xdr: clean up empty lines in .c and .h files
Split XDR into separate kernel module. Make krpc depend on xdr.Reviewed by: rmacklemDifferential Revision: https://reviews.freebsd.org/D24408
Move M_RPC malloc type into XDR. Both RPC and XDR libraries usethis type, but since RPC depends on XDR (not vice versa) we needit defined in XDR to make the module loadable without RPC.Reviewed
Move M_RPC malloc type into XDR. Both RPC and XDR libraries usethis type, but since RPC depends on XDR (not vice versa) we needit defined in XDR to make the module loadable without RPC.Reviewed by: rmacklemDifferential Revision: https://reviews.freebsd.org/D24408
show more ...
typo: s/impelmentation/implementation/.No functional change
sys: general adoption of SPDX licensing ID tags.Mainly focus on files that use BSD 2-Clause license, however the tool Iwas using misidentified many licenses so this was mostly a manual - errorpro
sys: general adoption of SPDX licensing ID tags.Mainly focus on files that use BSD 2-Clause license, however the tool Iwas using misidentified many licenses so this was mostly a manual - errorprone - task.The Software Package Data Exchange (SPDX) group provides a specificationto make it easier for automated tools to detect and summarize well knownopensource licenses. We are gradually adopting the specification, notingthat the tags are considered only advisory and do not, in any way,superceed or replace the license texts.No functional change intended.
* limit size of buffers to RPC_MAXDATASIZE * don't leak memory * be more picky about bad parametersFrom:https://raw.githubusercontent.com/guidovranken/rpcbomb/master/libtirpc_patch.txthttps://
* limit size of buffers to RPC_MAXDATASIZE * don't leak memory * be more picky about bad parametersFrom:https://raw.githubusercontent.com/guidovranken/rpcbomb/master/libtirpc_patch.txthttps://github.com/guidovranken/rpcbomb/blob/master/rpcbind_patch.txtvia NetBSD.Reviewed by: emaste, cem (earlier version)Differential Revision: https://reviews.freebsd.org/D10922MFC after: 3 days
RPC: for pointers replace 0 with NULL.These are mostly cosmetical, no functional change.Found with devel/coccinelle.
Use m_get() and m_getcl() instead of compat macros.
Finish r243882: mechanically substitute flags from historic mbufallocator with malloc(9) flags within sys.Sponsored by: Nginx, Inc.
Add a check for a NULL mbuf ptr at the beginning of xdrmbuf_inline()so that it returns failure instead of crashing when "m->m_len" isexecuted and m == NULL. The mbuf ptr can be NULL when a call to
Add a check for a NULL mbuf ptr at the beginning of xdrmbuf_inline()so that it returns failure instead of crashing when "m->m_len" isexecuted and m == NULL. The mbuf ptr can be NULL when a call toxdrmbuf_getbytes() gets the bytes it needs, but they are at the endof a short RPC reply. When this happens, xdrmbuf_getbytes() returnssuccess, but advances the mbuf ptr (xdrs->x_private) to m_next, whichis NULL. If this is followed by a call to xdrmbuf_getlong(), it callsxdrmbuf_inline(), which would cause a crash by accessing "m->m_len".Tested by: pho, serenity at exscape dot orgApproved by: re (rwatson), kib (mentor)
MFdevbranch 192944 - add FreeBSD implementation of xdrmem_control needed by zfs - have zfs define xdr_ops using FreeBSD's definition - remove solaris xdr files from zfs compile
Add memmove() to the kernel, making the kernel compile with Clang.When copying big structures, LLVM generates calls to memmove(), becauseit may not be able to figure out whether structures overlap
Add memmove() to the kernel, making the kernel compile with Clang.When copying big structures, LLVM generates calls to memmove(), becauseit may not be able to figure out whether structures overlap. This causedlinker errors to occur. memmove() is now implemented using bcopy().Ideally it would be the other way around, but that can be solved in thefuture. On ARM we don't do add anything, because it already hasmemmove().Discussed on: arch@Reviewed by: rdivacky
Use the remote address for access control, not the local address. This fixesthe nfsd problems that some people have with the new code.Add support for the vfs.nfsrv.nfs_privport sysctl which denies
Use the remote address for access control, not the local address. This fixesthe nfsd problems that some people have with the new code.Add support for the vfs.nfsrv.nfs_privport sysctl which denies access unlessthe client is using a port number less than 1024. Not really sure if this isparticularly useful since it doesn't add any real security.
Don't return a NULL mbuf from xdrmbuf_getall.
