From: Nicolas Williams <Nicolas.Williams-xsfywfwIY+M@public.gmane.org>
To: Trond Myklebust <Trond.Myklebust@netapp.com>
Cc: Tom Haynes <Thomas.Haynes-xsfywfwIY+M@public.gmane.org>,
NFS list <linux-nfs@vger.kernel.org>,
nfs-discuss-xZgeD5Kw2fzokhkdeNNY6A@public.gmane.org
Subject: Re: [nfs-discuss] mount.nfs: access denied by server
Date: Tue, 25 Aug 2009 18:37:58 -0500 [thread overview]
Message-ID: <20090825233758.GZ1033@Sun.COM> (raw)
In-Reply-To: <1251242416.5403.3.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
On Tue, Aug 25, 2009 at 07:20:16PM -0400, Trond Myklebust wrote:
> I was thinking of the case in which /foo/bar is not actually a mount
> point. :-)
Looking at code we have
nfs4_secinfo_recov() ->
nfs4_secinfo_vnode() ->
nfs4_secinfo_fh_otw() ->
secinfo_update()
And as you can see nfs4_secinfo_vnode() calls nfs4_secinfo_fh_otw() to
get the SECINFO for the affected FH, but, nfs4_secinfo_fh_otw() updates
the mount's server info.
Which means that WRONGSEC -> SECINFO -> updates the entire mount's sec.
I.e., if you have:
- server:/foo w/ sec=krb5
- server:/foo/bar in the _same_ filesystem (i.e., with same fsid) and
sec=krb5i
the client will probably thrash if you mount server:/foo because each
WRONGSEC from accessing server:/foo/baz will cause the client to update
the entire mount, which will lead to WRONGSEC from accessing
server:/foo/bar, which will lead to WRONGSEC from accessing
server:/foo/baz, which ...
> If we all agree that the server can only remove security flavours when
> crossing a mount point, then all is well, however the protocol doesn't
> strictly speaking say that has to be the case.
I agree, that sounds like a very good rule for now.
One could also argue that clients should handle this on a per-directory
basis, not per-mount. But first we'd have to agree that it's a good
idea to have nested "shares" in the same filesystem.
> That worries me...
Me too.
Nico
--
next prev parent reply other threads:[~2009-08-26 0:25 UTC|newest]
Thread overview: 55+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-08-20 7:13 mount.nfs: access denied by server Wu Fengguang
2009-08-20 7:19 ` Wu Fengguang
2009-08-20 13:02 ` Trond Myklebust
[not found] ` <1250773349.5352.23.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-21 1:27 ` Wu Fengguang
2009-08-21 1:27 ` Wu Fengguang
2009-08-21 2:36 ` Trond Myklebust
[not found] ` <1250822171.6514.29.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-21 17:50 ` Chuck Lever
2009-08-21 17:50 ` Chuck Lever
2009-08-22 1:48 ` Wu Fengguang
2009-08-21 18:16 ` Fwd: " Chuck Lever
2009-08-21 18:20 ` J. Bruce Fields
2009-08-21 20:20 ` Chuck Lever
2009-08-24 12:15 ` Fwd: " Steve Dickson
2009-08-21 18:24 ` J. Bruce Fields
2009-08-21 18:46 ` Chuck Lever
2009-08-21 20:04 ` J. Bruce Fields
2009-08-21 20:18 ` Tom Haynes
[not found] ` <4A8F0118.60705-xsfywfwIY+M@public.gmane.org>
2009-08-21 20:39 ` Peter Staubach
2009-08-21 20:59 ` J. Bruce Fields
2009-08-21 21:08 ` Trond Myklebust
[not found] ` <1250888892.5700.7.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-21 21:21 ` J. Bruce Fields
2009-08-21 20:36 ` Chuck Lever
2009-08-21 21:15 ` Trond Myklebust
[not found] ` <1250889345.5700.11.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-21 21:21 ` Tom Haynes
[not found] ` <4A8F0FCC.2080709-xsfywfwIY+M@public.gmane.org>
2009-08-21 21:25 ` Trond Myklebust
2009-08-21 21:30 ` J. Bruce Fields
2009-08-21 21:40 ` Trond Myklebust
[not found] ` <1250890836.5700.19.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-21 21:47 ` J. Bruce Fields
2009-08-21 21:51 ` Trond Myklebust
[not found] ` <1250891463.5700.21.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-24 16:10 ` J. Bruce Fields
2009-08-24 16:22 ` Chuck Lever
2009-08-24 17:06 ` Trond Myklebust
[not found] ` <1251133618.6325.262.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-24 17:41 ` J. Bruce Fields
2009-08-25 15:36 ` Chuck Lever
2009-08-25 16:49 ` Tom Haynes
[not found] ` <4A94162C.20904-xsfywfwIY+M@public.gmane.org>
2009-08-25 16:58 ` Trond Myklebust
[not found] ` <1251219492.25372.3.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-25 18:17 ` Tom Haynes
[not found] ` <4A942ACF.4030502-xsfywfwIY+M@public.gmane.org>
2009-08-25 18:39 ` Trond Myklebust
[not found] ` <1251225543.25372.22.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-25 18:43 ` Trond Myklebust
[not found] ` <1251225797.25372.25.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-25 22:17 ` Tom Haynes
[not found] ` <4A9462E4.5020404-xsfywfwIY+M@public.gmane.org>
2009-08-25 23:20 ` Trond Myklebust
[not found] ` <1251242416.5403.3.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-25 23:37 ` Nicolas Williams [this message]
[not found] ` <20090825233758.GZ1033-UdXhSnd/wVw@public.gmane.org>
2009-08-26 0:21 ` [nfs-discuss] " Trond Myklebust
[not found] ` <1251246105.5403.12.camel-rJ7iovZKK19ZJLDQqaL3InhyD016LWXt@public.gmane.org>
2009-08-26 21:03 ` Nicolas Williams
2009-08-25 17:40 ` Chuck Lever
2009-08-25 18:02 ` Tom Haynes
2009-08-25 18:10 ` J. Bruce Fields
2009-08-25 19:05 ` Chuck Lever
2009-08-21 22:21 ` Chuck Lever
2009-08-21 21:41 ` Chuck Lever
2009-08-21 19:07 ` Thomas Haynes
[not found] ` <760BE185-BE57-42C2-817C-6776B5B66667-xsfywfwIY+M@public.gmane.org>
2009-08-21 19:22 ` Chuck Lever
2009-08-21 19:40 ` Tom Haynes
[not found] ` <4A8EF847.8030500-xsfywfwIY+M@public.gmane.org>
2009-08-21 20:04 ` Chuck Lever
2009-08-21 20:41 ` Peter Staubach
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20090825233758.GZ1033@Sun.COM \
--to=nicolas.williams-xsfywfwiy+m@public.gmane.org \
--cc=Thomas.Haynes-xsfywfwIY+M@public.gmane.org \
--cc=Trond.Myklebust@netapp.com \
--cc=linux-nfs@vger.kernel.org \
--cc=nfs-discuss-xZgeD5Kw2fzokhkdeNNY6A@public.gmane.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.