All of lore.kernel.org
 help / color / mirror / Atom feed
From: "J. Bruce Fields" <bfields@fieldses.org>
To: Chuck Lever <Chuck.Lever@oracle.com>
Cc: Trond Myklebust <Trond.Myklebust@netapp.com>,
	NFS list <linux-nfs@vger.kernel.org>,
	Tom Haynes <Thomas.Haynes-UdXhSnd/wVw@public.gmane.org>,
	Steve Dickson <SteveD@redhat.com>
Subject: Re: Fwd: mount.nfs: access denied by server
Date: Fri, 21 Aug 2009 14:20:27 -0400	[thread overview]
Message-ID: <20090821182027.GD21043@fieldses.org> (raw)
In-Reply-To: <BAE89B4F-CA8C-46B2-82EA-9BAA438C1DF7@oracle.com>

On Fri, Aug 21, 2009 at 02:16:08PM -0400, Chuck Lever wrote:
> I want to understand the server bug a little more.  I glanced over RFC  
> 2623 and didn't see anything specific.
>
> Is it the case that only Linux NFSD does this, or do other servers do  
> it?  In other words, is this a typical server response, and if so, is  
> there a specific semantic attached to it?
>
> If no list is provided, should the client assume that only AUTH_NONE and 
> AUTH_SYS are supported, or instead, perhaps that the client can try to 
> use any flavor?  In other words, if no list is provided, let the mount 
> proceed no matter what was specified by sec= ?

I've sent the following to Steve to fix the server bug.

--b.

commit ceb3c96d68f47cf6a0c38ccd88b98c59c886e9fb
Author: J. Bruce Fields <bfields@citi.umich.edu>
Date:   Tue Jul 21 19:30:04 2009 -0400

    Don't give client an empty flavor list
    
    In the absence of an explicit sec= option on an export, rpc.mountd is
    returning a zero-length flavor list to clients in the MOUNT results.
    
    The linux client doesn't seem to mind, but the Solaris client
    (reasonably enough) is giving up; the symptom is a "security mode does
    not match" error on mount.
    
    We could modify the export-parsing code to ensure the secinfo array is
    nonzero.  But I think it's slightly simpler to handle this default case
    in the implementation of the MOUNT call.  This is more-or-less the same
    thing the kernel does when mountd passes it an export without any
    security flavors specified.
    
    Thanks to Tom Haynes for bug report and diagnosis.
    
    Signed-off-by: J. Bruce Fields <bfields@citi.umich.edu>

diff --git a/utils/mountd/mountd.c b/utils/mountd/mountd.c
index b59f939..888fd8c 100644
--- a/utils/mountd/mountd.c
+++ b/utils/mountd/mountd.c
@@ -359,6 +359,11 @@ static void set_authflavors(struct mountres3_ok *ok, nfs_export *exp)
 		flavors[i] = s->flav->fnum;
 		i++;
 	}
+	if (i == 0) {
+		/* default when there is no sec= option: */
+		i = 1;
+		flavors[0] = AUTH_UNIX;
+	}
 	ok->auth_flavors.auth_flavors_val = flavors;
 	ok->auth_flavors.auth_flavors_len = i;
 }

  reply	other threads:[~2009-08-21 18:20 UTC|newest]

Thread overview: 55+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-08-20  7:13 mount.nfs: access denied by server Wu Fengguang
2009-08-20  7:19 ` Wu Fengguang
2009-08-20 13:02 ` Trond Myklebust
     [not found]   ` <1250773349.5352.23.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-21  1:27     ` Wu Fengguang
2009-08-21  1:27       ` Wu Fengguang
2009-08-21  2:36       ` Trond Myklebust
     [not found]         ` <1250822171.6514.29.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-21 17:50           ` Chuck Lever
2009-08-21 17:50             ` Chuck Lever
2009-08-22  1:48             ` Wu Fengguang
2009-08-21 18:16         ` Fwd: " Chuck Lever
2009-08-21 18:20           ` J. Bruce Fields [this message]
2009-08-21 20:20             ` Chuck Lever
2009-08-24 12:15             ` Fwd: " Steve Dickson
2009-08-21 18:24           ` J. Bruce Fields
2009-08-21 18:46             ` Chuck Lever
2009-08-21 20:04               ` J. Bruce Fields
2009-08-21 20:18                 ` Tom Haynes
     [not found]                   ` <4A8F0118.60705-xsfywfwIY+M@public.gmane.org>
2009-08-21 20:39                     ` Peter Staubach
2009-08-21 20:59                       ` J. Bruce Fields
2009-08-21 21:08                         ` Trond Myklebust
     [not found]                           ` <1250888892.5700.7.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-21 21:21                             ` J. Bruce Fields
2009-08-21 20:36                 ` Chuck Lever
2009-08-21 21:15                   ` Trond Myklebust
     [not found]                     ` <1250889345.5700.11.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-21 21:21                       ` Tom Haynes
     [not found]                         ` <4A8F0FCC.2080709-xsfywfwIY+M@public.gmane.org>
2009-08-21 21:25                           ` Trond Myklebust
2009-08-21 21:30                       ` J. Bruce Fields
2009-08-21 21:40                         ` Trond Myklebust
     [not found]                           ` <1250890836.5700.19.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-21 21:47                             ` J. Bruce Fields
2009-08-21 21:51                               ` Trond Myklebust
     [not found]                                 ` <1250891463.5700.21.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-24 16:10                                   ` J. Bruce Fields
2009-08-24 16:22                                     ` Chuck Lever
2009-08-24 17:06                                     ` Trond Myklebust
     [not found]                                       ` <1251133618.6325.262.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-24 17:41                                         ` J. Bruce Fields
2009-08-25 15:36                                           ` Chuck Lever
2009-08-25 16:49                                             ` Tom Haynes
     [not found]                                               ` <4A94162C.20904-xsfywfwIY+M@public.gmane.org>
2009-08-25 16:58                                                 ` Trond Myklebust
     [not found]                                                   ` <1251219492.25372.3.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-25 18:17                                                     ` Tom Haynes
     [not found]                                                       ` <4A942ACF.4030502-xsfywfwIY+M@public.gmane.org>
2009-08-25 18:39                                                         ` Trond Myklebust
     [not found]                                                           ` <1251225543.25372.22.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-25 18:43                                                             ` Trond Myklebust
     [not found]                                                               ` <1251225797.25372.25.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-25 22:17                                                                 ` Tom Haynes
     [not found]                                                                   ` <4A9462E4.5020404-xsfywfwIY+M@public.gmane.org>
2009-08-25 23:20                                                                     ` Trond Myklebust
     [not found]                                                                       ` <1251242416.5403.3.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-25 23:37                                                                         ` [nfs-discuss] " Nicolas Williams
     [not found]                                                                           ` <20090825233758.GZ1033-UdXhSnd/wVw@public.gmane.org>
2009-08-26  0:21                                                                             ` Trond Myklebust
     [not found]                                                                               ` <1251246105.5403.12.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-26 21:03                                                                                 ` Nicolas Williams
2009-08-25 17:40                                                 ` Chuck Lever
2009-08-25 18:02                                                   ` Tom Haynes
2009-08-25 18:10                                                   ` J. Bruce Fields
2009-08-25 19:05                                                     ` Chuck Lever
2009-08-21 22:21                             ` Chuck Lever
2009-08-21 21:41                         ` Chuck Lever
2009-08-21 19:07             ` Thomas Haynes
     [not found]               ` <760BE185-BE57-42C2-817C-6776B5B66667-xsfywfwIY+M@public.gmane.org>
2009-08-21 19:22                 ` Chuck Lever
2009-08-21 19:40                   ` Tom Haynes
     [not found]                     ` <4A8EF847.8030500-xsfywfwIY+M@public.gmane.org>
2009-08-21 20:04                       ` Chuck Lever
2009-08-21 20:41                   ` Peter Staubach

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20090821182027.GD21043@fieldses.org \
    --to=bfields@fieldses.org \
    --cc=Chuck.Lever@oracle.com \
    --cc=SteveD@redhat.com \
    --cc=Thomas.Haynes-UdXhSnd/wVw@public.gmane.org \
    --cc=Trond.Myklebust@netapp.com \
    --cc=linux-nfs@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.