All of lore.kernel.org
 help / color / mirror / Atom feed
* NLM GRANT callback using AUTH_NULL is rejected
@ 2005-11-17 15:38 Lever, Charles
  2005-11-17 16:05 ` J. Bruce Fields
  2005-11-17 16:05 ` Olaf Kirch
  0 siblings, 2 replies; 7+ messages in thread
From: Lever, Charles @ 2005-11-17 15:38 UTC (permalink / raw)
  To: neilb; +Cc: Olaf Kirch, nfs

hi neil-

it looks like you have the most expertise in this area, so you are the
lucky victim today.

our filer sends NLM GRANTED callbacks back to clients using AUTH_NULL
authentication.  Linux clients always seem to reject these callbacks.

parsing through fs/lockd and net/sunrpc, i see a comment that indicates
that AUTH_NULL RPC requests are subject to IP access control (a la
/etc/exports).  theoretically, if lockd doesn't register the filer in
the ip_map cache, then all the filer's callbacks will be rejected,
right?

        - Chuck Lever
--
corporate:    <cel at netapp dot com>
personal:     <chucklever at bigfoot dot com>


-------------------------------------------------------
This SF.Net email is sponsored by the JBoss Inc.  Get Certified Today
Register for a JBoss Training Course.  Free Certification Exam
for All Training Attendees Through End of 2005. For more info visit:
http://ads.osdn.com/?ad_id=7628&alloc_id=16845&op=click
_______________________________________________
NFS maillist  -  NFS@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/nfs

^ permalink raw reply	[flat|nested] 7+ messages in thread
* RE: NLM GRANT callback using AUTH_NULL is rejected
@ 2005-11-17 16:20 Lever, Charles
  2005-11-17 16:27 ` J. Bruce Fields
                   ` (2 more replies)
  0 siblings, 3 replies; 7+ messages in thread
From: Lever, Charles @ 2005-11-17 16:20 UTC (permalink / raw)
  To: J. Bruce Fields; +Cc: neilb, Olaf Kirch, nfs

> On Thu, Nov 17, 2005 at 07:38:22AM -0800, Lever, Charles wrote:
> > our filer sends NLM GRANTED callbacks back to clients using=20
> AUTH_NULL
> > authentication.  Linux clients always seem to reject these=20
> callbacks.
> >=20
> > parsing through fs/lockd and net/sunrpc, i see a comment=20
> that indicates
> > that AUTH_NULL RPC requests are subject to IP access control (a la
> > /etc/exports).  theoretically, if lockd doesn't register=20
> the filer in
> > the ip_map cache, then all the filer's callbacks will be rejected,
> > right?
>=20
> See
>=20
> http://marc.theaimsgroup.com/?l=3Dlinux-nfs&m=3D110608174305835&w=3D2
>=20
> and following messages.  These appear to have gone into 2.6 in early
> March sometime, so I assume that was about 2.6.12?

thanks bruce.

ok, these appear not to be in RHEL 4 update 2, which is what our
internal test happens to be using at the moment.  i would assume that an
FC4 system running the latest update would already have this series of
patches integrated...?

was it the judgement of the community that no IP address checking for
AUTH_NULL callbacks is better than having at least *some* sanity
checking?  seems reasonable to me to register the IP address of the file
server so that not just any joe IP address can grant locks.
(limitations of authentication via IP address notwithstanding).

obtw, did you happen to have a test to see if GRANTED callbacks were
being accepted after your patch is applied?  that will save me the
trouble of working up a test myself.


-------------------------------------------------------
This SF.Net email is sponsored by the JBoss Inc.  Get Certified Today
Register for a JBoss Training Course.  Free Certification Exam
for All Training Attendees Through End of 2005. For more info visit:
http://ads.osdn.com/?ad_id=7628&alloc_id=16845&op=click
_______________________________________________
NFS maillist  -  NFS@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/nfs

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2005-11-17 19:11 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-11-17 15:38 NLM GRANT callback using AUTH_NULL is rejected Lever, Charles
2005-11-17 16:05 ` J. Bruce Fields
2005-11-17 16:05 ` Olaf Kirch
  -- strict thread matches above, loose matches on Subject: below --
2005-11-17 16:20 Lever, Charles
2005-11-17 16:27 ` J. Bruce Fields
2005-11-17 16:56 ` Trond Myklebust
2005-11-17 19:11 ` Steve Dickson

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.