* [PATCH RFC v3 0/5] NFS: isolate mTLS client credentials by network namespace
@ 2026-10-06 15:24 Chuck Lever
2026-10-06 15:24 ` [PATCH RFC v3 1/5] NFS: name the init_nfs_fs() error labels Chuck Lever
0 siblings, 1 reply; 2+ messages in thread
From: Chuck Lever @ 2026-10-06 15:24 UTC (permalink / raw)
To: Trond Myklebust, Anna Schumaker, David S. Miller, Jakub Kicinski,
Paolo Abeni, Simon Horman, Jonathan Corbet, Shuah Khan,
Randy Dunlap, Christian Brauner, David Howells, Sagi Grimberg,
Eric Dumazet
Cc: linux-nfs, keyrings, kernel-tls-handshake, netdev, linux-doc,
Chuck Lever
An xprtsec=mtls mount names its client certificate and private key
by keyring serial number. tlshd reads those keys with its own
credentials. Each key has to grant user read permission, and any
tlshd on the host that learns a serial number can read it.
The RFC thread asked whether the user or mount namespace is a
better binding than the network namespace. tlshd services the
handshake socket of one network namespace, so that is the namespace
tlshd already lives in.
https://lore.kernel.org/linux-nfs/20260602154740.49861-1-cel@kernel.org/
After this series each network namespace has its own .nfs keyring,
and the keyring's serial number travels with each handshake (patches
3-4). Possessing that keyring lets tlshd read a key that does not
grant user read permission. tls_handshake_accept() and tlshd already
link a keyring named in the handshake. The handshake genetlink ABI
and the cert_serial= and privkey_serial= mount options are not
changed.
The owner of the network namespace's user namespace now owns the
keyring, so global root on the host cannot write to a container's
keyring from outside.
nfstlskey, the provisioning tool that consumes the key type, is in
https://github.com/linux-nfs/ktls-utils/ .
Tested on v7.3-rc4 plus this series, on one Fedora VM as both NFS
client and NFSD, with tlshd from ktls-utils 1.4.0.
---
Changes in v3:
- Rebased on v7.3-rc6
- No reviews received; stripped the "RFC" Subject prefix
- Link to v2: https://patch.msgid.link/20260925-nfs-mtls-identity-v2-0-aa3ad17dd6c8@kernel.org
Changes in v2:
- Write "serial number" rather than "serial" throughout (Randy)
- Give the .nfs keyring to the netns's user_ns owner (sashiko)
- Link to v1: https://patch.msgid.link/20260918-nfs-mtls-identity-v1-0-197e568d78a7@kernel.org
---
Chuck Lever (5):
NFS: name the init_nfs_fs() error labels
NFS: allocate the .nfs keyring per network namespace
SUNRPC: pass a keyring serial number to the TLS handshake
NFS: name the namespace .nfs keyring in the x509 handshake
NFS: add a key type that reveals the namespace .nfs keyring serial number
Documentation/filesystems/nfs/index.rst | 1 +
Documentation/filesystems/nfs/keyring.rst | 69 ++++++++++
fs/nfs/client.c | 9 +-
fs/nfs/fs_context.c | 1 +
fs/nfs/inode.c | 211 ++++++++++++++++++++++--------
fs/nfs/netns.h | 9 ++
fs/nfs/nfs3client.c | 1 +
fs/nfs/nfs4client.c | 1 +
include/linux/sunrpc/xprt.h | 1 +
net/sunrpc/xprtsock.c | 1 +
10 files changed, 248 insertions(+), 56 deletions(-)
---
base-commit: a90ee4305c4a5df72c11b31dacfdc76e00fcf78a
change-id: 20260917-nfs-mtls-identity-04c14f6f348d
Best regards,
--
Chuck Lever <cel@kernel.org>
^ permalink raw reply [flat|nested] 2+ messages in thread* [PATCH RFC v3 1/5] NFS: name the init_nfs_fs() error labels
2026-10-06 15:24 [PATCH RFC v3 0/5] NFS: isolate mTLS client credentials by network namespace Chuck Lever
@ 2026-10-06 15:24 ` Chuck Lever
0 siblings, 0 replies; 2+ messages in thread
From: Chuck Lever @ 2026-10-06 15:24 UTC (permalink / raw)
To: Trond Myklebust, Anna Schumaker, David S. Miller, Jakub Kicinski,
Paolo Abeni, Simon Horman, Jonathan Corbet, Shuah Khan,
Randy Dunlap, Christian Brauner, David Howells, Sagi Grimberg,
Eric Dumazet
Cc: linux-nfs, keyrings, kernel-tls-handshake, netdev, linux-doc,
Chuck Lever
The unwind labels in init_nfs_fs() are numbered, and the numbering
already skips out8, so a reader has to count the label block to
learn what each one undoes. Inserting an init step means either
renumbering every label below it or leaving the sequence out of
order, and a goto that picks the wrong number unwinds the wrong
step.
Name each label for the step it undoes, as coding-style.rst asks.
Signed-off-by: Chuck Lever <cel@kernel.org>
---
fs/nfs/inode.c | 40 ++++++++++++++++++++--------------------
1 file changed, 20 insertions(+), 20 deletions(-)
diff --git a/fs/nfs/inode.c b/fs/nfs/inode.c
index 3022454f7698..832923be43a9 100644
--- a/fs/nfs/inode.c
+++ b/fs/nfs/inode.c
@@ -2722,64 +2722,64 @@ static int __init init_nfs_fs(void)
err = nfs_sysfs_init();
if (err < 0)
- goto out10;
+ goto err_keyring;
err = register_pernet_subsys(&nfs_net_ops);
if (err < 0)
- goto out9;
+ goto err_sysfs;
err = nfsiod_start();
if (err)
- goto out7;
+ goto err_pernet;
err = nfs_fs_proc_init();
if (err)
- goto out6;
+ goto err_nfsiod;
err = nfs_init_nfspagecache();
if (err)
- goto out5;
+ goto err_proc;
err = nfs_init_inodecache();
if (err)
- goto out4;
+ goto err_nfspagecache;
err = nfs_init_readpagecache();
if (err)
- goto out3;
+ goto err_inodecache;
err = nfs_init_writepagecache();
if (err)
- goto out2;
+ goto err_readpagecache;
err = nfs_init_directcache();
if (err)
- goto out1;
+ goto err_writepagecache;
err = register_nfs_fs();
if (err)
- goto out0;
+ goto err_directcache;
return 0;
-out0:
+err_directcache:
nfs_destroy_directcache();
-out1:
+err_writepagecache:
nfs_destroy_writepagecache();
-out2:
+err_readpagecache:
nfs_destroy_readpagecache();
-out3:
+err_inodecache:
nfs_destroy_inodecache();
-out4:
+err_nfspagecache:
nfs_destroy_nfspagecache();
-out5:
+err_proc:
nfs_fs_proc_exit();
-out6:
+err_nfsiod:
nfsiod_stop();
-out7:
+err_pernet:
unregister_pernet_subsys(&nfs_net_ops);
-out9:
+err_sysfs:
nfs_sysfs_exit();
-out10:
+err_keyring:
nfs_exit_keyring();
return err;
}
--
2.55.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-06 15:24 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-06 15:24 [PATCH RFC v3 0/5] NFS: isolate mTLS client credentials by network namespace Chuck Lever
2026-10-06 15:24 ` [PATCH RFC v3 1/5] NFS: name the init_nfs_fs() error labels Chuck Lever
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox