Path: csiph.com!fu-berlin.de!bofh.it!news.nic.it!robomod From: Sven Joachim Newsgroups: linux.debian.bugs.dist,linux.debian.kernel Subject: Bug#1041147: nfs-kernel-server: fsidd creates /fsid.sock Date: Sat, 15 Jul 2023 09:30:01 +0200 Message-ID: References: X-Mailbox-Line: From debian-bugs-dist-request@lists.debian.org Sat Jul 15 07:24:11 2023 Old-Return-Path: X-Spam-Flag: NO X-Spam-Score: -1.91 Reply-To: Sven Joachim , 1041147@bugs.debian.org Resent-To: debian-bugs-dist@lists.debian.org Resent-Cc: Debian kernel team X-Debian-Pr-Message: followup 1041147 X-Debian-Pr-Package: nfs-kernel-server X-Debian-Pr-Source: nfs-utils X-Ui-Sender-Class: 724b4f7f-cbec-4199-ad4e-598c01a50d3a User-Agent: Gnus/5.13 (Gnus v5.13) MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="=-=-=" X-Provags-ID: V03:K1:Hx2/ayywROObKCJRFGx07qXpC8iBgj+Qass/9a9Yh3+RZ+kvQiU naKK3xtqDgVhpxf/BaLpRKPSA9HA4rR1pqmTJNA6hhVc3RwxdxAHGPwWg2wkSUu5Pp2O2bd Id2egogl3Uw+JyZd5Ip4+IBfZdgQDufzsvOwYUoFG3lBA/VRb0tN2wvqpPuy8wQygoH2yH/ 9cO4m21zvdJd7Y0X1pFbA== Ui-Outboundreport: notjunk:1;M01:P0:kQ5qGi1iEq8=;DnVaGevqGN2OKxGQnSY0f78sRc5 PGLPAaNbjMTOdyAVzQ/wah76UsqC0VbJEmC5wV6iaZvac+J1dk0c9ghHdPwAx7/oHS5S6z74u NZVRNMCUBakkVu1V5bpPlBLimq8ZbEF8qAN/Ov2BANDgyEmWeByxZSo3Hw+VnToPrHjeoG05O rDnonb18Qsq4rnwX9cK+1GVsChQOrwyFHYXGe2rgY2wACoWIATQU8jfnWmTropL52WihLUF1v UaJGjdCkZcH0KngXqI4MBAxy4ntV3HpS4ODhPjl3ECaSdBdOkiWvs3zr/UbbK/XU3RtNIaRLB uK8oeJN2/QOsMk6/ZQdIt9Iy6yXawLCYwlqZZgHV/ZKu5oXZ5VwcHQzgNfpZ0mb5UEGFg43sy 04IjgRqRJUEfFfsf/pdFEP3GgmVN3WmtuqkfBJUbJAsoca/uXvST5JSNBehzNQ7eIeDFT/WeA yIOM3ieq1z3GKF5VcBwzvIYmcl2i0U9tdSbHgLIASmF0FJ+WhOCpVf4p2INtnyTTodYKNC11Y BdShrVxgZR341B0VDxuf3eGA9ai7PWnojdnLkcEvltMy6uKgVdOi4X6XbLHCYs2ipheJqAfV4 WFJQ14TPjrHOvWxfq/P9KqlP/Q+PwY+ps6DX78tGPi1F73SeACwR5s6EeZNr2DQbeQoa7DYXS bdkuP2uQPUEKypOMhMRaE4GE/aWRTQhdreqsUMLLHYteUOffkDol6f0+CNAshXLv0cKy7E5f0 Jsjmx/cKZl1sq85BPCOg/qf+lTG17qoGnYp//dvEIGl3jCUOTKA+rNdWVIzuAXMOV4re+gZKJ R/qy5XW657CCZirPonQavIJrDm5hA3chS/FPnXSuQiKX9+Eo5NDy8qXewTDwWRLAMwfDsEkID 7RR7+4ao09jBVNFJQNY7zi/ipCbffZv4NTDhe+qd0gwPgKebd8iV+nNs4IRKlNbzfSnvp5ADx lRoe+iv0pkI7QZ9gWe7pkxThyoY= X-Debian-Message: from BTS X-Mailing-List: archive/latest/1780625 List-ID: List-URL: Approved: robomod@news.nic.it Lines: 129 Organization: linux.* mail to news gateway Sender: robomod@news.nic.it X-Original-Date: Sat, 15 Jul 2023 09:20:06 +0200 X-Original-Message-ID: <87y1jhod3t.fsf@turtle.gmx.de> X-Original-References: <87a5vxpua1.fsf@turtle.gmx.de> <87a5vxpua1.fsf@turtle.gmx.de> Xref: csiph.com linux.debian.bugs.dist:1154309 linux.debian.kernel:79605 --=-=-= Content-Type: text/plain On 2023-07-15 08:23 +0200, Sven Joachim wrote: > Package: nfs-kernel-server > Version: 1:2.6.3-1 > > On my system I found a top level socket /fsid.sock which is created by > /lib/systemd/system/fsidd.service. This is obviously not the right > place for the socket, it should be put under /run. > > In the upstream git repository I have found a patch[1] which I will try > and report back, if nobody beats me to it. > > 1. http://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=e00ab3c0616fe6d83ab0710d9e7d989c299088f7 Adding that patch to the series file worked well for me, I am attaching it for your convenience. However, the now unused socket /fsid.sock remained on the system, so it should be cleaned up by the postinst script. --=-=-= Content-Type: text/x-diff Content-Disposition: inline; filename=0001-fsidd-provide-better-default-socket-name.patch Content-Transfer-Encoding: quoted-printable =46rom e00ab3c0616fe6d83ab0710d9e7d989c299088f7 Mon Sep 17 00:00:00 2001 From: NeilBrown Date: Thu, 11 May 2023 14:26:47 -0400 Subject: [PATCH] fsidd: provide better default socket name. Having the default socket name be in the current directory is a poor choice for a daemon that is expected to run as root. It is also likely better to use an "abstract" socket name. abstract names do not exist in the filesystem namespace and are local to a network namespace. Using an abstract name ensures that the nfsd, mountd, and fsidd are all in the same network namespace. This patch: - uses a single #define for the default socket name, rather than 2; - allows the socket name to start with '@' which is interpreted to be a request to use the abstract name space (systemd uses the same convention). - changes the default to "@/run/fsid.sock". I don't know of a formal standard for choosing names in the abstract name space, the defacto standard (seen in "ss -xa|grep @") is to use a name similar to what might be used in the filesystem. Acked-by: Richard Weinberger Signed-off-by: NeilBrown Signed-off-by: Steve Dickson =2D-- support/reexport/fsidd.c | 10 ++++++---- support/reexport/reexport.c | 3 +++ support/reexport/reexport.h | 2 +- 3 files changed, 10 insertions(+), 5 deletions(-) diff --git a/support/reexport/fsidd.c b/support/reexport/fsidd.c index 3fef1ef3..37649d06 100644 =2D-- a/support/reexport/fsidd.c +++ b/support/reexport/fsidd.c @@ -18,11 +18,10 @@ #include "conffile.h" #include "reexport_backend.h" +#include "reexport.h" #include "xcommon.h" #include "xlog.h" -#define FSID_SOCKET_NAME "fsid.sock" - static struct event_base *evbase; static struct reexpdb_backend_plugin *dbbackend =3D &sqlite_plug_ops; @@ -167,11 +166,14 @@ int main(void) sock_file =3D conf_get_str_with_def("reexport", "fsidd_socket", FSID_SOC= KET_NAME); - unlink(sock_file); - memset(&addr, 0, sizeof(struct sockaddr_un)); addr.sun_family =3D AF_UNIX; strncpy(addr.sun_path, sock_file, sizeof(addr.sun_path) - 1); + if (addr.sun_path[0] =3D=3D '@') + /* "abstract" socket namespace */ + addr.sun_path[0] =3D 0; + else + unlink(sock_file); srv =3D socket(AF_UNIX, SOCK_SEQPACKET | SOCK_NONBLOCK, 0); if (srv =3D=3D -1) { diff --git a/support/reexport/reexport.c b/support/reexport/reexport.c index eddc9bf4..d597a2f7 100644 =2D-- a/support/reexport/reexport.c +++ b/support/reexport/reexport.c @@ -38,6 +38,9 @@ static bool connect_fsid_service(void) memset(&addr, 0, sizeof(struct sockaddr_un)); addr.sun_family =3D AF_UNIX; strncpy(addr.sun_path, sock_file, sizeof(addr.sun_path) - 1); + if (addr.sun_path[0] =3D=3D '@') + /* "abstract" socket namespace */ + addr.sun_path[0] =3D 0; s =3D socket(AF_UNIX, SOCK_SEQPACKET, 0); if (s =3D=3D -1) { diff --git a/support/reexport/reexport.h b/support/reexport/reexport.h index 3bed03a9..856c3085 100644 =2D-- a/support/reexport/reexport.h +++ b/support/reexport/reexport.h @@ -13,6 +13,6 @@ int reexpdb_fsidnum_by_path(char *path, uint32_t *fsidnu= m, int may_create); int reexpdb_apply_reexport_settings(struct exportent *ep, char *flname, i= nt flline); void reexpdb_uncover_subvolume(uint32_t fsidnum); -#define FSID_SOCKET_NAME "fsid.sock" +#define FSID_SOCKET_NAME "@/run/fsid.sock" #endif /* REEXPORT_H */ =2D- 2.40.1 --=-=-=--