofp->nof_w_drw++;
-                       else if (accessMode == NFS_OPEN_SHARE_ACCESS_BOTH)
+                       } else if (accessMode == NFS_OPEN_SHARE_ACCESS_BOTH) {
                                nofp->nof_rw_drw++;
+                       }
                }
        }
 
@@ -2192,8 +2408,8 @@ nfs_open_file_remove_open_find(
        struct nfs_open_file *nofp,
        uint32_t accessMode,
        uint32_t denyMode,
-       uint32_t *newAccessMode,
-       uint32_t *newDenyMode,
+       uint8_t *newAccessMode,
+       uint8_t *newDenyMode,
        int *delegated)
 {
        /*
@@ -2206,65 +2422,72 @@ nfs_open_file_remove_open_find(
        if ((accessMode & NFS_OPEN_SHARE_ACCESS_READ) &&
            (nofp->nof_access & NFS_OPEN_SHARE_ACCESS_READ) &&
            ((nofp->nof_r + nofp->nof_d_r +
-             nofp->nof_rw + nofp->nof_d_rw +
-             nofp->nof_r_dw + nofp->nof_d_r_dw +
-             nofp->nof_rw_dw + nofp->nof_d_rw_dw +
-             nofp->nof_r_drw + nofp->nof_d_r_drw +
-             nofp->nof_rw_dw + nofp->nof_d_rw_dw) == 1))
+           nofp->nof_rw + nofp->nof_d_rw +
+           nofp->nof_r_dw + nofp->nof_d_r_dw +
+           nofp->nof_rw_dw + nofp->nof_d_rw_dw +
+           nofp->nof_r_drw + nofp->nof_d_r_drw +
+           nofp->nof_rw_dw + nofp->nof_d_rw_dw) == 1)) {
                *newAccessMode &= ~NFS_OPEN_SHARE_ACCESS_READ;
+       }
        if ((accessMode & NFS_OPEN_SHARE_ACCESS_WRITE) &&
            (nofp->nof_access & NFS_OPEN_SHARE_ACCESS_WRITE) &&
            ((nofp->nof_w + nofp->nof_d_w +
-             nofp->nof_rw + nofp->nof_d_rw +
-             nofp->nof_w_dw + nofp->nof_d_w_dw +
-             nofp->nof_rw_dw + nofp->nof_d_rw_dw +
-             nofp->nof_w_drw + nofp->nof_d_w_drw +
-             nofp->nof_rw_dw + nofp->nof_d_rw_dw) == 1))
+           nofp->nof_rw + nofp->nof_d_rw +
+           nofp->nof_w_dw + nofp->nof_d_w_dw +
+           nofp->nof_rw_dw + nofp->nof_d_rw_dw +
+           nofp->nof_w_drw + nofp->nof_d_w_drw +
+           nofp->nof_rw_dw + nofp->nof_d_rw_dw) == 1)) {
                *newAccessMode &= ~NFS_OPEN_SHARE_ACCESS_WRITE;
+       }
        if ((denyMode & NFS_OPEN_SHARE_DENY_READ) &&
            (nofp->nof_deny & NFS_OPEN_SHARE_DENY_READ) &&
            ((nofp->nof_r_drw + nofp->nof_d_r_drw +
-             nofp->nof_w_drw + nofp->nof_d_w_drw +
-             nofp->nof_rw_drw + nofp->nof_d_rw_drw) == 1))
+           nofp->nof_w_drw + nofp->nof_d_w_drw +
+           nofp->nof_rw_drw + nofp->nof_d_rw_drw) == 1)) {
                *newDenyMode &= ~NFS_OPEN_SHARE_DENY_READ;
+       }
        if ((denyMode & NFS_OPEN_SHARE_DENY_WRITE) &&
            (nofp->nof_deny & NFS_OPEN_SHARE_DENY_WRITE) &&
            ((nofp->nof_r_drw + nofp->nof_d_r_drw +
-             nofp->nof_w_drw + nofp->nof_d_w_drw +
-             nofp->nof_rw_drw + nofp->nof_d_rw_drw +
-             nofp->nof_r_dw + nofp->nof_d_r_dw +
-             nofp->nof_w_dw + nofp->nof_d_w_dw +
-             nofp->nof_rw_dw + nofp->nof_d_rw_dw) == 1))
+           nofp->nof_w_drw + nofp->nof_d_w_drw +
+           nofp->nof_rw_drw + nofp->nof_d_rw_drw +
+           nofp->nof_r_dw + nofp->nof_d_r_dw +
+           nofp->nof_w_dw + nofp->nof_d_w_dw +
+           nofp->nof_rw_dw + nofp->nof_d_rw_dw) == 1)) {
                *newDenyMode &= ~NFS_OPEN_SHARE_DENY_WRITE;
+       }
 
        /* Find the corresponding open access/deny mode counter. */
        if (denyMode == NFS_OPEN_SHARE_DENY_NONE) {
-               if (accessMode == NFS_OPEN_SHARE_ACCESS_READ)
+               if (accessMode == NFS_OPEN_SHARE_ACCESS_READ) {
                        *delegated = (nofp->nof_d_r != 0);
-               else if (accessMode == NFS_OPEN_SHARE_ACCESS_WRITE)
+               } else if (accessMode == NFS_OPEN_SHARE_ACCESS_WRITE) {
                        *delegated = (nofp->nof_d_w != 0);
-               else if (accessMode == NFS_OPEN_SHARE_ACCESS_BOTH)
+               } else if (accessMode == NFS_OPEN_SHARE_ACCESS_BOTH) {
                        *delegated = (nofp->nof_d_rw != 0);
-               else
+               } else {
                        *delegated = 0;
+               }
        } else if (denyMode == NFS_OPEN_SHARE_DENY_WRITE) {
-               if (accessMode == NFS_OPEN_SHARE_ACCESS_READ)
+               if (accessMode == NFS_OPEN_SHARE_ACCESS_READ) {
                        *delegated = (nofp->nof_d_r_dw != 0);
-               else if (accessMode == NFS_OPEN_SHARE_ACCESS_WRITE)
+               } else if (accessMode == NFS_OPEN_SHARE_ACCESS_WRITE) {
                        *delegated = (nofp->nof_d_w_dw != 0);
-               else if (accessMode == NFS_OPEN_SHARE_ACCESS_BOTH)
+               } else if (accessMode == NFS_OPEN_SHARE_ACCESS_BOTH) {
                        *delegated = (nofp->nof_d_rw_dw != 0);
-               else
+               } else {
                        *delegated = 0;
+               }
        } else { /* NFS_OPEN_SHARE_DENY_BOTH */
-               if (accessMode == NFS_OPEN_SHARE_ACCESS_READ)
+               if (accessMode == NFS_OPEN_SHARE_ACCESS_READ) {
                        *delegated = (nofp->nof_d_r_drw != 0);
-               else if (accessMode == NFS_OPEN_SHARE_ACCESS_WRITE)
+               } else if (accessMode == NFS_OPEN_SHARE_ACCESS_WRITE) {
                        *delegated = (nofp->nof_d_w_drw != 0);
-               else if (accessMode == NFS_OPEN_SHARE_ACCESS_BOTH)
+               } else if (accessMode == NFS_OPEN_SHARE_ACCESS_BOTH) {
                        *delegated = (nofp->nof_d_rw_drw != 0);
-               else
+               } else {
                        *delegated = 0;
+               }
        }
 }
 
@@ -2274,7 +2497,7 @@ nfs_open_file_remove_open_find(
 void
 nfs_open_file_remove_open(struct nfs_open_file *nofp, uint32_t accessMode, uint32_t denyMode)
 {
-       uint32_t newAccessMode, newDenyMode;
+       uint8_t newAccessMode, newDenyMode;
        int delegated = 0;
 
        lck_mtx_lock(&nofp->nof_lock);
@@ -2284,115 +2507,133 @@ nfs_open_file_remove_open(struct nfs_open_file *nofp, uint32_t accessMode, uint3
        if (denyMode == NFS_OPEN_SHARE_DENY_NONE) {
                if (accessMode == NFS_OPEN_SHARE_ACCESS_READ) {
                        if (delegated) {
-                               if (nofp->nof_d_r == 0)
+                               if (nofp->nof_d_r == 0) {
                                        NP(nofp->nof_np, "nfs: open(R) delegated count underrun, %d", kauth_cred_getuid(nofp->nof_owner->noo_cred));
-                               else
+                               } else {
                                        nofp->nof_d_r--;
+                               }
                        } else {
-                               if (nofp->nof_r == 0)
+                               if (nofp->nof_r == 0) {
                                        NP(nofp->nof_np, "nfs: open(R) count underrun, %d", kauth_cred_getuid(nofp->nof_owner->noo_cred));
-                               else
+                               } else {
                                        nofp->nof_r--;
+                               }
                        }
                } else if (accessMode == NFS_OPEN_SHARE_ACCESS_WRITE) {
                        if (delegated) {
-                               if (nofp->nof_d_w == 0)
+                               if (nofp->nof_d_w == 0) {
                                        NP(nofp->nof_np, "nfs: open(W) delegated count underrun, %d", kauth_cred_getuid(nofp->nof_owner->noo_cred));
-                               else
+                               } else {
                                        nofp->nof_d_w--;
+                               }
                        } else {
-                               if (nofp->nof_w == 0)
+                               if (nofp->nof_w == 0) {
                                        NP(nofp->nof_np, "nfs: open(W) count underrun, %d", kauth_cred_getuid(nofp->nof_owner->noo_cred));
-                               else
+                               } else {
                                        nofp->nof_w--;
+                               }
                        }
                } else if (accessMode == NFS_OPEN_SHARE_ACCESS_BOTH) {
                        if (delegated) {
-                               if (nofp->nof_d_rw == 0)
+                               if (nofp->nof_d_rw == 0) {
                                        NP(nofp->nof_np, "nfs: open(RW) delegated count underrun, %d", kauth_cred_getuid(nofp->nof_owner->noo_cred));
-                               else
+                               } else {
                                        nofp->nof_d_rw--;
+                               }
                        } else {
-                               if (nofp->nof_rw == 0)
+                               if (nofp->nof_rw == 0) {
                                        NP(nofp->nof_np, "nfs: open(RW) count underrun, %d", kauth_cred_getuid(nofp->nof_owner->noo_cred));
-                               else
+                               } else {
                                        nofp->nof_rw--;
+                               }
                        }
                }
        } else if (denyMode == NFS_OPEN_SHARE_DENY_WRITE) {
                if (accessMode == NFS_OPEN_SHARE_ACCESS_READ) {
                        if (delegated) {
-                               if (nofp->nof_d_r_dw == 0)
+                               if (nofp->nof_d_r_dw == 0) {
                                        NP(nofp->nof_np, "nfs: open(R,DW) delegated count underrun, %d", kauth_cred_getuid(nofp->nof_owner->noo_cred));
-                               else
+                               } else {
                                        nofp->nof_d_r_dw--;
+                               }
                        } else {
-                               if (nofp->nof_r_dw == 0)
+                               if (nofp->nof_r_dw == 0) {
                                        NP(nofp->nof_np, "nfs: open(R,DW) count underrun, %d", kauth_cred_getuid(nofp->nof_owner->noo_cred));
-                               else
+                               } else {
                                        nofp->nof_r_dw--;
+                               }
                        }
                } else if (accessMode == NFS_OPEN_SHARE_ACCESS_WRITE) {
                        if (delegated) {
-                               if (nofp->nof_d_w_dw == 0)
+                               if (nofp->nof_d_w_dw == 0) {
                                        NP(nofp->nof_np, "nfs: open(W,DW) delegated count underrun, %d", kauth_cred_getuid(nofp->nof_owner->noo_cred));
-                               else
+                               } else {
                                        nofp->nof_d_w_dw--;
+                               }
                        } else {
-                               if (nofp->nof_w_dw == 0)
+                               if (nofp->nof_w_dw == 0) {
                                        NP(nofp->nof_np, "nfs: open(W,DW) count underrun, %d", kauth_cred_getuid(nofp->nof_owner->noo_cred));
-                               else
+                               } else {
                                        nofp->nof_w_dw--;
+                               }
                        }
                } else if (accessMode == NFS_OPEN_SHARE_ACCESS_BOTH) {
                        if (delegated) {
-                               if (nofp->nof_d_rw_dw == 0)
+                               if (nofp->nof_d_rw_dw == 0) {
                                        NP(nofp->nof_np, "nfs: open(RW,DW) delegated count underrun, %d", kauth_cred_getuid(nofp->nof_owner->noo_cred));
-                               else
+                               } else {
                                        nofp->nof_d_rw_dw--;
+                               }
                        } else {
-                               if (nofp->nof_rw_dw == 0)
+                               if (nofp->nof_rw_dw == 0) {
                                        NP(nofp->nof_np, "nfs: open(RW,DW) count underrun, %d", kauth_cred_getuid(nofp->nof_owner->noo_cred));
-                               else
+                               } else {
                                        nofp->nof_rw_dw--;
+                               }
                        }
                }
        } else { /* NFS_OPEN_SHARE_DENY_BOTH */
                if (accessMode == NFS_OPEN_SHARE_ACCESS_READ) {
                        if (delegated) {
-                               if (nofp->nof_d_r_drw == 0)
+                               if (nofp->nof_d_r_drw == 0) {
                                        NP(nofp->nof_np, "nfs: open(R,DRW) delegated count underrun, %d", kauth_cred_getuid(nofp->nof_owner->noo_cred));
-                               else
+                               } else {
                                        nofp->nof_d_r_drw--;
+                               }
                        } else {
-                               if (nofp->nof_r_drw == 0)
+                               if (nofp->nof_r_drw == 0) {
                                        NP(nofp->nof_np, "nfs: open(R,DRW) count underrun, %d", kauth_cred_getuid(nofp->nof_owner->noo_cred));
-                               else
+                               } else {
                                        nofp->nof_r_drw--;
+                               }
                        }
                } else if (accessMode == NFS_OPEN_SHARE_ACCESS_WRITE) {
                        if (delegated) {
-                               if (nofp->nof_d_w_drw == 0)
+                               if (nofp->nof_d_w_drw == 0) {
                                        NP(nofp->nof_np, "nfs: open(W,DRW) delegated count underrun, %d", kauth_cred_getuid(nofp->nof_owner->noo_cred));
-                               else
+                               } else {
                                        nofp->nof_d_w_drw--;
+                               }
                        } else {
-                               if (nofp->nof_w_drw == 0)
+                               if (nofp->nof_w_drw == 0) {
                                        NP(nofp->nof_np, "nfs: open(W,DRW) count underrun, %d", kauth_cred_getuid(nofp->nof_owner->noo_cred));
-                               else
+                               } else {
                                        nofp->nof_w_drw--;
+                               }
                        }
                } else if (accessMode == NFS_OPEN_SHARE_ACCESS_BOTH) {
                        if (delegated) {
-                               if (nofp->nof_d_rw_drw == 0)
+                               if (nofp->nof_d_rw_drw == 0) {
                                        NP(nofp->nof_np, "nfs: open(RW,DRW) delegated count underrun, %d", kauth_cred_getuid(nofp->nof_owner->noo_cred));
-                               else
+                               } else {
                                        nofp->nof_d_rw_drw--;
+                               }
                        } else {
-                               if (nofp->nof_rw_drw == 0)
+                               if (nofp->nof_rw_drw == 0) {
                                        NP(nofp->nof_np, "nfs: open(RW,DRW) count underrun, %d", kauth_cred_getuid(nofp->nof_owner->noo_cred));
-                               else
+                               } else {
                                        nofp->nof_rw_drw--;
+                               }
                        }
                }
        }
@@ -2404,7 +2645,7 @@ nfs_open_file_remove_open(struct nfs_open_file *nofp, uint32_t accessMode, uint3
        lck_mtx_unlock(&nofp->nof_lock);
 }
 
-
+#if CONFIG_NFS4
 /*
  * Get the current (delegation, lock, open, default) stateid for this node.
  * If node has a delegation, use that stateid.
@@ -2425,20 +2666,23 @@ nfs_get_stateid(nfsnode_t np, thread_t thd, kauth_cred_t cred, nfs_stateid *sid)
        if (np->n_openflags & N_DELEG_MASK) {
                s = &np->n_dstateid;
        } else {
-               if (p)
+               if (p) {
                        nlop = nfs_lock_owner_find(np, p, 0);
+               }
                if (nlop && !TAILQ_EMPTY(&nlop->nlo_locks)) {
                        /* we hold locks, use lock stateid */
                        s = &nlop->nlo_stateid;
                } else if (((noop = nfs_open_owner_find(nmp, cred, 0))) &&
-                        (nfs_open_file_find(np, noop, &nofp, 0, 0, 0) == 0) &&
-                        !(nofp->nof_flags & NFS_OPEN_FILE_LOST) &&
-                        nofp->nof_access) {
+                   (nfs_open_file_find(np, noop, &nofp, 0, 0, 0) == 0) &&
+                   !(nofp->nof_flags & NFS_OPEN_FILE_LOST) &&
+                   nofp->nof_access) {
                        /* we (should) have the file open, use open stateid */
-                       if (nofp->nof_flags & NFS_OPEN_FILE_REOPEN)
+                       if (nofp->nof_flags & NFS_OPEN_FILE_REOPEN) {
                                nfs4_reopen(nofp, thd);
-                       if (!(nofp->nof_flags & NFS_OPEN_FILE_LOST))
+                       }
+                       if (!(nofp->nof_flags & NFS_OPEN_FILE_LOST)) {
                                s = &nofp->nof_stateid;
+                       }
                }
        }
 
@@ -2449,14 +2693,17 @@ nfs_get_stateid(nfsnode_t np, thread_t thd, kauth_cred_t cred, nfs_stateid *sid)
                sid->other[2] = s->other[2];
        } else {
                /* named attributes may not have a stateid for reads, so don't complain for them */
-               if (!(np->n_vattr.nva_flags & NFS_FFLAG_IS_ATTR))
+               if (!(np->n_vattr.nva_flags & NFS_FFLAG_IS_ATTR)) {
                        NP(np, "nfs_get_stateid: no stateid");
+               }
                sid->seqid = sid->other[0] = sid->other[1] = sid->other[2] = 0xffffffff;
        }
-       if (nlop)
+       if (nlop) {
                nfs_lock_owner_rele(nlop);
-       if (noop)
+       }
+       if (noop) {
                nfs_open_owner_rele(noop);
+       }
 }
 
 
@@ -2488,10 +2735,12 @@ nfs4_open_delegated(
 
 tryagain:
        action = 0;
-       if (accessMode & NFS_OPEN_SHARE_ACCESS_READ)
+       if (accessMode & NFS_OPEN_SHARE_ACCESS_READ) {
                action |= KAUTH_VNODE_READ_DATA;
-       if (accessMode & NFS_OPEN_SHARE_ACCESS_WRITE)
+       }
+       if (accessMode & NFS_OPEN_SHARE_ACCESS_WRITE) {
                action |= KAUTH_VNODE_WRITE_DATA;
+       }
 
        /* evaluate ACE (if we have one) */
        if (np->n_dace.ace_flags) {
@@ -2499,11 +2748,13 @@ tryagain:
                eval.ae_acl = &np->n_dace;
                eval.ae_count = 1;
                eval.ae_options = 0;
-               if (np->n_vattr.nva_uid == kauth_cred_getuid(cred))
+               if (np->n_vattr.nva_uid == kauth_cred_getuid(cred)) {
                        eval.ae_options |= KAUTH_AEVAL_IS_OWNER;
+               }
                error = kauth_cred_ismember_gid(cred, np->n_vattr.nva_gid, &ismember);
-               if (!error && ismember)
+               if (!error && ismember) {
                        eval.ae_options |= KAUTH_AEVAL_IN_GROUP;
+               }
 
                eval.ae_exp_gall = KAUTH_VNODE_GENERIC_ALL_BITS;
                eval.ae_exp_gread = KAUTH_VNODE_GENERIC_READ_BITS;
@@ -2512,8 +2763,9 @@ tryagain:
 
                error = kauth_acl_evaluate(cred, &eval);
 
-               if (!error && (eval.ae_result == KAUTH_RESULT_ALLOW))
+               if (!error && (eval.ae_result == KAUTH_RESULT_ALLOW)) {
                        authorized = 1;
+               }
        }
 
        if (!authorized) {
@@ -2523,8 +2775,9 @@ tryagain:
                naa.a_vp = NFSTOV(np);
                naa.a_action = action;
                naa.a_context = ctx;
-               if (!(error = nfs_vnop_access(&naa)))
+               if (!(error = nfs_vnop_access(&naa))) {
                        authorized = 1;
+               }
        }
 
        if (!authorized) {
@@ -2534,12 +2787,12 @@ tryagain:
                        readtoo = 0;
                        goto tryagain;
                }
-               return (error ? error : EACCES);
+               return error ? error : EACCES;
        }
 
        nfs_open_file_add_open(nofp, accessMode, denyMode, 1);
 
-       return (0);
+       return 0;
 }
 
 
@@ -2565,7 +2818,7 @@ nfs4_open(
        vnode_t dvp = NULL;
        struct componentname cn;
        const char *vname = NULL;
-       size_t namelen;
+       uint32_t namelen;
        char smallname[128];
        char *filename = NULL;
        int error = 0, readtoo = 0;
@@ -2577,14 +2830,15 @@ nfs4_open(
         * use the delegation if it's being returned.
         */
        if (np->n_openflags & N_DELEG_MASK) {
-               if ((error = nfs_open_state_set_busy(np, vfs_context_thread(ctx))))
-                       return (error);
+               if ((error = nfs_open_state_set_busy(np, vfs_context_thread(ctx)))) {
+                       return error;
+               }
                if ((np->n_openflags & N_DELEG_MASK) && !(np->n_openflags & N_DELEG_RETURN) &&
                    (((np->n_openflags & N_DELEG_MASK) == N_DELEG_WRITE) ||
-                    (!(accessMode & NFS_OPEN_SHARE_ACCESS_WRITE) && !(denyMode & NFS_OPEN_SHARE_DENY_READ)))) {
+                   (!(accessMode & NFS_OPEN_SHARE_ACCESS_WRITE) && !(denyMode & NFS_OPEN_SHARE_DENY_READ)))) {
                        error = nfs4_open_delegated(np, nofp, accessMode, denyMode, ctx);
                        nfs_open_state_clear_busy(np);
-                       return (error);
+                       return error;
                }
                nfs_open_state_clear_busy(np);
        }
@@ -2596,25 +2850,28 @@ nfs4_open(
         * from the n_parent we have stashed away.
         */
        if ((np->n_vattr.nva_flags & NFS_FFLAG_IS_ATTR) &&
-           (((dvp = np->n_parent)) && (error = vnode_get(dvp))))
+           (((dvp = np->n_parent)) && (error = vnode_get(dvp)))) {
                dvp = NULL;
-       if (!dvp)
+       }
+       if (!dvp) {
                dvp = vnode_getparent(vp);
+       }
        vname = vnode_getname(vp);
        if (!dvp || !vname) {
-               if (!error)
+               if (!error) {
                        error = EIO;
+               }
                goto out;
        }
        filename = &smallname[0];
        namelen = snprintf(filename, sizeof(smallname), "%s", vname);
        if (namelen >= sizeof(smallname)) {
-               MALLOC(filename, char *, namelen+1, M_TEMP, M_WAITOK);
+               MALLOC(filename, char *, namelen + 1, M_TEMP, M_WAITOK);
                if (!filename) {
                        error = ENOMEM;
                        goto out;
                }
-               snprintf(filename, namelen+1, "%s", vname);
+               snprintf(filename, namelen + 1, "%s", vname);
        }
        bzero(&cn, sizeof(cn));
        cn.cn_nameptr = filename;
@@ -2642,40 +2899,48 @@ tryagain:
        }
        nfs_open_file_add_open(nofp, accessMode, denyMode, 0);
 out:
-       if (filename && (filename != &smallname[0]))
+       if (filename && (filename != &smallname[0])) {
                FREE(filename, M_TEMP);
-       if (vname)
+       }
+       if (vname) {
                vnode_putname(vname);
-       if (dvp != NULLVP)
+       }
+       if (dvp != NULLVP) {
                vnode_put(dvp);
-       return (error);
+       }
+       return error;
 }
+#endif /* CONFIG_NFS4 */
 
 int
 nfs_vnop_mmap(
        struct vnop_mmap_args /* {
-               struct vnodeop_desc *a_desc;
-               vnode_t a_vp;
-               int a_fflags;
-               vfs_context_t a_context;
-       } */ *ap)
+                               *  struct vnodeop_desc *a_desc;
+                               *  vnode_t a_vp;
+                               *  int a_fflags;
+                               *  vfs_context_t a_context;
+                               *  } */*ap)
 {
        vfs_context_t ctx = ap->a_context;
        vnode_t vp = ap->a_vp;
        nfsnode_t np = VTONFS(vp);
-       int error = 0, accessMode, denyMode, delegated;
+       int error = 0, delegated = 0;
+       uint8_t accessMode, denyMode;
        struct nfsmount *nmp;
        struct nfs_open_owner *noop = NULL;
        struct nfs_open_file *nofp = NULL;
 
        nmp = VTONMP(vp);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
 
-       if (!vnode_isreg(vp) || !(ap->a_fflags & (PROT_READ|PROT_WRITE)))
-               return (EINVAL);
-       if (np->n_flag & NREVOKE)
-               return (EIO);
+       if (!vnode_isreg(vp) || !(ap->a_fflags & (PROT_READ | PROT_WRITE))) {
+               return EINVAL;
+       }
+       if (np->n_flag & NREVOKE) {
+               return EIO;
+       }
 
        /*
         * fflags contains some combination of: PROT_READ, PROT_WRITE
@@ -2683,25 +2948,27 @@ nfs_vnop_mmap(
         * read access is always there (regardless if PROT_READ is not set).
         */
        accessMode = NFS_OPEN_SHARE_ACCESS_READ;
-       if (ap->a_fflags & PROT_WRITE)
+       if (ap->a_fflags & PROT_WRITE) {
                accessMode |= NFS_OPEN_SHARE_ACCESS_WRITE;
+       }
        denyMode = NFS_OPEN_SHARE_DENY_NONE;
 
        noop = nfs_open_owner_find(nmp, vfs_context_ucred(ctx), 1);
-       if (!noop)
-               return (ENOMEM);
+       if (!noop) {
+               return ENOMEM;
+       }
 
 restart:
        error = nfs_mount_state_in_use_start(nmp, NULL);
        if (error) {
                nfs_open_owner_rele(noop);
-               return (error);
+               return error;
        }
        if (np->n_flag & NREVOKE) {
                error = EIO;
                nfs_mount_state_in_use_end(nmp, 0);
                nfs_open_owner_rele(noop);
-               return (error);
+               return error;
        }
 
        error = nfs_open_file_find(np, noop, &nofp, 0, 0, 1);
@@ -2709,15 +2976,19 @@ restart:
                NP(np, "nfs_vnop_mmap: no open file for owner, error %d, %d", error, kauth_cred_getuid(noop->noo_cred));
                error = EPERM;
        }
+#if CONFIG_NFS4
        if (!error && (nofp->nof_flags & NFS_OPEN_FILE_REOPEN)) {
-               nfs_mount_state_in_use_end(nmp, 0);
                error = nfs4_reopen(nofp, NULL);
                nofp = NULL;
-               if (!error)
+               if (!error) {
+                       nfs_mount_state_in_use_end(nmp, 0);
                        goto restart;
+               }
        }
-       if (!error)
+#endif
+       if (!error) {
                error = nfs_open_file_set_busy(nofp, NULL);
+       }
        if (error) {
                nofp = NULL;
                goto out;
@@ -2729,10 +3000,25 @@ restart:
         * So grab another open count matching the accessMode passed in.
         * If we already had an mmap open, prefer read/write without deny mode.
         * This means we may have to drop the current mmap open first.
+        *
+        * N.B. We should have an open for the mmap, because, mmap was
+        * called on an open descriptor, or we've created an open for read
+        * from reading the first page for execve. However, if we piggy
+        * backed on an existing NFS_OPEN_SHARE_ACCESS_READ/NFS_OPEN_SHARE_DENY_NONE
+        * that open may have closed.
         */
 
-       if (!nofp->nof_access) {
-               if (accessMode != NFS_OPEN_SHARE_ACCESS_READ) {
+       if (!(nofp->nof_access & NFS_OPEN_SHARE_ACCESS_READ)) {
+               if (nofp->nof_flags & NFS_OPEN_FILE_NEEDCLOSE) {
+                       /* We shouldn't get here. We've already open the file for execve */
+                       NP(np, "nfs_vnop_mmap: File already needs close access: 0x%x, cred: %d thread: %lld",
+                           nofp->nof_access, kauth_cred_getuid(nofp->nof_owner->noo_cred), thread_tid(vfs_context_thread(ctx)));
+               }
+               /*
+                * mmapings for execve are just for read. Get out with EPERM if the accessMode is not ACCESS_READ
+                * or the access would be denied. Other accesses should have an open descriptor for the mapping.
+                */
+               if (accessMode != NFS_OPEN_SHARE_ACCESS_READ || (accessMode & nofp->nof_deny)) {
                        /* not asking for just read access -> fail */
                        error = EPERM;
                        goto out;
@@ -2742,59 +3028,94 @@ restart:
                        /* NFS v2/v3 opens are always allowed - so just add it. */
                        nfs_open_file_add_open(nofp, NFS_OPEN_SHARE_ACCESS_READ, NFS_OPEN_SHARE_DENY_NONE, 0);
                        error = 0;
-               } else {
+               }
+#if CONFIG_NFS4
+               else {
                        error = nfs4_open(np, nofp, NFS_OPEN_SHARE_ACCESS_READ, NFS_OPEN_SHARE_DENY_NONE, ctx);
                }
-               if (!error)
+#endif
+               if (!error) {
                        nofp->nof_flags |= NFS_OPEN_FILE_NEEDCLOSE;
-               if (error)
+               }
+               if (error) {
                        goto out;
+               }
        }
 
        /* determine deny mode for open */
        if (accessMode == NFS_OPEN_SHARE_ACCESS_BOTH) {
                if (nofp->nof_d_rw || nofp->nof_d_rw_dw || nofp->nof_d_rw_drw) {
                        delegated = 1;
-                       if (nofp->nof_d_rw)
+                       if (nofp->nof_d_rw) {
                                denyMode = NFS_OPEN_SHARE_DENY_NONE;
-                       else if (nofp->nof_d_rw_dw)
+                       } else if (nofp->nof_d_rw_dw) {
                                denyMode = NFS_OPEN_SHARE_DENY_WRITE;
-                       else if (nofp->nof_d_rw_drw)
+                       } else if (nofp->nof_d_rw_drw) {
                                denyMode = NFS_OPEN_SHARE_DENY_BOTH;
+                       }
                } else if (nofp->nof_rw || nofp->nof_rw_dw || nofp->nof_rw_drw) {
                        delegated = 0;
-                       if (nofp->nof_rw)
+                       if (nofp->nof_rw) {
                                denyMode = NFS_OPEN_SHARE_DENY_NONE;
-                       else if (nofp->nof_rw_dw)
+                       } else if (nofp->nof_rw_dw) {
                                denyMode = NFS_OPEN_SHARE_DENY_WRITE;
-                       else if (nofp->nof_rw_drw)
+                       } else if (nofp->nof_rw_drw) {
                                denyMode = NFS_OPEN_SHARE_DENY_BOTH;
+                       }
                } else {
                        error = EPERM;
                }
        } else { /* NFS_OPEN_SHARE_ACCESS_READ */
                if (nofp->nof_d_r || nofp->nof_d_r_dw || nofp->nof_d_r_drw) {
                        delegated = 1;
-                       if (nofp->nof_d_r)
+                       if (nofp->nof_d_r) {
                                denyMode = NFS_OPEN_SHARE_DENY_NONE;
-                       else if (nofp->nof_d_r_dw)
+                       } else if (nofp->nof_d_r_dw) {
                                denyMode = NFS_OPEN_SHARE_DENY_WRITE;
-                       else if (nofp->nof_d_r_drw)
+                       } else if (nofp->nof_d_r_drw) {
                                denyMode = NFS_OPEN_SHARE_DENY_BOTH;
+                       }
                } else if (nofp->nof_r || nofp->nof_r_dw || nofp->nof_r_drw) {
                        delegated = 0;
-                       if (nofp->nof_r)
+                       if (nofp->nof_r) {
                                denyMode = NFS_OPEN_SHARE_DENY_NONE;
-                       else if (nofp->nof_r_dw)
+                       } else if (nofp->nof_r_dw) {
                                denyMode = NFS_OPEN_SHARE_DENY_WRITE;
-                       else if (nofp->nof_r_drw)
+                       } else if (nofp->nof_r_drw) {
                                denyMode = NFS_OPEN_SHARE_DENY_BOTH;
+                       }
+               } else if (nofp->nof_d_rw || nofp->nof_d_rw_dw || nofp->nof_d_rw_drw) {
+                       /*
+                        * This clause and the one below is to co-opt a read write access
+                        * for a read only mmaping. We probably got here in that an
+                        * existing rw open for an executable file already exists.
+                        */
+                       delegated = 1;
+                       accessMode = NFS_OPEN_SHARE_ACCESS_BOTH;
+                       if (nofp->nof_d_rw) {
+                               denyMode = NFS_OPEN_SHARE_DENY_NONE;
+                       } else if (nofp->nof_d_rw_dw) {
+                               denyMode = NFS_OPEN_SHARE_DENY_WRITE;
+                       } else if (nofp->nof_d_rw_drw) {
+                               denyMode = NFS_OPEN_SHARE_DENY_BOTH;
+                       }
+               } else if (nofp->nof_rw || nofp->nof_rw_dw || nofp->nof_rw_drw) {
+                       delegated = 0;
+                       accessMode = NFS_OPEN_SHARE_ACCESS_BOTH;
+                       if (nofp->nof_rw) {
+                               denyMode = NFS_OPEN_SHARE_DENY_NONE;
+                       } else if (nofp->nof_rw_dw) {
+                               denyMode = NFS_OPEN_SHARE_DENY_WRITE;
+                       } else if (nofp->nof_rw_drw) {
+                               denyMode = NFS_OPEN_SHARE_DENY_BOTH;
+                       }
                } else {
                        error = EPERM;
                }
        }
-       if (error) /* mmap mode without proper open mode */
+       if (error) /* mmap mode without proper open mode */
                goto out;
+       }
 
        /*
         * If the existing mmap access is more than the new access OR the
@@ -2802,15 +3123,17 @@ restart:
         * then we'll stick with the existing mmap open mode.
         */
        if ((nofp->nof_mmap_access > accessMode) ||
-           ((nofp->nof_mmap_access == accessMode) && (nofp->nof_mmap_deny <= denyMode)))
+           ((nofp->nof_mmap_access == accessMode) && (nofp->nof_mmap_deny <= denyMode))) {
                goto out;
+       }
 
        /* update mmap open mode */
        if (nofp->nof_mmap_access) {
                error = nfs_close(np, nofp, nofp->nof_mmap_access, nofp->nof_mmap_deny, ctx);
                if (error) {
-                       if (!nfs_mount_state_error_should_restart(error))
+                       if (!nfs_mount_state_error_should_restart(error)) {
                                NP(np, "nfs_vnop_mmap: close of previous mmap mode failed: %d, %d", error, kauth_cred_getuid(nofp->nof_owner->noo_cred));
+                       }
                        NP(np, "nfs_vnop_mmap: update, close error %d, %d", error, kauth_cred_getuid(nofp->nof_owner->noo_cred));
                        goto out;
                }
@@ -2822,14 +3145,16 @@ restart:
        nofp->nof_mmap_deny = denyMode;
 
 out:
-       if (nofp)
+       if (nofp) {
                nfs_open_file_clear_busy(nofp);
+       }
        if (nfs_mount_state_in_use_end(nmp, error)) {
                nofp = NULL;
                goto restart;
        }
-       if (noop)
+       if (noop) {
                nfs_open_owner_rele(noop);
+       }
 
        if (!error) {
                int ismapped = 0;
@@ -2843,24 +3168,61 @@ out:
                        lck_mtx_lock(&nmp->nm_lock);
                        nmp->nm_state &= ~NFSSTA_SQUISHY;
                        nmp->nm_curdeadtimeout = nmp->nm_deadtimeout;
-                       if (nmp->nm_curdeadtimeout <= 0)
+                       if (nmp->nm_curdeadtimeout <= 0) {
                                nmp->nm_deadto_start = 0;
+                       }
                        nmp->nm_mappers++;
                        lck_mtx_unlock(&nmp->nm_lock);
                }
        }
 
-       return (error);
+       return error;
 }
 
+int
+nfs_vnop_mmap_check(
+       struct vnop_mmap_check_args /* {
+                                     *  struct vnodeop_desc *a_desc;
+                                     *  vnode_t a_vp;
+                                     *  int a_flags;
+                                     *  vfs_context_t a_context;
+                                     *  } */*ap)
+{
+       vfs_context_t ctx = ap->a_context;
+       vnode_t vp = ap->a_vp;
+       struct nfsmount *nmp = VTONMP(vp);
+       struct vnop_access_args naa;
+       int error = 0;
+
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
+
+       if (vnode_isreg(vp)) {
+               /*
+                * We only need to ensure that a page-in will be
+                * possible with these credentials.  Everything
+                * else has been checked at other layers.
+                */
+               naa.a_desc = &vnop_access_desc;
+               naa.a_vp = vp;
+               naa.a_action = KAUTH_VNODE_READ_DATA;
+               naa.a_context = ctx;
+
+               /* compute actual success/failure based on accessibility */
+               error = nfs_vnop_access(&naa);
+       }
+
+       return error;
+}
 
 int
 nfs_vnop_mnomap(
        struct vnop_mnomap_args /* {
-               struct vnodeop_desc *a_desc;
-               vnode_t a_vp;
-               vfs_context_t a_context;
-       } */ *ap)
+                                 *  struct vnodeop_desc *a_desc;
+                                 *  vnode_t a_vp;
+                                 *  vfs_context_t a_context;
+                                 *  } */*ap)
 {
        vfs_context_t ctx = ap->a_context;
        vnode_t vp = ap->a_vp;
@@ -2870,10 +3232,11 @@ nfs_vnop_mnomap(
        off_t size;
        int error;
        int is_mapped_flag = 0;
-       
+
        nmp = VTONMP(vp);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
 
        nfs_node_lock_force(np);
        if (np->n_flag & NISMAPPED) {
@@ -2883,36 +3246,44 @@ nfs_vnop_mnomap(
        nfs_node_unlock(np);
        if (is_mapped_flag) {
                lck_mtx_lock(&nmp->nm_lock);
-               if (nmp->nm_mappers)
+               if (nmp->nm_mappers) {
                        nmp->nm_mappers--;
-               else
+               } else {
                        NP(np, "nfs_vnop_mnomap: removing mmap reference from mount, but mount has no files mmapped");
+               }
                lck_mtx_unlock(&nmp->nm_lock);
        }
 
        /* flush buffers/ubc before we drop the open (in case it's our last open) */
        nfs_flush(np, MNT_WAIT, vfs_context_thread(ctx), V_IGNORE_WRITEERR);
-       if (UBCINFOEXISTS(vp) && (size = ubc_getsize(vp)))
+       if (UBCINFOEXISTS(vp) && (size = ubc_getsize(vp))) {
                ubc_msync(vp, 0, size, NULL, UBC_PUSHALL | UBC_SYNC);
+       }
 
        /* walk all open files and close all mmap opens */
 loop:
        error = nfs_mount_state_in_use_start(nmp, NULL);
-       if (error)
-               return (error);
+       if (error) {
+               return error;
+       }
        lck_mtx_lock(&np->n_openlock);
        TAILQ_FOREACH(nofp, &np->n_opens, nof_link) {
-               if (!nofp->nof_mmap_access)
+               if (!nofp->nof_mmap_access) {
                        continue;
+               }
                lck_mtx_unlock(&np->n_openlock);
+#if CONFIG_NFS4
                if (nofp->nof_flags & NFS_OPEN_FILE_REOPEN) {
-                       nfs_mount_state_in_use_end(nmp, 0);
                        error = nfs4_reopen(nofp, NULL);
-                       if (!error)
+                       if (!error) {
+                               nfs_mount_state_in_use_end(nmp, 0);
                                goto loop;
+                       }
                }
-               if (!error)
+#endif
+               if (!error) {
                        error = nfs_open_file_set_busy(nofp, NULL);
+               }
                if (error) {
                        lck_mtx_lock(&np->n_openlock);
                        break;
@@ -2920,12 +3291,14 @@ loop:
                if (nofp->nof_mmap_access) {
                        error = nfs_close(np, nofp, nofp->nof_mmap_access, nofp->nof_mmap_deny, ctx);
                        if (!nfs_mount_state_error_should_restart(error)) {
-                               if (error) /* not a state-operation-restarting error, so just clear the access */
+                               if (error) /* not a state-operation-restarting error, so just clear the access */
                                        NP(np, "nfs_vnop_mnomap: close of mmap mode failed: %d, %d", error, kauth_cred_getuid(nofp->nof_owner->noo_cred));
+                               }
                                nofp->nof_mmap_access = nofp->nof_mmap_deny = 0;
                        }
-                       if (error)
+                       if (error) {
                                NP(np, "nfs_vnop_mnomap: error %d, %d", error, kauth_cred_getuid(nofp->nof_owner->noo_cred));
+                       }
                }
                nfs_open_file_clear_busy(nofp);
                nfs_mount_state_in_use_end(nmp, error);
@@ -2933,7 +3306,7 @@ loop:
        }
        lck_mtx_unlock(&np->n_openlock);
        nfs_mount_state_in_use_end(nmp, error);
-       return (error);
+       return error;
 }
 
 /*
@@ -2949,14 +3322,19 @@ nfs_lock_owner_find(nfsnode_t np, proc_t p, int alloc)
 tryagain:
        lck_mtx_lock(&np->n_openlock);
        TAILQ_FOREACH(nlop, &np->n_lock_owners, nlo_link) {
-               if (nlop->nlo_pid != pid)
+               os_ref_count_t newcount;
+
+               if (nlop->nlo_pid != pid) {
                        continue;
-               if (timevalcmp(&nlop->nlo_pid_start, &p->p_start, ==))
+               }
+               if (timevalcmp(&nlop->nlo_pid_start, &p->p_start, ==)) {
                        break;
+               }
                /* stale lock owner... reuse it if we can */
-               if (nlop->nlo_refcnt) {
+               if (os_ref_get_count(&nlop->nlo_refcnt)) {
                        TAILQ_REMOVE(&np->n_lock_owners, nlop, nlo_link);
                        nlop->nlo_flags &= ~NFS_LOCK_OWNER_LINK;
+                       newcount = os_ref_release_locked(&nlop->nlo_refcnt);
                        lck_mtx_unlock(&np->n_openlock);
                        goto tryagain;
                }
@@ -2969,10 +3347,11 @@ tryagain:
        if (!nlop && !newnlop && alloc) {
                lck_mtx_unlock(&np->n_openlock);
                MALLOC(newnlop, struct nfs_lock_owner *, sizeof(struct nfs_lock_owner), M_TEMP, M_WAITOK);
-               if (!newnlop)
-                       return (NULL);
+               if (!newnlop) {
+                       return NULL;
+               }
                bzero(newnlop, sizeof(*newnlop));
-               lck_mtx_init(&newnlop->nlo_lock, nfs_open_grp, LCK_ATTR_NULL);
+               lck_mtx_init(&newnlop->nlo_lock, &nfs_open_grp, LCK_ATTR_NULL);
                newnlop->nlo_pid = pid;
                newnlop->nlo_pid_start = p->p_start;
                newnlop->nlo_name = OSAddAtomic(1, &nfs_lock_owner_seqnum);
@@ -2981,18 +3360,21 @@ tryagain:
        }
        if (!nlop && newnlop) {
                newnlop->nlo_flags |= NFS_LOCK_OWNER_LINK;
+               os_ref_init(&newnlop->nlo_refcnt, NULL);
                TAILQ_INSERT_HEAD(&np->n_lock_owners, newnlop, nlo_link);
                nlop = newnlop;
        }
        lck_mtx_unlock(&np->n_openlock);
 
-       if (newnlop && (nlop != newnlop))
+       if (newnlop && (nlop != newnlop)) {
                nfs_lock_owner_destroy(newnlop);
+       }
 
-       if (nlop)
+       if (nlop) {
                nfs_lock_owner_ref(nlop);
+       }
 
-       return (nlop);
+       return nlop;
 }
 
 /*
@@ -3005,7 +3387,7 @@ nfs_lock_owner_destroy(struct nfs_lock_owner *nlop)
                nfs_open_owner_rele(nlop->nlo_open_owner);
                nlop->nlo_open_owner = NULL;
        }
-       lck_mtx_destroy(&nlop->nlo_lock, nfs_open_grp);
+       lck_mtx_destroy(&nlop->nlo_lock, &nfs_open_grp);
        FREE(nlop, M_TEMP);
 }
 
@@ -3016,7 +3398,7 @@ void
 nfs_lock_owner_ref(struct nfs_lock_owner *nlop)
 {
        lck_mtx_lock(&nlop->nlo_lock);
-       nlop->nlo_refcnt++;
+       os_ref_retain_locked(&nlop->nlo_refcnt);
        lck_mtx_unlock(&nlop->nlo_lock);
 }
 
@@ -3027,14 +3409,18 @@ nfs_lock_owner_ref(struct nfs_lock_owner *nlop)
 void
 nfs_lock_owner_rele(struct nfs_lock_owner *nlop)
 {
+       os_ref_count_t newcount;
+
        lck_mtx_lock(&nlop->nlo_lock);
-       if (nlop->nlo_refcnt < 1)
+       if (os_ref_get_count(&nlop->nlo_refcnt) < 1) {
                panic("nfs_lock_owner_rele: no refcnt");
-       nlop->nlo_refcnt--;
-       if (!nlop->nlo_refcnt && (nlop->nlo_flags & NFS_LOCK_OWNER_BUSY))
+       }
+       newcount = os_ref_release_locked(&nlop->nlo_refcnt);
+       if (!newcount && (nlop->nlo_flags & NFS_LOCK_OWNER_BUSY)) {
                panic("nfs_lock_owner_rele: busy");
+       }
        /* XXX we may potentially want to clean up idle/unused lock owner structures */
-       if (nlop->nlo_refcnt || (nlop->nlo_flags & NFS_LOCK_OWNER_LINK)) {
+       if (newcount || (nlop->nlo_flags & NFS_LOCK_OWNER_LINK)) {
                lck_mtx_unlock(&nlop->nlo_lock);
                return;
        }
@@ -3051,27 +3437,30 @@ int
 nfs_lock_owner_set_busy(struct nfs_lock_owner *nlop, thread_t thd)
 {
        struct nfsmount *nmp;
-       struct timespec ts = {2, 0};
+       struct timespec ts = { .tv_sec = 2, .tv_nsec = 0 };
        int error = 0, slpflag;
 
        nmp = nlop->nlo_open_owner->noo_mount;
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        slpflag = (NMFLAG(nmp, INTR) && thd) ? PCATCH : 0;
 
        lck_mtx_lock(&nlop->nlo_lock);
        while (nlop->nlo_flags & NFS_LOCK_OWNER_BUSY) {
-               if ((error = nfs_sigintr(nmp, NULL, thd, 0)))
+               if ((error = nfs_sigintr(nmp, NULL, thd, 0))) {
                        break;
+               }
                nlop->nlo_flags |= NFS_LOCK_OWNER_WANT;
                msleep(nlop, &nlop->nlo_lock, slpflag, "nfs_lock_owner_set_busy", &ts);
                slpflag = 0;
        }
-       if (!error)
+       if (!error) {
                nlop->nlo_flags |= NFS_LOCK_OWNER_BUSY;
+       }
        lck_mtx_unlock(&nlop->nlo_lock);
 
-       return (error);
+       return error;
 }
 
 /*
@@ -3084,13 +3473,15 @@ nfs_lock_owner_clear_busy(struct nfs_lock_owner *nlop)
        int wanted;
 
        lck_mtx_lock(&nlop->nlo_lock);
-       if (!(nlop->nlo_flags & NFS_LOCK_OWNER_BUSY))
+       if (!(nlop->nlo_flags & NFS_LOCK_OWNER_BUSY)) {
                panic("nfs_lock_owner_clear_busy");
+       }
        wanted = (nlop->nlo_flags & NFS_LOCK_OWNER_WANT);
-       nlop->nlo_flags &= ~(NFS_LOCK_OWNER_BUSY|NFS_LOCK_OWNER_WANT);
+       nlop->nlo_flags &= ~(NFS_LOCK_OWNER_BUSY | NFS_LOCK_OWNER_WANT);
        lck_mtx_unlock(&nlop->nlo_lock);
-       if (wanted)
+       if (wanted) {
                wakeup(nlop);
+       }
 }
 
 /*
@@ -3108,13 +3499,15 @@ nfs_lock_owner_insert_held_lock(struct nfs_lock_owner *nlop, struct nfs_file_loc
                TAILQ_INSERT_HEAD(&nlop->nlo_locks, newnflp, nfl_lolink);
        } else {
                TAILQ_FOREACH(nflp, &nlop->nlo_locks, nfl_lolink) {
-                       if (newnflp->nfl_start < nflp->nfl_start)
+                       if (newnflp->nfl_start < nflp->nfl_start) {
                                break;
+                       }
                }
-               if (nflp)
+               if (nflp) {
                        TAILQ_INSERT_BEFORE(nflp, newnflp, nfl_lolink);
-               else
+               } else {
                        TAILQ_INSERT_TAIL(&nlop->nlo_locks, newnflp, nfl_lolink);
+               }
        }
        lck_mtx_unlock(&nlop->nlo_lock);
 }
@@ -3135,14 +3528,15 @@ nfs_file_lock_alloc(struct nfs_lock_owner *nlop)
        lck_mtx_unlock(&nlop->nlo_lock);
        if (!nflp) {
                MALLOC(nflp, struct nfs_file_lock *, sizeof(struct nfs_file_lock), M_TEMP, M_WAITOK);
-               if (!nflp)
-                       return (NULL);
+               if (!nflp) {
+                       return NULL;
+               }
                bzero(nflp, sizeof(*nflp));
                nflp->nfl_flags |= NFS_FILE_LOCK_ALLOC;
                nflp->nfl_owner = nlop;
        }
        nfs_lock_owner_ref(nlop);
-       return (nflp);
+       return nflp;
 }
 
 /*
@@ -3158,7 +3552,7 @@ nfs_file_lock_destroy(struct nfs_file_lock *nflp)
                FREE(nflp, M_TEMP);
        } else {
                lck_mtx_lock(&nlop->nlo_lock);
-               bzero(nflp, sizeof(nflp));
+               bzero(nflp, sizeof(*nflp));
                lck_mtx_unlock(&nlop->nlo_lock);
        }
        nfs_lock_owner_rele(nlop);
@@ -3172,27 +3566,32 @@ int
 nfs_file_lock_conflict(struct nfs_file_lock *nflp1, struct nfs_file_lock *nflp2, int *willsplit)
 {
        /* no conflict if lock is dead */
-       if ((nflp1->nfl_flags & NFS_FILE_LOCK_DEAD) || (nflp2->nfl_flags & NFS_FILE_LOCK_DEAD))
-               return (0);
+       if ((nflp1->nfl_flags & NFS_FILE_LOCK_DEAD) || (nflp2->nfl_flags & NFS_FILE_LOCK_DEAD)) {
+               return 0;
+       }
        /* no conflict if it's ours - unless the lock style doesn't match */
        if ((nflp1->nfl_owner == nflp2->nfl_owner) &&
            ((nflp1->nfl_flags & NFS_FILE_LOCK_STYLE_MASK) == (nflp2->nfl_flags & NFS_FILE_LOCK_STYLE_MASK))) {
                if (willsplit && (nflp1->nfl_type != nflp2->nfl_type) &&
                    (nflp1->nfl_start > nflp2->nfl_start) &&
-                   (nflp1->nfl_end < nflp2->nfl_end))
+                   (nflp1->nfl_end < nflp2->nfl_end)) {
                        *willsplit = 1;
-               return (0);
+               }
+               return 0;
        }
        /* no conflict if ranges don't overlap */
-       if ((nflp1->nfl_start > nflp2->nfl_end) || (nflp1->nfl_end < nflp2->nfl_start))
-               return (0);
+       if ((nflp1->nfl_start > nflp2->nfl_end) || (nflp1->nfl_end < nflp2->nfl_start)) {
+               return 0;
+       }
        /* no conflict if neither lock is exclusive */
-       if ((nflp1->nfl_type != F_WRLCK) && (nflp2->nfl_type != F_WRLCK))
-               return (0);
+       if ((nflp1->nfl_type != F_WRLCK) && (nflp2->nfl_type != F_WRLCK)) {
+               return 0;
+       }
        /* conflict */
-       return (1);
+       return 1;
 }
 
+#if CONFIG_NFS4
 /*
  * Send an NFSv4 LOCK RPC to the server.
  */
@@ -3215,27 +3614,30 @@ nfs4_setlock_rpc(
        struct nfsreq_secinfo_args si;
 
        nmp = NFSTONMP(np);
-       if (!nmp)
-               return (ENXIO);
-       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL)
-               return (EINVAL);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
+       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL) {
+               return EINVAL;
+       }
 
        newlocker = (nlop->nlo_stategenid != nmp->nm_stategenid);
        locktype = (nflp->nfl_flags & NFS_FILE_LOCK_WAIT) ?
-                       ((nflp->nfl_type == F_WRLCK) ?
-                               NFS_LOCK_TYPE_WRITEW :
-                               NFS_LOCK_TYPE_READW) :
-                       ((nflp->nfl_type == F_WRLCK) ?
-                               NFS_LOCK_TYPE_WRITE :
-                               NFS_LOCK_TYPE_READ);
+           ((nflp->nfl_type == F_WRLCK) ?
+           NFS_LOCK_TYPE_WRITEW :
+           NFS_LOCK_TYPE_READW) :
+           ((nflp->nfl_type == F_WRLCK) ?
+           NFS_LOCK_TYPE_WRITE :
+           NFS_LOCK_TYPE_READ);
        if (newlocker) {
                error = nfs_open_file_set_busy(nofp, thd);
-               if (error)
-                       return (error);
+               if (error) {
+                       return error;
+               }
                error = nfs_open_owner_set_busy(nofp->nof_owner, thd);
                if (error) {
                        nfs_open_file_clear_busy(nofp);
-                       return (error);
+                       return error;
                }
                if (!nlop->nlo_open_owner) {
                        nfs_open_owner_ref(nofp->nof_owner);
@@ -3248,7 +3650,7 @@ nfs4_setlock_rpc(
                        nfs_open_owner_clear_busy(nofp->nof_owner);
                        nfs_open_file_clear_busy(nofp);
                }
-               return (error);
+               return error;
        }
 
        NFSREQ_SECINFO_SET(&si, np, NULL, 0, NULL, 0);
@@ -3258,7 +3660,7 @@ nfs4_setlock_rpc(
        // PUTFH, GETATTR, LOCK
        numops = 3;
        nfsm_chain_build_alloc_init(error, &nmreq, 33 * NFSX_UNSIGNED);
-       nfsm_chain_add_compound_header(error, &nmreq, "lock", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "lock", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, NFS_VER4, np->n_fhp, np->n_fhsize);
@@ -3285,10 +3687,11 @@ nfs4_setlock_rpc(
        nfsm_assert(error, (numops == 0), EPROTO);
        nfsmout_if(error);
 
-       error = nfs_request2(np, NULL, &nmreq, NFSPROC4_COMPOUND, thd, cred, &si, flags|R_NOINTR, &nmrep, &xid, &status);
+       error = nfs_request2(np, NULL, &nmreq, NFSPROC4_COMPOUND, thd, cred, &si, flags | R_NOINTR, &nmrep, &xid, &status);
 
-       if ((lockerror = nfs_node_lock(np)))
+       if ((lockerror = nfs_node_lock(np))) {
                error = lockerror;
+       }
        nfsm_chain_skip_tag(error, &nmrep);
        nfsm_chain_get_32(error, &nmrep, numops);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_PUTFH);
@@ -3302,11 +3705,13 @@ nfs4_setlock_rpc(
 
        /* Update the lock owner's stategenid once it appears the server has state for it. */
        /* We determine this by noting the request was successful (we got a stateid). */
-       if (newlocker && !error)
+       if (newlocker && !error) {
                nlop->nlo_stategenid = nmp->nm_stategenid;
+       }
 nfsmout:
-       if (!lockerror)
+       if (!lockerror) {
                nfs_node_unlock(np);
+       }
        nfs_lock_owner_clear_busy(nlop);
        if (newlocker) {
                nfs_open_owner_clear_busy(nofp->nof_owner);
@@ -3314,7 +3719,7 @@ nfsmout:
        }
        nfsm_chain_cleanup(&nmreq);
        nfsm_chain_cleanup(&nmrep);
-       return (error);
+       return error;
 }
 
 /*
@@ -3338,14 +3743,17 @@ nfs4_unlock_rpc(
        struct nfsreq_secinfo_args si;
 
        nmp = NFSTONMP(np);
-       if (!nmp)
-               return (ENXIO);
-       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL)
-               return (EINVAL);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
+       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL) {
+               return EINVAL;
+       }
 
        error = nfs_lock_owner_set_busy(nlop, NULL);
-       if (error)
-               return (error);
+       if (error) {
+               return error;
+       }
 
        NFSREQ_SECINFO_SET(&si, np, NULL, 0, NULL, 0);
        nfsm_chain_null(&nmreq);
@@ -3354,7 +3762,7 @@ nfs4_unlock_rpc(
        // PUTFH, GETATTR, LOCKU
        numops = 3;
        nfsm_chain_build_alloc_init(error, &nmreq, 26 * NFSX_UNSIGNED);
-       nfsm_chain_add_compound_header(error, &nmreq, "unlock", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "unlock", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, NFS_VER4, np->n_fhp, np->n_fhsize);
@@ -3372,10 +3780,11 @@ nfs4_unlock_rpc(
        nfsm_assert(error, (numops == 0), EPROTO);
        nfsmout_if(error);
 
-       error = nfs_request2(np, NULL, &nmreq, NFSPROC4_COMPOUND, thd, cred, &si, flags|R_NOINTR, &nmrep, &xid, &status);
+       error = nfs_request2(np, NULL, &nmreq, NFSPROC4_COMPOUND, thd, cred, &si, flags | R_NOINTR, &nmrep, &xid, &status);
 
-       if ((lockerror = nfs_node_lock(np)))
+       if ((lockerror = nfs_node_lock(np))) {
                error = lockerror;
+       }
        nfsm_chain_skip_tag(error, &nmrep);
        nfsm_chain_get_32(error, &nmrep, numops);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_PUTFH);
@@ -3387,12 +3796,13 @@ nfs4_unlock_rpc(
        nfs_owner_seqid_increment(NULL, nlop, error);
        nfsm_chain_get_stateid(error, &nmrep, &nlop->nlo_stateid);
 nfsmout:
-       if (!lockerror)
+       if (!lockerror) {
                nfs_node_unlock(np);
+       }
        nfs_lock_owner_clear_busy(nlop);
        nfsm_chain_cleanup(&nmreq);
        nfsm_chain_cleanup(&nmrep);
-       return (error);
+       return error;
 }
 
 /*
@@ -3415,10 +3825,12 @@ nfs4_getlock_rpc(
        struct nfsreq_secinfo_args si;
 
        nmp = NFSTONMP(np);
-       if (!nmp)
-               return (ENXIO);
-       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL)
-               return (EINVAL);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
+       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL) {
+               return EINVAL;
+       }
 
        lockerror = ENOENT;
        NFSREQ_SECINFO_SET(&si, np, NULL, 0, NULL, 0);
@@ -3428,7 +3840,7 @@ nfs4_getlock_rpc(
        // PUTFH, GETATTR, LOCKT
        numops = 3;
        nfsm_chain_build_alloc_init(error, &nmreq, 26 * NFSX_UNSIGNED);
-       nfsm_chain_add_compound_header(error, &nmreq, "locktest", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "locktest", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, NFS_VER4, np->n_fhp, np->n_fhsize);
@@ -3447,8 +3859,9 @@ nfs4_getlock_rpc(
 
        error = nfs_request(np, NULL, &nmreq, NFSPROC4_COMPOUND, ctx, &si, &nmrep, &xid, &status);
 
-       if ((lockerror = nfs_node_lock(np)))
+       if ((lockerror = nfs_node_lock(np))) {
                error = lockerror;
+       }
        nfsm_chain_skip_tag(error, &nmrep);
        nfsm_chain_get_32(error, &nmrep, numops);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_PUTFH);
@@ -3470,13 +3883,14 @@ nfs4_getlock_rpc(
                fl->l_type = F_UNLCK;
        }
 nfsmout:
-       if (!lockerror)
+       if (!lockerror) {
                nfs_node_unlock(np);
+       }
        nfsm_chain_cleanup(&nmreq);
        nfsm_chain_cleanup(&nmrep);
-       return (error);
+       return error;
 }
-
+#endif /* CONFIG_NFS4 */
 
 /*
  * Check for any conflicts with the given lock.
@@ -3499,21 +3913,25 @@ nfs_advlock_getlock(
        int error = 0, answered = 0;
 
        nmp = NFSTONMP(np);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
 
 restart:
-       if ((error = nfs_mount_state_in_use_start(nmp, vfs_context_thread(ctx))))
-               return (error);
+       if ((error = nfs_mount_state_in_use_start(nmp, vfs_context_thread(ctx)))) {
+               return error;
+       }
 
        lck_mtx_lock(&np->n_openlock);
        /* scan currently held locks for conflict */
        TAILQ_FOREACH(nflp, &np->n_locks, nfl_link) {
-               if (nflp->nfl_flags & (NFS_FILE_LOCK_BLOCKED|NFS_FILE_LOCK_DEAD))
+               if (nflp->nfl_flags & (NFS_FILE_LOCK_BLOCKED | NFS_FILE_LOCK_DEAD)) {
                        continue;
+               }
                if ((start <= nflp->nfl_end) && (end >= nflp->nfl_start) &&
-                   ((fl->l_type == F_WRLCK) || (nflp->nfl_type == F_WRLCK)))
+                   ((fl->l_type == F_WRLCK) || (nflp->nfl_type == F_WRLCK))) {
                        break;
+               }
        }
        if (nflp) {
                /* found a conflicting lock */
@@ -3534,15 +3952,16 @@ restart:
        lck_mtx_unlock(&np->n_openlock);
        if (answered) {
                nfs_mount_state_in_use_end(nmp, 0);
-               return (0);
+               return 0;
        }
 
        /* no conflict found locally, so ask the server */
        error = nmp->nm_funcs->nf_getlock_rpc(np, nlop, fl, start, end, ctx);
 
-       if (nfs_mount_state_in_use_end(nmp, error))
+       if (nfs_mount_state_in_use_end(nmp, error)) {
                goto restart;
-       return (error);
+       }
+       return error;
 }
 
 /*
@@ -3572,25 +3991,29 @@ nfs_advlock_setlock(
        struct nfs_file_lock *newnflp, *nflp, *nflp2 = NULL, *nextnflp, *flocknflp = NULL;
        struct nfs_file_lock *coalnflp;
        int error = 0, error2, willsplit = 0, delay, slpflag, busy = 0, inuse = 0, restart, inqueue = 0;
-       struct timespec ts = {1, 0};
+       struct timespec ts = { .tv_sec = 1, .tv_nsec = 0 };
 
        nmp = NFSTONMP(np);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        slpflag = NMFLAG(nmp, INTR) ? PCATCH : 0;
 
-       if ((type != F_RDLCK) && (type != F_WRLCK))
-               return (EINVAL);
+       if ((type != F_RDLCK) && (type != F_WRLCK)) {
+               return EINVAL;
+       }
 
        /* allocate a new lock */
        newnflp = nfs_file_lock_alloc(nlop);
-       if (!newnflp)
-               return (ENOLCK);
+       if (!newnflp) {
+               return ENOLCK;
+       }
        newnflp->nfl_start = start;
        newnflp->nfl_end = end;
        newnflp->nfl_type = type;
-       if (op == F_SETLKW)
+       if (op == F_SETLKW) {
                newnflp->nfl_flags |= NFS_FILE_LOCK_WAIT;
+       }
        newnflp->nfl_flags |= style;
        newnflp->nfl_flags |= NFS_FILE_LOCK_BLOCKED;
 
@@ -3602,18 +4025,21 @@ nfs_advlock_setlock(
                 * have a shared flock-style lock.
                 */
                nflp = TAILQ_FIRST(&nlop->nlo_locks);
-               if (nflp && ((nflp->nfl_flags & NFS_FILE_LOCK_STYLE_MASK) != NFS_FILE_LOCK_STYLE_FLOCK))
+               if (nflp && ((nflp->nfl_flags & NFS_FILE_LOCK_STYLE_MASK) != NFS_FILE_LOCK_STYLE_FLOCK)) {
                        nflp = NULL;
-               if (nflp && (nflp->nfl_type != F_RDLCK))
+               }
+               if (nflp && (nflp->nfl_type != F_RDLCK)) {
                        nflp = NULL;
+               }
                flocknflp = nflp;
        }
 
 restart:
        restart = 0;
        error = nfs_mount_state_in_use_start(nmp, vfs_context_thread(ctx));
-       if (error)
+       if (error) {
                goto error_out;
+       }
        inuse = 1;
        if (np->n_flag & NREVOKE) {
                error = EIO;
@@ -3621,14 +4047,17 @@ restart:
                inuse = 0;
                goto error_out;
        }
+#if CONFIG_NFS4
        if (nofp->nof_flags & NFS_OPEN_FILE_REOPEN) {
                nfs_mount_state_in_use_end(nmp, 0);
                inuse = 0;
                error = nfs4_reopen(nofp, vfs_context_thread(ctx));
-               if (error)
+               if (error) {
                        goto error_out;
+               }
                goto restart;
        }
+#endif
 
        lck_mtx_lock(&np->n_openlock);
        if (!inqueue) {
@@ -3640,8 +4069,9 @@ restart:
        /* scan current list of locks (held and pending) for conflicts */
        for (nflp = TAILQ_NEXT(newnflp, nfl_link); nflp; nflp = nextnflp) {
                nextnflp = TAILQ_NEXT(nflp, nfl_link);
-               if (!nfs_file_lock_conflict(newnflp, nflp, &willsplit))
+               if (!nfs_file_lock_conflict(newnflp, nflp, &willsplit)) {
                        continue;
+               }
                /* Conflict */
                if (!(newnflp->nfl_flags & NFS_FILE_LOCK_WAIT)) {
                        error = EAGAIN;
@@ -3661,8 +4091,9 @@ restart:
                                inuse = 0;
                                error = nfs_advlock_unlock(np, nofp, nlop, 0, UINT64_MAX, NFS_FILE_LOCK_STYLE_FLOCK, ctx);
                                flocknflp = NULL;
-                               if (!error)
+                               if (!error) {
                                        error = nfs_mount_state_in_use_start(nmp, vfs_context_thread(ctx));
+                               }
                                if (error) {
                                        lck_mtx_lock(&np->n_openlock);
                                        break;
@@ -3670,8 +4101,9 @@ restart:
                                inuse = 1;
                                lck_mtx_lock(&np->n_openlock);
                                /* no need to block/sleep if the conflict is gone */
-                               if (!nfs_file_lock_conflict(newnflp, nflp, NULL))
+                               if (!nfs_file_lock_conflict(newnflp, nflp, NULL)) {
                                        break;
+                               }
                        }
                        msleep(nflp, &np->n_openlock, slpflag, "nfs_advlock_setlock_blocked", &ts);
                        slpflag = 0;
@@ -3685,25 +4117,29 @@ restart:
                                lck_mtx_lock(&np->n_openlock);
                                break;
                        }
-                       if (!error && (np->n_flag & NREVOKE))
+                       if (!error && (np->n_flag & NREVOKE)) {
                                error = EIO;
+                       }
                } while (!error && nfs_file_lock_conflict(newnflp, nflp, NULL));
                nflp->nfl_blockcnt--;
                if ((nflp->nfl_flags & NFS_FILE_LOCK_DEAD) && !nflp->nfl_blockcnt) {
                        TAILQ_REMOVE(&np->n_locks, nflp, nfl_link);
                        nfs_file_lock_destroy(nflp);
                }
-               if (error || restart)
+               if (error || restart) {
                        break;
+               }
                /* We have released n_openlock and we can't trust that nextnflp is still valid. */
                /* So, start this lock-scanning loop over from where it started. */
                nextnflp = TAILQ_NEXT(newnflp, nfl_link);
        }
        lck_mtx_unlock(&np->n_openlock);
-       if (restart)
+       if (restart) {
                goto restart;
-       if (error)
+       }
+       if (error) {
                goto error_out;
+       }
 
        if (willsplit) {
                /*
@@ -3719,11 +4155,13 @@ restart:
        }
 
        /* once scan for local conflicts is clear, send request to server */
-       if ((error = nfs_open_state_set_busy(np, vfs_context_thread(ctx))))
+       if ((error = nfs_open_state_set_busy(np, vfs_context_thread(ctx)))) {
                goto error_out;
+       }
        busy = 1;
        delay = 0;
        do {
+#if CONFIG_NFS4
                /* do we have a delegation? (that we're not returning?) */
                if ((np->n_openflags & N_DELEG_MASK) && !(np->n_openflags & N_DELEG_RETURN)) {
                        if (np->n_openflags & N_DELEG_WRITE) {
@@ -3744,23 +4182,35 @@ restart:
                                 * with an open it knows about.
                                 */
                                if ((!nofp->nof_rw_drw && !nofp->nof_w_drw && !nofp->nof_r_drw &&
-                                    !nofp->nof_rw_dw && !nofp->nof_w_dw && !nofp->nof_r_dw &&
-                                    !nofp->nof_rw && !nofp->nof_w && !nofp->nof_r) &&
+                                   !nofp->nof_rw_dw && !nofp->nof_w_dw && !nofp->nof_r_dw &&
+                                   !nofp->nof_rw && !nofp->nof_w && !nofp->nof_r) &&
                                    (nofp->nof_d_rw_drw || nofp->nof_d_w_drw || nofp->nof_d_r_drw ||
-                                    nofp->nof_d_rw_dw || nofp->nof_d_w_dw || nofp->nof_d_r_dw ||
-                                    nofp->nof_d_rw || nofp->nof_d_w || nofp->nof_d_r)) {
+                                   nofp->nof_d_rw_dw || nofp->nof_d_w_dw || nofp->nof_d_r_dw ||
+                                   nofp->nof_d_rw || nofp->nof_d_w || nofp->nof_d_r)) {
                                        error = nfs4_claim_delegated_state_for_open_file(nofp, 0);
-                                       if (error)
+                                       if (error) {
                                                break;
+                                       }
                                }
                        }
                }
-               if (np->n_flag & NREVOKE)
+#endif
+               if (np->n_flag & NREVOKE) {
                        error = EIO;
-               if (!error)
+               }
+               if (!error) {
+                       if (busy) {
+                               nfs_open_state_clear_busy(np);
+                               busy = 0;
+                       }
                        error = nmp->nm_funcs->nf_setlock_rpc(np, nofp, newnflp, 0, 0, vfs_context_thread(ctx), vfs_context_ucred(ctx));
-               if (!error || ((error != NFSERR_DENIED) && (error != NFSERR_GRACE)))
+                       if (!busy && !nfs_open_state_set_busy(np, vfs_context_thread(ctx))) {
+                               busy = 1;
+                       }
+               }
+               if (!error || ((error != NFSERR_DENIED) && (error != NFSERR_GRACE))) {
                        break;
+               }
                /* request was denied due to either conflict or grace period */
                if ((error == NFSERR_DENIED) && !(newnflp->nfl_flags & NFS_FILE_LOCK_WAIT)) {
                        error = EAGAIN;
@@ -3770,12 +4220,15 @@ restart:
                        /* release any currently held shared lock before sleeping */
                        nfs_open_state_clear_busy(np);
                        busy = 0;
-                       nfs_mount_state_in_use_end(nmp, 0);
-                       inuse = 0;
+                       if (inuse) {
+                               nfs_mount_state_in_use_end(nmp, 0);
+                               inuse = 0;
+                       }
                        error2 = nfs_advlock_unlock(np, nofp, nlop, 0, UINT64_MAX, NFS_FILE_LOCK_STYLE_FLOCK, ctx);
                        flocknflp = NULL;
-                       if (!error2)
+                       if (!error2) {
                                error2 = nfs_mount_state_in_use_start(nmp, vfs_context_thread(ctx));
+                       }
                        if (!error2) {
                                inuse = 1;
                                error2 = nfs_open_state_set_busy(np, vfs_context_thread(ctx));
@@ -3791,11 +4244,13 @@ restart:
                 * Except for retries of blocked v2/v3 request where we've already waited a bit.
                 */
                if ((nmp->nm_vers >= NFS_VER4) || (error == NFSERR_GRACE)) {
-                       if (error == NFSERR_GRACE)
+                       if (error == NFSERR_GRACE) {
                                delay = 4;
-                       if (delay < 4)
+                       }
+                       if (delay < 4) {
                                delay++;
-                       tsleep(newnflp, slpflag, "nfs_advlock_setlock_delay", delay * (hz/2));
+                       }
+                       tsleep(newnflp, slpflag, "nfs_advlock_setlock_delay", delay * (hz / 2));
                        slpflag = 0;
                }
                error = nfs_sigintr(NFSTONMP(np), NULL, vfs_context_thread(ctx), 0);
@@ -3803,12 +4258,15 @@ restart:
                        /* looks like we have a recover pending... restart */
                        nfs_open_state_clear_busy(np);
                        busy = 0;
-                       nfs_mount_state_in_use_end(nmp, 0);
-                       inuse = 0;
+                       if (inuse) {
+                               nfs_mount_state_in_use_end(nmp, 0);
+                               inuse = 0;
+                       }
                        goto restart;
                }
-               if (!error && (np->n_flag & NREVOKE))
+               if (!error && (np->n_flag & NREVOKE)) {
                        error = EIO;
+               }
        } while (!error);
 
 error_out:
@@ -3833,18 +4291,22 @@ error_out:
                        wakeup(newnflp);
                } else {
                        /* remove newnflp from lock list and destroy */
-                       if (inqueue)
+                       if (inqueue) {
                                TAILQ_REMOVE(&np->n_locks, newnflp, nfl_link);
+                       }
                        nfs_file_lock_destroy(newnflp);
                }
                lck_mtx_unlock(&np->n_openlock);
-               if (busy)
+               if (busy) {
                        nfs_open_state_clear_busy(np);
-               if (inuse)
+               }
+               if (inuse) {
                        nfs_mount_state_in_use_end(nmp, error);
-               if (nflp2)
+               }
+               if (nflp2) {
                        nfs_file_lock_destroy(nflp2);
-               return (error);
+               }
+               return error;
        }
 
        /* server granted the lock */
@@ -3857,16 +4319,21 @@ error_out:
         * It's possible that a single lock may need to be split.
         */
        TAILQ_FOREACH_SAFE(nflp, &np->n_locks, nfl_link, nextnflp) {
-               if (nflp == newnflp)
+               if (nflp == newnflp) {
                        continue;
-               if (nflp->nfl_flags & (NFS_FILE_LOCK_BLOCKED|NFS_FILE_LOCK_DEAD))
+               }
+               if (nflp->nfl_flags & (NFS_FILE_LOCK_BLOCKED | NFS_FILE_LOCK_DEAD)) {
                        continue;
-               if (nflp->nfl_owner != nlop)
+               }
+               if (nflp->nfl_owner != nlop) {
                        continue;
-               if ((newnflp->nfl_flags & NFS_FILE_LOCK_STYLE_MASK) != (nflp->nfl_flags & NFS_FILE_LOCK_STYLE_MASK))
+               }
+               if ((newnflp->nfl_flags & NFS_FILE_LOCK_STYLE_MASK) != (nflp->nfl_flags & NFS_FILE_LOCK_STYLE_MASK)) {
                        continue;
-               if ((newnflp->nfl_start > nflp->nfl_end) || (newnflp->nfl_end < nflp->nfl_start))
+               }
+               if ((newnflp->nfl_start > nflp->nfl_end) || (newnflp->nfl_end < nflp->nfl_start)) {
                        continue;
+               }
                /* here's one to update */
                if ((newnflp->nfl_start <= nflp->nfl_start) && (newnflp->nfl_end >= nflp->nfl_end)) {
                        /* The entire lock is being replaced. */
@@ -3879,7 +4346,7 @@ error_out:
                        /* We're replacing a range in the middle of a lock. */
                        /* The current lock will be split into two locks. */
                        /* Update locks and insert new lock after current lock. */
-                       nflp2->nfl_flags |= (nflp->nfl_flags & (NFS_FILE_LOCK_STYLE_MASK|NFS_FILE_LOCK_DELEGATED));
+                       nflp2->nfl_flags |= (nflp->nfl_flags & (NFS_FILE_LOCK_STYLE_MASK | NFS_FILE_LOCK_DELEGATED));
                        nflp2->nfl_type = nflp->nfl_type;
                        nflp2->nfl_start = newnflp->nfl_end + 1;
                        nflp2->nfl_end = nflp->nfl_end;
@@ -3922,12 +4389,15 @@ error_out:
                 * checking locks that are further down the list.
                 */
                TAILQ_FOREACH_SAFE(nflp, &np->n_locks, nfl_link, nextnflp) {
-                       if (nflp->nfl_flags & (NFS_FILE_LOCK_BLOCKED|NFS_FILE_LOCK_DEAD))
+                       if (nflp->nfl_flags & (NFS_FILE_LOCK_BLOCKED | NFS_FILE_LOCK_DEAD)) {
                                continue;
-                       if (nflp->nfl_owner != nlop)
+                       }
+                       if (nflp->nfl_owner != nlop) {
                                continue;
-                       if ((nflp->nfl_flags & NFS_FILE_LOCK_STYLE_MASK) != NFS_FILE_LOCK_STYLE_POSIX)
+                       }
+                       if ((nflp->nfl_flags & NFS_FILE_LOCK_STYLE_MASK) != NFS_FILE_LOCK_STYLE_POSIX) {
                                continue;
+                       }
                        if (((coalnflp = TAILQ_PREV(nflp, nfs_file_lock_queue, nfl_lolink))) &&
                            ((coalnflp->nfl_flags & NFS_FILE_LOCK_STYLE_MASK) == NFS_FILE_LOCK_STYLE_POSIX) &&
                            (coalnflp->nfl_type == nflp->nfl_type) &&
@@ -3947,8 +4417,9 @@ error_out:
                                TAILQ_REMOVE(&nlop->nlo_locks, nflp, nfl_lolink);
                                lck_mtx_unlock(&nlop->nlo_lock);
                        }
-                       if (!(nflp->nfl_flags & NFS_FILE_LOCK_DEAD))
+                       if (!(nflp->nfl_flags & NFS_FILE_LOCK_DEAD)) {
                                continue;
+                       }
                        if (nflp->nfl_blockcnt) {
                                /* wake up anyone blocked on this lock */
                                wakeup(nflp);
@@ -3962,11 +4433,14 @@ error_out:
 
        lck_mtx_unlock(&np->n_openlock);
        nfs_open_state_clear_busy(np);
-       nfs_mount_state_in_use_end(nmp, error);
 
-       if (nflp2)
+       if (inuse) {
+               nfs_mount_state_in_use_end(nmp, error);
+       }
+       if (nflp2) {
                nfs_file_lock_destroy(nflp2);
-       return (error);
+       }
+       return error;
 }
 
 /*
@@ -3975,7 +4449,11 @@ error_out:
 int
 nfs_advlock_unlock(
        nfsnode_t np,
-       struct nfs_open_file *nofp,
+       struct nfs_open_file *nofp
+#if !CONFIG_NFS4
+       __unused
+#endif
+       ,
        struct nfs_lock_owner *nlop,
        uint64_t start,
        uint64_t end,
@@ -3987,22 +4465,27 @@ nfs_advlock_unlock(
        int error = 0, willsplit = 0, send_unlock_rpcs = 1;
 
        nmp = NFSTONMP(np);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
 
 restart:
-       if ((error = nfs_mount_state_in_use_start(nmp, NULL)))
-               return (error);
+       if ((error = nfs_mount_state_in_use_start(nmp, NULL))) {
+               return error;
+       }
+#if CONFIG_NFS4
        if (nofp->nof_flags & NFS_OPEN_FILE_REOPEN) {
                nfs_mount_state_in_use_end(nmp, 0);
                error = nfs4_reopen(nofp, NULL);
-               if (error)
-                       return (error);
+               if (error) {
+                       return error;
+               }
                goto restart;
        }
+#endif
        if ((error = nfs_open_state_set_busy(np, NULL))) {
                nfs_mount_state_in_use_end(nmp, error);
-               return (error);
+               return error;
        }
 
        lck_mtx_lock(&np->n_openlock);
@@ -4013,14 +4496,18 @@ restart:
                 * going to be one, we'll allocate one now.
                 */
                TAILQ_FOREACH_SAFE(nflp, &np->n_locks, nfl_link, nextnflp) {
-                       if (nflp->nfl_flags & (NFS_FILE_LOCK_BLOCKED|NFS_FILE_LOCK_DEAD))
+                       if (nflp->nfl_flags & (NFS_FILE_LOCK_BLOCKED | NFS_FILE_LOCK_DEAD)) {
                                continue;
-                       if (nflp->nfl_owner != nlop)
+                       }
+                       if (nflp->nfl_owner != nlop) {
                                continue;
-                       if ((nflp->nfl_flags & NFS_FILE_LOCK_STYLE_MASK) != style)
+                       }
+                       if ((nflp->nfl_flags & NFS_FILE_LOCK_STYLE_MASK) != style) {
                                continue;
-                       if ((start > nflp->nfl_end) || (end < nflp->nfl_start))
+                       }
+                       if ((start > nflp->nfl_end) || (end < nflp->nfl_start)) {
                                continue;
+                       }
                        if ((start > nflp->nfl_start) && (end < nflp->nfl_end)) {
                                willsplit = 1;
                                break;
@@ -4031,8 +4518,9 @@ restart:
                        nfs_open_state_clear_busy(np);
                        nfs_mount_state_in_use_end(nmp, 0);
                        newnflp = nfs_file_lock_alloc(nlop);
-                       if (!newnflp)
-                               return (ENOMEM);
+                       if (!newnflp) {
+                               return ENOMEM;
+                       }
                        goto restart;
                }
        }
@@ -4041,7 +4529,7 @@ restart:
         * Free all of our locks in the given range.
         *
         * Note that this process requires sending requests to the server.
-        * Because of this, we will release the n_openlock while performing 
+        * Because of this, we will release the n_openlock while performing
         * the unlock RPCs.  The N_OPENBUSY state keeps the state of *held*
         * locks from changing underneath us.  However, other entries in the
         * list may be removed.  So we need to be careful walking the list.
@@ -4055,8 +4543,9 @@ restart:
         */
        if ((style == NFS_FILE_LOCK_STYLE_POSIX) &&
            ((nflp = TAILQ_FIRST(&nlop->nlo_locks))) &&
-           ((nflp->nfl_flags & NFS_FILE_LOCK_STYLE_MASK) == NFS_FILE_LOCK_STYLE_FLOCK))
+           ((nflp->nfl_flags & NFS_FILE_LOCK_STYLE_MASK) == NFS_FILE_LOCK_STYLE_FLOCK)) {
                send_unlock_rpcs = 0;
+       }
        if ((style == NFS_FILE_LOCK_STYLE_FLOCK) &&
            ((nflp = TAILQ_FIRST(&nlop->nlo_locks))) &&
            ((nflp->nfl_flags & NFS_FILE_LOCK_STYLE_MASK) == NFS_FILE_LOCK_STYLE_FLOCK) &&
@@ -4069,52 +4558,58 @@ restart:
                        if ((nflp->nfl_flags & NFS_FILE_LOCK_STYLE_MASK) == NFS_FILE_LOCK_STYLE_POSIX) {
                                /* unlock the range preceding this lock */
                                lck_mtx_unlock(&np->n_openlock);
-                               error = nmp->nm_funcs->nf_unlock_rpc(np, nlop, type, s, nflp->nfl_start-1, 0,
-                                               vfs_context_thread(ctx), vfs_context_ucred(ctx));
+                               error = nmp->nm_funcs->nf_unlock_rpc(np, nlop, type, s, nflp->nfl_start - 1, 0,
+                                   vfs_context_thread(ctx), vfs_context_ucred(ctx));
                                if (nfs_mount_state_error_should_restart(error)) {
                                        nfs_open_state_clear_busy(np);
                                        nfs_mount_state_in_use_end(nmp, error);
                                        goto restart;
                                }
                                lck_mtx_lock(&np->n_openlock);
-                               if (error)
+                               if (error) {
                                        goto out;
-                               s = nflp->nfl_end+1;
+                               }
+                               s = nflp->nfl_end + 1;
                        }
                        nflp = TAILQ_NEXT(nflp, nfl_lolink);
                }
                if (!delegated) {
                        lck_mtx_unlock(&np->n_openlock);
                        error = nmp->nm_funcs->nf_unlock_rpc(np, nlop, type, s, end, 0,
-                                       vfs_context_thread(ctx), vfs_context_ucred(ctx));
+                           vfs_context_thread(ctx), vfs_context_ucred(ctx));
                        if (nfs_mount_state_error_should_restart(error)) {
                                nfs_open_state_clear_busy(np);
                                nfs_mount_state_in_use_end(nmp, error);
                                goto restart;
                        }
                        lck_mtx_lock(&np->n_openlock);
-                       if (error)
+                       if (error) {
                                goto out;
+                       }
                }
                send_unlock_rpcs = 0;
        }
 
        TAILQ_FOREACH_SAFE(nflp, &np->n_locks, nfl_link, nextnflp) {
-               if (nflp->nfl_flags & (NFS_FILE_LOCK_BLOCKED|NFS_FILE_LOCK_DEAD))
+               if (nflp->nfl_flags & (NFS_FILE_LOCK_BLOCKED | NFS_FILE_LOCK_DEAD)) {
                        continue;
-               if (nflp->nfl_owner != nlop)
+               }
+               if (nflp->nfl_owner != nlop) {
                        continue;
-               if ((nflp->nfl_flags & NFS_FILE_LOCK_STYLE_MASK) != style)
+               }
+               if ((nflp->nfl_flags & NFS_FILE_LOCK_STYLE_MASK) != style) {
                        continue;
-               if ((start > nflp->nfl_end) || (end < nflp->nfl_start))
+               }
+               if ((start > nflp->nfl_end) || (end < nflp->nfl_start)) {
                        continue;
+               }
                /* here's one to unlock */
                if ((start <= nflp->nfl_start) && (end >= nflp->nfl_end)) {
                        /* The entire lock is being unlocked. */
                        if (send_unlock_rpcs && !(nflp->nfl_flags & NFS_FILE_LOCK_DELEGATED)) {
                                lck_mtx_unlock(&np->n_openlock);
                                error = nmp->nm_funcs->nf_unlock_rpc(np, nlop, nflp->nfl_type, nflp->nfl_start, nflp->nfl_end, 0,
-                                               vfs_context_thread(ctx), vfs_context_ucred(ctx));
+                                   vfs_context_thread(ctx), vfs_context_ucred(ctx));
                                if (nfs_mount_state_error_should_restart(error)) {
                                        nfs_open_state_clear_busy(np);
                                        nfs_mount_state_in_use_end(nmp, error);
@@ -4123,8 +4618,9 @@ restart:
                                lck_mtx_lock(&np->n_openlock);
                        }
                        nextnflp = TAILQ_NEXT(nflp, nfl_link);
-                       if (error)
+                       if (error) {
                                break;
+                       }
                        nflp->nfl_flags |= NFS_FILE_LOCK_DEAD;
                        lck_mtx_lock(&nlop->nlo_lock);
                        TAILQ_REMOVE(&nlop->nlo_locks, nflp, nfl_lolink);
@@ -4136,7 +4632,7 @@ restart:
                        if (send_unlock_rpcs && !(nflp->nfl_flags & NFS_FILE_LOCK_DELEGATED)) {
                                lck_mtx_unlock(&np->n_openlock);
                                error = nmp->nm_funcs->nf_unlock_rpc(np, nlop, nflp->nfl_type, start, end, 0,
-                                               vfs_context_thread(ctx), vfs_context_ucred(ctx));
+                                   vfs_context_thread(ctx), vfs_context_ucred(ctx));
                                if (nfs_mount_state_error_should_restart(error)) {
                                        nfs_open_state_clear_busy(np);
                                        nfs_mount_state_in_use_end(nmp, error);
@@ -4144,10 +4640,11 @@ restart:
                                }
                                lck_mtx_lock(&np->n_openlock);
                        }
-                       if (error)
+                       if (error) {
                                break;
+                       }
                        /* update locks and insert new lock after current lock */
-                       newnflp->nfl_flags |= (nflp->nfl_flags & (NFS_FILE_LOCK_STYLE_MASK|NFS_FILE_LOCK_DELEGATED));
+                       newnflp->nfl_flags |= (nflp->nfl_flags & (NFS_FILE_LOCK_STYLE_MASK | NFS_FILE_LOCK_DELEGATED));
                        newnflp->nfl_type = nflp->nfl_type;
                        newnflp->nfl_start = end + 1;
                        newnflp->nfl_end = nflp->nfl_end;
@@ -4161,7 +4658,7 @@ restart:
                        if (send_unlock_rpcs && !(nflp->nfl_flags & NFS_FILE_LOCK_DELEGATED)) {
                                lck_mtx_unlock(&np->n_openlock);
                                error = nmp->nm_funcs->nf_unlock_rpc(np, nlop, nflp->nfl_type, start, nflp->nfl_end, 0,
-                                               vfs_context_thread(ctx), vfs_context_ucred(ctx));
+                                   vfs_context_thread(ctx), vfs_context_ucred(ctx));
                                if (nfs_mount_state_error_should_restart(error)) {
                                        nfs_open_state_clear_busy(np);
                                        nfs_mount_state_in_use_end(nmp, error);
@@ -4170,15 +4667,16 @@ restart:
                                lck_mtx_lock(&np->n_openlock);
                        }
                        nextnflp = TAILQ_NEXT(nflp, nfl_link);
-                       if (error)
+                       if (error) {
                                break;
+                       }
                        nflp->nfl_end = start - 1;
                } else if (end < nflp->nfl_end) {
                        /* We're unlocking the start of a lock. */
                        if (send_unlock_rpcs && !(nflp->nfl_flags & NFS_FILE_LOCK_DELEGATED)) {
                                lck_mtx_unlock(&np->n_openlock);
                                error = nmp->nm_funcs->nf_unlock_rpc(np, nlop, nflp->nfl_type, nflp->nfl_start, end, 0,
-                                               vfs_context_thread(ctx), vfs_context_ucred(ctx));
+                                   vfs_context_thread(ctx), vfs_context_ucred(ctx));
                                if (nfs_mount_state_error_should_restart(error)) {
                                        nfs_open_state_clear_busy(np);
                                        nfs_mount_state_in_use_end(nmp, error);
@@ -4187,8 +4685,9 @@ restart:
                                lck_mtx_lock(&np->n_openlock);
                        }
                        nextnflp = TAILQ_NEXT(nflp, nfl_link);
-                       if (error)
+                       if (error) {
                                break;
+                       }
                        nflp->nfl_start = end + 1;
                }
                if (nflp->nfl_blockcnt) {
@@ -4205,9 +4704,10 @@ out:
        nfs_open_state_clear_busy(np);
        nfs_mount_state_in_use_end(nmp, 0);
 
-       if (newnflp)
+       if (newnflp) {
                nfs_file_lock_destroy(newnflp);
-       return (error);
+       }
+       return error;
 }
 
 /*
@@ -4216,14 +4716,14 @@ out:
 int
 nfs_vnop_advlock(
        struct vnop_advlock_args /* {
-               struct vnodeop_desc *a_desc;
-               vnode_t a_vp;
-               caddr_t a_id;
-               int a_op;
-               struct flock *a_fl;
-               int a_flags;
-               vfs_context_t a_context;
-       } */ *ap)
+                                  *  struct vnodeop_desc *a_desc;
+                                  *  vnode_t a_vp;
+                                  *  caddr_t a_id;
+                                  *  int a_op;
+                                  *  struct flock *a_fl;
+                                  *  int a_flags;
+                                  *  vfs_context_t a_context;
+                                  *  } */*ap)
 {
        vnode_t vp = ap->a_vp;
        nfsnode_t np = VTONFS(ap->a_vp);
@@ -4242,22 +4742,26 @@ nfs_vnop_advlock(
 #define OFF_MAX QUAD_MAX
 
        nmp = VTONMP(ap->a_vp);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        lck_mtx_lock(&nmp->nm_lock);
        if ((nmp->nm_vers <= NFS_VER3) && (nmp->nm_lockmode == NFS_LOCK_MODE_DISABLED)) {
                lck_mtx_unlock(&nmp->nm_lock);
-               return (ENOTSUP);
+               return ENOTSUP;
        }
        lck_mtx_unlock(&nmp->nm_lock);
 
-       if (np->n_flag & NREVOKE)
-               return (EIO);
+       if (np->n_flag & NREVOKE) {
+               return EIO;
+       }
        vtype = vnode_vtype(ap->a_vp);
-       if (vtype == VDIR) /* ignore lock requests on directories */
-               return (0);
-       if (vtype != VREG) /* anything other than regular files is invalid */
-               return (EINVAL);
+       if (vtype == VDIR) { /* ignore lock requests on directories */
+               return 0;
+       }
+       if (vtype != VREG) { /* anything other than regular files is invalid */
+               return EINVAL;
+       }
 
        /* Convert the flock structure into a start and end. */
        switch (fl->l_whence) {
@@ -4272,54 +4776,65 @@ nfs_vnop_advlock(
        case SEEK_END:
                /* need to flush, and refetch attributes to make */
                /* sure we have the correct end of file offset   */
-               if ((error = nfs_node_lock(np)))
-                       return (error);
+               if ((error = nfs_node_lock(np))) {
+                       return error;
+               }
                modified = (np->n_flag & NMODIFIED);
                nfs_node_unlock(np);
-               if (modified && ((error = nfs_vinvalbuf(vp, V_SAVE, ctx, 1))))
-                       return (error);
-               if ((error = nfs_getattr(np, NULL, ctx, NGA_UNCACHED)))
-                       return (error);
+               if (modified && ((error = nfs_vinvalbuf(vp, V_SAVE, ctx, 1)))) {
+                       return error;
+               }
+               if ((error = nfs_getattr(np, NULL, ctx, NGA_UNCACHED))) {
+                       return error;
+               }
                nfs_data_lock(np, NFS_DATA_LOCK_SHARED);
                if ((np->n_size > OFF_MAX) ||
-                   ((fl->l_start > 0) && (np->n_size > (u_quad_t)(OFF_MAX - fl->l_start))))
+                   ((fl->l_start > 0) && (np->n_size > (u_quad_t)(OFF_MAX - fl->l_start)))) {
                        error = EOVERFLOW;
+               }
                lstart = np->n_size + fl->l_start;
                nfs_data_unlock(np);
-               if (error)
-                       return (error);
+               if (error) {
+                       return error;
+               }
                break;
        default:
-               return (EINVAL);
+               return EINVAL;
+       }
+       if (lstart < 0) {
+               return EINVAL;
        }
-       if (lstart < 0)
-               return (EINVAL);
        start = lstart;
        if (fl->l_len == 0) {
                end = UINT64_MAX;
        } else if (fl->l_len > 0) {
-               if ((fl->l_len - 1) > (OFF_MAX - lstart))
-                       return (EOVERFLOW);
+               if ((fl->l_len - 1) > (OFF_MAX - lstart)) {
+                       return EOVERFLOW;
+               }
                end = start - 1 + fl->l_len;
        } else { /* l_len is negative */
-               if ((lstart + fl->l_len) < 0)
-                       return (EINVAL);
+               if ((lstart + fl->l_len) < 0) {
+                       return EINVAL;
+               }
                end = start - 1;
                start += fl->l_len;
        }
-       if ((nmp->nm_vers == NFS_VER2) && ((start > INT32_MAX) || (fl->l_len && (end > INT32_MAX))))
-               return (EINVAL);
+       if ((nmp->nm_vers == NFS_VER2) && ((start > INT32_MAX) || (fl->l_len && (end > INT32_MAX)))) {
+               return EINVAL;
+       }
 
        style = (flags & F_FLOCK) ? NFS_FILE_LOCK_STYLE_FLOCK : NFS_FILE_LOCK_STYLE_POSIX;
-       if ((style == NFS_FILE_LOCK_STYLE_FLOCK) && ((start != 0) || (end != UINT64_MAX)))
-               return (EINVAL);
+       if ((style == NFS_FILE_LOCK_STYLE_FLOCK) && ((start != 0) || (end != UINT64_MAX))) {
+               return EINVAL;
+       }
 
        /* find the lock owner, alloc if not unlock */
        nlop = nfs_lock_owner_find(np, vfs_context_proc(ctx), (op != F_UNLCK));
        if (!nlop) {
                error = (op == F_UNLCK) ? 0 : ENOMEM;
-               if (error)
+               if (error) {
                        NP(np, "nfs_vnop_advlock: no lock owner, error %d", error);
+               }
                goto out;
        }
 
@@ -4334,20 +4849,26 @@ nfs_vnop_advlock(
                        goto out;
                }
                /* find the open file */
+#if CONFIG_NFS4
 restart:
+#endif
                error = nfs_open_file_find(np, noop, &nofp, 0, 0, 0);
-               if (error)
+               if (error) {
                        error = EBADF;
+               }
                if (!error && (nofp->nof_flags & NFS_OPEN_FILE_LOST)) {
                        NP(np, "nfs_vnop_advlock: LOST %d", kauth_cred_getuid(nofp->nof_owner->noo_cred));
                        error = EIO;
                }
+#if CONFIG_NFS4
                if (!error && (nofp->nof_flags & NFS_OPEN_FILE_REOPEN)) {
                        error = nfs4_reopen(nofp, ((op == F_UNLCK) ? NULL : vfs_context_thread(ctx)));
                        nofp = NULL;
-                       if (!error)
+                       if (!error) {
                                goto restart;
+                       }
                }
+#endif
                if (error) {
                        NP(np, "nfs_vnop_advlock: no open file %d, %d", error, kauth_cred_getuid(noop->noo_cred));
                        goto out;
@@ -4355,8 +4876,9 @@ restart:
                if (op == F_UNLCK) {
                        error = nfs_advlock_unlock(np, nofp, nlop, start, end, style, ctx);
                } else if ((op == F_SETLK) || (op == F_SETLKW)) {
-                       if ((op == F_SETLK) && (flags & F_WAIT))
+                       if ((op == F_SETLK) && (flags & F_WAIT)) {
                                op = F_SETLKW;
+                       }
                        error = nfs_advlock_setlock(np, nofp, nlop, op, start, end, style, fl->l_type, ctx);
                } else {
                        /* not getlk, unlock or lock? */
@@ -4365,11 +4887,13 @@ restart:
        }
 
 out:
-       if (nlop)
+       if (nlop) {
                nfs_lock_owner_rele(nlop);
-       if (noop)
+       }
+       if (noop) {
                nfs_open_owner_rele(noop);
-       return (error);
+       }
+       return error;
 }
 
 /*
@@ -4381,14 +4905,17 @@ nfs_check_for_locks(struct nfs_open_owner *noop, struct nfs_open_file *nofp)
        struct nfs_lock_owner *nlop;
 
        TAILQ_FOREACH(nlop, &nofp->nof_np->n_lock_owners, nlo_link) {
-               if (nlop->nlo_open_owner != noop)
+               if (nlop->nlo_open_owner != noop) {
                        continue;
-               if (!TAILQ_EMPTY(&nlop->nlo_locks))
+               }
+               if (!TAILQ_EMPTY(&nlop->nlo_locks)) {
                        break;
+               }
        }
-       return (nlop ? 1 : 0);
+       return nlop ? 1 : 0;
 }
 
+#if CONFIG_NFS4
 /*
  * Reopen simple (no deny, no locks) open state that was lost.
  */
@@ -4403,22 +4930,23 @@ nfs4_reopen(struct nfs_open_file *nofp, thread_t thd)
        struct componentname cn;
        const char *vname = NULL;
        const char *name = NULL;
-       size_t namelen;
+       uint32_t namelen;
        char smallname[128];
        char *filename = NULL;
        int error = 0, done = 0, slpflag = NMFLAG(nmp, INTR) ? PCATCH : 0;
-       struct timespec ts = { 1, 0 };
+       struct timespec ts = { .tv_sec = 1, .tv_nsec = 0 };
 
        lck_mtx_lock(&nofp->nof_lock);
        while (nofp->nof_flags & NFS_OPEN_FILE_REOPENING) {
-               if ((error = nfs_sigintr(nmp, NULL, thd, 0)))
+               if ((error = nfs_sigintr(nmp, NULL, thd, 0))) {
                        break;
-               msleep(&nofp->nof_flags, &nofp->nof_lock, slpflag|(PZERO-1), "nfsreopenwait", &ts);
+               }
+               msleep(&nofp->nof_flags, &nofp->nof_lock, slpflag | (PZERO - 1), "nfsreopenwait", &ts);
                slpflag = 0;
        }
        if (error || !(nofp->nof_flags & NFS_OPEN_FILE_REOPEN)) {
                lck_mtx_unlock(&nofp->nof_lock);
-               return (error);
+               return error;
        }
        nofp->nof_flags |= NFS_OPEN_FILE_REOPENING;
        lck_mtx_unlock(&nofp->nof_lock);
@@ -4432,6 +4960,7 @@ nfs4_reopen(struct nfs_open_file *nofp, thread_t thd)
                struct nfs_sillyrename *nsp = np->n_sillyrename;
                dvp = NFSTOV(nsp->nsr_dnp);
                if ((error = vnode_get(dvp))) {
+                       dvp = NULLVP;
                        nfs_node_unlock(np);
                        goto out;
                }
@@ -4444,14 +4973,17 @@ nfs4_reopen(struct nfs_open_file *nofp, thread_t thd)
                 * from the n_parent we have stashed away.
                 */
                if ((np->n_vattr.nva_flags & NFS_FFLAG_IS_ATTR) &&
-                   (((dvp = np->n_parent)) && (error = vnode_get(dvp))))
+                   (((dvp = np->n_parent)) && (error = vnode_get(dvp)))) {
                        dvp = NULL;
-               if (!dvp)
+               }
+               if (!dvp) {
                        dvp = vnode_getparent(vp);
+               }
                vname = vnode_getname(vp);
                if (!dvp || !vname) {
-                       if (!error)
+                       if (!error) {
                                error = EIO;
+                       }
                        nfs_node_unlock(np);
                        goto out;
                }
@@ -4460,12 +4992,12 @@ nfs4_reopen(struct nfs_open_file *nofp, thread_t thd)
        filename = &smallname[0];
        namelen = snprintf(filename, sizeof(smallname), "%s", name);
        if (namelen >= sizeof(smallname)) {
-               MALLOC(filename, char *, namelen+1, M_TEMP, M_WAITOK);
+               MALLOC(filename, char *, namelen + 1, M_TEMP, M_WAITOK);
                if (!filename) {
                        error = ENOMEM;
                        goto out;
                }
-               snprintf(filename, namelen+1, "%s", name);
+               snprintf(filename, namelen + 1, "%s", name);
        }
        nfs_node_unlock(np);
        bzero(&cn, sizeof(cn));
@@ -4474,43 +5006,53 @@ nfs4_reopen(struct nfs_open_file *nofp, thread_t thd)
 
 restart:
        done = 0;
-       if ((error = nfs_mount_state_in_use_start(nmp, thd)))
+       if ((error = nfs_mount_state_in_use_start(nmp, thd))) {
                goto out;
+       }
 
-       if (nofp->nof_rw)
+       if (nofp->nof_rw) {
                error = nfs4_open_reopen_rpc(nofp, thd, noop->noo_cred, &cn, dvp, &vp, NFS_OPEN_SHARE_ACCESS_BOTH, NFS_OPEN_SHARE_DENY_NONE);
-       if (!error && nofp->nof_w)
+       }
+       if (!error && nofp->nof_w) {
                error = nfs4_open_reopen_rpc(nofp, thd, noop->noo_cred, &cn, dvp, &vp, NFS_OPEN_SHARE_ACCESS_WRITE, NFS_OPEN_SHARE_DENY_NONE);
-       if (!error && nofp->nof_r)
+       }
+       if (!error && nofp->nof_r) {
                error = nfs4_open_reopen_rpc(nofp, thd, noop->noo_cred, &cn, dvp, &vp, NFS_OPEN_SHARE_ACCESS_READ, NFS_OPEN_SHARE_DENY_NONE);
+       }
 
        if (nfs_mount_state_in_use_end(nmp, error)) {
-               if (error == NFSERR_GRACE)
+               if (error == NFSERR_GRACE) {
                        goto restart;
+               }
                printf("nfs4_reopen: RPC failed, error %d, lost %d, %s\n", error,
-                       (nofp->nof_flags & NFS_OPEN_FILE_LOST) ? 1 : 0, name ? name : "???");
+                   (nofp->nof_flags & NFS_OPEN_FILE_LOST) ? 1 : 0, name ? name : "???");
                error = 0;
                goto out;
        }
        done = 1;
 out:
-       if (error && (error != EINTR) && (error != ERESTART))
+       if (error && (error != EINTR) && (error != ERESTART)) {
                nfs_revoke_open_state_for_node(np);
+       }
        lck_mtx_lock(&nofp->nof_lock);
        nofp->nof_flags &= ~NFS_OPEN_FILE_REOPENING;
-       if (done)
+       if (done) {
                nofp->nof_flags &= ~NFS_OPEN_FILE_REOPEN;
-       else if (error)
+       } else if (error) {
                printf("nfs4_reopen: failed, error %d, lost %d, %s\n", error,
-                       (nofp->nof_flags & NFS_OPEN_FILE_LOST) ? 1 : 0, name ? name : "???");
+                   (nofp->nof_flags & NFS_OPEN_FILE_LOST) ? 1 : 0, name ? name : "???");
+       }
        lck_mtx_unlock(&nofp->nof_lock);
-       if (filename && (filename != &smallname[0]))
+       if (filename && (filename != &smallname[0])) {
                FREE(filename, M_TEMP);
-       if (vname)
+       }
+       if (vname) {
                vnode_putname(vname);
-       if (dvp != NULLVP)
+       }
+       if (dvp != NULLVP) {
                vnode_put(dvp);
-       return (error);
+       }
+       return error;
 }
 
 /*
@@ -4528,8 +5070,8 @@ nfs4_open_rpc(
        int share_access,
        int share_deny)
 {
-       return (nfs4_open_rpc_internal(nofp, ctx, vfs_context_thread(ctx), vfs_context_ucred(ctx),
-                                       cnp, vap, dvp, vpp, create, share_access, share_deny));
+       return nfs4_open_rpc_internal(nofp, ctx, vfs_context_thread(ctx), vfs_context_ucred(ctx),
+                  cnp, vap, dvp, vpp, create, share_access, share_deny);
 }
 
 /*
@@ -4546,7 +5088,7 @@ nfs4_open_reopen_rpc(
        int share_access,
        int share_deny)
 {
-       return (nfs4_open_rpc_internal(nofp, NULL, thd, cred, cnp, NULL, dvp, vpp, NFS_OPEN_NOCREATE, share_access, share_deny));
+       return nfs4_open_rpc_internal(nofp, NULL, thd, cred, cnp, NULL, dvp, vpp, NFS_OPEN_NOCREATE, share_access, share_deny);
 }
 
 /*
@@ -4576,7 +5118,7 @@ nfs4_open_confirm_rpc(
        // PUTFH, OPEN_CONFIRM, GETATTR
        numops = 3;
        nfsm_chain_build_alloc_init(error, &nmreq, 23 * NFSX_UNSIGNED);
-       nfsm_chain_add_compound_header(error, &nmreq, "open_confirm", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "open_confirm", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, nmp->nm_vers, fhp, fhlen);
@@ -4605,7 +5147,7 @@ nfs4_open_confirm_rpc(
 nfsmout:
        nfsm_chain_cleanup(&nmreq);
        nfsm_chain_cleanup(&nmrep);
-       return (error);
+       return error;
 }
 
 /*
@@ -4630,7 +5172,7 @@ nfs4_open_rpc_internal(
 {
        struct nfsmount *nmp;
        struct nfs_open_owner *noop = nofp->nof_owner;
-       struct nfs_vattr nvattr;
+       struct nfs_vattr *nvattr;
        int error = 0, open_error = EIO, lockerror = ENOENT, busyerror = ENOENT, status;
        int nfsvers, namedattrs, numops, exclusive = 0, gotuid, gotgid;
        u_int64_t xid, savedxid = 0;
@@ -4641,24 +5183,28 @@ nfs4_open_rpc_internal(
        uint32_t bitmap[NFS_ATTR_BITMAP_LEN], bmlen;
        uint32_t rflags, delegation, recall;
        struct nfs_stateid stateid, dstateid, *sid;
-       fhandle_t fh;
-       struct nfsreq rq, *req = &rq;
-       struct nfs_dulookup dul;
+       fhandle_t *fh;
+       struct nfsreq *req;
+       struct nfs_dulookup *dul;
        char sbuf[64], *s;
        uint32_t ace_type, ace_flags, ace_mask, len, slen;
        struct kauth_ace ace;
        struct nfsreq_secinfo_args si;
 
-       if (create && !ctx)
-               return (EINVAL);
+       if (create && !ctx) {
+               return EINVAL;
+       }
 
        nmp = VTONMP(dvp);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        nfsvers = nmp->nm_vers;
        namedattrs = (nmp->nm_fsattr.nfsa_flags & NFS_FSFLAG_NAMED_ATTR);
-       if (dnp->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL)
-               return (EINVAL);
+       bzero(&dstateid, sizeof(dstateid));
+       if (dnp->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL) {
+               return EINVAL;
+       }
 
        np = *vpp ? VTONFS(*vpp) : NULL;
        if (create && vap) {
@@ -4666,8 +5212,9 @@ nfs4_open_rpc_internal(
                nfs_avoid_needless_id_setting_on_create(dnp, vap, ctx);
                gotuid = VATTR_IS_ACTIVE(vap, va_uid);
                gotgid = VATTR_IS_ACTIVE(vap, va_gid);
-               if (exclusive && (!VATTR_IS_ACTIVE(vap, va_access_time) || !VATTR_IS_ACTIVE(vap, va_modify_time)))
+               if (exclusive && (!VATTR_IS_ACTIVE(vap, va_access_time) || !VATTR_IS_ACTIVE(vap, va_modify_time))) {
                        vap->va_vaflags |= VA_UTIMES_NULL;
+               }
        } else {
                exclusive = gotuid = gotgid = 0;
        }
@@ -4678,14 +5225,21 @@ nfs4_open_rpc_internal(
                sid = &stateid;
        }
 
-       if ((error = nfs_open_owner_set_busy(noop, thd)))
-               return (error);
+       if ((error = nfs_open_owner_set_busy(noop, thd))) {
+               return error;
+       }
+
+       fh = zalloc(nfs_fhandle_zone);
+       req = zalloc(nfs_req_zone);
+       MALLOC(dul, struct nfs_dulookup *, sizeof(*dul), M_TEMP, M_WAITOK);
+       MALLOC(nvattr, struct nfs_vattr *, sizeof(*nvattr), M_TEMP, M_WAITOK);
+
 again:
        rflags = delegation = recall = 0;
        ace.ace_flags = 0;
        s = sbuf;
        slen = sizeof(sbuf);
-       NVATTR_INIT(&nvattr);
+       NVATTR_INIT(nvattr);
        NFSREQ_SECINFO_SET(&si, dnp, NULL, 0, cnp->cn_nameptr, cnp->cn_namelen);
 
        nfsm_chain_null(&nmreq);
@@ -4694,7 +5248,7 @@ again:
        // PUTFH, SAVEFH, OPEN(CREATE?), GETATTR(FH), RESTOREFH, GETATTR
        numops = 6;
        nfsm_chain_build_alloc_init(error, &nmreq, 53 * NFSX_UNSIGNED + cnp->cn_namelen);
-       nfsm_chain_add_compound_header(error, &nmreq, create ? "create" : "open", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, create ? "create" : "open", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, nfsvers, dnp->n_fhp, dnp->n_fhsize);
@@ -4736,26 +5290,31 @@ again:
        nfsm_chain_add_bitmap_supported(error, &nmreq, nfs_getattr_bitmap, nmp, dnp);
        nfsm_chain_build_done(error, &nmreq);
        nfsm_assert(error, (numops == 0), EPROTO);
-       if (!error)
+       if (!error) {
                error = busyerror = nfs_node_set_busy(dnp, thd);
+       }
        nfsmout_if(error);
 
-       if (create && !namedattrs)
-               nfs_dulookup_init(&dul, dnp, cnp->cn_nameptr, cnp->cn_namelen, ctx);
+       if (create && !namedattrs) {
+               nfs_dulookup_init(dul, dnp, cnp->cn_nameptr, cnp->cn_namelen, ctx);
+       }
 
        error = nfs_request_async(dnp, NULL, &nmreq, NFSPROC4_COMPOUND, thd, cred, &si, R_NOINTR, NULL, &req);
        if (!error) {
-               if (create && !namedattrs)
-                       nfs_dulookup_start(&dul, dnp, ctx);
+               if (create && !namedattrs) {
+                       nfs_dulookup_start(dul, dnp, ctx);
+               }
                error = nfs_request_async_finish(req, &nmrep, &xid, &status);
                savedxid = xid;
        }
 
-       if (create && !namedattrs)
-               nfs_dulookup_finish(&dul, dnp, ctx);
+       if (create && !namedattrs) {
+               nfs_dulookup_finish(dul, dnp, ctx);
+       }
 
-       if ((lockerror = nfs_node_lock(dnp)))
+       if ((lockerror = nfs_node_lock(dnp))) {
                error = lockerror;
+       }
        nfsm_chain_skip_tag(error, &nmrep);
        nfsm_chain_get_32(error, &nmrep, numops);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_PUTFH);
@@ -4769,7 +5328,7 @@ again:
        bmlen = NFS_ATTR_BITMAP_LEN;
        nfsm_chain_get_bitmap(error, &nmrep, bitmap, bmlen);
        nfsm_chain_get_32(error, &nmrep, delegation);
-       if (!error)
+       if (!error) {
                switch (delegation) {
                case NFS_OPEN_DELEGATE_NONE:
                        break;
@@ -4777,8 +5336,9 @@ again:
                case NFS_OPEN_DELEGATE_WRITE:
                        nfsm_chain_get_stateid(error, &nmrep, &dstateid);
                        nfsm_chain_get_32(error, &nmrep, recall);
-                       if (delegation == NFS_OPEN_DELEGATE_WRITE) // space (skip) XXX
+                       if (delegation == NFS_OPEN_DELEGATE_WRITE) // space (skip) XXX
                                nfsm_chain_adv(error, &nmrep, 3 * NFSX_UNSIGNED);
+                       }
                        /* if we have any trouble accepting the ACE, just invalidate it */
                        ace_type = ace_flags = ace_mask = len = 0;
                        nfsm_chain_get_32(error, &nmrep, ace_type);
@@ -4789,70 +5349,81 @@ again:
                        ace.ace_flags |= nfs4_ace_nfsflags_to_vfsflags(ace_flags);
                        ace.ace_rights = nfs4_ace_nfsmask_to_vfsrights(ace_mask);
                        if (!error && (len >= slen)) {
-                               MALLOC(s, char*, len+1, M_TEMP, M_WAITOK);
-                               if (s)
-                                       slen = len+1;
-                               else
+                               MALLOC(s, char*, len + 1, M_TEMP, M_WAITOK);
+                               if (s) {
+                                       slen = len + 1;
+                               } else {
                                        ace.ace_flags = 0;
+                               }
                        }
-                       if (s)
+                       if (s) {
                                nfsm_chain_get_opaque(error, &nmrep, len, s);
-                       else
+                       } else {
                                nfsm_chain_adv(error, &nmrep, nfsm_rndup(len));
+                       }
                        if (!error && s) {
                                s[len] = '\0';
-                               if (nfs4_id2guid(s, &ace.ace_applicable, (ace_flags & NFS_ACE_IDENTIFIER_GROUP)))
+                               if (nfs4_id2guid(s, &ace.ace_applicable, (ace_flags & NFS_ACE_IDENTIFIER_GROUP))) {
                                        ace.ace_flags = 0;
+                               }
                        }
-                       if (error || !s)
+                       if (error || !s) {
                                ace.ace_flags = 0;
-                       if (s && (s != sbuf))
+                       }
+                       if (s && (s != sbuf)) {
                                FREE(s, M_TEMP);
+                       }
                        break;
                default:
                        error = EBADRPC;
                        break;
                }
+       }
        /* At this point if we have no error, the object was created/opened. */
        open_error = error;
        nfsmout_if(error);
-       if (create && vap && !exclusive)
+       if (create && vap && !exclusive) {
                nfs_vattr_set_supported(bitmap, vap);
+       }
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
        nfsmout_if(error);
-       error = nfs4_parsefattr(&nmrep, NULL, &nvattr, &fh, NULL, NULL);
+       error = nfs4_parsefattr(&nmrep, NULL, nvattr, fh, NULL, NULL);
        nfsmout_if(error);
-       if (!NFS_BITMAP_ISSET(nvattr.nva_bitmap, NFS_FATTR_FILEHANDLE)) {
+       if (!NFS_BITMAP_ISSET(nvattr->nva_bitmap, NFS_FATTR_FILEHANDLE)) {
                printf("nfs: open/create didn't return filehandle? %s\n", cnp->cn_nameptr);
                error = EBADRPC;
                goto nfsmout;
        }
-       if (!create && np && !NFS_CMPFH(np, fh.fh_data, fh.fh_len)) {
+       if (!create && np && !NFS_CMPFH(np, fh->fh_data, fh->fh_len)) {
                // XXX for the open case, what if fh doesn't match the vnode we think we're opening?
                // Solaris Named Attributes may do this due to a bug.... so don't warn for named attributes.
-               if (!(np->n_vattr.nva_flags & NFS_FFLAG_IS_ATTR))
+               if (!(np->n_vattr.nva_flags & NFS_FFLAG_IS_ATTR)) {
                        NP(np, "nfs4_open_rpc: warning: file handle mismatch");
+               }
        }
        /* directory attributes: if we don't get them, make sure to invalidate */
        nfsm_chain_op_check(error, &nmrep, NFS_OP_RESTOREFH);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
        nfsm_chain_loadattr(error, &nmrep, dnp, nfsvers, &xid);
-       if (error)
+       if (error) {
                NATTRINVALIDATE(dnp);
+       }
        nfsmout_if(error);
 
-       if (rflags & NFS_OPEN_RESULT_LOCKTYPE_POSIX)
+       if (rflags & NFS_OPEN_RESULT_LOCKTYPE_POSIX) {
                nofp->nof_flags |= NFS_OPEN_FILE_POSIXLOCK;
+       }
 
        if (rflags & NFS_OPEN_RESULT_CONFIRM) {
                nfs_node_unlock(dnp);
                lockerror = ENOENT;
-               NVATTR_CLEANUP(&nvattr);
-               error = nfs4_open_confirm_rpc(nmp, dnp, fh.fh_data, fh.fh_len, noop, sid, thd, cred, &nvattr, &xid);
+               NVATTR_CLEANUP(nvattr);
+               error = nfs4_open_confirm_rpc(nmp, dnp, fh->fh_data, fh->fh_len, noop, sid, thd, cred, nvattr, &xid);
                nfsmout_if(error);
                savedxid = xid;
-               if ((lockerror = nfs_node_lock(dnp)))
+               if ((lockerror = nfs_node_lock(dnp))) {
                        error = lockerror;
+               }
        }
 
 nfsmout:
@@ -4869,21 +5440,25 @@ nfsmout:
                lockerror = ENOENT;
                nfs_getattr(dnp, NULL, ctx, NGA_CACHED);
        }
-       if (!lockerror)
+       if (!lockerror) {
                nfs_node_unlock(dnp);
-       if (!error && !np && fh.fh_len) {
+       }
+       if (!error && !np && fh->fh_len) {
                /* create the vnode with the filehandle and attributes */
                xid = savedxid;
-               error = nfs_nget(NFSTOMP(dnp), dnp, cnp, fh.fh_data, fh.fh_len, &nvattr, &xid, rq.r_auth, NG_MAKEENTRY, &newnp);
-               if (!error)
+               error = nfs_nget(NFSTOMP(dnp), dnp, cnp, fh->fh_data, fh->fh_len, nvattr, &xid, req->r_auth, NG_MAKEENTRY, &newnp);
+               if (!error) {
                        newvp = NFSTOV(newnp);
+               }
        }
-       NVATTR_CLEANUP(&nvattr);
-       if (!busyerror)
+       NVATTR_CLEANUP(nvattr);
+       if (!busyerror) {
                nfs_node_clear_busy(dnp);
+       }
        if ((delegation == NFS_OPEN_DELEGATE_READ) || (delegation == NFS_OPEN_DELEGATE_WRITE)) {
-               if (!np)
+               if (!np) {
                        np = newnp;
+               }
                if (!error && np && !recall) {
                        /* stuff the delegation state in the node */
                        lck_mtx_lock(&np->n_openlock);
@@ -4893,15 +5468,16 @@ nfsmout:
                        np->n_dace = ace;
                        if (np->n_dlink.tqe_next == NFSNOLIST) {
                                lck_mtx_lock(&nmp->nm_lock);
-                               if (np->n_dlink.tqe_next == NFSNOLIST)
+                               if (np->n_dlink.tqe_next == NFSNOLIST) {
                                        TAILQ_INSERT_TAIL(&nmp->nm_delegations, np, n_dlink);
+                               }
                                lck_mtx_unlock(&nmp->nm_lock);
                        }
                        lck_mtx_unlock(&np->n_openlock);
                } else {
                        /* give the delegation back */
                        if (np) {
-                               if (NFS_CMPFH(np, fh.fh_data, fh.fh_len)) {
+                               if (NFS_CMPFH(np, fh->fh_data, fh->fh_len)) {
                                        /* update delegation state and return it */
                                        lck_mtx_lock(&np->n_openlock);
                                        np->n_openflags &= ~N_DELEG_MASK;
@@ -4910,19 +5486,21 @@ nfsmout:
                                        np->n_dace = ace;
                                        if (np->n_dlink.tqe_next == NFSNOLIST) {
                                                lck_mtx_lock(&nmp->nm_lock);
-                                               if (np->n_dlink.tqe_next == NFSNOLIST)
+                                               if (np->n_dlink.tqe_next == NFSNOLIST) {
                                                        TAILQ_INSERT_TAIL(&nmp->nm_delegations, np, n_dlink);
+                                               }
                                                lck_mtx_unlock(&nmp->nm_lock);
                                        }
                                        lck_mtx_unlock(&np->n_openlock);
                                        /* don't need to send a separate delegreturn for fh */
-                                       fh.fh_len = 0;
+                                       fh->fh_len = 0;
                                }
                                /* return np's current delegation */
                                nfs4_delegation_return(np, 0, thd, cred);
                        }
-                       if (fh.fh_len) /* return fh's delegation if it wasn't for np */
-                               nfs4_delegreturn_rpc(nmp, fh.fh_data, fh.fh_len, &dstateid, 0, thd, cred);
+                       if (fh->fh_len) { /* return fh's delegation if it wasn't for np */
+                               nfs4_delegreturn_rpc(nmp, fh->fh_data, fh->fh_len, &dstateid, 0, thd, cred);
+                       }
                }
        }
        if (error) {
@@ -4946,13 +5524,18 @@ nfsmout:
                                error = nfs4_setattr_rpc(newnp, vap, ctx);
                        }
                }
-               if (error)
+               if (error) {
                        vnode_put(newvp);
-               else
+               } else {
                        *vpp = newvp;
+               }
        }
        nfs_open_owner_clear_busy(noop);
-       return (error);
+       NFS_ZFREE(nfs_fhandle_zone, fh);
+       NFS_ZFREE(nfs_req_zone, req);
+       FREE(dul, M_TEMP);
+       FREE(nvattr, M_TEMP);
+       return error;
 }
 
 
@@ -4968,7 +5551,7 @@ nfs4_claim_delegated_open_rpc(
 {
        struct nfsmount *nmp;
        struct nfs_open_owner *noop = nofp->nof_owner;
-       struct nfs_vattr nvattr;
+       struct nfs_vattr *nvattr;
        int error = 0, lockerror = ENOENT, status;
        int nfsvers, numops;
        u_int64_t xid;
@@ -4976,7 +5559,7 @@ nfs4_claim_delegated_open_rpc(
        struct nfsm_chain nmreq, nmrep;
        uint32_t bitmap[NFS_ATTR_BITMAP_LEN], bmlen;
        uint32_t rflags = 0, delegation, recall = 0;
-       fhandle_t fh;
+       fhandle_t *fh;
        struct nfs_stateid dstateid;
        char sbuf[64], *s = sbuf;
        uint32_t ace_type, ace_flags, ace_mask, len, slen = sizeof(sbuf);
@@ -4984,14 +5567,17 @@ nfs4_claim_delegated_open_rpc(
        vnode_t dvp = NULL;
        const char *vname = NULL;
        const char *name = NULL;
-       size_t namelen;
+       uint32_t namelen;
        char smallname[128];
        char *filename = NULL;
        struct nfsreq_secinfo_args si;
 
        nmp = NFSTONMP(np);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
+       fh = zalloc(nfs_fhandle_zone);
+       MALLOC(nvattr, struct nfs_vattr *, sizeof(*nvattr), M_TEMP, M_WAITOK);
        nfsvers = nmp->nm_vers;
 
        nfs_node_lock_force(np);
@@ -5003,6 +5589,7 @@ nfs4_claim_delegated_open_rpc(
                struct nfs_sillyrename *nsp = np->n_sillyrename;
                dvp = NFSTOV(nsp->nsr_dnp);
                if ((error = vnode_get(dvp))) {
+                       dvp = NULLVP;
                        nfs_node_unlock(np);
                        goto out;
                }
@@ -5015,14 +5602,17 @@ nfs4_claim_delegated_open_rpc(
                 * from the n_parent we have stashed away.
                 */
                if ((np->n_vattr.nva_flags & NFS_FFLAG_IS_ATTR) &&
-                   (((dvp = np->n_parent)) && (error = vnode_get(dvp))))
+                   (((dvp = np->n_parent)) && (error = vnode_get(dvp)))) {
                        dvp = NULL;
-               if (!dvp)
+               }
+               if (!dvp) {
                        dvp = vnode_getparent(NFSTOV(np));
+               }
                vname = vnode_getname(NFSTOV(np));
                if (!dvp || !vname) {
-                       if (!error)
+                       if (!error) {
                                error = EIO;
+                       }
                        nfs_node_unlock(np);
                        goto out;
                }
@@ -5031,19 +5621,20 @@ nfs4_claim_delegated_open_rpc(
        filename = &smallname[0];
        namelen = snprintf(filename, sizeof(smallname), "%s", name);
        if (namelen >= sizeof(smallname)) {
-               MALLOC(filename, char *, namelen+1, M_TEMP, M_WAITOK);
+               MALLOC(filename, char *, namelen + 1, M_TEMP, M_WAITOK);
                if (!filename) {
                        error = ENOMEM;
+                       nfs_node_unlock(np);
                        goto out;
                }
-               snprintf(filename, namelen+1, "%s", name);
+               snprintf(filename, namelen + 1, "%s", name);
        }
        nfs_node_unlock(np);
 
-       if ((error = nfs_open_owner_set_busy(noop, NULL)))
-               return (error);
-
-       NVATTR_INIT(&nvattr);
+       if ((error = nfs_open_owner_set_busy(noop, NULL))) {
+               goto out;
+       }
+       NVATTR_INIT(nvattr);
        delegation = NFS_OPEN_DELEGATE_NONE;
        dstateid = np->n_dstateid;
        NFSREQ_SECINFO_SET(&si, VTONFS(dvp), NULL, 0, filename, namelen);
@@ -5054,7 +5645,7 @@ nfs4_claim_delegated_open_rpc(
        // PUTFH, OPEN, GETATTR(FH)
        numops = 3;
        nfsm_chain_build_alloc_init(error, &nmreq, 48 * NFSX_UNSIGNED);
-       nfsm_chain_add_compound_header(error, &nmreq, "open_claim_d", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "open_claim_d", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, nfsvers, VTONFS(dvp)->n_fhp, VTONFS(dvp)->n_fhsize);
@@ -5083,10 +5674,11 @@ nfs4_claim_delegated_open_rpc(
        nfsmout_if(error);
 
        error = nfs_request2(np, nmp->nm_mountp, &nmreq, NFSPROC4_COMPOUND, current_thread(),
-                       noop->noo_cred, &si, flags|R_NOINTR, &nmrep, &xid, &status);
+           noop->noo_cred, &si, flags | R_NOINTR, &nmrep, &xid, &status);
 
-       if ((lockerror = nfs_node_lock(np)))
+       if ((lockerror = nfs_node_lock(np))) {
                error = lockerror;
+       }
        nfsm_chain_skip_tag(error, &nmrep);
        nfsm_chain_get_32(error, &nmrep, numops);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_PUTFH);
@@ -5099,25 +5691,27 @@ nfs4_claim_delegated_open_rpc(
        bmlen = NFS_ATTR_BITMAP_LEN;
        nfsm_chain_get_bitmap(error, &nmrep, bitmap, bmlen);
        nfsm_chain_get_32(error, &nmrep, delegation);
-       if (!error)
+       if (!error) {
                switch (delegation) {
                case NFS_OPEN_DELEGATE_NONE:
                        // if (!(np->n_openflags & N_DELEG_RETURN)) /* don't warn if delegation is being returned */
-                       //      printf("nfs: open delegated claim didn't return a delegation %s\n", filename ? filename : "???");
+                       //      printf("nfs: open delegated claim didn't return a delegation %s\n", filename ? filename : "???");
                        break;
                case NFS_OPEN_DELEGATE_READ:
                case NFS_OPEN_DELEGATE_WRITE:
                        if ((((np->n_openflags & N_DELEG_MASK) == N_DELEG_READ) &&
-                            (delegation == NFS_OPEN_DELEGATE_WRITE)) ||
+                           (delegation == NFS_OPEN_DELEGATE_WRITE)) ||
                            (((np->n_openflags & N_DELEG_MASK) == N_DELEG_WRITE) &&
-                            (delegation == NFS_OPEN_DELEGATE_READ)))
+                           (delegation == NFS_OPEN_DELEGATE_READ))) {
                                printf("nfs: open delegated claim returned a different delegation type! have %s got %s %s\n",
-                                    ((np->n_openflags & N_DELEG_MASK) == N_DELEG_WRITE) ? "W" : "R",
-                                    (delegation == NFS_OPEN_DELEGATE_WRITE) ? "W" : "R", filename ? filename : "???");
+                                   ((np->n_openflags & N_DELEG_MASK) == N_DELEG_WRITE) ? "W" : "R",
+                                   (delegation == NFS_OPEN_DELEGATE_WRITE) ? "W" : "R", filename ? filename : "???");
+                       }
                        nfsm_chain_get_stateid(error, &nmrep, &dstateid);
                        nfsm_chain_get_32(error, &nmrep, recall);
-                       if (delegation == NFS_OPEN_DELEGATE_WRITE) // space (skip) XXX
+                       if (delegation == NFS_OPEN_DELEGATE_WRITE) // space (skip) XXX
                                nfsm_chain_adv(error, &nmrep, 3 * NFSX_UNSIGNED);
+                       }
                        /* if we have any trouble accepting the ACE, just invalidate it */
                        ace_type = ace_flags = ace_mask = len = 0;
                        nfsm_chain_get_32(error, &nmrep, ace_type);
@@ -5128,25 +5722,30 @@ nfs4_claim_delegated_open_rpc(
                        ace.ace_flags |= nfs4_ace_nfsflags_to_vfsflags(ace_flags);
                        ace.ace_rights = nfs4_ace_nfsmask_to_vfsrights(ace_mask);
                        if (!error && (len >= slen)) {
-                               MALLOC(s, char*, len+1, M_TEMP, M_WAITOK);
-                               if (s)
-                                       slen = len+1;
-                               else
+                               MALLOC(s, char*, len + 1, M_TEMP, M_WAITOK);
+                               if (s) {
+                                       slen = len + 1;
+                               } else {
                                        ace.ace_flags = 0;
+                               }
                        }
-                       if (s)
+                       if (s) {
                                nfsm_chain_get_opaque(error, &nmrep, len, s);
-                       else
+                       } else {
                                nfsm_chain_adv(error, &nmrep, nfsm_rndup(len));
+                       }
                        if (!error && s) {
                                s[len] = '\0';
-                               if (nfs4_id2guid(s, &ace.ace_applicable, (ace_flags & NFS_ACE_IDENTIFIER_GROUP)))
+                               if (nfs4_id2guid(s, &ace.ace_applicable, (ace_flags & NFS_ACE_IDENTIFIER_GROUP))) {
                                        ace.ace_flags = 0;
+                               }
                        }
-                       if (error || !s)
+                       if (error || !s) {
                                ace.ace_flags = 0;
-                       if (s && (s != sbuf))
+                       }
+                       if (s && (s != sbuf)) {
                                FREE(s, M_TEMP);
+                       }
                        if (!error) {
                                /* stuff the latest delegation state in the node */
                                lck_mtx_lock(&np->n_openlock);
@@ -5156,8 +5755,9 @@ nfs4_claim_delegated_open_rpc(
                                np->n_dace = ace;
                                if (np->n_dlink.tqe_next == NFSNOLIST) {
                                        lck_mtx_lock(&nmp->nm_lock);
-                                       if (np->n_dlink.tqe_next == NFSNOLIST)
+                                       if (np->n_dlink.tqe_next == NFSNOLIST) {
                                                TAILQ_INSERT_TAIL(&nmp->nm_delegations, np, n_dlink);
+                                       }
                                        lck_mtx_unlock(&nmp->nm_lock);
                                }
                                lck_mtx_unlock(&np->n_openlock);
@@ -5167,31 +5767,37 @@ nfs4_claim_delegated_open_rpc(
                        error = EBADRPC;
                        break;
                }
+       }
        nfsmout_if(error);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
-       error = nfs4_parsefattr(&nmrep, NULL, &nvattr, &fh, NULL, NULL);
+       error = nfs4_parsefattr(&nmrep, NULL, nvattr, fh, NULL, NULL);
        nfsmout_if(error);
-       if (!NFS_BITMAP_ISSET(nvattr.nva_bitmap, NFS_FATTR_FILEHANDLE)) {
+       if (!NFS_BITMAP_ISSET(nvattr->nva_bitmap, NFS_FATTR_FILEHANDLE)) {
                printf("nfs: open reclaim didn't return filehandle? %s\n", filename ? filename : "???");
                error = EBADRPC;
                goto nfsmout;
        }
-       if (!NFS_CMPFH(np, fh.fh_data, fh.fh_len)) {
+       if (!NFS_CMPFH(np, fh->fh_data, fh->fh_len)) {
                // XXX what if fh doesn't match the vnode we think we're re-opening?
                // Solaris Named Attributes may do this due to a bug.... so don't warn for named attributes.
-               if (!(np->n_vattr.nva_flags & NFS_FFLAG_IS_ATTR))
+               if (!(np->n_vattr.nva_flags & NFS_FFLAG_IS_ATTR)) {
                        printf("nfs4_claim_delegated_open_rpc: warning: file handle mismatch %s\n", filename ? filename : "???");
+               }
        }
-       error = nfs_loadattrcache(np, &nvattr, &xid, 1);
+       error = nfs_loadattrcache(np, nvattr, &xid, 1);
        nfsmout_if(error);
-       if (rflags & NFS_OPEN_RESULT_LOCKTYPE_POSIX)
+       if (rflags & NFS_OPEN_RESULT_LOCKTYPE_POSIX) {
                nofp->nof_flags |= NFS_OPEN_FILE_POSIXLOCK;
+       }
 nfsmout:
-       NVATTR_CLEANUP(&nvattr);
+       NVATTR_CLEANUP(nvattr);
+       FREE(nvattr, M_TEMP);
+       NFS_ZFREE(nfs_fhandle_zone, fh);
        nfsm_chain_cleanup(&nmreq);
        nfsm_chain_cleanup(&nmrep);
-       if (!lockerror)
+       if (!lockerror) {
                nfs_node_unlock(np);
+       }
        nfs_open_owner_clear_busy(noop);
        if ((delegation == NFS_OPEN_DELEGATE_READ) || (delegation == NFS_OPEN_DELEGATE_WRITE)) {
                if (recall) {
@@ -5205,14 +5811,17 @@ nfsmout:
        }
 out:
        // if (!error)
-       //      printf("nfs: open claim delegated (%d, %d) succeeded for %s\n", share_access, share_deny, filename ? filename : "???");
-       if (filename && (filename != &smallname[0]))
+       //      printf("nfs: open claim delegated (%d, %d) succeeded for %s\n", share_access, share_deny, filename ? filename : "???");
+       if (filename && (filename != &smallname[0])) {
                FREE(filename, M_TEMP);
-       if (vname)
+       }
+       if (vname) {
                vnode_putname(vname);
-       if (dvp != NULLVP)
+       }
+       if (dvp != NULLVP) {
                vnode_put(dvp);
-       return (error);
+       }
+       return error;
 }
 
 /*
@@ -5226,7 +5835,7 @@ nfs4_open_reclaim_rpc(
 {
        struct nfsmount *nmp;
        struct nfs_open_owner *noop = nofp->nof_owner;
-       struct nfs_vattr nvattr;
+       struct nfs_vattr *nvattr;
        int error = 0, lockerror = ENOENT, status;
        int nfsvers, numops;
        u_int64_t xid;
@@ -5234,7 +5843,7 @@ nfs4_open_reclaim_rpc(
        struct nfsm_chain nmreq, nmrep;
        uint32_t bitmap[NFS_ATTR_BITMAP_LEN], bmlen;
        uint32_t rflags = 0, delegation, recall = 0;
-       fhandle_t fh;
+       fhandle_t *fh;
        struct nfs_stateid dstateid;
        char sbuf[64], *s = sbuf;
        uint32_t ace_type, ace_flags, ace_mask, len, slen = sizeof(sbuf);
@@ -5242,14 +5851,18 @@ nfs4_open_reclaim_rpc(
        struct nfsreq_secinfo_args si;
 
        nmp = NFSTONMP(np);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        nfsvers = nmp->nm_vers;
 
-       if ((error = nfs_open_owner_set_busy(noop, NULL)))
-               return (error);
+       if ((error = nfs_open_owner_set_busy(noop, NULL))) {
+               return error;
+       }
 
-       NVATTR_INIT(&nvattr);
+       fh = zalloc(nfs_fhandle_zone);
+       MALLOC(nvattr, struct nfs_vattr *, sizeof(*nvattr), M_TEMP, M_WAITOK);
+       NVATTR_INIT(nvattr);
        delegation = NFS_OPEN_DELEGATE_NONE;
        dstateid = np->n_dstateid;
        NFSREQ_SECINFO_SET(&si, np, NULL, 0, NULL, 0);
@@ -5260,7 +5873,7 @@ nfs4_open_reclaim_rpc(
        // PUTFH, OPEN, GETATTR(FH)
        numops = 3;
        nfsm_chain_build_alloc_init(error, &nmreq, 48 * NFSX_UNSIGNED);
-       nfsm_chain_add_compound_header(error, &nmreq, "open_reclaim", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "open_reclaim", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, nfsvers, np->n_fhp, np->n_fhsize);
@@ -5278,8 +5891,8 @@ nfs4_open_reclaim_rpc(
        // open_claim4
        nfsm_chain_add_32(error, &nmreq, NFS_CLAIM_PREVIOUS);
        delegation = (np->n_openflags & N_DELEG_READ) ? NFS_OPEN_DELEGATE_READ :
-                       (np->n_openflags & N_DELEG_WRITE) ? NFS_OPEN_DELEGATE_WRITE :
-                       NFS_OPEN_DELEGATE_NONE;
+           (np->n_openflags & N_DELEG_WRITE) ? NFS_OPEN_DELEGATE_WRITE :
+           NFS_OPEN_DELEGATE_NONE;
        nfsm_chain_add_32(error, &nmreq, delegation);
        delegation = NFS_OPEN_DELEGATE_NONE;
        numops--;
@@ -5292,10 +5905,11 @@ nfs4_open_reclaim_rpc(
        nfsmout_if(error);
 
        error = nfs_request2(np, nmp->nm_mountp, &nmreq, NFSPROC4_COMPOUND, current_thread(),
-                       noop->noo_cred, &si, R_RECOVER|R_NOINTR, &nmrep, &xid, &status);
+           noop->noo_cred, &si, R_RECOVER | R_NOINTR, &nmrep, &xid, &status);
 
-       if ((lockerror = nfs_node_lock(np)))
+       if ((lockerror = nfs_node_lock(np))) {
                error = lockerror;
+       }
        nfsm_chain_skip_tag(error, &nmrep);
        nfsm_chain_get_32(error, &nmrep, numops);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_PUTFH);
@@ -5308,7 +5922,7 @@ nfs4_open_reclaim_rpc(
        bmlen = NFS_ATTR_BITMAP_LEN;
        nfsm_chain_get_bitmap(error, &nmrep, bitmap, bmlen);
        nfsm_chain_get_32(error, &nmrep, delegation);
-       if (!error)
+       if (!error) {
                switch (delegation) {
                case NFS_OPEN_DELEGATE_NONE:
                        if (np->n_openflags & N_DELEG_MASK) {
@@ -5327,8 +5941,9 @@ nfs4_open_reclaim_rpc(
                case NFS_OPEN_DELEGATE_WRITE:
                        nfsm_chain_get_stateid(error, &nmrep, &dstateid);
                        nfsm_chain_get_32(error, &nmrep, recall);
-                       if (delegation == NFS_OPEN_DELEGATE_WRITE) // space (skip) XXX
+                       if (delegation == NFS_OPEN_DELEGATE_WRITE) // space (skip) XXX
                                nfsm_chain_adv(error, &nmrep, 3 * NFSX_UNSIGNED);
+                       }
                        /* if we have any trouble accepting the ACE, just invalidate it */
                        ace_type = ace_flags = ace_mask = len = 0;
                        nfsm_chain_get_32(error, &nmrep, ace_type);
@@ -5339,25 +5954,30 @@ nfs4_open_reclaim_rpc(
                        ace.ace_flags |= nfs4_ace_nfsflags_to_vfsflags(ace_flags);
                        ace.ace_rights = nfs4_ace_nfsmask_to_vfsrights(ace_mask);
                        if (!error && (len >= slen)) {
-                               MALLOC(s, char*, len+1, M_TEMP, M_WAITOK);
-                               if (s)
-                                       slen = len+1;
-                               else
+                               MALLOC(s, char*, len + 1, M_TEMP, M_WAITOK);
+                               if (s) {
+                                       slen = len + 1;
+                               } else {
                                        ace.ace_flags = 0;
+                               }
                        }
-                       if (s)
+                       if (s) {
                                nfsm_chain_get_opaque(error, &nmrep, len, s);
-                       else
+                       } else {
                                nfsm_chain_adv(error, &nmrep, nfsm_rndup(len));
+                       }
                        if (!error && s) {
                                s[len] = '\0';
-                               if (nfs4_id2guid(s, &ace.ace_applicable, (ace_flags & NFS_ACE_IDENTIFIER_GROUP)))
+                               if (nfs4_id2guid(s, &ace.ace_applicable, (ace_flags & NFS_ACE_IDENTIFIER_GROUP))) {
                                        ace.ace_flags = 0;
+                               }
                        }
-                       if (error || !s)
+                       if (error || !s) {
                                ace.ace_flags = 0;
-                       if (s && (s != sbuf))
+                       }
+                       if (s && (s != sbuf)) {
                                FREE(s, M_TEMP);
+                       }
                        if (!error) {
                                /* stuff the delegation state in the node */
                                lck_mtx_lock(&np->n_openlock);
@@ -5367,8 +5987,9 @@ nfs4_open_reclaim_rpc(
                                np->n_dace = ace;
                                if (np->n_dlink.tqe_next == NFSNOLIST) {
                                        lck_mtx_lock(&nmp->nm_lock);
-                                       if (np->n_dlink.tqe_next == NFSNOLIST)
+                                       if (np->n_dlink.tqe_next == NFSNOLIST) {
                                                TAILQ_INSERT_TAIL(&nmp->nm_delegations, np, n_dlink);
+                                       }
                                        lck_mtx_unlock(&nmp->nm_lock);
                                }
                                lck_mtx_unlock(&np->n_openlock);
@@ -5378,41 +5999,48 @@ nfs4_open_reclaim_rpc(
                        error = EBADRPC;
                        break;
                }
+       }
        nfsmout_if(error);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
-       error = nfs4_parsefattr(&nmrep, NULL, &nvattr, &fh, NULL, NULL);
+       error = nfs4_parsefattr(&nmrep, NULL, nvattr, fh, NULL, NULL);
        nfsmout_if(error);
-       if (!NFS_BITMAP_ISSET(nvattr.nva_bitmap, NFS_FATTR_FILEHANDLE)) {
+       if (!NFS_BITMAP_ISSET(nvattr->nva_bitmap, NFS_FATTR_FILEHANDLE)) {
                NP(np, "nfs: open reclaim didn't return filehandle?");
                error = EBADRPC;
                goto nfsmout;
        }
-       if (!NFS_CMPFH(np, fh.fh_data, fh.fh_len)) {
+       if (!NFS_CMPFH(np, fh->fh_data, fh->fh_len)) {
                // XXX what if fh doesn't match the vnode we think we're re-opening?
                // That should be pretty hard in this case, given that we are doing
                // the open reclaim using the file handle (and not a dir/name pair).
                // Solaris Named Attributes may do this due to a bug.... so don't warn for named attributes.
-               if (!(np->n_vattr.nva_flags & NFS_FFLAG_IS_ATTR))
+               if (!(np->n_vattr.nva_flags & NFS_FFLAG_IS_ATTR)) {
                        NP(np, "nfs4_open_reclaim_rpc: warning: file handle mismatch");
+               }
        }
-       error = nfs_loadattrcache(np, &nvattr, &xid, 1);
+       error = nfs_loadattrcache(np, nvattr, &xid, 1);
        nfsmout_if(error);
-       if (rflags & NFS_OPEN_RESULT_LOCKTYPE_POSIX)
+       if (rflags & NFS_OPEN_RESULT_LOCKTYPE_POSIX) {
                nofp->nof_flags |= NFS_OPEN_FILE_POSIXLOCK;
+       }
 nfsmout:
        // if (!error)
-       //      NP(np, "nfs: open reclaim (%d, %d) succeeded", share_access, share_deny);
-       NVATTR_CLEANUP(&nvattr);
+       //      NP(np, "nfs: open reclaim (%d, %d) succeeded", share_access, share_deny);
+       NVATTR_CLEANUP(nvattr);
+       FREE(nvattr, M_TEMP);
+       NFS_ZFREE(nfs_fhandle_zone, fh);
        nfsm_chain_cleanup(&nmreq);
        nfsm_chain_cleanup(&nmrep);
-       if (!lockerror)
+       if (!lockerror) {
                nfs_node_unlock(np);
+       }
        nfs_open_owner_clear_busy(noop);
        if ((delegation == NFS_OPEN_DELEGATE_READ) || (delegation == NFS_OPEN_DELEGATE_WRITE)) {
-               if (recall)
+               if (recall) {
                        nfs4_delegation_return_enqueue(np);
+               }
        }
-       return (error);
+       return error;
 }
 
 int
@@ -5429,12 +6057,14 @@ nfs4_open_downgrade_rpc(
        struct nfsreq_secinfo_args si;
 
        nmp = NFSTONMP(np);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        nfsvers = nmp->nm_vers;
 
-       if ((error = nfs_open_owner_set_busy(noop, NULL)))
-               return (error);
+       if ((error = nfs_open_owner_set_busy(noop, NULL))) {
+               return error;
+       }
 
        NFSREQ_SECINFO_SET(&si, np, NULL, 0, NULL, 0);
        nfsm_chain_null(&nmreq);
@@ -5443,7 +6073,7 @@ nfs4_open_downgrade_rpc(
        // PUTFH, OPEN_DOWNGRADE, GETATTR
        numops = 3;
        nfsm_chain_build_alloc_init(error, &nmreq, 23 * NFSX_UNSIGNED);
-       nfsm_chain_add_compound_header(error, &nmreq, "open_downgrd", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "open_downgrd", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, nfsvers, np->n_fhp, np->n_fhsize);
@@ -5460,11 +6090,12 @@ nfs4_open_downgrade_rpc(
        nfsm_assert(error, (numops == 0), EPROTO);
        nfsmout_if(error);
        error = nfs_request2(np, NULL, &nmreq, NFSPROC4_COMPOUND,
-                       vfs_context_thread(ctx), vfs_context_ucred(ctx),
-                       &si, R_NOINTR, &nmrep, &xid, &status);
+           vfs_context_thread(ctx), vfs_context_ucred(ctx),
+           &si, R_NOINTR, &nmrep, &xid, &status);
 
-       if ((lockerror = nfs_node_lock(np)))
+       if ((lockerror = nfs_node_lock(np))) {
                error = lockerror;
+       }
        nfsm_chain_skip_tag(error, &nmrep);
        nfsm_chain_get_32(error, &nmrep, numops);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_PUTFH);
@@ -5475,12 +6106,13 @@ nfs4_open_downgrade_rpc(
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
        nfsm_chain_loadattr(error, &nmrep, np, nfsvers, &xid);
 nfsmout:
-       if (!lockerror)
+       if (!lockerror) {
                nfs_node_unlock(np);
+       }
        nfs_open_owner_clear_busy(noop);
        nfsm_chain_cleanup(&nmreq);
        nfsm_chain_cleanup(&nmrep);
-       return (error);
+       return error;
 }
 
 int
@@ -5499,12 +6131,14 @@ nfs4_close_rpc(
        struct nfsreq_secinfo_args si;
 
        nmp = NFSTONMP(np);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        nfsvers = nmp->nm_vers;
 
-       if ((error = nfs_open_owner_set_busy(noop, NULL)))
-               return (error);
+       if ((error = nfs_open_owner_set_busy(noop, NULL))) {
+               return error;
+       }
 
        NFSREQ_SECINFO_SET(&si, np, NULL, 0, NULL, 0);
        nfsm_chain_null(&nmreq);
@@ -5513,7 +6147,7 @@ nfs4_close_rpc(
        // PUTFH, CLOSE, GETATTR
        numops = 3;
        nfsm_chain_build_alloc_init(error, &nmreq, 23 * NFSX_UNSIGNED);
-       nfsm_chain_add_compound_header(error, &nmreq, "close", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "close", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, nfsvers, np->n_fhp, np->n_fhsize);
@@ -5527,10 +6161,11 @@ nfs4_close_rpc(
        nfsm_chain_build_done(error, &nmreq);
        nfsm_assert(error, (numops == 0), EPROTO);
        nfsmout_if(error);
-       error = nfs_request2(np, NULL, &nmreq, NFSPROC4_COMPOUND, thd, cred, &si, flags|R_NOINTR, &nmrep, &xid, &status);
+       error = nfs_request2(np, NULL, &nmreq, NFSPROC4_COMPOUND, thd, cred, &si, flags | R_NOINTR, &nmrep, &xid, &status);
 
-       if ((lockerror = nfs_node_lock(np)))
+       if ((lockerror = nfs_node_lock(np))) {
                error = lockerror;
+       }
        nfsm_chain_skip_tag(error, &nmrep);
        nfsm_chain_get_32(error, &nmrep, numops);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_PUTFH);
@@ -5541,12 +6176,13 @@ nfs4_close_rpc(
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
        nfsm_chain_loadattr(error, &nmrep, np, nfsvers, &xid);
 nfsmout:
-       if (!lockerror)
+       if (!lockerror) {
                nfs_node_unlock(np);
+       }
        nfs_open_owner_clear_busy(noop);
        nfsm_chain_cleanup(&nmreq);
        nfsm_chain_cleanup(&nmrep);
-       return (error);
+       return error;
 }
 
 
@@ -5620,8 +6256,9 @@ nfs4_claim_delegated_state_for_open_file(struct nfs_open_file *nofp, int flags)
        if (!error && nofp->nof_d_rw) {
                error = nfs4_claim_delegated_open_rpc(nofp, NFS_OPEN_SHARE_ACCESS_BOTH, NFS_OPEN_SHARE_DENY_NONE, flags);
                /* for some errors, we should just try reopening the file */
-               if (nfs_mount_state_error_delegation_lost(error))
+               if (nfs_mount_state_error_delegation_lost(error)) {
                        reopen = error;
+               }
                if (!error || reopen) {
                        lck_mtx_lock(&nofp->nof_lock);
                        nofp->nof_rw += nofp->nof_d_rw;
@@ -5634,8 +6271,9 @@ nfs4_claim_delegated_state_for_open_file(struct nfs_open_file *nofp, int flags)
                if (!error) {
                        error = nfs4_claim_delegated_open_rpc(nofp, NFS_OPEN_SHARE_ACCESS_WRITE, NFS_OPEN_SHARE_DENY_NONE, flags);
                        /* for some errors, we should just try reopening the file */
-                       if (nfs_mount_state_error_delegation_lost(error))
+                       if (nfs_mount_state_error_delegation_lost(error)) {
                                reopen = error;
+                       }
                }
                if (!error || reopen) {
                        lck_mtx_lock(&nofp->nof_lock);
@@ -5648,8 +6286,9 @@ nfs4_claim_delegated_state_for_open_file(struct nfs_open_file *nofp, int flags)
                if (!error) {
                        error = nfs4_claim_delegated_open_rpc(nofp, NFS_OPEN_SHARE_ACCESS_READ, NFS_OPEN_SHARE_DENY_NONE, flags);
                        /* for some errors, we should just try reopening the file */
-                       if (nfs_mount_state_error_delegation_lost(error))
+                       if (nfs_mount_state_error_delegation_lost(error)) {
                                reopen = error;
+                       }
                }
                if (!error || reopen) {
                        lck_mtx_lock(&nofp->nof_lock);
@@ -5673,58 +6312,65 @@ nfs4_claim_delegated_state_for_open_file(struct nfs_open_file *nofp, int flags)
                if (reopen && (nfs_check_for_locks(noop, nofp) == 0)) {
                        /* just reopen the file on next access */
                        NP(nofp->nof_np, "nfs4_claim_delegated_state_for_open_file: %d, need reopen, %d",
-                               reopen, kauth_cred_getuid(nofp->nof_owner->noo_cred));
+                           reopen, kauth_cred_getuid(nofp->nof_owner->noo_cred));
                        lck_mtx_lock(&nofp->nof_lock);
                        nofp->nof_flags |= NFS_OPEN_FILE_REOPEN;
                        lck_mtx_unlock(&nofp->nof_lock);
-                       return (0);
+                       return 0;
                }
-               if (reopen)
+               if (reopen) {
                        NP(nofp->nof_np, "nfs4_claim_delegated_state_for_open_file: %d, locks prevent reopen, %d",
-                               reopen, kauth_cred_getuid(nofp->nof_owner->noo_cred));
+                           reopen, kauth_cred_getuid(nofp->nof_owner->noo_cred));
+               }
        }
 
        if (!error && ((nmp = NFSTONMP(nofp->nof_np)))) {
                /* claim delegated locks */
                TAILQ_FOREACH(nlop, &nofp->nof_np->n_lock_owners, nlo_link) {
-                       if (nlop->nlo_open_owner != noop)
+                       if (nlop->nlo_open_owner != noop) {
                                continue;
+                       }
                        TAILQ_FOREACH_SAFE(nflp, &nlop->nlo_locks, nfl_lolink, nextnflp) {
                                /* skip dead & blocked lock requests (shouldn't be any in the held lock list) */
-                               if (nflp->nfl_flags & (NFS_FILE_LOCK_DEAD|NFS_FILE_LOCK_BLOCKED))
+                               if (nflp->nfl_flags & (NFS_FILE_LOCK_DEAD | NFS_FILE_LOCK_BLOCKED)) {
                                        continue;
+                               }
                                /* skip non-delegated locks */
-                               if (!(nflp->nfl_flags & NFS_FILE_LOCK_DELEGATED))
+                               if (!(nflp->nfl_flags & NFS_FILE_LOCK_DELEGATED)) {
                                        continue;
+                               }
                                error = nmp->nm_funcs->nf_setlock_rpc(nofp->nof_np, nofp, nflp, 0, flags, current_thread(), noop->noo_cred);
                                if (error) {
                                        NP(nofp->nof_np, "nfs: delegated lock claim (0x%llx, 0x%llx) failed %d, %d",
-                                               nflp->nfl_start, nflp->nfl_end, error, kauth_cred_getuid(nofp->nof_owner->noo_cred));
+                                           nflp->nfl_start, nflp->nfl_end, error, kauth_cred_getuid(nofp->nof_owner->noo_cred));
                                        break;
                                }
                                // else {
-                               //      NP(nofp->nof_np, "nfs: delegated lock claim (0x%llx, 0x%llx) succeeded, %d",
-                               //              nflp->nfl_start, nflp->nfl_end, kauth_cred_getuid(nofp->nof_owner->noo_cred));
+                               //      NP(nofp->nof_np, "nfs: delegated lock claim (0x%llx, 0x%llx) succeeded, %d",
+                               //              nflp->nfl_start, nflp->nfl_end, kauth_cred_getuid(nofp->nof_owner->noo_cred));
                                // }
                        }
-                       if (error)
+                       if (error) {
                                break;
+                       }
                }
        }
 
-       if (!error)  /* all state claimed successfully! */
-               return (0);
+       if (!error) { /* all state claimed successfully! */
+               return 0;
+       }
 
        /* restart if it looks like a problem more than just losing the delegation */
        if (!nfs_mount_state_error_delegation_lost(error) &&
            ((error == ETIMEDOUT) || nfs_mount_state_error_should_restart(error))) {
                NP(nofp->nof_np, "nfs delegated lock claim error %d, %d", error, kauth_cred_getuid(nofp->nof_owner->noo_cred));
-               if ((error == ETIMEDOUT) && ((nmp = NFSTONMP(nofp->nof_np))))
+               if ((error == ETIMEDOUT) && ((nmp = NFSTONMP(nofp->nof_np)))) {
                        nfs_need_reconnect(nmp);
-               return (error);
+               }
+               return error;
        }
 
-       /* delegated state lost (once held but now not claimable) */ 
+       /* delegated state lost (once held but now not claimable) */
        NP(nofp->nof_np, "nfs delegated state claim error %d, state lost, %d", error, kauth_cred_getuid(nofp->nof_owner->noo_cred));
 
        /*
@@ -5741,8 +6387,9 @@ nfs4_claim_delegated_state_for_open_file(struct nfs_open_file *nofp, int flags)
        /* revoke all open file state */
        nfs_revoke_open_state_for_node(nofp->nof_np);
 
-       return (error);
+       return error;
 }
+#endif /* CONFIG_NFS4*/
 
 /*
  * Release all open state for the given node.
@@ -5757,12 +6404,14 @@ nfs_release_open_state_for_node(nfsnode_t np, int force)
        /* drop held locks */
        TAILQ_FOREACH_SAFE(nflp, &np->n_locks, nfl_link, nextnflp) {
                /* skip dead & blocked lock requests */
-               if (nflp->nfl_flags & (NFS_FILE_LOCK_DEAD|NFS_FILE_LOCK_BLOCKED))
+               if (nflp->nfl_flags & (NFS_FILE_LOCK_DEAD | NFS_FILE_LOCK_BLOCKED)) {
                        continue;
+               }
                /* send an unlock if not a delegated lock */
-               if (!force && nmp && !(nflp->nfl_flags & NFS_FILE_LOCK_DELEGATED))
+               if (!force && nmp && !(nflp->nfl_flags & NFS_FILE_LOCK_DELEGATED)) {
                        nmp->nm_funcs->nf_unlock_rpc(np, nflp->nfl_owner, F_WRLCK, nflp->nfl_start, nflp->nfl_end, R_RECOVER,
-                               NULL, nflp->nfl_owner->nlo_open_owner->noo_cred);
+                           NULL, nflp->nfl_owner->nlo_open_owner->noo_cred);
+               }
                /* kill/remove the lock */
                lck_mtx_lock(&np->n_openlock);
                nflp->nfl_flags |= NFS_FILE_LOCK_DEAD;
@@ -5784,16 +6433,20 @@ nfs_release_open_state_for_node(nfsnode_t np, int force)
 
        /* drop all opens */
        TAILQ_FOREACH(nofp, &np->n_opens, nof_link) {
-               if (nofp->nof_flags & NFS_OPEN_FILE_LOST)
+               if (nofp->nof_flags & NFS_OPEN_FILE_LOST) {
                        continue;
+               }
                /* mark open state as lost */
                lck_mtx_lock(&nofp->nof_lock);
                nofp->nof_flags &= ~NFS_OPEN_FILE_REOPEN;
                nofp->nof_flags |= NFS_OPEN_FILE_LOST;
-               
+
                lck_mtx_unlock(&nofp->nof_lock);
-               if (!force && nmp && (nmp->nm_vers >= NFS_VER4))
+#if CONFIG_NFS4
+               if (!force && nmp && (nmp->nm_vers >= NFS_VER4)) {
                        nfs4_close_rpc(np, nofp, NULL, nofp->nof_owner->noo_cred, R_RECOVER);
+               }
+#endif
        }
 
        lck_mtx_unlock(&np->n_openlock);
@@ -5811,8 +6464,7 @@ nfs_revoke_open_state_for_node(nfsnode_t np)
 
        /* mark node as needing to be revoked */
        nfs_node_lock_force(np);
-       if (np->n_flag & NREVOKE)  /* already revoked? */
-       {
+       if (np->n_flag & NREVOKE) { /* already revoked? */
                NP(np, "nfs_revoke_open_state_for_node(): already revoked");
                nfs_node_unlock(np);
                return;
@@ -5832,6 +6484,7 @@ nfs_revoke_open_state_for_node(nfsnode_t np)
        }
 }
 
+#if CONFIG_NFS4
 /*
  * Claim the delegated open combinations that each of this node's open files hold.
  */
@@ -5848,19 +6501,21 @@ restart:
        TAILQ_FOREACH(nofp, &np->n_opens, nof_link) {
                if (!nofp->nof_d_rw_drw && !nofp->nof_d_w_drw && !nofp->nof_d_r_drw &&
                    !nofp->nof_d_rw_dw && !nofp->nof_d_w_dw && !nofp->nof_d_r_dw &&
-                   !nofp->nof_d_rw && !nofp->nof_d_w && !nofp->nof_d_r)
+                   !nofp->nof_d_rw && !nofp->nof_d_w && !nofp->nof_d_r) {
                        continue;
+               }
                lck_mtx_unlock(&np->n_openlock);
                error = nfs4_claim_delegated_state_for_open_file(nofp, flags);
                lck_mtx_lock(&np->n_openlock);
-               if (error)
+               if (error) {
                        break;
+               }
                goto restart;
        }
 
        lck_mtx_unlock(&np->n_openlock);
 
-       return (error);
+       return error;
 }
 
 /*
@@ -5874,16 +6529,18 @@ nfs4_delegation_return_enqueue(nfsnode_t np)
        struct nfsmount *nmp;
 
        nmp = NFSTONMP(np);
-       if (!nmp)
+       if (nfs_mount_gone(nmp)) {
                return;
+       }
 
        lck_mtx_lock(&np->n_openlock);
        np->n_openflags |= N_DELEG_RETURN;
        lck_mtx_unlock(&np->n_openlock);
 
        lck_mtx_lock(&nmp->nm_lock);
-       if (np->n_dreturn.tqe_next == NFSNOLIST)
+       if (np->n_dreturn.tqe_next == NFSNOLIST) {
                TAILQ_INSERT_TAIL(&nmp->nm_dreturnq, np, n_dreturn);
+       }
        nfs_mount_sock_thread_wake(nmp);
        lck_mtx_unlock(&nmp->nm_lock);
 }
@@ -5895,34 +6552,39 @@ int
 nfs4_delegation_return(nfsnode_t np, int flags, thread_t thd, kauth_cred_t cred)
 {
        struct nfsmount *nmp;
-       fhandle_t fh;
+       fhandle_t *fh;
        nfs_stateid dstateid;
        int error;
 
        nmp = NFSTONMP(np);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
+
+       fh = zalloc(nfs_fhandle_zone);
 
        /* first, make sure the node's marked for delegation return */
        lck_mtx_lock(&np->n_openlock);
-       np->n_openflags |= (N_DELEG_RETURN|N_DELEG_RETURNING);
+       np->n_openflags |= (N_DELEG_RETURN | N_DELEG_RETURNING);
        lck_mtx_unlock(&np->n_openlock);
 
        /* make sure nobody else is using the delegation state */
-       if ((error = nfs_open_state_set_busy(np, NULL)))
+       if ((error = nfs_open_state_set_busy(np, NULL))) {
                goto out;
+       }
 
        /* claim any delegated state */
-       if ((error = nfs4_claim_delegated_state_for_node(np, flags)))
+       if ((error = nfs4_claim_delegated_state_for_node(np, flags))) {
                goto out;
+       }
 
        /* return the delegation */
        lck_mtx_lock(&np->n_openlock);
        dstateid = np->n_dstateid;
-       fh.fh_len = np->n_fhsize;
-       bcopy(np->n_fhp, &fh.fh_data, fh.fh_len);
+       fh->fh_len = np->n_fhsize;
+       bcopy(np->n_fhp, fh->fh_data, fh->fh_len);
        lck_mtx_unlock(&np->n_openlock);
-       error = nfs4_delegreturn_rpc(NFSTONMP(np), fh.fh_data, fh.fh_len, &dstateid, flags, thd, cred);
+       error = nfs4_delegreturn_rpc(NFSTONMP(np), fh->fh_data, fh->fh_len, &dstateid, flags, thd, cred);
        /* assume delegation is gone for all errors except ETIMEDOUT, NFSERR_*MOVED */
        if ((error != ETIMEDOUT) && (error != NFSERR_MOVED) && (error != NFSERR_LEASE_MOVED)) {
                lck_mtx_lock(&np->n_openlock);
@@ -5945,13 +6607,14 @@ out:
        }
        lck_mtx_unlock(&nmp->nm_lock);
        lck_mtx_lock(&np->n_openlock);
-       np->n_openflags &= ~(N_DELEG_RETURN|N_DELEG_RETURNING);
+       np->n_openflags &= ~(N_DELEG_RETURN | N_DELEG_RETURNING);
        lck_mtx_unlock(&np->n_openlock);
 
        if (error) {
                NP(np, "nfs4_delegation_return, error %d", error);
-               if (error == ETIMEDOUT)
+               if (error == ETIMEDOUT) {
                        nfs_need_reconnect(nmp);
+               }
                if (nfs_mount_state_error_should_restart(error)) {
                        /* make sure recovery happens */
                        lck_mtx_lock(&nmp->nm_lock);
@@ -5961,8 +6624,8 @@ out:
        }
 
        nfs_open_state_clear_busy(np);
-
-       return (error);
+       NFS_ZFREE(nfs_fhandle_zone, fh);
+       return error;
 }
 
 /*
@@ -5983,7 +6646,7 @@ nfs4_delegreturn_rpc(struct nfsmount *nmp, u_char *fhp, int fhlen, struct nfs_st
        // PUTFH, DELEGRETURN
        numops = 2;
        nfsm_chain_build_alloc_init(error, &nmreq, 16 * NFSX_UNSIGNED);
-       nfsm_chain_add_compound_header(error, &nmreq, "delegreturn", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "delegreturn", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, nmp->nm_vers, fhp, fhlen);
@@ -6001,9 +6664,9 @@ nfs4_delegreturn_rpc(struct nfsmount *nmp, u_char *fhp, int fhlen, struct nfs_st
 nfsmout:
        nfsm_chain_cleanup(&nmreq);
        nfsm_chain_cleanup(&nmrep);
-       return (error);
+       return error;
 }
-
+#endif /* CONFIG_NFS4 */
 
 /*
  * NFS read call.
@@ -6015,12 +6678,12 @@ nfsmout:
 int
 nfs_vnop_read(
        struct vnop_read_args /* {
-               struct vnodeop_desc *a_desc;
-               vnode_t a_vp;
-               struct uio *a_uio;
-               int a_ioflag;
-               vfs_context_t a_context;
-       } */ *ap)
+                               *  struct vnodeop_desc *a_desc;
+                               *  vnode_t a_vp;
+                               *  struct uio *a_uio;
+                               *  int a_ioflag;
+                               *  vfs_context_t a_context;
+                               *  } */*ap)
 {
        vnode_t vp = ap->a_vp;
        vfs_context_t ctx = ap->a_context;
@@ -6030,74 +6693,122 @@ nfs_vnop_read(
        struct nfs_open_file *nofp;
        int error;
 
-       if (vnode_vtype(ap->a_vp) != VREG)
+       if (vnode_vtype(ap->a_vp) != VREG) {
                return (vnode_vtype(vp) == VDIR) ? EISDIR : EPERM;
+       }
 
        np = VTONFS(vp);
        nmp = NFSTONMP(np);
-       if (!nmp)
-               return (ENXIO);
-       if (np->n_flag & NREVOKE)
-               return (EIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
+       if (np->n_flag & NREVOKE) {
+               return EIO;
+       }
 
        noop = nfs_open_owner_find(nmp, vfs_context_ucred(ctx), 1);
-       if (!noop)
-               return (ENOMEM);
+       if (!noop) {
+               return ENOMEM;
+       }
 restart:
        error = nfs_open_file_find(np, noop, &nofp, 0, 0, 1);
        if (!error && (nofp->nof_flags & NFS_OPEN_FILE_LOST)) {
                NP(np, "nfs_vnop_read: LOST %d", kauth_cred_getuid(noop->noo_cred));
                error = EIO;
        }
+#if CONFIG_NFS4
        if (!error && (nofp->nof_flags & NFS_OPEN_FILE_REOPEN)) {
                error = nfs4_reopen(nofp, vfs_context_thread(ctx));
                nofp = NULL;
-               if (!error)
+               if (!error) {
                        goto restart;
+               }
        }
+#endif
        if (error) {
                nfs_open_owner_rele(noop);
-               return (error);
+               return error;
        }
-       if (!nofp->nof_access) {
-               /* we don't have the file open, so open it for read access */
-               error = nfs_mount_state_in_use_start(nmp, vfs_context_thread(ctx));
-               if (error) {
+       /*
+        * Since the read path is a hot path, if we already have
+        * read access, lets go and try and do the read, without
+        * busying the mount and open file node for this open owner.
+        *
+        * N.B. This is inherently racy w.r.t. an execve using
+        * an already open file, in that the read at the end of
+        * this routine will be racing with a potential close.
+        * The code below ultimately has the same problem. In practice
+        * this does not seem to be an issue.
+        */
+       if (nofp->nof_access & NFS_OPEN_SHARE_ACCESS_READ) {
+               nfs_open_owner_rele(noop);
+               goto do_read;
+       }
+       error = nfs_mount_state_in_use_start(nmp, vfs_context_thread(ctx));
+       if (error) {
+               nfs_open_owner_rele(noop);
+               return error;
+       }
+       /*
+        * If we don't have a file already open with the access we need (read) then
+        * we need to open one. Otherwise we just co-opt an open. We might not already
+        * have access because we're trying to read the first page of the
+        * file for execve.
+        */
+       error = nfs_open_file_set_busy(nofp, vfs_context_thread(ctx));
+       if (error) {
+               nfs_mount_state_in_use_end(nmp, 0);
+               nfs_open_owner_rele(noop);
+               return error;
+       }
+       if (!(nofp->nof_access & NFS_OPEN_SHARE_ACCESS_READ)) {
+               /* we don't have the file open, so open it for read access if we're not denied */
+               if (nofp->nof_flags & NFS_OPEN_FILE_NEEDCLOSE) {
+                       NP(np, "nfs_vnop_read: File already needs close access: 0x%x, cred: %d thread: %lld",
+                           nofp->nof_access, kauth_cred_getuid(nofp->nof_owner->noo_cred), thread_tid(vfs_context_thread(ctx)));
+               }
+               if (nofp->nof_deny & NFS_OPEN_SHARE_DENY_READ) {
+                       nfs_open_file_clear_busy(nofp);
+                       nfs_mount_state_in_use_end(nmp, 0);
                        nfs_open_owner_rele(noop);
-                       return (error);
+                       return EPERM;
                }
                if (np->n_flag & NREVOKE) {
                        error = EIO;
+                       nfs_open_file_clear_busy(nofp);
                        nfs_mount_state_in_use_end(nmp, 0);
                        nfs_open_owner_rele(noop);
-                       return (error);
+                       return error;
                }
-               error = nfs_open_file_set_busy(nofp, vfs_context_thread(ctx));
-               if (error)
-                       nofp = NULL;
-               if (!error) {
-                       if (nmp->nm_vers < NFS_VER4) {
-                               /* NFS v2/v3 opens are always allowed - so just add it. */
-                               nfs_open_file_add_open(nofp, NFS_OPEN_SHARE_ACCESS_READ, NFS_OPEN_SHARE_DENY_NONE, 0);
-                       } else {
-                               error = nfs4_open(np, nofp, NFS_OPEN_SHARE_ACCESS_READ, NFS_OPEN_SHARE_DENY_NONE, ctx);
-                       }
+               if (nmp->nm_vers < NFS_VER4) {
+                       /* NFS v2/v3 opens are always allowed - so just add it. */
+                       nfs_open_file_add_open(nofp, NFS_OPEN_SHARE_ACCESS_READ, NFS_OPEN_SHARE_DENY_NONE, 0);
+               }
+#if CONFIG_NFS4
+               else {
+                       error = nfs4_open(np, nofp, NFS_OPEN_SHARE_ACCESS_READ, NFS_OPEN_SHARE_DENY_NONE, ctx);
                }
-               if (!error)
+#endif
+               if (!error) {
                        nofp->nof_flags |= NFS_OPEN_FILE_NEEDCLOSE;
-               if (nofp)
-                       nfs_open_file_clear_busy(nofp);
-               if (nfs_mount_state_in_use_end(nmp, error)) {
-                       nofp = NULL;
-                       goto restart;
                }
        }
+       if (nofp) {
+               nfs_open_file_clear_busy(nofp);
+       }
+       if (nfs_mount_state_in_use_end(nmp, error)) {
+               nofp = NULL;
+               goto restart;
+       }
        nfs_open_owner_rele(noop);
-       if (error)
-               return (error);
-       return (nfs_bioread(VTONFS(ap->a_vp), ap->a_uio, ap->a_ioflag, ap->a_context));
+       if (error) {
+               return error;
+       }
+do_read:
+       return nfs_bioread(VTONFS(ap->a_vp), ap->a_uio, ap->a_ioflag, ap->a_context);
 }
 
+#if CONFIG_NFS4
 /*
  * Note: the NFSv4 CREATE RPC is for everything EXCEPT regular files.
  * Files are created using the NFSv4 OPEN RPC.  So we must open the
@@ -6106,13 +6817,13 @@ restart:
 int
 nfs4_vnop_create(
        struct vnop_create_args /* {
-               struct vnodeop_desc *a_desc;
-               vnode_t a_dvp;
-               vnode_t *a_vpp;
-               struct componentname *a_cnp;
-               struct vnode_attr *a_vap;
-               vfs_context_t a_context;
-       } */ *ap)
+                                 *  struct vnodeop_desc *a_desc;
+                                 *  vnode_t a_dvp;
+                                 *  vnode_t *a_vpp;
+                                 *  struct componentname *a_cnp;
+                                 *  struct vnode_attr *a_vap;
+                                 *  vfs_context_t a_context;
+                                 *  } */*ap)
 {
        vfs_context_t ctx = ap->a_context;
        struct componentname *cnp = ap->a_cnp;
@@ -6126,21 +6837,24 @@ nfs4_vnop_create(
        struct nfs_open_file *newnofp = NULL, *nofp = NULL;
 
        nmp = VTONMP(dvp);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
 
-       if (vap)
+       if (vap) {
                nfs_avoid_needless_id_setting_on_create(VTONFS(dvp), vap, ctx);
+       }
 
        noop = nfs_open_owner_find(nmp, vfs_context_ucred(ctx), 1);
-       if (!noop)
-               return (ENOMEM);
+       if (!noop) {
+               return ENOMEM;
+       }
 
 restart:
        error = nfs_mount_state_in_use_start(nmp, vfs_context_thread(ctx));
        if (error) {
                nfs_open_owner_rele(noop);
-               return (error);
+               return error;
        }
 
        /* grab a provisional, nodeless open file */
@@ -6151,18 +6865,21 @@ restart:
        }
        if (!error && (newnofp->nof_flags & NFS_OPEN_FILE_REOPEN)) {
                /* This shouldn't happen given that this is a new, nodeless nofp */
-               nfs_mount_state_in_use_end(nmp, 0);
                error = nfs4_reopen(newnofp, vfs_context_thread(ctx));
                nfs_open_file_destroy(newnofp);
                newnofp = NULL;
-               if (!error)
+               if (!error) {
+                       nfs_mount_state_in_use_end(nmp, 0);
                        goto restart;
+               }
        }
-       if (!error)
+       if (!error) {
                error = nfs_open_file_set_busy(newnofp, vfs_context_thread(ctx));
+       }
        if (error) {
-               if (newnofp)
+               if (newnofp) {
                        nfs_open_file_destroy(newnofp);
+               }
                newnofp = NULL;
                goto out;
        }
@@ -6202,8 +6919,9 @@ restart:
                                        VATTR_INIT(&vattr);
                                        VATTR_SET(&vattr, va_mode, vap->va_mode);
                                        nfs4_setattr_rpc(np, &vattr, ctx);
-                                       if (!error2)
+                                       if (!error2) {
                                                error = 0;
+                                       }
                                }
                        }
                        if (error) {
@@ -6244,8 +6962,9 @@ restart:
                busyerror = nfs_open_file_set_busy(nofp, NULL);
                nfs_open_file_add_open(nofp, accessMode, denyMode, 0);
                nofp->nof_stateid = newnofp->nof_stateid;
-               if (newnofp->nof_flags & NFS_OPEN_FILE_POSIXLOCK)
+               if (newnofp->nof_flags & NFS_OPEN_FILE_POSIXLOCK) {
                        nofp->nof_flags |= NFS_OPEN_FILE_POSIXLOCK;
+               }
                nfs_open_file_clear_busy(newnofp);
                nfs_open_file_destroy(newnofp);
        }
@@ -6254,16 +6973,18 @@ restart:
        nofp->nof_flags |= NFS_OPEN_FILE_CREATE;
        nofp->nof_creator = current_thread();
 out:
-       if (nofp && !busyerror)
+       if (nofp && !busyerror) {
                nfs_open_file_clear_busy(nofp);
+       }
        if (nfs_mount_state_in_use_end(nmp, error)) {
                nofp = newnofp = NULL;
                busyerror = 0;
                goto restart;
        }
-       if (noop)
+       if (noop) {
                nfs_open_owner_rele(noop);
-       return (error);
+       }
+       return error;
 }
 
 /*
@@ -6280,28 +7001,30 @@ nfs4_create_rpc(
        nfsnode_t *npp)
 {
        struct nfsmount *nmp;
-       struct nfs_vattr nvattr;
+       struct nfs_vattr *nvattr;
        int error = 0, create_error = EIO, lockerror = ENOENT, busyerror = ENOENT, status;
        int nfsvers, namedattrs, numops;
-       u_int64_t xid, savedxid = 0;
+       u_int64_t xid = 0, savedxid = 0;
        nfsnode_t np = NULL;
        vnode_t newvp = NULL;
        struct nfsm_chain nmreq, nmrep;
        uint32_t bitmap[NFS_ATTR_BITMAP_LEN], bmlen;
        const char *tag;
        nfs_specdata sd;
-       fhandle_t fh;
-       struct nfsreq rq, *req = &rq;
-       struct nfs_dulookup dul;
+       fhandle_t *fh;
+       struct nfsreq *req;
+       struct nfs_dulookup *dul;
        struct nfsreq_secinfo_args si;
 
        nmp = NFSTONMP(dnp);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        nfsvers = nmp->nm_vers;
        namedattrs = (nmp->nm_fsattr.nfsa_flags & NFS_FSFLAG_NAMED_ATTR);
-       if (dnp->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL)
-               return (EINVAL);
+       if (dnp->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL) {
+               return EINVAL;
+       }
 
        sd.specdata1 = sd.specdata2 = 0;
 
@@ -6312,8 +7035,9 @@ nfs4_create_rpc(
        case NFBLK:
        case NFCHR:
                tag = "mknod";
-               if (!VATTR_IS_ACTIVE(vap, va_rdev))
-                       return (EINVAL);
+               if (!VATTR_IS_ACTIVE(vap, va_rdev)) {
+                       return EINVAL;
+               }
                sd.specdata1 = major(vap->va_rdev);
                sd.specdata2 = minor(vap->va_rdev);
                break;
@@ -6325,24 +7049,29 @@ nfs4_create_rpc(
                tag = "mkdir";
                break;
        default:
-               return (EINVAL);
+               return EINVAL;
        }
 
+       fh = zalloc(nfs_fhandle_zone);
+       req = zalloc(nfs_req_zone);
+       MALLOC(dul, struct nfs_dulookup *, sizeof(*dul), M_TEMP, M_WAITOK);
+       MALLOC(nvattr, struct nfs_vattr *, sizeof(*nvattr), M_TEMP, M_WAITOK);
        nfs_avoid_needless_id_setting_on_create(dnp, vap, ctx);
 
        error = busyerror = nfs_node_set_busy(dnp, vfs_context_thread(ctx));
-       if (!namedattrs)
-               nfs_dulookup_init(&dul, dnp, cnp->cn_nameptr, cnp->cn_namelen, ctx);
+       if (!namedattrs) {
+               nfs_dulookup_init(dul, dnp, cnp->cn_nameptr, cnp->cn_namelen, ctx);
+       }
 
        NFSREQ_SECINFO_SET(&si, dnp, NULL, 0, NULL, 0);
-       NVATTR_INIT(&nvattr);
+       NVATTR_INIT(nvattr);
        nfsm_chain_null(&nmreq);
        nfsm_chain_null(&nmrep);
 
        // PUTFH, SAVEFH, CREATE, GETATTR(FH), RESTOREFH, GETATTR
        numops = 6;
        nfsm_chain_build_alloc_init(error, &nmreq, 66 * NFSX_UNSIGNED);
-       nfsm_chain_add_compound_header(error, &nmreq, tag, numops);
+       nfsm_chain_add_compound_header(error, &nmreq, tag, nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, nfsvers, dnp->n_fhp, dnp->n_fhsize);
@@ -6374,15 +7103,17 @@ nfs4_create_rpc(
        nfsmout_if(error);
 
        error = nfs_request_async(dnp, NULL, &nmreq, NFSPROC4_COMPOUND,
-                       vfs_context_thread(ctx), vfs_context_ucred(ctx), &si, 0, NULL, &req);
+           vfs_context_thread(ctx), vfs_context_ucred(ctx), &si, 0, NULL, &req);
        if (!error) {
-               if (!namedattrs)
-                       nfs_dulookup_start(&dul, dnp, ctx);
+               if (!namedattrs) {
+                       nfs_dulookup_start(dul, dnp, ctx);
+               }
                error = nfs_request_async_finish(req, &nmrep, &xid, &status);
        }
 
-       if ((lockerror = nfs_node_lock(dnp)))
+       if ((lockerror = nfs_node_lock(dnp))) {
                error = lockerror;
+       }
        nfsm_chain_skip_tag(error, &nmrep);
        nfsm_chain_get_32(error, &nmrep, numops);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_PUTFH);
@@ -6399,9 +7130,9 @@ nfs4_create_rpc(
        nfs_vattr_set_supported(bitmap, vap);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
        nfsmout_if(error);
-       error = nfs4_parsefattr(&nmrep, NULL, &nvattr, &fh, NULL, NULL);
+       error = nfs4_parsefattr(&nmrep, NULL, nvattr, fh, NULL, NULL);
        nfsmout_if(error);
-       if (!NFS_BITMAP_ISSET(nvattr.nva_bitmap, NFS_FATTR_FILEHANDLE)) {
+       if (!NFS_BITMAP_ISSET(nvattr->nva_bitmap, NFS_FATTR_FILEHANDLE)) {
                printf("nfs: create/%s didn't return filehandle? %s\n", tag, cnp->cn_nameptr);
                error = EBADRPC;
                goto nfsmout;
@@ -6411,8 +7142,9 @@ nfs4_create_rpc(
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
        savedxid = xid;
        nfsm_chain_loadattr(error, &nmrep, dnp, nfsvers, &xid);
-       if (error)
+       if (error) {
                NATTRINVALIDATE(dnp);
+       }
 
 nfsmout:
        nfsm_chain_cleanup(&nmreq);
@@ -6429,17 +7161,24 @@ nfsmout:
                nfs_getattr(dnp, NULL, ctx, NGA_CACHED);
        }
 
-       if (!error && fh.fh_len) {
+       if (!error && fh->fh_len) {
                /* create the vnode with the filehandle and attributes */
                xid = savedxid;
-               error = nfs_nget(NFSTOMP(dnp), dnp, cnp, fh.fh_data, fh.fh_len, &nvattr, &xid, rq.r_auth, NG_MAKEENTRY, &np);
-               if (!error)
+               error = nfs_nget(NFSTOMP(dnp), dnp, cnp, fh->fh_data, fh->fh_len, nvattr, &xid, req->r_auth, NG_MAKEENTRY, &np);
+               if (!error) {
                        newvp = NFSTOV(np);
+               }
        }
-       NVATTR_CLEANUP(&nvattr);
 
-       if (!namedattrs)
-               nfs_dulookup_finish(&dul, dnp, ctx);
+       if (!namedattrs) {
+               nfs_dulookup_finish(dul, dnp, ctx);
+       }
+
+       NVATTR_CLEANUP(nvattr);
+       NFS_ZFREE(nfs_fhandle_zone, fh);
+       NFS_ZFREE(nfs_req_zone, req);
+       FREE(dul, M_TEMP);
+       FREE(nvattr, M_TEMP);
 
        /*
         * Kludge: Map EEXIST => 0 assuming that you have a reply to a retry
@@ -6449,12 +7188,14 @@ nfsmout:
                error = nfs_lookitup(dnp, cnp->cn_nameptr, cnp->cn_namelen, ctx, &np);
                if (!error) {
                        newvp = NFSTOV(np);
-                       if (vnode_vtype(newvp) != nfstov_type(type, nfsvers))
+                       if (vnode_vtype(newvp) != nfstov_type(type, nfsvers)) {
                                error = EEXIST;
+                       }
                }
        }
-       if (!busyerror)
+       if (!busyerror) {
                nfs_node_clear_busy(dnp);
+       }
        if (error) {
                if (newvp) {
                        nfs_node_unlock(np);
@@ -6464,30 +7205,32 @@ nfsmout:
                nfs_node_unlock(np);
                *npp = np;
        }
-       return (error);
+       return error;
 }
 
 int
 nfs4_vnop_mknod(
        struct vnop_mknod_args /* {
-               struct vnodeop_desc *a_desc;
-               vnode_t a_dvp;
-               vnode_t *a_vpp;
-               struct componentname *a_cnp;
-               struct vnode_attr *a_vap;
-               vfs_context_t a_context;
-       } */ *ap)
+                                *  struct vnodeop_desc *a_desc;
+                                *  vnode_t a_dvp;
+                                *  vnode_t *a_vpp;
+                                *  struct componentname *a_cnp;
+                                *  struct vnode_attr *a_vap;
+                                *  vfs_context_t a_context;
+                                *  } */*ap)
 {
        nfsnode_t np = NULL;
        struct nfsmount *nmp;
        int error;
 
        nmp = VTONMP(ap->a_dvp);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
 
-       if (!VATTR_IS_ACTIVE(ap->a_vap, va_type))
-               return (EINVAL);
+       if (!VATTR_IS_ACTIVE(ap->a_vap, va_type)) {
+               return EINVAL;
+       }
        switch (ap->a_vap->va_type) {
        case VBLK:
        case VCHR:
@@ -6495,68 +7238,71 @@ nfs4_vnop_mknod(
        case VSOCK:
                break;
        default:
-               return (ENOTSUP);
+               return ENOTSUP;
        }
 
        error = nfs4_create_rpc(ap->a_context, VTONFS(ap->a_dvp), ap->a_cnp, ap->a_vap,
-                       vtonfs_type(ap->a_vap->va_type, nmp->nm_vers), NULL, &np);
-       if (!error)
+           vtonfs_type(ap->a_vap->va_type, nmp->nm_vers), NULL, &np);
+       if (!error) {
                *ap->a_vpp = NFSTOV(np);
-       return (error);
+       }
+       return error;
 }
 
 int
 nfs4_vnop_mkdir(
        struct vnop_mkdir_args /* {
-               struct vnodeop_desc *a_desc;
-               vnode_t a_dvp;
-               vnode_t *a_vpp;
-               struct componentname *a_cnp;
-               struct vnode_attr *a_vap;
-               vfs_context_t a_context;
-       } */ *ap)
+                                *  struct vnodeop_desc *a_desc;
+                                *  vnode_t a_dvp;
+                                *  vnode_t *a_vpp;
+                                *  struct componentname *a_cnp;
+                                *  struct vnode_attr *a_vap;
+                                *  vfs_context_t a_context;
+                                *  } */*ap)
 {
        nfsnode_t np = NULL;
        int error;
 
        error = nfs4_create_rpc(ap->a_context, VTONFS(ap->a_dvp), ap->a_cnp, ap->a_vap,
-                       NFDIR, NULL, &np);
-       if (!error)
+           NFDIR, NULL, &np);
+       if (!error) {
                *ap->a_vpp = NFSTOV(np);
-       return (error);
+       }
+       return error;
 }
 
 int
 nfs4_vnop_symlink(
        struct vnop_symlink_args /* {
-               struct vnodeop_desc *a_desc;
-               vnode_t a_dvp;
-               vnode_t *a_vpp;
-               struct componentname *a_cnp;
-               struct vnode_attr *a_vap;
-               char *a_target;
-               vfs_context_t a_context;
-       } */ *ap)
+                                  *  struct vnodeop_desc *a_desc;
+                                  *  vnode_t a_dvp;
+                                  *  vnode_t *a_vpp;
+                                  *  struct componentname *a_cnp;
+                                  *  struct vnode_attr *a_vap;
+                                  *  char *a_target;
+                                  *  vfs_context_t a_context;
+                                  *  } */*ap)
 {
        nfsnode_t np = NULL;
        int error;
 
        error = nfs4_create_rpc(ap->a_context, VTONFS(ap->a_dvp), ap->a_cnp, ap->a_vap,
-                       NFLNK, ap->a_target, &np);
-       if (!error)
+           NFLNK, ap->a_target, &np);
+       if (!error) {
                *ap->a_vpp = NFSTOV(np);
-       return (error);
+       }
+       return error;
 }
 
 int
 nfs4_vnop_link(
        struct vnop_link_args /* {
-               struct vnodeop_desc *a_desc;
-               vnode_t a_vp;
-               vnode_t a_tdvp;
-               struct componentname *a_cnp;
-               vfs_context_t a_context;
-       } */ *ap)
+                               *  struct vnodeop_desc *a_desc;
+                               *  vnode_t a_vp;
+                               *  vnode_t a_tdvp;
+                               *  struct componentname *a_cnp;
+                               *  vfs_context_t a_context;
+                               *  } */*ap)
 {
        vfs_context_t ctx = ap->a_context;
        vnode_t vp = ap->a_vp;
@@ -6571,17 +7317,21 @@ nfs4_vnop_link(
        struct nfsm_chain nmreq, nmrep;
        struct nfsreq_secinfo_args si;
 
-       if (vnode_mount(vp) != vnode_mount(tdvp))
-               return (EXDEV);
+       if (vnode_mount(vp) != vnode_mount(tdvp)) {
+               return EXDEV;
+       }
 
        nmp = VTONMP(vp);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        nfsvers = nmp->nm_vers;
-       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL)
-               return (EINVAL);
-       if (tdnp->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL)
-               return (EINVAL);
+       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL) {
+               return EINVAL;
+       }
+       if (tdnp->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL) {
+               return EINVAL;
+       }
 
        /*
         * Push all writes to the server, so that the attribute cache
@@ -6590,8 +7340,9 @@ nfs4_vnop_link(
         */
        nfs_flush(np, MNT_WAIT, vfs_context_thread(ctx), V_IGNORE_WRITEERR);
 
-       if ((error = nfs_node_set_busy2(tdnp, np, vfs_context_thread(ctx))))
-               return (error);
+       if ((error = nfs_node_set_busy2(tdnp, np, vfs_context_thread(ctx)))) {
+               return error;
+       }
 
        NFSREQ_SECINFO_SET(&si, np, NULL, 0, NULL, 0);
        nfsm_chain_null(&nmreq);
@@ -6600,7 +7351,7 @@ nfs4_vnop_link(
        // PUTFH(SOURCE), SAVEFH, PUTFH(DIR), LINK, GETATTR(DIR), RESTOREFH, GETATTR
        numops = 7;
        nfsm_chain_build_alloc_init(error, &nmreq, 29 * NFSX_UNSIGNED + cnp->cn_namelen);
-       nfsm_chain_add_compound_header(error, &nmreq, "link", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "link", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, nfsvers, np->n_fhp, np->n_fhsize);
@@ -6640,42 +7391,47 @@ nfs4_vnop_link(
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
        savedxid = xid;
        nfsm_chain_loadattr(error, &nmrep, tdnp, nfsvers, &xid);
-       if (error)
+       if (error) {
                NATTRINVALIDATE(tdnp);
+       }
        /* link attributes: if we don't get them, make sure to invalidate */
        nfsm_chain_op_check(error, &nmrep, NFS_OP_RESTOREFH);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
        xid = savedxid;
        nfsm_chain_loadattr(error, &nmrep, np, nfsvers, &xid);
-       if (error)
+       if (error) {
                NATTRINVALIDATE(np);
+       }
 nfsmout:
        nfsm_chain_cleanup(&nmreq);
        nfsm_chain_cleanup(&nmrep);
-       if (!lockerror)
+       if (!lockerror) {
                tdnp->n_flag |= NMODIFIED;
+       }
        /* Kludge: Map EEXIST => 0 assuming that it is a reply to a retry. */
-       if (error == EEXIST)
+       if (error == EEXIST) {
                error = 0;
+       }
        if (!error && (tdnp->n_flag & NNEGNCENTRIES)) {
                tdnp->n_flag &= ~NNEGNCENTRIES;
                cache_purge_negatives(tdvp);
        }
-       if (!lockerror)
+       if (!lockerror) {
                nfs_node_unlock2(tdnp, np);
+       }
        nfs_node_clear_busy2(tdnp, np);
-       return (error);
+       return error;
 }
 
 int
 nfs4_vnop_rmdir(
        struct vnop_rmdir_args /* {
-               struct vnodeop_desc *a_desc;
-               vnode_t a_dvp;
-               vnode_t a_vp;
-               struct componentname *a_cnp;
-               vfs_context_t a_context;
-       } */ *ap)
+                                *  struct vnodeop_desc *a_desc;
+                                *  vnode_t a_dvp;
+                                *  vnode_t a_vp;
+                                *  struct componentname *a_cnp;
+                                *  vfs_context_t a_context;
+                                *  } */*ap)
 {
        vfs_context_t ctx = ap->a_context;
        vnode_t vp = ap->a_vp;
@@ -6685,54 +7441,61 @@ nfs4_vnop_rmdir(
        int error = 0, namedattrs;
        nfsnode_t np = VTONFS(vp);
        nfsnode_t dnp = VTONFS(dvp);
-       struct nfs_dulookup dul;
+       struct nfs_dulookup *dul;
 
-       if (vnode_vtype(vp) != VDIR)
-               return (EINVAL);
+       if (vnode_vtype(vp) != VDIR) {
+               return EINVAL;
+       }
 
        nmp = NFSTONMP(dnp);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
        namedattrs = (nmp->nm_fsattr.nfsa_flags & NFS_FSFLAG_NAMED_ATTR);
 
-       if ((error = nfs_node_set_busy2(dnp, np, vfs_context_thread(ctx))))
-               return (error);
+       if ((error = nfs_node_set_busy2(dnp, np, vfs_context_thread(ctx)))) {
+               return error;
+       }
 
+       MALLOC(dul, struct nfs_dulookup *, sizeof(*dul), M_TEMP, M_WAITOK);
        if (!namedattrs) {
-               nfs_dulookup_init(&dul, dnp, cnp->cn_nameptr, cnp->cn_namelen, ctx);
-               nfs_dulookup_start(&dul, dnp, ctx);
+               nfs_dulookup_init(dul, dnp, cnp->cn_nameptr, cnp->cn_namelen, ctx);
+               nfs_dulookup_start(dul, dnp, ctx);
        }
 
        error = nfs4_remove_rpc(dnp, cnp->cn_nameptr, cnp->cn_namelen,
-                       vfs_context_thread(ctx), vfs_context_ucred(ctx));
+           vfs_context_thread(ctx), vfs_context_ucred(ctx));
 
        nfs_name_cache_purge(dnp, np, cnp, ctx);
        /* nfs_getattr() will check changed and purge caches */
        nfs_getattr(dnp, NULL, ctx, NGA_CACHED);
-       if (!namedattrs)
-               nfs_dulookup_finish(&dul, dnp, ctx);
+       if (!namedattrs) {
+               nfs_dulookup_finish(dul, dnp, ctx);
+       }
        nfs_node_clear_busy2(dnp, np);
 
        /*
         * Kludge: Map ENOENT => 0 assuming that you have a reply to a retry.
         */
-       if (error == ENOENT)
+       if (error == ENOENT) {
                error = 0;
+       }
        if (!error) {
                /*
                 * remove nfsnode from hash now so we can't accidentally find it
                 * again if another object gets created with the same filehandle
                 * before this vnode gets reclaimed
                 */
-               lck_mtx_lock(nfs_node_hash_mutex);
+               lck_mtx_lock(&nfs_node_hash_mutex);
                if (np->n_hflag & NHHASHED) {
                        LIST_REMOVE(np, n_hash);
                        np->n_hflag &= ~NHHASHED;
                        FSDBG(266, 0, np, np->n_flag, 0xb1eb1e);
                }
-               lck_mtx_unlock(nfs_node_hash_mutex);
+               lck_mtx_unlock(&nfs_node_hash_mutex);
        }
-       return (error);
+       FREE(dul, M_TEMP);
+       return error;
 }
 
 /*
@@ -6768,34 +7531,40 @@ nfs4_named_attr_dir_get(nfsnode_t np, int fetch, vfs_context_t ctx)
        struct nfsm_chain nmreq, nmrep;
        u_int64_t xid;
        uint32_t bitmap[NFS_ATTR_BITMAP_LEN];
-       fhandle_t fh;
-       struct nfs_vattr nvattr;
+       fhandle_t *fh;
+       struct nfs_vattr *nvattr;
        struct componentname cn;
-       struct nfsreq rq, *req = &rq;
+       struct nfsreq *req;
        struct nfsreq_secinfo_args si;
 
        nmp = NFSTONMP(np);
-       if (!nmp)
-               return (NULL);
-       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL)
-               return (NULL);
+       if (nfs_mount_gone(nmp)) {
+               return NULL;
+       }
+       if (np->n_vattr.nva_flags & NFS_FFLAG_TRIGGER_REFERRAL) {
+               return NULL;
+       }
 
        NFSREQ_SECINFO_SET(&si, np, NULL, 0, NULL, 0);
-       NVATTR_INIT(&nvattr);
+       fh = zalloc(nfs_fhandle_zone);
+       req = zalloc(nfs_req_zone);
+       MALLOC(nvattr, struct nfs_vattr *, sizeof(*nvattr), M_TEMP, M_WAITOK);
+       NVATTR_INIT(nvattr);
        nfsm_chain_null(&nmreq);
        nfsm_chain_null(&nmrep);
 
        bzero(&cn, sizeof(cn));
        cn.cn_nameptr = __CAST_AWAY_QUALIFIER(_PATH_FORKSPECIFIER, const, char *); /* "/..namedfork/" */
-       cn.cn_namelen = strlen(_PATH_FORKSPECIFIER);
+       cn.cn_namelen = NFS_STRLEN_INT(_PATH_FORKSPECIFIER);
        cn.cn_nameiop = LOOKUP;
 
        if (np->n_attrdirfh) {
                // XXX can't set parent correctly (to np) yet
-               error = nfs_nget(nmp->nm_mountp, NULL, &cn, np->n_attrdirfh+1, *np->n_attrdirfh,
-                               NULL, NULL, RPCAUTH_UNKNOWN, NG_NOCREATE, &adnp);
-               if (adnp)
+               error = nfs_nget(nmp->nm_mountp, NULL, &cn, np->n_attrdirfh + 1, *np->n_attrdirfh,
+                   NULL, NULL, RPCAUTH_UNKNOWN, NG_NOCREATE, &adnp);
+               if (adnp) {
                        goto nfsmout;
+               }
        }
        if (!fetch) {
                error = ENOENT;
@@ -6805,7 +7574,7 @@ nfs4_named_attr_dir_get(nfsnode_t np, int fetch, vfs_context_t ctx)
        // PUTFH, OPENATTR, GETATTR
        numops = 3;
        nfsm_chain_build_alloc_init(error, &nmreq, 22 * NFSX_UNSIGNED);
-       nfsm_chain_add_compound_header(error, &nmreq, "openattr", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "openattr", nmp->nm_minor_vers, numops);
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
        nfsm_chain_add_fh(error, &nmreq, nmp->nm_vers, np->n_fhp, np->n_fhsize);
@@ -6817,14 +7586,15 @@ nfs4_named_attr_dir_get(nfsnode_t np, int fetch, vfs_context_t ctx)
        NFS_COPY_ATTRIBUTES(nfs_getattr_bitmap, bitmap);
        NFS_BITMAP_SET(bitmap, NFS_FATTR_FILEHANDLE);
        nfsm_chain_add_bitmap_masked(error, &nmreq, bitmap,
-               NFS_ATTR_BITMAP_LEN, nmp->nm_fsattr.nfsa_supp_attr);
+           NFS_ATTR_BITMAP_LEN, nmp->nm_fsattr.nfsa_supp_attr);
        nfsm_chain_build_done(error, &nmreq);
        nfsm_assert(error, (numops == 0), EPROTO);
        nfsmout_if(error);
        error = nfs_request_async(np, NULL, &nmreq, NFSPROC4_COMPOUND,
-                       vfs_context_thread(ctx), vfs_context_ucred(ctx), &si, 0, NULL, &req);
-       if (!error)
+           vfs_context_thread(ctx), vfs_context_ucred(ctx), &si, 0, NULL, &req);
+       if (!error) {
                error = nfs_request_async_finish(req, &nmrep, &xid, &status);
+       }
 
        nfsm_chain_skip_tag(error, &nmrep);
        nfsm_chain_get_32(error, &nmrep, numops);
@@ -6832,44 +7602,51 @@ nfs4_named_attr_dir_get(nfsnode_t np, int fetch, vfs_context_t ctx)
        nfsm_chain_op_check(error, &nmrep, NFS_OP_OPENATTR);
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
        nfsmout_if(error);
-       error = nfs4_parsefattr(&nmrep, NULL, &nvattr, &fh, NULL, NULL);
+       error = nfs4_parsefattr(&nmrep, NULL, nvattr, fh, NULL, NULL);
        nfsmout_if(error);
-       if (!NFS_BITMAP_ISSET(nvattr.nva_bitmap, NFS_FATTR_FILEHANDLE) || !fh.fh_len) {
+       if (!NFS_BITMAP_ISSET(nvattr->nva_bitmap, NFS_FATTR_FILEHANDLE) || !fh->fh_len) {
                error = ENOENT;
                goto nfsmout;
        }
-       if (!np->n_attrdirfh || (*np->n_attrdirfh != fh.fh_len)) {
+       if (!np->n_attrdirfh || (*np->n_attrdirfh != fh->fh_len)) {
                /* (re)allocate attrdir fh buffer */
-               if (np->n_attrdirfh)
+               if (np->n_attrdirfh) {
                        FREE(np->n_attrdirfh, M_TEMP);
-               MALLOC(np->n_attrdirfh, u_char*, fh.fh_len+1, M_TEMP, M_WAITOK);
+               }
+               MALLOC(np->n_attrdirfh, u_char*, fh->fh_len + 1, M_TEMP, M_WAITOK);
        }
        if (!np->n_attrdirfh) {
                error = ENOMEM;
                goto nfsmout;
        }
        /* cache the attrdir fh in the node */
-       *np->n_attrdirfh = fh.fh_len;
-       bcopy(fh.fh_data, np->n_attrdirfh+1, fh.fh_len);
+       *np->n_attrdirfh = (unsigned char)fh->fh_len; /* No truncation because fh_len's value is checked during nfs4_parsefattr() */
+       bcopy(fh->fh_data, np->n_attrdirfh + 1, fh->fh_len);
        /* create node for attrdir */
        // XXX can't set parent correctly (to np) yet
-       error = nfs_nget(NFSTOMP(np), NULL, &cn, fh.fh_data, fh.fh_len, &nvattr, &xid, rq.r_auth, 0, &adnp);
+       error = nfs_nget(NFSTOMP(np), NULL, &cn, fh->fh_data, fh->fh_len, nvattr, &xid, req->r_auth, 0, &adnp);
 nfsmout:
-       NVATTR_CLEANUP(&nvattr);
+       NVATTR_CLEANUP(nvattr);
+       NFS_ZFREE(nfs_fhandle_zone, fh);
+       NFS_ZFREE(nfs_req_zone, req);
+       FREE(nvattr, M_TEMP);
        nfsm_chain_cleanup(&nmreq);
        nfsm_chain_cleanup(&nmrep);
 
        if (adnp) {
                /* sanity check that this node is an attribute directory */
-               if (adnp->n_vattr.nva_type != VDIR)
+               if (adnp->n_vattr.nva_type != VDIR) {
                        error = EINVAL;
-               if (!(adnp->n_vattr.nva_flags & NFS_FFLAG_IS_ATTR))
+               }
+               if (!(adnp->n_vattr.nva_flags & NFS_FFLAG_IS_ATTR)) {
                        error = EINVAL;
+               }
                nfs_node_unlock(adnp);
-               if (error)
+               if (error) {
                        vnode_put(NFSTOV(adnp));
+               }
        }
-       return (error ? NULL : adnp);
+       return error ? NULL : adnp;
 }
 
 /*
@@ -6893,10 +7670,10 @@ nfsmout:
  * the lookup/open, we lock both the node and the attribute directory node.
  */
 
-#define NFS_GET_NAMED_ATTR_CREATE              0x1
-#define NFS_GET_NAMED_ATTR_CREATE_GUARDED      0x2
-#define NFS_GET_NAMED_ATTR_TRUNCATE            0x4
-#define NFS_GET_NAMED_ATTR_PREFETCH            0x8
+#define NFS_GET_NAMED_ATTR_CREATE               0x1
+#define NFS_GET_NAMED_ATTR_CREATE_GUARDED       0x2
+#define NFS_GET_NAMED_ATTR_TRUNCATE             0x4
+#define NFS_GET_NAMED_ATTR_PREFETCH             0x8
 
 int
 nfs4_named_attr_get(
@@ -6913,16 +7690,16 @@ nfs4_named_attr_get(
        int inuse = 0, adlockerror = ENOENT, busyerror = ENOENT, adbusyerror = ENOENT, nofpbusyerror = ENOENT;
        int create, guarded, prefetch, truncate, noopbusy = 0;
        int open, status, numops, hadattrdir, negnamecache;
-       struct nfs_vattr nvattr;
+       struct nfs_vattr *nvattr;
        struct vnode_attr vattr;
        nfsnode_t adnp = NULL, anp = NULL;
        vnode_t avp = NULL;
-       u_int64_t xid, savedxid = 0;
+       u_int64_t xid = 0, savedxid = 0;
        struct nfsm_chain nmreq, nmrep;
        uint32_t bitmap[NFS_ATTR_BITMAP_LEN], bmlen;
-       uint32_t denyMode, rflags, delegation, recall, eof, rlen, retlen;
+       uint32_t denyMode = 0, rflags, delegation, recall, eof, rlen, retlen;
        nfs_stateid stateid, dstateid;
-       fhandle_t fh;
+       fhandle_t *fh;
        struct nfs_open_owner *noop = NULL;
        struct nfs_open_file *newnofp = NULL, *nofp = NULL;
        struct vnop_access_args naa;
@@ -6932,20 +7709,25 @@ nfs4_named_attr_get(
        char sbuf[64], *s;
        uint32_t ace_type, ace_flags, ace_mask, len, slen;
        struct kauth_ace ace;
-       struct nfsreq rq, *req = &rq;
+       struct nfsreq *req;
        struct nfsreq_secinfo_args si;
 
        *anpp = NULL;
-       fh.fh_len = 0;
        rflags = delegation = recall = eof = rlen = retlen = 0;
        ace.ace_flags = 0;
        s = sbuf;
        slen = sizeof(sbuf);
 
        nmp = NFSTONMP(np);
-       if (!nmp)
-               return (ENXIO);
-       NVATTR_INIT(&nvattr);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
+       fh = zalloc(nfs_fhandle_zone);
+       req = zalloc(nfs_req_zone);
+       MALLOC(nvattr, struct nfs_vattr *, sizeof(*nvattr), M_TEMP, M_WAITOK);
+       NVATTR_INIT(nvattr);
+       fh->fh_len = 0;
+       bzero(&dstateid, sizeof(dstateid));
        negnamecache = !NMFLAG(nmp, NONEGNAMECACHE);
        thd = vfs_context_thread(ctx);
        cred = vfs_context_ucred(ctx);
@@ -6955,12 +7737,15 @@ nfs4_named_attr_get(
        prefetch = (flags & NFS_GET_NAMED_ATTR_PREFETCH);
 
        if (!create) {
-               error = nfs_getattr(np, &nvattr, ctx, NGA_CACHED);
-               if (error)
-                       return (error);
-               if (NFS_BITMAP_ISSET(nvattr.nva_bitmap, NFS_FATTR_NAMED_ATTR) &&
-                   !(nvattr.nva_flags & NFS_FFLAG_HAS_NAMED_ATTRS))
-                       return (ENOATTR);
+               error = nfs_getattr(np, nvattr, ctx, NGA_CACHED);
+               if (error) {
+                       goto out_free;
+               }
+               if (NFS_BITMAP_ISSET(nvattr->nva_bitmap, NFS_FATTR_NAMED_ATTR) &&
+                   !(nvattr->nva_flags & NFS_FFLAG_HAS_NAMED_ATTRS)) {
+                       error = ENOATTR;
+                       goto out_free;
+               }
        } else if (accessMode == NFS_OPEN_SHARE_ACCESS_NONE) {
                /* shouldn't happen... but just be safe */
                printf("nfs4_named_attr_get: create with no access %s\n", cnp->cn_nameptr);
@@ -6974,16 +7759,19 @@ nfs4_named_attr_get(
                 * and set NFS_OPEN_FILE_CREATE.
                 */
                denyMode = NFS_OPEN_SHARE_DENY_NONE;
-               if (prefetch && guarded)
+               if (prefetch && guarded) {
                        prefetch = 0;  /* no sense prefetching data that can't be there */
-
+               }
                noop = nfs_open_owner_find(nmp, vfs_context_ucred(ctx), 1);
-               if (!noop)
-                       return (ENOMEM);
+               if (!noop) {
+                       error = ENOMEM;
+                       goto out_free;
+               }
        }
 
-       if ((error = busyerror = nfs_node_set_busy(np, vfs_context_thread(ctx))))
-               return (error);
+       if ((error = busyerror = nfs_node_set_busy(np, vfs_context_thread(ctx)))) {
+               goto out_free;
+       }
 
        adnp = nfs4_named_attr_dir_get(np, 0, ctx);
        hadattrdir = (adnp != NULL);
@@ -6998,8 +7786,9 @@ nfs4_named_attr_get(
        nfsm_chain_null(&nmrep);
 
        if (hadattrdir) {
-               if ((error = adbusyerror = nfs_node_set_busy(adnp, vfs_context_thread(ctx))))
+               if ((error = adbusyerror = nfs_node_set_busy(adnp, vfs_context_thread(ctx)))) {
                        goto nfsmout;
+               }
                /* nfs_getattr() will check changed and purge caches */
                error = nfs_getattr(adnp, NULL, ctx, NGA_CACHED);
                nfsmout_if(error);
@@ -7011,20 +7800,22 @@ nfs4_named_attr_get(
                case 0:
                        /* cache miss */
                        /* try dir buf cache lookup */
-                       error = nfs_dir_buf_cache_lookup(adnp, &anp, cnp, ctx, 0);
+                       error = nfs_dir_buf_cache_lookup(adnp, &anp, cnp, ctx, 0, NULL);
                        if (!error && anp) {
                                /* dir buf cache hit */
                                *anpp = anp;
                                error = -1;
                        }
-                       if (error != -1) /* cache miss */
+                       if (error != -1) /* cache miss */
                                break;
-                       /* FALLTHROUGH */
+                       }
+                       OS_FALLTHROUGH;
                case -1:
                        /* cache hit, not really an error */
                        OSAddAtomic64(1, &nfsstats.lookupcache_hits);
-                       if (!anp && avp)
+                       if (!anp && avp) {
                                *anpp = anp = VTONFS(avp);
+                       }
 
                        nfs_node_clear_busy(adnp);
                        adbusyerror = ENOENT;
@@ -7037,7 +7828,7 @@ nfs4_named_attr_get(
 
                        /* compute actual success/failure based on accessibility */
                        error = nfs_vnop_access(&naa);
-                       /* FALLTHROUGH */
+                       OS_FALLTHROUGH;
                default:
                        /* we either found it, or hit an error */
                        if (!error && guarded) {
@@ -7047,8 +7838,9 @@ nfs4_named_attr_get(
                                *anpp = anp = NULL;
                        }
                        /* we're done if error or we don't need to open */
-                       if (error || !open)
+                       if (error || !open) {
                                goto nfsmout;
+                       }
                        /* no error and we need to open... */
                }
        }
@@ -7070,18 +7862,22 @@ restart:
                        error = EIO;
                }
                if (!error && (newnofp->nof_flags & NFS_OPEN_FILE_REOPEN)) {
-                       nfs_mount_state_in_use_end(nmp, 0);
                        error = nfs4_reopen(newnofp, vfs_context_thread(ctx));
                        nfs_open_file_destroy(newnofp);
                        newnofp = NULL;
-                       if (!error)
+                       if (!error) {
+                               nfs_mount_state_in_use_end(nmp, 0);
+                               inuse = 0;
                                goto restart;
+                       }
                }
-               if (!error)
+               if (!error) {
                        error = nfs_open_file_set_busy(newnofp, vfs_context_thread(ctx));
+               }
                if (error) {
-                       if (newnofp)
+                       if (newnofp) {
                                nfs_open_file_destroy(newnofp);
+                       }
                        newnofp = NULL;
                        goto nfsmout;
                }
@@ -7096,8 +7892,9 @@ restart:
                                nofp = newnofp;
                                nofpbusyerror = 0;
                                newnofp = NULL;
-                               if (nofpp)
+                               if (nofpp) {
                                        *nofpp = nofp;
+                               }
                        }
                        goto nfsmout;
                }
@@ -7116,8 +7913,9 @@ restart:
 
        if (open) {
                /* need to mark the open owner busy during the RPC */
-               if ((error = nfs_open_owner_set_busy(noop, thd)))
+               if ((error = nfs_open_owner_set_busy(noop, thd))) {
                        goto nfsmout;
+               }
                noopbusy = 1;
        }
 
@@ -7130,12 +7928,14 @@ restart:
         * At a minimum we're sending: PUTFH, LOOKUP/OPEN, GETATTR, PUTFH, GETATTR
         */
        numops = 5;
-       if (!hadattrdir)
-               numops += 3;    // also sending: OPENATTR, GETATTR, OPENATTR
-       if (prefetch)
-               numops += 4;    // also sending: SAVEFH, RESTOREFH, NVERIFY, READ
+       if (!hadattrdir) {
+               numops += 3;    // also sending: OPENATTR, GETATTR, OPENATTR
+       }
+       if (prefetch) {
+               numops += 4;    // also sending: SAVEFH, RESTOREFH, NVERIFY, READ
+       }
        nfsm_chain_build_alloc_init(error, &nmreq, 64 * NFSX_UNSIGNED + cnp->cn_namelen);
-       nfsm_chain_add_compound_header(error, &nmreq, "getnamedattr", numops);
+       nfsm_chain_add_compound_header(error, &nmreq, "getnamedattr", nmp->nm_minor_vers, numops);
        if (hadattrdir) {
                numops--;
                nfsm_chain_add_32(error, &nmreq, NFS_OP_PUTFH);
@@ -7152,7 +7952,7 @@ restart:
                NFS_COPY_ATTRIBUTES(nfs_getattr_bitmap, bitmap);
                NFS_BITMAP_SET(bitmap, NFS_FATTR_FILEHANDLE);
                nfsm_chain_add_bitmap_masked(error, &nmreq, bitmap,
-                       NFS_ATTR_BITMAP_LEN, nmp->nm_fsattr.nfsa_supp_attr);
+                   NFS_ATTR_BITMAP_LEN, nmp->nm_fsattr.nfsa_supp_attr);
        }
        if (open) {
                numops--;
@@ -7167,8 +7967,9 @@ restart:
                if (create) {
                        nfsm_chain_add_32(error, &nmreq, guarded);
                        VATTR_INIT(&vattr);
-                       if (truncate)
+                       if (truncate) {
                                VATTR_SET(&vattr, va_data_size, 0);
+                       }
                        nfsm_chain_add_fattr4(error, &nmreq, &vattr, nmp);
                }
                nfsm_chain_add_32(error, &nmreq, NFS_CLAIM_NULL);
@@ -7183,7 +7984,7 @@ restart:
        NFS_COPY_ATTRIBUTES(nfs_getattr_bitmap, bitmap);
        NFS_BITMAP_SET(bitmap, NFS_FATTR_FILEHANDLE);
        nfsm_chain_add_bitmap_masked(error, &nmreq, bitmap,
-               NFS_ATTR_BITMAP_LEN, nmp->nm_fsattr.nfsa_supp_attr);
+           NFS_ATTR_BITMAP_LEN, nmp->nm_fsattr.nfsa_supp_attr);
        if (prefetch) {
                numops--;
                nfsm_chain_add_32(error, &nmreq, NFS_OP_SAVEFH);
@@ -7203,7 +8004,7 @@ restart:
        numops--;
        nfsm_chain_add_32(error, &nmreq, NFS_OP_GETATTR);
        nfsm_chain_add_bitmap_masked(error, &nmreq, nfs_getattr_bitmap,
-               NFS_ATTR_BITMAP_LEN, nmp->nm_fsattr.nfsa_supp_attr);
+           NFS_ATTR_BITMAP_LEN, nmp->nm_fsattr.nfsa_supp_attr);
        if (prefetch) {
                numops--;
                nfsm_chain_add_32(error, &nmreq, NFS_OP_RESTOREFH);
@@ -7222,12 +8023,14 @@ restart:
        nfsm_assert(error, (numops == 0), EPROTO);
        nfsmout_if(error);
        error = nfs_request_async(hadattrdir ? adnp : np, NULL, &nmreq, NFSPROC4_COMPOUND,
-                       vfs_context_thread(ctx), vfs_context_ucred(ctx), &si, open ? R_NOINTR: 0, NULL, &req);
-       if (!error)
+           vfs_context_thread(ctx), vfs_context_ucred(ctx), &si, open ? R_NOINTR: 0, NULL, &req);
+       if (!error) {
                error = nfs_request_async_finish(req, &nmrep, &xid, &status);
+       }
 
-       if (hadattrdir && ((adlockerror = nfs_node_lock(adnp))))
+       if (hadattrdir && ((adlockerror = nfs_node_lock(adnp)))) {
                error = adlockerror;
+       }
        savedxid = xid;
        nfsm_chain_skip_tag(error, &nmrep);
        nfsm_chain_get_32(error, &nmrep, numops);
@@ -7236,27 +8039,28 @@ restart:
                nfsm_chain_op_check(error, &nmrep, NFS_OP_OPENATTR);
                nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
                nfsmout_if(error);
-               error = nfs4_parsefattr(&nmrep, NULL, &nvattr, &fh, NULL, NULL);
+               error = nfs4_parsefattr(&nmrep, NULL, nvattr, fh, NULL, NULL);
                nfsmout_if(error);
-               if (NFS_BITMAP_ISSET(nvattr.nva_bitmap, NFS_FATTR_FILEHANDLE) && fh.fh_len) {
-                       if (!np->n_attrdirfh || (*np->n_attrdirfh != fh.fh_len)) {
+               if (NFS_BITMAP_ISSET(nvattr->nva_bitmap, NFS_FATTR_FILEHANDLE) && fh->fh_len) {
+                       if (!np->n_attrdirfh || (*np->n_attrdirfh != fh->fh_len)) {
                                /* (re)allocate attrdir fh buffer */
-                               if (np->n_attrdirfh)
+                               if (np->n_attrdirfh) {
                                        FREE(np->n_attrdirfh, M_TEMP);
-                               MALLOC(np->n_attrdirfh, u_char*, fh.fh_len+1, M_TEMP, M_WAITOK);
+                               }
+                               MALLOC(np->n_attrdirfh, u_char*, fh->fh_len + 1, M_TEMP, M_WAITOK);
                        }
                        if (np->n_attrdirfh) {
                                /* remember the attrdir fh in the node */
-                               *np->n_attrdirfh = fh.fh_len;
-                               bcopy(fh.fh_data, np->n_attrdirfh+1, fh.fh_len);
+                               *np->n_attrdirfh = (unsigned char)fh->fh_len;  /* No truncation because fh_len's value is checked during nfs4_parsefattr() */
+                               bcopy(fh->fh_data, np->n_attrdirfh + 1, fh->fh_len);
                                /* create busied node for attrdir */
                                struct componentname cn;
                                bzero(&cn, sizeof(cn));
                                cn.cn_nameptr = __CAST_AWAY_QUALIFIER(_PATH_FORKSPECIFIER, const, char *); /* "/..namedfork/" */
-                               cn.cn_namelen = strlen(_PATH_FORKSPECIFIER);
+                               cn.cn_namelen = NFS_STRLEN_INT(_PATH_FORKSPECIFIER);
                                cn.cn_nameiop = LOOKUP;
                                // XXX can't set parent correctly (to np) yet
-                               error = nfs_nget(NFSTOMP(np), NULL, &cn, fh.fh_data, fh.fh_len, &nvattr, &xid, rq.r_auth, 0, &adnp);
+                               error = nfs_nget(NFSTOMP(np), NULL, &cn, fh->fh_data, fh->fh_len, nvattr, &xid, req->r_auth, 0, &adnp);
                                if (!error) {
                                        adlockerror = 0;
                                        /* set the node busy */
@@ -7267,8 +8071,8 @@ restart:
                                error = 0;
                        }
                }
-               NVATTR_CLEANUP(&nvattr);
-               fh.fh_len = 0;
+               NVATTR_CLEANUP(nvattr);
+               fh->fh_len = 0;
        }
        if (open) {
                nfsm_chain_op_check(error, &nmrep, NFS_OP_OPEN);
@@ -7279,7 +8083,7 @@ restart:
                bmlen = NFS_ATTR_BITMAP_LEN;
                nfsm_chain_get_bitmap(error, &nmrep, bitmap, bmlen);
                nfsm_chain_get_32(error, &nmrep, delegation);
-               if (!error)
+               if (!error) {
                        switch (delegation) {
                        case NFS_OPEN_DELEGATE_NONE:
                                break;
@@ -7287,8 +8091,9 @@ restart:
                        case NFS_OPEN_DELEGATE_WRITE:
                                nfsm_chain_get_stateid(error, &nmrep, &dstateid);
                                nfsm_chain_get_32(error, &nmrep, recall);
-                               if (delegation == NFS_OPEN_DELEGATE_WRITE) // space (skip) XXX
+                               if (delegation == NFS_OPEN_DELEGATE_WRITE) // space (skip) XXX
                                        nfsm_chain_adv(error, &nmrep, 3 * NFSX_UNSIGNED);
+                               }
                                /* if we have any trouble accepting the ACE, just invalidate it */
                                ace_type = ace_flags = ace_mask = len = 0;
                                nfsm_chain_get_32(error, &nmrep, ace_type);
@@ -7299,30 +8104,36 @@ restart:
                                ace.ace_flags |= nfs4_ace_nfsflags_to_vfsflags(ace_flags);
                                ace.ace_rights = nfs4_ace_nfsmask_to_vfsrights(ace_mask);
                                if (!error && (len >= slen)) {
-                                       MALLOC(s, char*, len+1, M_TEMP, M_WAITOK);
-                                       if (s)
-                                               slen = len+1;
-                                       else
+                                       MALLOC(s, char*, len + 1, M_TEMP, M_WAITOK);
+                                       if (s) {
+                                               slen = len + 1;
+                                       } else {
                                                ace.ace_flags = 0;
+                                       }
                                }
-                               if (s)
+                               if (s) {
                                        nfsm_chain_get_opaque(error, &nmrep, len, s);
-                               else
+                               } else {
                                        nfsm_chain_adv(error, &nmrep, nfsm_rndup(len));
+                               }
                                if (!error && s) {
                                        s[len] = '\0';
-                                       if (nfs4_id2guid(s, &ace.ace_applicable, (ace_flags & NFS_ACE_IDENTIFIER_GROUP)))
+                                       if (nfs4_id2guid(s, &ace.ace_applicable, (ace_flags & NFS_ACE_IDENTIFIER_GROUP))) {
                                                ace.ace_flags = 0;
+                                       }
                                }
-                               if (error || !s)
+                               if (error || !s) {
                                        ace.ace_flags = 0;
-                               if (s && (s != sbuf))
+                               }
+                               if (s && (s != sbuf)) {
                                        FREE(s, M_TEMP);
+                               }
                                break;
                        default:
                                error = EBADRPC;
                                break;
                        }
+               }
                /* At this point if we have no error, the object was created/opened. */
                open_error = error;
        } else {
@@ -7330,17 +8141,19 @@ restart:
        }
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
        nfsmout_if(error);
-       error = nfs4_parsefattr(&nmrep, NULL, &nvattr, &fh, NULL, NULL);
+       error = nfs4_parsefattr(&nmrep, NULL, nvattr, fh, NULL, NULL);
        nfsmout_if(error);
-       if (!NFS_BITMAP_ISSET(nvattr.nva_bitmap, NFS_FATTR_FILEHANDLE) || !fh.fh_len) {
+       if (!NFS_BITMAP_ISSET(nvattr->nva_bitmap, NFS_FATTR_FILEHANDLE) || !fh->fh_len) {
                error = EIO;
                goto nfsmout;
        }
-       if (prefetch)
+       if (prefetch) {
                nfsm_chain_op_check(error, &nmrep, NFS_OP_SAVEFH);
+       }
        nfsm_chain_op_check(error, &nmrep, NFS_OP_PUTFH);
-       if (!hadattrdir)
+       if (!hadattrdir) {
                nfsm_chain_op_check(error, &nmrep, NFS_OP_OPENATTR);
+       }
        nfsm_chain_op_check(error, &nmrep, NFS_OP_GETATTR);
        nfsmout_if(error);
        xid = savedxid;
@@ -7348,19 +8161,21 @@ restart:
        nfsmout_if(error);
 
        if (open) {
-               if (rflags & NFS_OPEN_RESULT_LOCKTYPE_POSIX)
+               if (rflags & NFS_OPEN_RESULT_LOCKTYPE_POSIX) {
                        newnofp->nof_flags |= NFS_OPEN_FILE_POSIXLOCK;
+               }
                if (rflags & NFS_OPEN_RESULT_CONFIRM) {
                        if (adnp) {
                                nfs_node_unlock(adnp);
                                adlockerror = ENOENT;
                        }
-                       NVATTR_CLEANUP(&nvattr);
-                       error = nfs4_open_confirm_rpc(nmp, adnp ? adnp : np, fh.fh_data, fh.fh_len, noop, &newnofp->nof_stateid, thd, cred, &nvattr, &xid);
+                       NVATTR_CLEANUP(nvattr);
+                       error = nfs4_open_confirm_rpc(nmp, adnp ? adnp : np, fh->fh_data, fh->fh_len, noop, &newnofp->nof_stateid, thd, cred, nvattr, &xid);
                        nfsmout_if(error);
                        savedxid = xid;
-                       if ((adlockerror = nfs_node_lock(adnp)))
+                       if ((adlockerror = nfs_node_lock(adnp))) {
                                error = adlockerror;
+                       }
                }
        }
 
@@ -7385,10 +8200,10 @@ nfsmout:
                nfs_node_unlock(adnp);
                adlockerror = ENOENT;
        }
-       if (!error && !anp && fh.fh_len) {
+       if (!error && !anp && fh->fh_len) {
                /* create the vnode with the filehandle and attributes */
                xid = savedxid;
-               error = nfs_nget(NFSTOMP(np), adnp, cnp, fh.fh_data, fh.fh_len, &nvattr, &xid, rq.r_auth, NG_MAKEENTRY, &anp);
+               error = nfs_nget(NFSTOMP(np), adnp, cnp, fh->fh_data, fh->fh_len, nvattr, &xid, req->r_auth, NG_MAKEENTRY, &anp);
                if (!error) {
                        *anpp = anp;
                        nfs_node_unlock(anp);
@@ -7413,8 +8228,9 @@ nfsmout:
                                nofpbusyerror = nfs_open_file_set_busy(nofp, NULL);
                                nfs_open_file_add_open(nofp, accessMode, denyMode, 0);
                                nofp->nof_stateid = newnofp->nof_stateid;
-                               if (newnofp->nof_flags & NFS_OPEN_FILE_POSIXLOCK)
+                               if (newnofp->nof_flags & NFS_OPEN_FILE_POSIXLOCK) {
                                        nofp->nof_flags |= NFS_OPEN_FILE_POSIXLOCK;
+                               }
                                nfs_open_file_clear_busy(newnofp);
                                nfs_open_file_destroy(newnofp);
                                newnofp = NULL;
@@ -7425,12 +8241,13 @@ nfsmout:
                                /* mark the node as holding a create-initiated open */
                                nofp->nof_flags |= NFS_OPEN_FILE_CREATE;
                                nofp->nof_creator = current_thread();
-                               if (nofpp)
+                               if (nofpp) {
                                        *nofpp = nofp;
+                               }
                        }
                }
        }
-       NVATTR_CLEANUP(&nvattr);
+       NVATTR_CLEANUP(nvattr);
        if (open && ((delegation == NFS_OPEN_DELEGATE_READ) || (delegation == NFS_OPEN_DELEGATE_WRITE))) {
                if (!error && anp && !recall) {
                        /* stuff the delegation state in the node */
@@ -7441,15 +8258,16 @@ nfsmout:
                        anp->n_dace = ace;
                        if (anp->n_dlink.tqe_next == NFSNOLIST) {
                                lck_mtx_lock(&nmp->nm_lock);
-                               if (anp->n_dlink.tqe_next == NFSNOLIST)
+                               if (anp->n_dlink.tqe_next == NFSNOLIST) {
                                        TAILQ_INSERT_TAIL(&nmp->nm_delegations, anp, n_dlink);
+                               }
                                lck_mtx_unlock(&nmp->nm_lock);
                        }
                        lck_mtx_unlock(&anp->n_openlock);
                } else {
                        /* give the delegation back */
                        if (anp) {
-                               if (NFS_CMPFH(anp, fh.fh_data, fh.fh_len)) {
+                               if (NFS_CMPFH(anp, fh->fh_data, fh->fh_len)) {
                                        /* update delegation state and return it */
                                        lck_mtx_lock(&anp->n_openlock);
                                        anp->n_openflags &= ~N_DELEG_MASK;
@@ -7458,19 +8276,21 @@ nfsmout:
                                        anp->n_dace = ace;
                                        if (anp->n_dlink.tqe_next == NFSNOLIST) {
                                                lck_mtx_lock(&nmp->nm_lock);
-                                               if (anp->n_dlink.tqe_next == NFSNOLIST)
+                                               if (anp->n_dlink.tqe_next == NFSNOLIST) {
                                                        TAILQ_INSERT_TAIL(&nmp->nm_delegations, anp, n_dlink);
+                                               }
                                                lck_mtx_unlock(&nmp->nm_lock);
                                        }
                                        lck_mtx_unlock(&anp->n_openlock);
                                        /* don't need to send a separate delegreturn for fh */
-                                       fh.fh_len = 0;
+                                       fh->fh_len = 0;
                                }
                                /* return anp's current delegation */
                                nfs4_delegation_return(anp, 0, thd, cred);
                        }
-                       if (fh.fh_len) /* return fh's delegation if it wasn't for anp */
-                               nfs4_delegreturn_rpc(nmp, fh.fh_data, fh.fh_len, &dstateid, 0, thd, cred);
+                       if (fh->fh_len) { /* return fh's delegation if it wasn't for anp */
+                               nfs4_delegreturn_rpc(nmp, fh->fh_data, fh->fh_len, &dstateid, 0, thd, cred);
+                       }
                }
        }
        if (open) {
@@ -7503,6 +8323,7 @@ nfsmout:
                        }
                        goto restart;
                }
+               inuse = 0;
                if (noop) {
                        if (noopbusy) {
                                nfs_open_owner_clear_busy(noop);
@@ -7534,36 +8355,40 @@ nfsmout:
                         */
                        struct nfsbuf *bp = NULL;
                        int lastpg;
-                       uint32_t pagemask;
+                       nfsbufpgs pagemask, pagemaskand;
 
                        retlen = MIN(retlen, rlen);
 
                        /* check if node needs size update or invalidation */
-                       if (ISSET(anp->n_flag, NUPDATESIZE))
+                       if (ISSET(anp->n_flag, NUPDATESIZE)) {
                                nfs_data_update_size(anp, 0);
+                       }
                        if (!(error = nfs_node_lock(anp))) {
                                if (anp->n_flag & NNEEDINVALIDATE) {
                                        anp->n_flag &= ~NNEEDINVALIDATE;
                                        nfs_node_unlock(anp);
-                                       error = nfs_vinvalbuf(NFSTOV(anp), V_SAVE|V_IGNORE_WRITEERR, ctx, 1);
-                                       if (!error) /* lets play it safe and just drop the data */
+                                       error = nfs_vinvalbuf(NFSTOV(anp), V_SAVE | V_IGNORE_WRITEERR, ctx, 1);
+                                       if (!error) /* lets play it safe and just drop the data */
                                                error = EIO;
+                                       }
                                } else {
                                        nfs_node_unlock(anp);
                                }
                        }
 
                        /* calculate page mask for the range of data read */
-                       lastpg = (trunc_page_32(retlen) - 1) / PAGE_SIZE;
-                       pagemask = ((1 << (lastpg + 1)) - 1);
+                       lastpg = (retlen - 1) / PAGE_SIZE;
+                       nfs_buf_pgs_get_page_mask(&pagemask, lastpg + 1);
 
-                       if (!error)
-                               error = nfs_buf_get(anp, 0, nmp->nm_biosize, thd, NBLK_READ|NBLK_NOWAIT, &bp);
+                       if (!error) {
+                               error = nfs_buf_get(anp, 0, nmp->nm_biosize, thd, NBLK_READ | NBLK_NOWAIT, &bp);
+                       }
                        /* don't save the data if dirty or potential I/O conflict */
-                       if (!error && bp && !bp->nb_dirtyoff && !(bp->nb_dirty & pagemask) &&
+                       nfs_buf_pgs_bit_and(&bp->nb_dirty, &pagemask, &pagemaskand);
+                       if (!error && bp && !bp->nb_dirtyoff && !nfs_buf_pgs_is_set(&pagemaskand) &&
                            timevalcmp(&anp->n_lastio, &now, <)) {
                                OSAddAtomic64(1, &nfsstats.read_bios);
-                               CLR(bp->nb_flags, (NB_DONE|NB_ASYNC));
+                               CLR(bp->nb_flags, (NB_DONE | NB_ASYNC));
                                SET(bp->nb_flags, NB_READ);
                                NFS_BUF_MAP(bp);
                                nfsm_chain_get_opaque(error, &nmrep, retlen, bp->nb_data);
@@ -7573,16 +8398,18 @@ nfsmout:
                                } else {
                                        bp->nb_offio = 0;
                                        bp->nb_endio = rlen;
-                                       if ((retlen > 0) && (bp->nb_endio < (int)retlen))
+                                       if ((retlen > 0) && (bp->nb_endio < (int)retlen)) {
                                                bp->nb_endio = retlen;
+                                       }
                                        if (eof || (retlen == 0)) {
                                                /* zero out the remaining data (up to EOF) */
                                                off_t rpcrem, eofrem, rem;
                                                rpcrem = (rlen - retlen);
                                                eofrem = anp->n_size - (NBOFF(bp) + retlen);
                                                rem = (rpcrem < eofrem) ? rpcrem : eofrem;
-                                               if (rem > 0)
+                                               if (rem > 0) {
                                                        bzero(bp->nb_data + retlen, rem);
+                                               }
                                        } else if ((retlen < rlen) && !ISSET(bp->nb_flags, NB_ERROR)) {
                                                /* ugh... short read ... just invalidate for now... */
                                                SET(bp->nb_flags, NB_INVAL);
@@ -7591,8 +8418,9 @@ nfsmout:
                                nfs_buf_read_finish(bp);
                                microuptime(&anp->n_lastio);
                        }
-                       if (bp)
+                       if (bp) {
                                nfs_buf_release(bp, 1);
+                       }
                }
                error = 0; /* ignore any transient error in processing the prefetch */
        }
@@ -7604,15 +8432,23 @@ nfsmout:
                nfs_node_clear_busy(np);
                busyerror = ENOENT;
        }
-       if (adnp)
+       if (adnp) {
                vnode_put(NFSTOV(adnp));
+       }
+       if (inuse) {
+               nfs_mount_state_in_use_end(nmp, error);
+       }
        if (error && *anpp) {
                vnode_put(NFSTOV(*anpp));
                *anpp = NULL;
        }
        nfsm_chain_cleanup(&nmreq);
        nfsm_chain_cleanup(&nmrep);
-       return (error);
+out_free:
+       NFS_ZFREE(nfs_fhandle_zone, fh);
+       NFS_ZFREE(nfs_req_zone, req);
+       FREE(nvattr, M_TEMP);
+       return error;
 }
 
 /*
@@ -7628,20 +8464,22 @@ nfs4_named_attr_remove(nfsnode_t np, nfsnode_t anp, const char *name, vfs_contex
        int error, putanp = 0;
 
        nmp = NFSTONMP(np);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
 
        bzero(&cn, sizeof(cn));
        cn.cn_nameptr = __CAST_AWAY_QUALIFIER(name, const, char *);
-       cn.cn_namelen = strlen(name);
+       cn.cn_namelen = NFS_STRLEN_INT(name);
        cn.cn_nameiop = DELETE;
        cn.cn_flags = 0;
 
        if (!anp) {
                error = nfs4_named_attr_get(np, &cn, NFS_OPEN_SHARE_ACCESS_NONE,
-                               0, ctx, &anp, NULL);
-               if ((!error && !anp) || (error == ENOATTR))
+                   0, ctx, &anp, NULL);
+               if ((!error && !anp) || (error == ENOATTR)) {
                        error = ENOENT;
+               }
                if (error) {
                        if (anp) {
                                vnode_put(NFSTOV(anp));
@@ -7652,8 +8490,9 @@ nfs4_named_attr_remove(nfsnode_t np, nfsnode_t anp, const char *name, vfs_contex
                putanp = 1;
        }
 
-       if ((error = nfs_node_set_busy(np, vfs_context_thread(ctx))))
+       if ((error = nfs_node_set_busy(np, vfs_context_thread(ctx)))) {
                goto out;
+       }
        adnp = nfs4_named_attr_dir_get(np, 1, ctx);
        nfs_node_clear_busy(np);
        if (!adnp) {
@@ -7669,48 +8508,57 @@ nfs4_named_attr_remove(nfsnode_t np, nfsnode_t anp, const char *name, vfs_contex
        vra.a_context = ctx;
        error = nfs_vnop_remove(&vra);
 out:
-       if (adnp)
+       if (adnp) {
                vnode_put(NFSTOV(adnp));
-       if (putanp)
+       }
+       if (putanp) {
                vnode_put(NFSTOV(anp));
-       return (error);
+       }
+       return error;
 }
 
 int
 nfs4_vnop_getxattr(
        struct vnop_getxattr_args /* {
-               struct vnodeop_desc *a_desc;
-               vnode_t a_vp;
-               const char * a_name;
-               uio_t a_uio;
-               size_t *a_size;
-               int a_options;
-               vfs_context_t a_context;
-       } */ *ap)
+                                   *  struct vnodeop_desc *a_desc;
+                                   *  vnode_t a_vp;
+                                   *  const char * a_name;
+                                   *  uio_t a_uio;
+                                   *  size_t *a_size;
+                                   *  int a_options;
+                                   *  vfs_context_t a_context;
+                                   *  } */*ap)
 {
        vfs_context_t ctx = ap->a_context;
        struct nfsmount *nmp;
-       struct nfs_vattr nvattr;
+       struct nfs_vattr *nvattr;
        struct componentname cn;
        nfsnode_t anp;
        int error = 0, isrsrcfork;
 
        nmp = VTONMP(ap->a_vp);
-       if (!nmp)
-               return (ENXIO);
-
-       if (!(nmp->nm_fsattr.nfsa_flags & NFS_FSFLAG_NAMED_ATTR))
-               return (ENOTSUP);
-       error = nfs_getattr(VTONFS(ap->a_vp), &nvattr, ctx, NGA_CACHED);
-       if (error)
-               return (error);
-       if (NFS_BITMAP_ISSET(nvattr.nva_bitmap, NFS_FATTR_NAMED_ATTR) &&
-           !(nvattr.nva_flags & NFS_FFLAG_HAS_NAMED_ATTRS))
-               return (ENOATTR);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
+
+       if (!(nmp->nm_fsattr.nfsa_flags & NFS_FSFLAG_NAMED_ATTR)) {
+               return ENOTSUP;
+       }
+
+       MALLOC(nvattr, struct nfs_vattr *, sizeof(*nvattr), M_TEMP, M_WAITOK);
+       error = nfs_getattr(VTONFS(ap->a_vp), nvattr, ctx, NGA_CACHED);
+       if (error) {
+               goto out;
+       }
+       if (NFS_BITMAP_ISSET(nvattr->nva_bitmap, NFS_FATTR_NAMED_ATTR) &&
+           !(nvattr->nva_flags & NFS_FFLAG_HAS_NAMED_ATTRS)) {
+               error = ENOATTR;
+               goto out;
+       }
 
        bzero(&cn, sizeof(cn));
        cn.cn_nameptr = __CAST_AWAY_QUALIFIER(ap->a_name, const, char *);
-       cn.cn_namelen = strlen(ap->a_name);
+       cn.cn_namelen = NFS_STRLEN_INT(ap->a_name);
        cn.cn_nameiop = LOOKUP;
        cn.cn_flags = MAKEENTRY;
 
@@ -7718,30 +8566,35 @@ nfs4_vnop_getxattr(
        isrsrcfork = (bcmp(ap->a_name, XATTR_RESOURCEFORK_NAME, sizeof(XATTR_RESOURCEFORK_NAME)) == 0);
 
        error = nfs4_named_attr_get(VTONFS(ap->a_vp), &cn, NFS_OPEN_SHARE_ACCESS_NONE,
-                       !isrsrcfork ? NFS_GET_NAMED_ATTR_PREFETCH : 0, ctx, &anp, NULL);
-       if ((!error && !anp) || (error == ENOENT))
+           !isrsrcfork ? NFS_GET_NAMED_ATTR_PREFETCH : 0, ctx, &anp, NULL);
+       if ((!error && !anp) || (error == ENOENT)) {
                error = ENOATTR;
+       }
        if (!error) {
-               if (ap->a_uio)
+               if (ap->a_uio) {
                        error = nfs_bioread(anp, ap->a_uio, 0, ctx);
-               else
+               } else {
                        *ap->a_size = anp->n_size;
+               }
        }
-       if (anp)
+       if (anp) {
                vnode_put(NFSTOV(anp));
-       return (error);
+       }
+out:
+       FREE(nvattr, M_TEMP);
+       return error;
 }
 
 int
 nfs4_vnop_setxattr(
        struct vnop_setxattr_args /* {
-               struct vnodeop_desc *a_desc;
-               vnode_t a_vp;
-               const char * a_name;
-               uio_t a_uio;
-               int a_options;
-               vfs_context_t a_context;
-       } */ *ap)
+                                   *  struct vnodeop_desc *a_desc;
+                                   *  vnode_t a_vp;
+                                   *  const char * a_name;
+                                   *  uio_t a_uio;
+                                   *  int a_options;
+                                   *  vfs_context_t a_context;
+                                   *  } */*ap)
 {
        vfs_context_t ctx = ap->a_context;
        int options = ap->a_options;
@@ -7755,54 +8608,62 @@ nfs4_vnop_setxattr(
        uint8_t finfo[FINDERINFOSIZE];
        uint32_t *finfop;
        struct nfs_open_file *nofp = NULL;
-       char uio_buf [ UIO_SIZEOF(1) ];
+       char uio_buf[UIO_SIZEOF(1)];
        uio_t auio;
        struct vnop_write_args vwa;
 
        nmp = VTONMP(ap->a_vp);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
 
-       if (!(nmp->nm_fsattr.nfsa_flags & NFS_FSFLAG_NAMED_ATTR))
-               return (ENOTSUP);
+       if (!(nmp->nm_fsattr.nfsa_flags & NFS_FSFLAG_NAMED_ATTR)) {
+               return ENOTSUP;
+       }
 
-       if ((options & XATTR_CREATE) && (options & XATTR_REPLACE))
-               return (EINVAL);
+       if ((options & XATTR_CREATE) && (options & XATTR_REPLACE)) {
+               return EINVAL;
+       }
 
        /* XXX limitation based on need to back up uio on short write */
        if (uio_iovcnt(uio) > 1) {
                printf("nfs4_vnop_setxattr: iovcnt > 1\n");
-               return (EINVAL);
+               return EINVAL;
        }
 
        bzero(&cn, sizeof(cn));
        cn.cn_nameptr = __CAST_AWAY_QUALIFIER(name, const, char *);
-       cn.cn_namelen = strlen(name);
+       cn.cn_namelen = NFS_STRLEN_INT(name);
        cn.cn_nameiop = CREATE;
        cn.cn_flags = MAKEENTRY;
 
        isfinderinfo = (bcmp(name, XATTR_FINDERINFO_NAME, sizeof(XATTR_FINDERINFO_NAME)) == 0);
        isrsrcfork = isfinderinfo ? 0 : (bcmp(name, XATTR_RESOURCEFORK_NAME, sizeof(XATTR_RESOURCEFORK_NAME)) == 0);
-       if (!isrsrcfork)
+       if (!isrsrcfork) {
                uio_setoffset(uio, 0);
+       }
        if (isfinderinfo) {
-               if (uio_resid(uio) != sizeof(finfo))
-                       return (ERANGE);
+               if (uio_resid(uio) != sizeof(finfo)) {
+                       return ERANGE;
+               }
                error = uiomove((char*)&finfo, sizeof(finfo), uio);
-               if (error)
-                       return (error);
+               if (error) {
+                       return error;
+               }
                /* setting a FinderInfo of all zeroes means remove the FinderInfo */
                empty = 1;
-               for (i=0, finfop=(uint32_t*)&finfo; i < (int)(sizeof(finfo)/sizeof(uint32_t)); i++)
+               for (i = 0, finfop = (uint32_t*)&finfo; i < (int)(sizeof(finfo) / sizeof(uint32_t)); i++) {
                        if (finfop[i]) {
                                empty = 0;
                                break;
                        }
-               if (empty && !(options & (XATTR_CREATE|XATTR_REPLACE))) {
+               }
+               if (empty && !(options & (XATTR_CREATE | XATTR_REPLACE))) {
                        error = nfs4_named_attr_remove(VTONFS(ap->a_vp), anp, name, ctx);
-                       if (error == ENOENT)
+                       if (error == ENOENT) {
                                error = 0;
-                       return (error);
+                       }
+                       return error;
                }
                /* first, let's see if we get a create/replace error */
        }
@@ -7816,19 +8677,24 @@ nfs4_vnop_setxattr(
         * that by setting the size to 0 on create/open.
         */
        flags = 0;
-       if (!(options & XATTR_REPLACE))
+       if (!(options & XATTR_REPLACE)) {
                flags |= NFS_GET_NAMED_ATTR_CREATE;
-       if (options & XATTR_CREATE)
+       }
+       if (options & XATTR_CREATE) {
                flags |= NFS_GET_NAMED_ATTR_CREATE_GUARDED;
-       if (!isrsrcfork)
+       }
+       if (!isrsrcfork) {
                flags |= NFS_GET_NAMED_ATTR_TRUNCATE;
+       }
 
        error = nfs4_named_attr_get(VTONFS(ap->a_vp), &cn, NFS_OPEN_SHARE_ACCESS_BOTH,
-                       flags, ctx, &anp, &nofp);
-       if (!error && !anp)
+           flags, ctx, &anp, &nofp);
+       if (!error && !anp) {
                error = ENOATTR;
-       if (error)
+       }
+       if (error) {
                goto out;
+       }
        /* grab the open state from the get/create/open */
        if (nofp && !(error = nfs_open_file_set_busy(nofp, NULL))) {
                nofp->nof_flags &= ~NFS_OPEN_FILE_CREATE;
@@ -7837,8 +8703,9 @@ nfs4_vnop_setxattr(
        }
 
        /* Setting an empty FinderInfo really means remove it, skip to the close/remove */
-       if (isfinderinfo && empty)
+       if (isfinderinfo && empty) {
                goto doclose;
+       }
 
        /*
         * Write the data out and flush.
@@ -7859,66 +8726,75 @@ nfs4_vnop_setxattr(
        }
        if (vwa.a_uio) {
                error = nfs_vnop_write(&vwa);
-               if (!error)
+               if (!error) {
                        error = nfs_flush(anp, MNT_WAIT, vfs_context_thread(ctx), 0);
+               }
        }
 doclose:
        /* Close the xattr. */
        if (nofp) {
                int busyerror = nfs_open_file_set_busy(nofp, NULL);
                closeerror = nfs_close(anp, nofp, NFS_OPEN_SHARE_ACCESS_BOTH, NFS_OPEN_SHARE_DENY_NONE, ctx);
-               if (!busyerror)
+               if (!busyerror) {
                        nfs_open_file_clear_busy(nofp);
+               }
        }
-       if (!error && isfinderinfo && empty) { /* Setting an empty FinderInfo really means remove it */ 
+       if (!error && isfinderinfo && empty) { /* Setting an empty FinderInfo really means remove it */
                error = nfs4_named_attr_remove(VTONFS(ap->a_vp), anp, name, ctx);
-               if (error == ENOENT)
+               if (error == ENOENT) {
                        error = 0;
+               }
        }
-       if (!error)
+       if (!error) {
                error = closeerror;
+       }
 out:
-       if (anp)
+       if (anp) {
                vnode_put(NFSTOV(anp));
-       if (error == ENOENT)
+       }
+       if (error == ENOENT) {
                error = ENOATTR;
-       return (error);
+       }
+       return error;
 }
 
 int
 nfs4_vnop_removexattr(
        struct vnop_removexattr_args /* {
-               struct vnodeop_desc *a_desc;
-               vnode_t a_vp;
-               const char * a_name;
-               int a_options;
-               vfs_context_t a_context;
-       } */ *ap)
+                                      *  struct vnodeop_desc *a_desc;
+                                      *  vnode_t a_vp;
+                                      *  const char * a_name;
+                                      *  int a_options;
+                                      *  vfs_context_t a_context;
+                                      *  } */*ap)
 {
        struct nfsmount *nmp = VTONMP(ap->a_vp);
        int error;
 
-       if (!nmp)
-               return (ENXIO);
-       if (!(nmp->nm_fsattr.nfsa_flags & NFS_FSFLAG_NAMED_ATTR))
-               return (ENOTSUP);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
+       if (!(nmp->nm_fsattr.nfsa_flags & NFS_FSFLAG_NAMED_ATTR)) {
+               return ENOTSUP;
+       }
 
        error = nfs4_named_attr_remove(VTONFS(ap->a_vp), NULL, ap->a_name, ap->a_context);
-       if (error == ENOENT)
+       if (error == ENOENT) {
                error = ENOATTR;
-       return (error);
+       }
+       return error;
 }
 
 int
 nfs4_vnop_listxattr(
        struct vnop_listxattr_args /* {
-               struct vnodeop_desc *a_desc;
-               vnode_t a_vp;
-               uio_t a_uio;
-               size_t *a_size;
-               int a_options;
-               vfs_context_t a_context;
-       } */ *ap)
+                                    *  struct vnodeop_desc *a_desc;
+                                    *  vnode_t a_vp;
+                                    *  uio_t a_uio;
+                                    *  size_t *a_size;
+                                    *  int a_options;
+                                    *  vfs_context_t a_context;
+                                    *  } */*ap)
 {
        vfs_context_t ctx = ap->a_context;
        nfsnode_t np = VTONFS(ap->a_vp);
@@ -7926,45 +8802,56 @@ nfs4_vnop_listxattr(
        nfsnode_t adnp = NULL;
        struct nfsmount *nmp;
        int error, done, i;
-       struct nfs_vattr nvattr;
+       struct nfs_vattr *nvattr;
        uint64_t cookie, nextcookie, lbn = 0;
        struct nfsbuf *bp = NULL;
        struct nfs_dir_buf_header *ndbhp;
        struct direntry *dp;
 
        nmp = VTONMP(ap->a_vp);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
 
-       if (!(nmp->nm_fsattr.nfsa_flags & NFS_FSFLAG_NAMED_ATTR))
-               return (ENOTSUP);
+       if (!(nmp->nm_fsattr.nfsa_flags & NFS_FSFLAG_NAMED_ATTR)) {
+               return ENOTSUP;
+       }
 
-       error = nfs_getattr(np, &nvattr, ctx, NGA_CACHED);
-       if (error)
-               return (error);
-       if (NFS_BITMAP_ISSET(nvattr.nva_bitmap, NFS_FATTR_NAMED_ATTR) &&
-           !(nvattr.nva_flags & NFS_FFLAG_HAS_NAMED_ATTRS))
-               return (0);
+       MALLOC(nvattr, struct nfs_vattr *, sizeof(*nvattr), M_TEMP, M_WAITOK);
+       error = nfs_getattr(np, nvattr, ctx, NGA_CACHED);
+       if (error) {
+               goto out_free;
+       }
+       if (NFS_BITMAP_ISSET(nvattr->nva_bitmap, NFS_FATTR_NAMED_ATTR) &&
+           !(nvattr->nva_flags & NFS_FFLAG_HAS_NAMED_ATTRS)) {
+               error = 0;
+               goto out_free;
+       }
 
-       if ((error = nfs_node_set_busy(np, vfs_context_thread(ctx))))
-               return (error);
+       if ((error = nfs_node_set_busy(np, vfs_context_thread(ctx)))) {
+               goto out_free;
+       }
        adnp = nfs4_named_attr_dir_get(np, 1, ctx);
        nfs_node_clear_busy(np);
-       if (!adnp)
+       if (!adnp) {
                goto out;
+       }
 
-       if ((error = nfs_node_lock(adnp)))
+       if ((error = nfs_node_lock(adnp))) {
                goto out;
+       }
 
        if (adnp->n_flag & NNEEDINVALIDATE) {
                adnp->n_flag &= ~NNEEDINVALIDATE;
                nfs_invaldir(adnp);
                nfs_node_unlock(adnp);
                error = nfs_vinvalbuf(NFSTOV(adnp), 0, ctx, 1);
-               if (!error)
+               if (!error) {
                        error = nfs_node_lock(adnp);
-               if (error)
+               }
+               if (error) {
                        goto out;
+               }
        }
 
        /*
@@ -7973,17 +8860,20 @@ nfs4_vnop_listxattr(
        if (adnp->n_flag & NMODIFIED) {
                nfs_invaldir(adnp);
                nfs_node_unlock(adnp);
-               if ((error = nfs_vinvalbuf(NFSTOV(adnp), 0, ctx, 1)))
+               if ((error = nfs_vinvalbuf(NFSTOV(adnp), 0, ctx, 1))) {
                        goto out;
+               }
        } else {
                nfs_node_unlock(adnp);
        }
        /* nfs_getattr() will check changed and purge caches */
-       if ((error = nfs_getattr(adnp, &nvattr, ctx, NGA_UNCACHED)))
+       if ((error = nfs_getattr(adnp, nvattr, ctx, NGA_UNCACHED))) {
                goto out;
+       }
 
-       if (uio && (uio_resid(uio) == 0))
+       if (uio && (uio_resid(uio) == 0)) {
                goto out;
+       }
 
        done = 0;
        nextcookie = lbn = 0;
@@ -7993,8 +8883,9 @@ nfs4_vnop_listxattr(
                cookie = nextcookie;
 getbuffer:
                error = nfs_buf_get(adnp, lbn, NFS_DIRBLKSIZ, vfs_context_thread(ctx), NBLK_READ, &bp);
-               if (error)
+               if (error) {
                        goto out;
+               }
                ndbhp = (struct nfs_dir_buf_header*)bp->nb_data;
                if (!ISSET(bp->nb_flags, NB_CACHE) || !ISSET(ndbhp->ndbh_flags, NDB_FULL)) {
                        if (!ISSET(bp->nb_flags, NB_CACHE)) { /* initialize the buffer */
@@ -8004,35 +8895,40 @@ getbuffer:
                                ndbhp->ndbh_ncgen = adnp->n_ncgen;
                        }
                        error = nfs_buf_readdir(bp, ctx);
-                       if (error == NFSERR_DIRBUFDROPPED)
+                       if (error == NFSERR_DIRBUFDROPPED) {
                                goto getbuffer;
-                       if (error)
+                       }
+                       if (error) {
                                nfs_buf_release(bp, 1);
+                       }
                        if (error && (error != ENXIO) && (error != ETIMEDOUT) && (error != EINTR) && (error != ERESTART)) {
                                if (!nfs_node_lock(adnp)) {
                                        nfs_invaldir(adnp);
                                        nfs_node_unlock(adnp);
                                }
                                nfs_vinvalbuf(NFSTOV(adnp), 0, ctx, 1);
-                               if (error == NFSERR_BAD_COOKIE)
+                               if (error == NFSERR_BAD_COOKIE) {
                                        error = ENOENT;
+                               }
                        }
-                       if (error)
+                       if (error) {
                                goto out;
+                       }
                }
 
                /* go through all the entries copying/counting */
                dp = NFS_DIR_BUF_FIRST_DIRENTRY(bp);
-               for (i=0; i < ndbhp->ndbh_count; i++) {
+               for (i = 0; i < ndbhp->ndbh_count; i++) {
                        if (!xattr_protected(dp->d_name)) {
                                if (uio == NULL) {
                                        *ap->a_size += dp->d_namlen + 1;
                                } else if (uio_resid(uio) < (dp->d_namlen + 1)) {
                                        error = ERANGE;
                                } else {
-                                       error = uiomove(dp->d_name, dp->d_namlen+1, uio);
-                                       if (error && (error != EFAULT))
+                                       error = uiomove(dp->d_name, dp->d_namlen + 1, uio);
+                                       if (error && (error != EFAULT)) {
                                                error = ERANGE;
+                                       }
                                }
                        }
                        nextcookie = dp->d_seekoff;
@@ -8043,8 +8939,9 @@ getbuffer:
                        /* hit end of buffer, move to next buffer */
                        lbn = nextcookie;
                        /* if we also hit EOF, we're done */
-                       if (ISSET(ndbhp->ndbh_flags, NDB_EOF))
+                       if (ISSET(ndbhp->ndbh_flags, NDB_EOF)) {
                                done = 1;
+                       }
                }
                if (!error && !done && (nextcookie == cookie)) {
                        printf("nfs readdir cookie didn't change 0x%llx, %d/%d\n", cookie, i, ndbhp->ndbh_count);
@@ -8053,71 +8950,85 @@ getbuffer:
                nfs_buf_release(bp, 1);
        }
 out:
-       if (adnp)
+       if (adnp) {
                vnode_put(NFSTOV(adnp));
-       return (error);
+       }
+out_free:
+       FREE(nvattr, M_TEMP);
+       return error;
 }
 
 #if NAMEDSTREAMS
 int
 nfs4_vnop_getnamedstream(
        struct vnop_getnamedstream_args /* {
-               struct vnodeop_desc *a_desc;
-               vnode_t a_vp;
-               vnode_t *a_svpp;
-               const char *a_name;
-               enum nsoperation a_operation;
-               int a_flags;
-               vfs_context_t a_context;
-       } */ *ap)
+                                         *  struct vnodeop_desc *a_desc;
+                                         *  vnode_t a_vp;
+                                         *  vnode_t *a_svpp;
+                                         *  const char *a_name;
+                                         *  enum nsoperation a_operation;
+                                         *  int a_flags;
+                                         *  vfs_context_t a_context;
+                                         *  } */*ap)
 {
        vfs_context_t ctx = ap->a_context;
        struct nfsmount *nmp;
-       struct nfs_vattr nvattr;
+       struct nfs_vattr *nvattr;
        struct componentname cn;
        nfsnode_t anp;
        int error = 0;
 
        nmp = VTONMP(ap->a_vp);
-       if (!nmp)
-               return (ENXIO);
-
-       if (!(nmp->nm_fsattr.nfsa_flags & NFS_FSFLAG_NAMED_ATTR))
-               return (ENOTSUP);
-       error = nfs_getattr(VTONFS(ap->a_vp), &nvattr, ctx, NGA_CACHED);
-       if (error)
-               return (error);
-       if (NFS_BITMAP_ISSET(nvattr.nva_bitmap, NFS_FATTR_NAMED_ATTR) &&
-           !(nvattr.nva_flags & NFS_FFLAG_HAS_NAMED_ATTRS))
-               return (ENOATTR);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
+
+       if (!(nmp->nm_fsattr.nfsa_flags & NFS_FSFLAG_NAMED_ATTR)) {
+               return ENOTSUP;
+       }
+
+       MALLOC(nvattr, struct nfs_vattr *, sizeof(*nvattr), M_TEMP, M_WAITOK);
+       error = nfs_getattr(VTONFS(ap->a_vp), nvattr, ctx, NGA_CACHED);
+       if (error) {
+               goto out;
+       }
+       if (NFS_BITMAP_ISSET(nvattr->nva_bitmap, NFS_FATTR_NAMED_ATTR) &&
+           !(nvattr->nva_flags & NFS_FFLAG_HAS_NAMED_ATTRS)) {
+               error = ENOATTR;
+               goto out;
+       }
 
        bzero(&cn, sizeof(cn));
        cn.cn_nameptr = __CAST_AWAY_QUALIFIER(ap->a_name, const, char *);
-       cn.cn_namelen = strlen(ap->a_name);
+       cn.cn_namelen = NFS_STRLEN_INT(ap->a_name);
        cn.cn_nameiop = LOOKUP;
        cn.cn_flags = MAKEENTRY;
 
        error = nfs4_named_attr_get(VTONFS(ap->a_vp), &cn, NFS_OPEN_SHARE_ACCESS_NONE,
-                       0, ctx, &anp, NULL);
-       if ((!error && !anp) || (error == ENOENT))
+           0, ctx, &anp, NULL);
+       if ((!error && !anp) || (error == ENOENT)) {
                error = ENOATTR;
-       if (!error && anp)
+       }
+       if (!error && anp) {
                *ap->a_svpp = NFSTOV(anp);
-       else if (anp)
+       } else if (anp) {
                vnode_put(NFSTOV(anp));
-       return (error);
+       }
+out:
+       FREE(nvattr, M_TEMP);
+       return error;
 }
 
 int
 nfs4_vnop_makenamedstream(
        struct vnop_makenamedstream_args /* {
-               struct vnodeop_desc *a_desc;
-               vnode_t *a_svpp;
-               vnode_t a_vp;
-               const char *a_name;
-               int a_flags;
-               vfs_context_t a_context;
-       } */ *ap)
+                                          *  struct vnodeop_desc *a_desc;
+                                          *  vnode_t *a_svpp;
+                                          *  vnode_t a_vp;
+                                          *  const char *a_name;
+                                          *  int a_flags;
+                                          *  vfs_context_t a_context;
+                                          *  } */*ap)
 {
        vfs_context_t ctx = ap->a_context;
        struct nfsmount *nmp;
@@ -8126,55 +9037,64 @@ nfs4_vnop_makenamedstream(
        int error = 0;
 
        nmp = VTONMP(ap->a_vp);
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
 
-       if (!(nmp->nm_fsattr.nfsa_flags & NFS_FSFLAG_NAMED_ATTR))
-               return (ENOTSUP);
+       if (!(nmp->nm_fsattr.nfsa_flags & NFS_FSFLAG_NAMED_ATTR)) {
+               return ENOTSUP;
+       }
 
        bzero(&cn, sizeof(cn));
        cn.cn_nameptr = __CAST_AWAY_QUALIFIER(ap->a_name, const, char *);
-       cn.cn_namelen = strlen(ap->a_name);
+       cn.cn_namelen = NFS_STRLEN_INT(ap->a_name);
        cn.cn_nameiop = CREATE;
        cn.cn_flags = MAKEENTRY;
 
        error = nfs4_named_attr_get(VTONFS(ap->a_vp), &cn, NFS_OPEN_SHARE_ACCESS_BOTH,
-                       NFS_GET_NAMED_ATTR_CREATE, ctx, &anp, NULL);
-       if ((!error && !anp) || (error == ENOENT))
+           NFS_GET_NAMED_ATTR_CREATE, ctx, &anp, NULL);
+       if ((!error && !anp) || (error == ENOENT)) {
                error = ENOATTR;
-       if (!error && anp)
+       }
+       if (!error && anp) {
                *ap->a_svpp = NFSTOV(anp);
-       else if (anp)
+       } else if (anp) {
                vnode_put(NFSTOV(anp));
-       return (error);
+       }
+       return error;
 }
 
 int
 nfs4_vnop_removenamedstream(
        struct vnop_removenamedstream_args /* {
-               struct vnodeop_desc *a_desc;
-               vnode_t a_vp;
-               vnode_t a_svp;
-               const char *a_name;
-               int a_flags;
-               vfs_context_t a_context;
-       } */ *ap)
+                                            *  struct vnodeop_desc *a_desc;
+                                            *  vnode_t a_vp;
+                                            *  vnode_t a_svp;
+                                            *  const char *a_name;
+                                            *  int a_flags;
+                                            *  vfs_context_t a_context;
+                                            *  } */*ap)
 {
        struct nfsmount *nmp = VTONMP(ap->a_vp);
        nfsnode_t np = ap->a_vp ? VTONFS(ap->a_vp) : NULL;
        nfsnode_t anp = ap->a_svp ? VTONFS(ap->a_svp) : NULL;
 
-       if (!nmp)
-               return (ENXIO);
+       if (nfs_mount_gone(nmp)) {
+               return ENXIO;
+       }
 
        /*
         * Given that a_svp is a named stream, checking for
         * named attribute support is kinda pointless.
         */
-       if (!(nmp->nm_fsattr.nfsa_flags & NFS_FSFLAG_NAMED_ATTR))
-               return (ENOTSUP);
+       if (!(nmp->nm_fsattr.nfsa_flags & NFS_FSFLAG_NAMED_ATTR)) {
+               return ENOTSUP;
+       }
 
-       return (nfs4_named_attr_remove(np, anp, ap->a_name, ap->a_context));
+       return nfs4_named_attr_remove(np, anp, ap->a_name, ap->a_context);
 }
 
 #endif
+#endif /* CONFIG_NFS4 */
+
+#endif /* CONFIG_NFS_CLIENT */