Linux Documentation
 help / color / mirror / Atom feed
From: "Chuck Lever" <cel@kernel.org>
To: "Hannes Reinecke" <hare@suse.de>,
	"Trond Myklebust" <trondmy@kernel.org>,
	"Anna Schumaker" <anna@kernel.org>,
	"David S. Miller" <davem@davemloft.net>,
	"Eric Dumazet" <edumazet@google.com>,
	"Jakub Kicinski" <kuba@kernel.org>,
	"Paolo Abeni" <pabeni@redhat.com>,
	"Simon Horman" <horms@kernel.org>,
	"Jonathan Corbet" <corbet@lwn.net>,
	"Shuah Khan" <skhan@linuxfoundation.org>,
	"Randy Dunlap" <rdunlap@infradead.org>,
	"Christian Brauner" <brauner@kernel.org>,
	"David Howells" <dhowells@redhat.com>,
	"Sagi Grimberg" <sagi@grimberg.me>
Cc: linux-nfs@vger.kernel.org, keyrings@vger.kernel.org,
	kernel-tls-handshake@lists.linux.dev, netdev@vger.kernel.org,
	linux-doc@vger.kernel.org
Subject: Re: [PATCH RFC 2/5] NFS: allocate the .nfs keyring per network namespace
Date: Fri, 18 Sep 2026 11:15:27 -0400	[thread overview]
Message-ID: <81bade19-10d6-4fc7-9a57-eef85afe76cf@app.fastmail.com> (raw)
In-Reply-To: <bbc4ff6f-aa38-4862-96fe-518c3b4df4d6@suse.de>



On Fri, Sep 18, 2026, at 10:44 AM, Hannes Reinecke wrote:
> On 9/18/26 4:05 PM, Chuck Lever wrote:
>> Commit 87268f7a4f1f ("nfs: create a kernel keyring") allocates one
>> .nfs keyring at module load, and nothing in the NFS client reads it.
>> One module-wide keyring also cannot isolate x.509 credentials
>> between network namespaces. Each tlshd instance services the
>> handshake socket of one network namespace, so a credential
>> provisioned for that namespace's mounts has to be reachable by that
>> tlshd and by no other.
>> 
>> Allocate one .nfs keyring per network namespace in nfs_net_init()
>> and release it in nfs_net_exit(). tlshd finds a keyring by name
>> through /proc/keys, which is not namespace scoped, so each handshake
>> request has to carry the keyring serial instead. Allocate the
>> keyring under a kernel credential rather than that of the task
>> creating the namespace, so an LSM labels every namespace's keyring
>> the same way.

> Curiously enough, I had been pondering a similar issue.
> Thing is, when running within a container (eg a docker one) access
> access to /proc/keys might be restricted, and from what I've
> gathered each container gets its own, _empty_ keyring.
> (certainly an empty session keyring ...).
> So I wonder what'll happen with the predefined keyrings (like the
> .nvme keyring); one possibility is surely to make them network
> namespace aware.
> But the alternative approach I'm exploring is to allow each container
> to create its own (.nvme) keyring; that would have the advantage of
> being more flexible and we wouldn't need to rely on 'magic' names.

IMO we need to hear from the folks who have deep keyring expertise
to understand what is most flexible and most idiomatic. I'm certainly
not expert enough to make those calls.

It would be great if tlshd's NVMe and NFS/NFSD keyring support
behaved consistently with each other, but perhaps that's just my
compulsion for symmetry talking.

I'm willing to take a look at patches, if you have any.


-- 
Chuck Lever (Come to NFS bake-a-thon! https://nfsv4bat.org)

  reply	other threads:[~2026-09-18 15:15 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-18 14:05 [PATCH RFC 0/5] NFS: isolate mTLS client credentials by network namespace Chuck Lever
2026-09-18 14:05 ` [PATCH RFC 1/5] NFS: name the init_nfs_fs() error labels Chuck Lever
2026-09-18 14:05 ` [PATCH RFC 2/5] NFS: allocate the .nfs keyring per network namespace Chuck Lever
2026-09-18 14:44   ` Hannes Reinecke
2026-09-18 15:15     ` Chuck Lever [this message]
2026-09-19 16:22     ` Chuck Lever
2026-09-18 14:05 ` [PATCH RFC 3/5] SUNRPC: pass a keyring serial to the TLS handshake Chuck Lever
2026-09-18 14:05 ` [PATCH RFC 4/5] NFS: name the namespace .nfs keyring in the x509 handshake Chuck Lever
2026-09-18 14:05 ` [PATCH RFC 5/5] NFS: add a key type that reveals the namespace .nfs keyring serial Chuck Lever
2026-09-18 18:00   ` Randy Dunlap
2026-09-19 15:59     ` Chuck Lever
2026-09-18 17:21 ` [PATCH RFC 0/5] NFS: isolate mTLS client credentials by network namespace Benjamin Coddington
2026-09-19 15:46   ` Chuck Lever
2026-09-21  8:45   ` Hannes Reinecke
2026-09-21 11:17     ` Benjamin Coddington

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=81bade19-10d6-4fc7-9a57-eef85afe76cf@app.fastmail.com \
    --to=cel@kernel.org \
    --cc=anna@kernel.org \
    --cc=brauner@kernel.org \
    --cc=corbet@lwn.net \
    --cc=davem@davemloft.net \
    --cc=dhowells@redhat.com \
    --cc=edumazet@google.com \
    --cc=hare@suse.de \
    --cc=horms@kernel.org \
    --cc=kernel-tls-handshake@lists.linux.dev \
    --cc=keyrings@vger.kernel.org \
    --cc=kuba@kernel.org \
    --cc=linux-doc@vger.kernel.org \
    --cc=linux-nfs@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=rdunlap@infradead.org \
    --cc=sagi@grimberg.me \
    --cc=skhan@linuxfoundation.org \
    --cc=trondmy@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox