From: Mike Snitzer <snitzer@kernel.org>
To: Chuck Lever <chuck.lever@oracle.com>,
Jeff Layton <jlayton@kernel.org>,
Trond Myklebust <trond.myklebust@hammerspace.com>,
Anna Schumaker <anna.schumaker@oracle.com>
Cc: linux-nfs@vger.kernel.org
Subject: [RFC PATCH 05/11] NFSD: add NFS4 reexport support for SETACL nfs4_acl passthru
Date: Thu, 19 Feb 2026 17:13:46 -0500 [thread overview]
Message-ID: <20260219221352.40554-6-snitzer@kernel.org> (raw)
In-Reply-To: <20260219221352.40554-1-snitzer@kernel.org>
From: Mike Snitzer <snitzer@hammerspace.com>
Allow NFSD's 4.1 reexport of a 4.2 mount to perform SETACL by passing
thru nfs4_acl that was decoded from 4.1 client directly to 4.2
client.
Update nfsd4_decode_acl() to save the ACL's payload off to an xdr_buf
in the nfs4_acl. But only do the work to decode that ACL payload into
pages stored in the nfs4_acl, via nfsd4_decode_nfs4_acl_passthru(), if
the exported filesystem supports nfs4_acl passthru (like NFSv4 client
does).
Signed-off-by: Mike Snitzer <snitzer@hammerspace.com>
---
fs/nfsd/nfs4proc.c | 27 +++++++++++++++++++++------
fs/nfsd/nfs4xdr.c | 43 ++++++++++++++++++++++++++++++++++++++++++-
fs/nfsd/xdr4.h | 2 ++
3 files changed, 65 insertions(+), 7 deletions(-)
diff --git a/fs/nfsd/nfs4proc.c b/fs/nfsd/nfs4proc.c
index 9a21e94a4215..796954a24cde 100644
--- a/fs/nfsd/nfs4proc.c
+++ b/fs/nfsd/nfs4proc.c
@@ -1219,6 +1219,7 @@ nfsd4_setattr(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
};
bool save_no_wcc, deleg_attrs;
struct nfs4_stid *st = NULL;
+ struct dentry *dentry;
struct inode *inode;
__be32 status = nfs_ok;
int err;
@@ -1276,12 +1277,14 @@ nfsd4_setattr(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
goto out;
}
- inode = cstate->current_fh.fh_dentry->d_inode;
- status = nfsd4_acl_to_attr(S_ISDIR(inode->i_mode) ? NF4DIR : NF4REG,
- setattr->sa_acl, &attrs);
-
- if (status)
- goto out;
+ dentry = cstate->current_fh.fh_dentry;
+ inode = dentry->d_inode;
+ if (IS_POSIXACL(inode)) {
+ status = nfsd4_acl_to_attr(S_ISDIR(inode->i_mode) ? NF4DIR : NF4REG,
+ setattr->sa_acl, &attrs);
+ if (status)
+ goto out;
+ }
save_no_wcc = cstate->current_fh.fh_no_wcc;
cstate->current_fh.fh_no_wcc = true;
status = nfsd_setattr(rqstp, &cstate->current_fh, &attrs, NULL);
@@ -1292,6 +1295,18 @@ nfsd4_setattr(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
status = nfserrno(attrs.na_dpaclerr);
if (!status)
status = nfserrno(attrs.na_paclerr);
+ if (!status && !IS_POSIXACL(inode) && setattr->sa_acl &&
+ exportfs_may_passthru_nfs4acl(dentry->d_sb->s_export_op)) {
+ const struct export_operations *ops = dentry->d_sb->s_export_op;
+ if (likely(ops->setacl)) {
+ status = nfsd4_decode_nfs4_acl_passthru(rqstp->rq_argp,
+ setattr->sa_bmval, &setattr->sa_acl);
+ if (status)
+ goto out;
+ status = nfserrno(ops->setacl(inode, setattr->sa_acl));
+ } else
+ status = nfserr_attrnotsupp;
+ }
out:
fh_drop_write(&cstate->current_fh);
out_err:
diff --git a/fs/nfsd/nfs4xdr.c b/fs/nfsd/nfs4xdr.c
index cacdd6285e90..f14c2fb45142 100644
--- a/fs/nfsd/nfs4xdr.c
+++ b/fs/nfsd/nfs4xdr.c
@@ -287,6 +287,45 @@ nfsd4_decode_bitmap4(struct nfsd4_compoundargs *argp, u32 *bmval, u32 bmlen)
return status == -EBADMSG ? nfserr_bad_xdr : nfs_ok;
}
+__be32 nfsd4_decode_nfs4_acl_passthru(struct nfsd4_compoundargs *argp,
+ u32 *bmval, struct nfs4_acl **acl)
+{
+ u32 acl_len = (*acl)->payload.len;
+ unsigned int pgbase, num_pages;
+ struct xdr_stream xdr;
+ __be32 status = nfs_ok;
+ void *p;
+
+ xdr_init_decode(&xdr, &(*acl)->payload,
+ (*acl)->payload.head[0].iov_base, NULL);
+
+ p = xdr_inline_decode(&xdr, acl_len);
+ if (p == NULL) {
+ status = nfserr_bad_xdr;
+ goto out;
+ }
+
+ pgbase = (unsigned long)p & ~PAGE_MASK;
+ num_pages = DIV_ROUND_UP(pgbase + acl_len, PAGE_SIZE);
+
+ *acl = svcxdr_tmpalloc(argp, (sizeof(struct nfs4_acl) +
+ num_pages * sizeof(struct page *)));
+ if (*acl == NULL) {
+ status = nfserr_jukebox;
+ goto out;
+ }
+
+ (*acl)->type = NFS4ACL_ACL;
+ (*acl)->len = acl_len;
+ (*acl)->pgbase = pgbase;
+
+ for (int i = 0; i < num_pages; i++)
+ (*acl)->pages[i] = virt_to_page(p + (i << PAGE_SHIFT));
+out:
+ xdr_finish_decode(&xdr);
+ return status;
+}
+
static __be32
nfsd4_decode_nfsace4(struct xdr_stream *xdr, struct svc_rqst *rqstp,
struct nfs4_ace *ace)
@@ -325,7 +364,7 @@ nfsd4_decode_acl(struct nfsd4_compoundargs *argp, struct nfs4_acl **acl,
u32 acl_len)
{
- struct xdr_buf payload;
+ struct xdr_buf payload, saved_payload;
struct xdr_stream xdr;
struct nfs4_ace *ace;
__be32 status = nfs_ok;
@@ -333,6 +372,7 @@ nfsd4_decode_acl(struct nfsd4_compoundargs *argp, struct nfs4_acl **acl,
if (!xdr_stream_subsegment(argp->xdr, &payload, acl_len))
return nfserr_bad_xdr;
+ memcpy(&saved_payload, &payload, sizeof(struct xdr_buf));
xdr_init_decode(&xdr, &payload, payload.head[0].iov_base, NULL);
@@ -356,6 +396,7 @@ nfsd4_decode_acl(struct nfsd4_compoundargs *argp, struct nfs4_acl **acl,
status = nfserr_jukebox;
goto out;
}
+ memcpy(&(*acl)->payload, &saved_payload, sizeof(struct xdr_buf));
(*acl)->naces = count;
for (ace = (*acl)->aces; ace < (*acl)->aces + count; ace++) {
diff --git a/fs/nfsd/xdr4.h b/fs/nfsd/xdr4.h
index 417e9ad9fbb3..d3561ce76a12 100644
--- a/fs/nfsd/xdr4.h
+++ b/fs/nfsd/xdr4.h
@@ -1011,6 +1011,8 @@ extern __be32 nfsd4_test_stateid(struct svc_rqst *rqstp,
extern __be32 nfsd4_free_stateid(struct svc_rqst *rqstp,
struct nfsd4_compound_state *, union nfsd4_op_u *);
extern void nfsd4_bump_seqid(struct nfsd4_compound_state *, __be32 nfserr);
+__be32 nfsd4_decode_nfs4_acl_passthru(struct nfsd4_compoundargs *,
+ u32 *bmval, struct nfs4_acl **acl);
enum nfsd4_op_flags {
ALLOWED_WITHOUT_FH = 1 << 0, /* No current filehandle required */
--
2.44.0
next prev parent reply other threads:[~2026-02-19 22:14 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-02-19 22:13 [RFC PATCH 00/11] NFS/NFSD: nfs4_acl passthru for NFSv4 reexport Mike Snitzer
2026-02-19 22:13 ` [RFC PATCH 01/11] exportfs: add ability to advertise NFSv4 ACL passthru support Mike Snitzer
2026-02-19 22:13 ` [RFC PATCH 02/11] NFSD: factor out nfsd_supports_nfs4_acl() to nfsd/acl.h Mike Snitzer
2026-02-19 22:13 ` [RFC PATCH 03/11] NFS/NFSD: data structure enablement for nfs4_acl passthru support Mike Snitzer
2026-02-19 22:13 ` [RFC PATCH 04/11] NFSD: prepare to support SETACL nfs4_acl passthru Mike Snitzer
2026-02-19 22:13 ` Mike Snitzer [this message]
2026-02-19 22:13 ` [RFC PATCH 06/11] NFSD: add NFS4 reexport support for GETACL " Mike Snitzer
2026-02-19 22:13 ` [RFC PATCH 07/11] NFSD: add NFS4ACL_DACL and NFS4ACL_SACL passthru support Mike Snitzer
2026-02-19 22:13 ` [RFC PATCH 08/11] NFSD: avoid extra nfs4_acl passthru work unless needed Mike Snitzer
2026-02-19 22:13 ` [RFC PATCH 09/11] NFSv4: add reexport support for SETACL nfs4_acl passthru Mike Snitzer
2026-02-19 22:13 ` [RFC PATCH 10/11] NFSv4: add reexport support for GETACL " Mike Snitzer
2026-02-19 22:13 ` [RFC PATCH 11/11] NFSv4: set EXPORT_OP_NFSV4_ACL_PASSTHRU flag Mike Snitzer
2026-02-19 22:21 ` [RFC PATCH 00/11] NFS/NFSD: nfs4_acl passthru for NFSv4 reexport Chuck Lever
2026-02-19 23:07 ` Mike Snitzer
2026-02-20 15:46 ` Chuck Lever
2026-02-19 23:57 ` Trond Myklebust
2026-02-20 15:33 ` Chuck Lever
2026-02-22 17:53 ` Chuck Lever
2026-02-22 19:39 ` Mike Snitzer
2026-02-22 20:31 ` Chuck Lever
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260219221352.40554-6-snitzer@kernel.org \
--to=snitzer@kernel.org \
--cc=anna.schumaker@oracle.com \
--cc=chuck.lever@oracle.com \
--cc=jlayton@kernel.org \
--cc=linux-nfs@vger.kernel.org \
--cc=trond.myklebust@hammerspace.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox