Linux NFS development
 help / color / mirror / Atom feed
From: Neil Brown <neilb@suse.de>
To: "J. Bruce Fields" <bfields@fieldses.org>
Cc: nfs@lists.sourceforge.net, "Talpey,
	Thomas" <Thomas.Talpey@netapp.com>,
	Simon Peter <simon.peter@gmx.de>
Subject: Re: Delays on "first" access to a NFS mount
Date: Thu, 8 Mar 2007 09:37:18 +1100	[thread overview]
Message-ID: <17903.16030.26119.464793@notabene.brown> (raw)
In-Reply-To: message from J. Bruce Fields on Wednesday March 7

On Wednesday March 7, bfields@fieldses.org wrote:
> 
> Well, non-head-hurty ideas always welcomed.  I've got two export-related
> problems to fix:
> 
> 	- Our current NFSv4 pseudofs fsid=0 hack is a pain to administer
> 	  and results in inconsistent paths across different NFS
> 	  versions.

You've got to put that v4 pseudo root somewhere...
It just needs cleverness in nfs-utils to auto-bind-mount things into
the pseudoroot...  but I guess people cannot magically unmount things
then.

How about this.  We add an export option "follow-symlinks" so that
when nfsd is asked to stat a symlink it does a 'stat' instead of an
'lstat' (effectively).
Then we get mountd to make a tmpfs in /var/lib/nfs/pseudoroot which
contains directories and symlinks to the various export points names
in etab.  This tmpfs is exported as fsid=0,follow-symlinks.

Problem solved?

Ofcourse if different clients get to see different exports, then we
might need multiple tmpfs's in /var/lib/nfs/pseudoroot/$CLIENT/ ....

> 
> 	- The trick of using the pseudoflavor as a client name (so doing
> 
> 		/export	 gss/krb5(rw)
> 	
> 	  instead of
> 
> 		/export *(sec=krb5,rw)
> 
> 	  ), is inconsistent with what other os's do, and makes it
> 	  impossible to specify restrictions based both on flavor and on
> 	  ip network/dns name/netgroup.

Yeeesssss.  If you are using crypto-security, then the
source-ip-address (which is a terribly weak form of security) should
be irrelevant.  But I think you've convinced me that some people have
valid cases for the combined tested.  Grumble Grumble ;-) 

> 
> While I'm at it Trond and Christoph and others seem to be asking whether
> we can't make some more fundamental changes, such as:
> 
> 	- Maintaining a static in-kernel exports table instead of
> 	  loading it on demand from mountd, and
> 

Don't like that idea at all.  Demand-loading is a good thing.

> 	- divorcing the exports namespace completely from any local
> 	  process namespace, to the extent that you could even just say
> 	  "I want to export /dev/sda7 as /usr/local/bin" without first 
> 	  mounting /dev/sda7 someplace.

I like that even less.  Much much less.  Way way way less.  Yuck.

Having a private name-space for nfsd and co might be OK, but that is
the closest I could come to the above suggestion, and even then I'm not
convinced.  I think private name spaces are a very powerful tool that
should be used very very carefully.  There is plenty of room for
confusion of the poor sysadmin if you start doing too much with
private name spaces.

If you built a system where every daemon has a private namespace, then
having one for nfsd would be ok, but it really should be a system wide
approach to management, not an approach only used by nfsd.

NeilBrown

-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys-and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
NFS maillist  -  NFS@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/nfs

  reply	other threads:[~2007-03-07 22:37 UTC|newest]

Thread overview: 45+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-03-07 10:23 Delays on "first" access to a NFS mount Simon Peter
2007-03-07 12:38 ` Talpey, Thomas
2007-03-07 13:22   ` Simon Peter
2007-03-07 15:06   ` Simon Peter
2007-03-07 15:10     ` Simon Peter
2007-03-07 15:42     ` J. Bruce Fields
2007-03-07 18:44       ` Simon Peter
2007-03-07 20:29         ` J. Bruce Fields
2007-03-07 21:46           ` Simon Peter
2007-03-07 22:05             ` J. Bruce Fields
2007-03-07 23:19               ` Simon Peter
2007-03-07 22:09           ` Neil Brown
2007-03-08 15:49           ` Simon Peter
2007-03-09 13:02           ` Simon Peter
2007-03-09 14:59             ` J. Bruce Fields
2007-03-07 20:31         ` Talpey, Thomas
2007-03-07 20:50           ` J. Bruce Fields
2007-03-07 21:07             ` Talpey, Thomas
2007-03-07 21:17               ` J. Bruce Fields
2007-03-07 21:23                 ` Talpey, Thomas
2007-03-07 21:54                   ` J. Bruce Fields
2007-03-07 22:37                     ` Neil Brown [this message]
2007-03-07 23:06                       ` J. Bruce Fields
2007-03-07 23:39                         ` Neil Brown
2007-03-08  5:14                           ` J. Bruce Fields
2007-03-08  5:42                             ` Neil Brown
2007-03-08 13:43                             ` Olaf Kirch
2007-03-08 21:27                               ` J. Bruce Fields
2007-03-09 15:02                                 ` Olaf Kirch
2007-03-16 21:47                         ` Christoph Hellwig
2007-03-16 21:54                           ` J. Bruce Fields
2007-03-16 21:57                             ` Christoph Hellwig
2007-03-07 23:24                       ` J. Bruce Fields
2007-03-07 23:51                         ` Neil Brown
2007-03-08  4:36                           ` J. Bruce Fields
2007-03-08 13:27                     ` Olaf Kirch
2007-03-08 21:46                       ` J. Bruce Fields
2007-03-07 22:15                   ` Neil Brown
2007-03-07 21:40             ` Simon Peter
2007-03-07 22:17               ` Neil Brown
2007-03-07 22:36                 ` Talpey, Thomas
2007-03-07 22:48                   ` Neil Brown
2007-03-07 22:56                     ` Talpey, Thomas
2007-03-07 22:12             ` Neil Brown
2007-03-07 22:23               ` J. Bruce Fields

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=17903.16030.26119.464793@notabene.brown \
    --to=neilb@suse.de \
    --cc=Thomas.Talpey@netapp.com \
    --cc=bfields@fieldses.org \
    --cc=nfs@lists.sourceforge.net \
    --cc=simon.peter@gmx.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox