From: Chuck Lever <cel@kernel.org>
To: Anna Schumaker <anna@kernel.org>,
Trond Myklebust <trond.myklebust@hammerspace.com>
Cc: <linux-nfs@vger.kernel.org>
Subject: [PATCH v1] NFS: use TCP for MOUNT when xprtsec= selects TLS
Date: Wed, 16 Sep 2026 16:43:36 -0400 [thread overview]
Message-ID: <20260916204336.14436-1-cel@kernel.org> (raw)
An NFSv2 or NFSv3 text mount that specifies xprtsec= but no
mountproto= crashes in nfs_init_timeout_values():
RIP: 0010:nfs_init_timeout_values+0x10a/0x110 [nfs]
Call Trace:
nfs_mount+0x1c3/0x330 [nfs]
nfs_try_get_tree+0x1e5/0x460 [nfs]
nfs_get_tree+0x64d/0x6d0 [nfs]
vfs_get_tree+0x2b/0xe0
vfs_cmd_create+0x5f/0xd0
vfs_fsconfig_locked+0x50/0x130
__se_sys_fsconfig+0x2f9/0x3a0
nfs_validate_transport_protocol() sets nfs_server.protocol to
XPRT_TRANSPORT_TCP_TLS when xprtsec= is present, but the switch in
nfs_set_mount_transport_protocol() has no case for that value.
mount_server.protocol stays zero, and nfs_init_timeout_values()
calls BUG() on a transport it does not recognize.
mount.nfs always appends mountproto= after probing the server's
rpcbind, so only a caller that bypasses it, such as "mount -i" or a
program that drives fsconfig() directly, reaches the crash.
Select TCP for MOUNT when the NFS transport is XPRT_TRANSPORT_TCP_TLS.
nfs_mount() requests no transport security, so MOUNT already runs
over plain TCP whenever mount.nfs supplies mountproto=tcp.
Fixes: c8407f2e560c ("NFS: Add an "xprtsec=" NFS mount option")
Signed-off-by: Chuck Lever <cel@kernel.org>
---
fs/nfs/fs_context.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/fs/nfs/fs_context.c b/fs/nfs/fs_context.c
index 1967de7d1dff..a7393ff05494 100644
--- a/fs/nfs/fs_context.c
+++ b/fs/nfs/fs_context.c
@@ -402,6 +402,7 @@ static void nfs_set_mount_transport_protocol(struct nfs_fs_context *ctx)
ctx->mount_server.protocol = XPRT_TRANSPORT_UDP;
break;
case XPRT_TRANSPORT_TCP:
+ case XPRT_TRANSPORT_TCP_TLS:
case XPRT_TRANSPORT_RDMA:
ctx->mount_server.protocol = XPRT_TRANSPORT_TCP;
}
--
2.55.0
next reply other threads:[~2026-09-16 20:43 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-16 20:43 Chuck Lever [this message]
2026-09-17 10:30 ` [v1] NFS: use TCP for MOUNT when xprtsec= selects TLS Prabhakar Pujeri
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260916204336.14436-1-cel@kernel.org \
--to=cel@kernel.org \
--cc=anna@kernel.org \
--cc=linux-nfs@vger.kernel.org \
--cc=trond.myklebust@hammerspace.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox