From: Simo Sorce <simo@redhat.com>
To: bfields@redhat.com
Cc: linux-nfs@vger.kernel.org, Simo Sorce <simo@redhat.com>
Subject: [PATCH 0/4] Add support for new RPCSEC_GSS upcall mechanism for nfsd
Date: Fri, 25 May 2012 18:09:52 -0400 [thread overview]
Message-ID: <1337983796-26476-1-git-send-email-simo@redhat.com> (raw)
This patchset implements a new upcall mechanism that uses the sunrpc
client to talk to gssproxy[1], a new userspace daemon that handles gssapi
operations on behalf of other processes on the system.
The main driver for this new mechanism is to overcome limitations with
the current daemon and upcall. The current code cannot handle tickets
larger than approximatively 2k and cannot handle sending back large user
credential sets to the kernel.
These patches have been tested against the development version of gssproxy
tagged as kernel_v0.1 in the master repo[2].
I have tested walking into mountpoints using tickets artificially pumped
up to 64k and the user is properly authorized, after the accept_se_context
call is performed through the new upcall mechanism and gssproxy.
The gssproxy has the potential of handling also init_sec_context calls,
but at the moment the only targeted system is nfsd.
Simo.
[1] https://fedorahosted.org/gss-proxy/
[2] http://git.fedorahosted.org/git/?p=gss-proxy.git;a=shortlog;h=refs/tags/kernel_v0.1
NOTE: Included are all changes request and agreed on the list recently,
kmalloc changes and containers compatibility changes.
Pacthes rebased on top of Bruce Field's for-3.5 tree.
Simo Sorce (4):
SUNRPC: conditionally return endtime from import_sec_context
SUNRPC: Document a bit RPCGSS handling in the NFS Server
SUNRPC: Add RPC based upcall mechanism for RPCGSS auth
SUNRPC: Use gssproxy upcall for nfsd's RPCGSS authentication.
Documentation/filesystems/nfs/00-INDEX | 2 +
Documentation/filesystems/nfs/knfsd-rpcgss.txt | 65 ++
include/linux/sunrpc/auth_gss.h | 3 +
include/linux/sunrpc/gss_api.h | 2 +
include/linux/sunrpc/svcauth_gss.h | 2 +-
net/sunrpc/auth_gss/Makefile | 4 +-
net/sunrpc/auth_gss/auth_gss.c | 11 +-
net/sunrpc/auth_gss/gss_krb5_mech.c | 3 +
net/sunrpc/auth_gss/gss_mech_switch.c | 5 +-
net/sunrpc/auth_gss/gss_rpc_upcall.c | 353 +++++++++
net/sunrpc/auth_gss/gss_rpc_upcall.h | 43 ++
net/sunrpc/auth_gss/gss_rpc_xdr.c | 907 ++++++++++++++++++++++++
net/sunrpc/auth_gss/gss_rpc_xdr.h | 269 +++++++
net/sunrpc/auth_gss/svcauth_gss.c | 226 ++++++-
14 files changed, 1875 insertions(+), 20 deletions(-)
create mode 100644 Documentation/filesystems/nfs/knfsd-rpcgss.txt
create mode 100644 net/sunrpc/auth_gss/gss_rpc_upcall.c
create mode 100644 net/sunrpc/auth_gss/gss_rpc_upcall.h
create mode 100644 net/sunrpc/auth_gss/gss_rpc_xdr.c
create mode 100644 net/sunrpc/auth_gss/gss_rpc_xdr.h
--
1.7.7.6
next reply other threads:[~2012-05-25 22:10 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-05-25 22:09 Simo Sorce [this message]
2012-05-25 22:09 ` [PATCH 1/4] SUNRPC: conditionally return endtime from import_sec_context Simo Sorce
2012-05-25 22:09 ` [PATCH 2/4] SUNRPC: Document a bit RPCGSS handling in the NFS Server Simo Sorce
2012-05-25 22:09 ` [PATCH 3/4] SUNRPC: Add RPC based upcall mechanism for RPCGSS auth Simo Sorce
2012-05-25 22:09 ` [PATCH 4/4] SUNRPC: Use gssproxy upcall for nfsd's RPCGSS authentication Simo Sorce
2012-07-10 20:49 ` [PATCH 0/4] Add support for new RPCSEC_GSS upcall mechanism for nfsd J. Bruce Fields
2012-07-10 21:05 ` J. Bruce Fields
2012-07-12 12:39 ` J. Bruce Fields
2012-07-12 22:05 ` Simo Sorce
2012-07-12 22:42 ` J. Bruce Fields
2012-07-10 21:52 ` Myklebust, Trond
2012-07-10 21:56 ` J. Bruce Fields
2012-07-10 22:12 ` Myklebust, Trond
2012-07-10 22:25 ` Myklebust, Trond
2012-07-10 22:38 ` J. Bruce Fields
2012-07-10 22:58 ` Myklebust, Trond
2012-07-11 17:03 ` J. Bruce Fields
2012-07-11 17:27 ` J. Bruce Fields
2012-07-11 17:49 ` Myklebust, Trond
2012-07-12 22:10 ` J. Bruce Fields
2012-07-13 15:43 ` J. Bruce Fields
2012-08-08 19:36 ` J. Bruce Fields
2012-08-08 19:43 ` J. Bruce Fields
2012-08-08 20:12 ` Stanislav Kinsbursky
2012-08-21 14:16 ` J. Bruce Fields
2012-08-21 14:25 ` Myklebust, Trond
2012-08-21 14:29 ` J. Bruce Fields
2012-08-21 14:27 ` Stanislav Kinsbursky
2012-08-10 13:07 ` Stanislav Kinsbursky
2012-07-11 11:15 ` Simo Sorce
2012-07-13 15:45 ` J. Bruce Fields
2012-07-13 15:55 ` Simo Sorce
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1337983796-26476-1-git-send-email-simo@redhat.com \
--to=simo@redhat.com \
--cc=bfields@redhat.com \
--cc=linux-nfs@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).