Implement support for RPCSEC_GSS authentication to both the NFS clientand server. This replaces the RPC implementation of the NFS client andserver with the newer RPC implementation originally devel
Implement support for RPCSEC_GSS authentication to both the NFS clientand server. This replaces the RPC implementation of the NFS client andserver with the newer RPC implementation originally developed(actually ported from the userland sunrpc code) to support the NFSLock Manager. I have tested this code extensively and I believe it isstable and that performance is at least equal to the legacy RPCimplementation.The NFS code currently contains support for both the new RPCimplementation and the older legacy implementation inherited from theoriginal NFS codebase. The default is to use the new implementation -add the NFS_LEGACYRPC option to fall back to the old code. When Imerge this support back to RELENG_7, I will probably change this sothat users have to 'opt in' to get the new code.To use RPCSEC_GSS on either client or server, you must build a kernelwhich includes the KGSSAPI option and the crypto device. On theuserland side, you must build at least a new libc, mountd, mount_nfsand gssd. You must install new versions of /etc/rc.d/gssd and/etc/rc.d/nfsd and add 'gssd_enable=YES' to /etc/rc.conf.As long as gssd is running, you should be able to mount an NFSfilesystem from a server that requires RPCSEC_GSS authentication. Themount itself can happen without any kerberos credentials but allaccess to the filesystem will be denied unless the accessing user hasa valid ticket file in the standard place (/tmp/krb5cc_<uid>). Thereis currently no support for situations where the ticket file is in adifferent place, such as when the user logged in via SSH and hasdelegated credentials from that login. This restriction is alsopresent in Solaris and Linux. In theory, we could improve this infuture, possibly using Brooks Davis' implementation of variantsymlinks.Supporting RPCSEC_GSS on a server is nearly as simple. You must createservice creds for the server in the form 'nfs/<fqdn>@<REALM>' andinstall them in /etc/krb5.keytab. The standard heimdal utility ktutilmakes this fairly easy. After the service creds have been created, youcan add a '-sec=krb5' option to /etc/exports and restart both mountdand nfsd.The only other difference an administrator should notice is that nfsddoesn't fork to create service threads any more. In normal operation,there will be two nfsd processes, one in userland waiting for TCPconnections and one in the kernel handling requests. The latterprocess will create as many kthreads as required - these should bevisible via 'top -H'. The code has some support for varying the numberof service threads according to load but initially at least, nfsd usesa fixed number of threads according to the value supplied to its '-n'option.Sponsored by: Isilon SystemsMFC after: 1 month
Add the new kernel-mode NFS Lock Manager. To use it instead of theuser-mode lock manager, build a kernel with the NFSLOCKD option andadd '-k' to 'rpc_lockd_flags' in rc.conf.Highlights include:
Add the new kernel-mode NFS Lock Manager. To use it instead of theuser-mode lock manager, build a kernel with the NFSLOCKD option andadd '-k' to 'rpc_lockd_flags' in rc.conf.Highlights include:* Thread-safe kernel RPC client - many threads can use the same RPC client handle safely with replies being de-multiplexed at the socket upcall (typically driven directly by the NIC interrupt) and handed off to whichever thread matches the reply. For UDP sockets, many RPC clients can share the same socket. This allows the use of a single privileged UDP port number to talk to an arbitrary number of remote hosts.* Single-threaded kernel RPC server. Adding support for multi-threaded server would be relatively straightforward and would follow approximately the Solaris KPI. A single thread should be sufficient for the NLM since it should rarely block in normal operation.* Kernel mode NLM server supporting cancel requests and granted callbacks. I've tested the NLM server reasonably extensively - it passes both my own tests and the NFS Connectathon locking tests running on Solaris, Mac OS X and Ubuntu Linux.* Userland NLM client supported. While the NLM server doesn't have support for the local NFS client's locking needs, it does have to field async replies and granted callbacks from remote NLMs that the local client has contacted. We relay these replies to the userland rpc.lockd over a local domain RPC socket.* Robust deadlock detection for the local lock manager. In particular it will detect deadlocks caused by a lock request that covers more than one blocking request. As required by the NLM protocol, all deadlock detection happens synchronously - a user is guaranteed that if a lock request isn't rejected immediately, the lock will eventually be granted. The old system allowed for a 'deferred deadlock' condition where a blocked lock request could wake up and find that some other deadlock-causing lock owner had beaten them to the lock.* Since both local and remote locks are managed by the same kernel locking code, local and remote processes can safely use file locks for mutual exclusion. Local processes have no fairness advantage compared to remote processes when contending to lock a region that has just been unlocked - the local lock manager enforces a strict first-come first-served model for both local and remote lockers.Sponsored by: Isilon SystemsPR: 95247 107555 115524 116679MFC after: 2 weeks