From: Pranjal Shrivastava <praan@google.com>
To: linux-nfs@vger.kernel.org, Trond Myklebust <trondmy@kernel.org>,
Anna Schumaker <anna@kernel.org>
Cc: Chuck Lever <cel@kernel.org>, Jeff Layton <jlayton@kernel.org>,
linux-kernel@vger.kernel.org, Christoph Hellwig <hch@lst.de>,
Logan Gunthorpe <logang@deltatee.com>,
Jason Gunthorpe <jgg@ziepe.ca>,
linux-pci@vger.kernel.org, linux-rdma@vger.kernel.org,
Shivaji Kant <shivajikant@google.com>,
Tom Talpey <tom@talpey.com>, Leon Romanovsky <leon@kernel.org>,
Unnati Sachan <unnatisachan@google.com>,
Pranjal Shrivastava <praan@google.com>
Subject: [RFC PATCH v1 6/8] nfs: refuse P2PDMA pages with krb5i and krb5p
Date: Tue, 6 Oct 2026 23:32:46 +0000 [thread overview]
Message-ID: <20261006233248.705086-7-praan@google.com> (raw)
In-Reply-To: <20261006233248.705086-1-praan@google.com>
krb5i checksums and krb5p encrypts the payload via CPU accesses
while the RPC is encoded, before the transport can refuse it.
Fail such READs and WRITEs with -EREMOTEIO in nfs_pgio_prepare(),
before encoding. Check the task's RPC client, which for a WRITE may
be the krb5i client that SP4_MACH_CRED swaps in.
Signed-off-by: Pranjal Shrivastava <praan@google.com>
---
fs/nfs/pagelist.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/fs/nfs/pagelist.c b/fs/nfs/pagelist.c
index 3ec4e1e5fe1f..ec535ed3051d 100644
--- a/fs/nfs/pagelist.c
+++ b/fs/nfs/pagelist.c
@@ -771,6 +771,14 @@ static void nfs_pgio_prepare(struct rpc_task *task, void *calldata)
{
struct nfs_pgio_header *hdr = calldata;
int err;
+
+ /* P2PDMA payloads move only by DMA */
+ if (hdr->args.p2pdma &&
+ test_bit(RPCAUTH_AUTH_DATATOUCH,
+ &task->tk_client->cl_auth->au_flags)) {
+ rpc_exit(task, -EREMOTEIO);
+ return;
+ }
err = NFS_PROTO(hdr->inode)->pgio_rpc_prepare(task, hdr);
if (err)
rpc_exit(task, err);
--
2.56.0.rc1.315.gc6ed9934b7-goog
next prev parent reply other threads:[~2026-10-06 23:33 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-06 23:32 [RFC PATCH v1 0/8] nfs: PCI P2PDMA for O_DIRECT over RDMA Pranjal Shrivastava
2026-10-06 23:32 ` [RFC PATCH v1 1/8] sunrpc: introduce XDRBUF_P2PDMA flag Pranjal Shrivastava
2026-10-06 23:32 ` [RFC PATCH v1 2/8] sunrpc: fail only the RPC a transport refuses Pranjal Shrivastava
2026-10-06 23:32 ` [RFC PATCH v1 3/8] xprtrdma: move P2PDMA payloads only via chunks Pranjal Shrivastava
2026-10-06 23:32 ` [RFC PATCH v1 4/8] xprtrdma: return -EREMOTEIO on P2PDMA map failure Pranjal Shrivastava
2026-10-06 23:32 ` [RFC PATCH v1 5/8] nfs: tag READ/WRITE RPCs carrying P2PDMA pages Pranjal Shrivastava
2026-10-06 23:32 ` Pranjal Shrivastava [this message]
2026-10-06 23:32 ` [RFC PATCH v1 7/8] nfs: allow LOCALIO for P2PDMA pages only as aligned direct I/O Pranjal Shrivastava
2026-10-06 23:32 ` [RFC PATCH v1 8/8] nfs: allow P2PDMA pages for O_DIRECT on RDMA mounts Pranjal Shrivastava
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261006233248.705086-7-praan@google.com \
--to=praan@google.com \
--cc=anna@kernel.org \
--cc=cel@kernel.org \
--cc=hch@lst.de \
--cc=jgg@ziepe.ca \
--cc=jlayton@kernel.org \
--cc=leon@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-nfs@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=linux-rdma@vger.kernel.org \
--cc=logang@deltatee.com \
--cc=shivajikant@google.com \
--cc=tom@talpey.com \
--cc=trondmy@kernel.org \
--cc=unnatisachan@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®