All of lore.kernel.org
 help / color / mirror / Atom feed
From: "J. Bruce Fields" <bfields@fieldses.org>
To: Christopher Metter
	<christopher.metter-jNDFPZUTrfSeRcrpBB1ZFQkon6kHRKkiG9Ur7JDdleE@public.gmane.org>
Cc: linux-nfs@vger.kernel.org
Subject: Re: Problems Migrating from NFSv3 to NFSv4
Date: Fri, 20 Nov 2009 13:15:38 -0500	[thread overview]
Message-ID: <20091120181538.GA8841@fieldses.org> (raw)
In-Reply-To: <4B054EF8.7000102-jNDFPZUTrfSeRcrpBB1ZFQkon6kHRKkiG9Ur7JDdleE@public.gmane.org>

On Thu, Nov 19, 2009 at 02:58:16PM +0100, Christopher Metter wrote:
> J. Bruce Fields schrieb:
>> On Mon, Nov 16, 2009 at 07:57:57PM +0100, Christopher Metter wrote:
>>   
>>> Hi there folks!
>>>
>>> Im trying to migrate from NFSv3 to NFSv4. I've read diverse Articles 
>>> and  Howtos, but i cant find a solution to my problem.
>>>
>>> For better understanding: My NFSv4 Root is /srv/data/, a Folder that  
>>> existed before and has diverse Subfolders in it. These Folders are   
>>> really there and are not mounted by "mount --bind".
>>>
>>> The Servers IP: 192.168.0.10
>>> Client1: 192.168.0.1
>>> Client2: 192.168.0.2
>>>
>>> Setup with NFSv3:
>>> 2 Folders (scratch and software) were shared for 2 Clients. In 
>>> Scratch  both clients had full RW-access and on software only Client2 
>>> had rw,  Client1 had RO.
>>> Config:
>>> /srv/data/scratch-all    *(rw,async,no_root_squash,nohide,no_subtree_check)
>>> /srv/data/software      
>>> 10.0.12.4(ro,sync,no_root_squash,nohide,no_subtree_check)   
>>> 10.0.12.5(rw,sync,no_root_squash,nohide,no_subtree_check)
>>>
>>> My NFSv4 Config (from Server/etc/exports)
>>> |/srv/data/   
>>> 192.168.0.2(rw,sync,fsid=0,insecure,no_root_squash,no_subtree_check)  
>>> 192.168.0.1(rw,sync,fsid=0,insecure,no_root_squash,no_subtree_check)
>>> /srv/data/scratch *(rw,async,no_root_squash,no_subtree_check)
>>> /srv/data/software 
>>> 192.168.0.1(ro,sync,no_root_squash,no_subtree_check)   
>>> 192.168.0.2(rw,sync,no_root_squash,no_subtree_check)
>>> |
>>> After that i mounted from Client1 and Client2  the Sharefolders   
>>> directrly (e.g. software: mount -t nfs4 -o intr,hard,rw   
>>> 192.168.0.10:/software  /targetfolder), everything works perfect, 
>>> every  Client has its specific rights and so on.
>>>
>>> But if im mounting Servers Root (mount -t nfs4 -o intr,hard,rw   
>>> 192.168.0.10:/ /targetfolder)  from Client1 I do have complete RW 
>>> Access  to the full "Data" folder, even with RW for Software (which i 
>>> set for  RO).
>>>     
>>
>> Exports don't operate on "folders", only on filesystems: if you export
>> /srv/data/ read-write, and if /srv/data/software is on the same
>> filesystem as /srv/data, then /srv/data will also be exported, and also
>> writeable.
>>
>> --b
> Is there a workaround to this behavior? Or a trick to get an NFSv4 Setup  
> corresponding to the NFSv3 Setup?

If you add a trivial mountpoint there with:

	"mount --bind /srv/data/software /srv/data/software"

I think that will do the job.

Note this isn't really secure--this will prevent users on 192.168.0.1
from accidentally modifying software/, but won't do anything against
someone malicious with access to the network.

--b.

      parent reply	other threads:[~2009-11-20 18:15 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-11-16 18:57 Problems Migrating from NFSv3 to NFSv4 Christopher Metter
     [not found] ` <4B01A0B5.80501-jNDFPZUTrfSeRcrpBB1ZFQkon6kHRKkiG9Ur7JDdleE@public.gmane.org>
2009-11-17 14:13   ` Steve Dickson
     [not found]     ` <4B02AF7D.4090503-AfCzQyP5zfLQT0dZR+AlfA@public.gmane.org>
2009-11-18 12:02       ` Christopher Metter
2009-11-18 21:14   ` J. Bruce Fields
2009-11-19 13:58     ` Christopher Metter
     [not found]       ` <4B054EF8.7000102-jNDFPZUTrfSeRcrpBB1ZFQkon6kHRKkiG9Ur7JDdleE@public.gmane.org>
2009-11-20 18:15         ` J. Bruce Fields [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20091120181538.GA8841@fieldses.org \
    --to=bfields@fieldses.org \
    --cc=christopher.metter-jNDFPZUTrfSeRcrpBB1ZFQkon6kHRKkiG9Ur7JDdleE@public.gmane.org \
    --cc=linux-nfs@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.