]> git.decadent.org.uk Git - nfs-utils.git/blob - utils/mountd/v4root.c
v4root: set the time-to-live for V4ROOT exports to the DEFAULT.
[nfs-utils.git] / utils / mountd / v4root.c
1 /*
2  * Copyright (C) 2009 Red Hat <nfs@redhat.com>
3  *
4  * support/export/v4root.c
5  *
6  * Routines used to support NFSv4 pseudo roots
7  *
8  */
9
10 #ifdef HAVE_CONFIG_H
11 #include <config.h>
12 #endif
13
14 #include <sys/types.h>
15 #include <sys/stat.h>
16 #include <sys/queue.h>
17 #include <stdio.h>
18 #include <stdlib.h>
19 #include <ctype.h>
20
21 #include <unistd.h>
22 #include <errno.h>
23
24 #include "xlog.h"
25 #include "exportfs.h"
26 #include "nfslib.h"
27 #include "misc.h"
28 #include "v4root.h"
29
30 int v4root_needed;
31
32 static nfs_export pseudo_root = {
33         .m_next = NULL,
34         .m_client = NULL,
35         .m_export = {
36                 .e_hostname = "*",
37                 .e_path = "/",
38                 .e_flags = NFSEXP_READONLY | NFSEXP_ROOTSQUASH
39                                 | NFSEXP_NOSUBTREECHECK | NFSEXP_FSID
40                                 | NFSEXP_V4ROOT,
41                 .e_anonuid = 65534,
42                 .e_anongid = 65534,
43                 .e_squids = NULL,
44                 .e_nsquids = 0,
45                 .e_sqgids = NULL,
46                 .e_nsqgids = 0,
47                 .e_fsid = 0,
48                 .e_mountpoint = NULL,
49                 .e_ttl = DEFAULT_TTL,
50         },
51         .m_exported = 0,
52         .m_xtabent = 1,
53         .m_mayexport = 1,
54         .m_changed = 0,
55         .m_warned = 0,
56 };
57
58 void set_pseudofs_security(struct exportent *pseudo, struct exportent *source)
59 {
60         struct sec_entry *se;
61         int i;
62
63         if (source->e_flags & NFSEXP_INSECURE_PORT)
64                 pseudo->e_flags |= NFSEXP_INSECURE_PORT;
65         for (se = source->e_secinfo; se->flav; se++) {
66                 struct sec_entry *new;
67
68                 i = secinfo_addflavor(se->flav, pseudo);
69                 new = &pseudo->e_secinfo[i];
70
71                 if (se->flags & NFSEXP_INSECURE_PORT)
72                         new->flags |= NFSEXP_INSECURE_PORT;
73         }
74 }
75
76 /*
77  * Create a pseudo export
78  */
79 static struct exportent *
80 v4root_create(char *path, nfs_export *export)
81 {
82         nfs_export *exp;
83         struct exportent eep;
84         struct exportent *curexp = &export->m_export;
85
86         dupexportent(&eep, &pseudo_root.m_export);
87         eep.e_hostname = curexp->e_hostname;
88         strncpy(eep.e_path, path, sizeof(eep.e_path));
89         if (strcmp(path, "/") != 0)
90                 eep.e_flags &= ~NFSEXP_FSID;
91         set_pseudofs_security(&eep, curexp);
92         exp = export_create(&eep, 0);
93         if (exp == NULL)
94                 return NULL;
95         xlog(D_CALL, "v4root_create: path '%s'", exp->m_export.e_path);
96         return &exp->m_export;
97 }
98
99 /*
100  * Make sure the kernel has pseudo root support.
101  */
102 static int
103 v4root_support(void)
104 {
105         struct export_features *ef;
106         static int warned = 0;
107
108         ef = get_export_features();
109
110         if (ef->flags & NFSEXP_V4ROOT)
111                 return 1;
112         if (!warned) {
113                 xlog(L_WARNING, "Kernel does not have pseudo root support.");
114                 xlog(L_WARNING, "NFS v4 mounts will be disabled unless fsid=0");
115                 xlog(L_WARNING, "is specfied in /etc/exports file.");
116                 warned++;
117         }
118         return 0;
119 }
120
121 int pseudofs_update(char *hostname, char *path, nfs_export *source)
122 {
123         nfs_export *exp;
124
125         exp = export_lookup(hostname, path, 0);
126         if (exp && !(exp->m_export.e_flags & NFSEXP_V4ROOT))
127                 return 0;
128         if (!exp) {
129                 if (v4root_create(path, source) == NULL) {
130                         xlog(L_WARNING, "v4root_set: Unable to create "
131                                         "pseudo export for '%s'", path);
132                         return -ENOMEM;
133                 }
134                 return 0;
135         }
136         /* Update an existing V4ROOT export: */
137         set_pseudofs_security(&exp->m_export, &source->m_export);
138         return 0;
139 }
140
141 static int v4root_add_parents(nfs_export *exp)
142 {
143         char *hostname = exp->m_export.e_hostname;
144         char *path;
145         char *ptr;
146
147         path = strdup(exp->m_export.e_path);
148         if (!path) {
149                 xlog(L_WARNING, "v4root_add_parents: Unable to create "
150                                 "pseudo export for '%s'", exp->m_export.e_path);
151                 return -ENOMEM;
152         }
153         for (ptr = path + 1; ptr; ptr = strchr(ptr, '/')) {
154                 int ret;
155                 char saved;
156
157                 saved = *ptr;
158                 *ptr = '\0';
159                 ret = pseudofs_update(hostname, path, exp);
160                 if (ret)
161                         return ret;
162                 *ptr = saved;
163                 ptr++;
164         }
165         free(path);
166         return 0;
167 }
168
169 /*
170  * Create pseudo exports by running through the real export
171  * looking at the components of the path that make up the export.
172  * Those path components, if not exported, will become pseudo
173  * exports allowing them to be found when the kernel does an upcall
174  * looking for components of the v4 mount.
175  */
176 void
177 v4root_set()
178 {
179         nfs_export      *exp;
180         int     i;
181
182         if (!v4root_needed)
183                 return;
184         if (!v4root_support())
185                 return;
186
187         for (i = 0; i < MCL_MAXTYPES; i++) {
188                 for (exp = exportlist[i].p_head; exp; exp = exp->m_next) {
189                         if (exp->m_export.e_flags & NFSEXP_V4ROOT)
190                                 /*
191                                  * We just added this one, so its
192                                  * parents are already dealt with!
193                                  */
194                                 continue;
195
196                         if (strcmp(exp->m_export.e_path, "/") == 0 &&
197                             !(exp->m_export.e_flags & NFSEXP_FSID)) {
198                                 /* Force '/' to be exported as fsid == 0*/
199                                 exp->m_export.e_flags |= NFSEXP_FSID;
200                                 exp->m_export.e_fsid = 0;
201                         }
202
203                         v4root_add_parents(exp);
204                         /* XXX: error handling! */
205                 }
206         }
207 }