Linux NFS development
 help / color / mirror / Atom feed
From: Chuck Lever <cel@kernel.org>
To: NeilBrown <neilb@ownmail.net>, Jeff Layton <jlayton@kernel.org>,
	Olga Kornievskaia <okorniev@redhat.com>,
	Dai Ngo <dai.ngo@oracle.com>, Tom Talpey <tom@talpey.com>
Cc: <linux-nfs@vger.kernel.org>
Subject: [PATCH v1] SUNRPC: offer RPC-with-TLS only on services that implement it
Date: Fri, 25 Sep 2026 11:13:43 -0400	[thread overview]
Message-ID: <20260925151343.529200-1-cel@kernel.org> (raw)

svcauth_tls_accept() offers STARTTLS on every service whose
transport class has a handshake method. The NFSv4.0 callback
service listens on TCP, so an NFS server that sends CB_NULL with
AUTH_TLS gets a STARTTLS reply. The callback thread then blocks in
svc_tcp_handshake() for up to SVC_HANDSHAKE_TO, waiting for a
handshake the NFS client is not configured to complete. The
callback service runs a small thread pool shared by every NFSv4.0
server in the network namespace, so a malicious server can stall
callbacks from other servers by repeating the probe on each
reconnect. lockd has the same exposure. It runs a single thread on
every NFS client host to receive NLM_GRANTED callbacks and does not
support RPC-with-TLS.

Add a per-service flag that a service sets when it implements
RPC-with-TLS, and have svcauth_tls_accept() answer an AUTH_TLS
probe on any other service with a plain AUTH_NULL verifier, as
RFC 9289 Section 4.1 prescribes for a server that does not support
TLS. NFSD is the only service that sets the flag.

Fixes: 74aaf96feaca ("SUNRPC: Teach server to recognize RPC_AUTH_TLS")
Signed-off-by: Chuck Lever <cel@kernel.org>
---
 fs/nfsd/nfssvc.c           | 1 +
 include/linux/sunrpc/svc.h | 2 ++
 net/sunrpc/svcauth_unix.c  | 2 +-
 3 files changed, 4 insertions(+), 1 deletion(-)

diff --git a/fs/nfsd/nfssvc.c b/fs/nfsd/nfssvc.c
index ffc58a76c1fc..3705dba837e7 100644
--- a/fs/nfsd/nfssvc.c
+++ b/fs/nfsd/nfssvc.c
@@ -680,6 +680,7 @@ int nfsd_create_serv(struct net *net, bool no_rpcbind)
 		return -ENOMEM;
 	}
 	serv->sv_reply_sent = nfsd_cache_reply_sent;
+	serv->sv_tls = true;
 
 	/* svc_bind() reads this, so set it first. */
 	serv->sv_no_rpcbind = no_rpcbind;
diff --git a/include/linux/sunrpc/svc.h b/include/linux/sunrpc/svc.h
index bdff8ccb92c7..5af08e326146 100644
--- a/include/linux/sunrpc/svc.h
+++ b/include/linux/sunrpc/svc.h
@@ -91,6 +91,8 @@ struct svc_serv {
 	bool			sv_is_pooled;	/* is this a pooled service? */
 	/* Caller registers with rpcbind itself. Set before svc_bind(). */
 	bool			sv_no_rpcbind;
+	/* Service implements RPC-with-TLS; offer STARTTLS to AUTH_TLS probes. */
+	bool			sv_tls;
 	struct svc_pool *	sv_pools;	/* array of thread pools */
 	int			(*sv_threadfn)(void *data);
 
diff --git a/net/sunrpc/svcauth_unix.c b/net/sunrpc/svcauth_unix.c
index 1e5a421ef2cb..ad8a73653e42 100644
--- a/net/sunrpc/svcauth_unix.c
+++ b/net/sunrpc/svcauth_unix.c
@@ -1151,7 +1151,7 @@ svcauth_tls_accept(struct svc_rqst *rqstp)
 	if (cred->cr_group_info == NULL)
 		return SVC_CLOSE;
 
-	if (xprt->xpt_ops->xpo_handshake) {
+	if (xprt->xpt_ops->xpo_handshake && rqstp->rq_server->sv_tls) {
 		p = xdr_reserve_space(&rqstp->rq_res_stream, XDR_UNIT * 2 + 8);
 		if (!p)
 			return SVC_CLOSE;
-- 
2.54.0


                 reply	other threads:[~2026-09-25 15:13 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260925151343.529200-1-cel@kernel.org \
    --to=cel@kernel.org \
    --cc=dai.ngo@oracle.com \
    --cc=jlayton@kernel.org \
    --cc=linux-nfs@vger.kernel.org \
    --cc=neilb@ownmail.net \
    --cc=okorniev@redhat.com \
    --cc=tom@talpey.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox