From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f44.google.com (mail-wm1-f44.google.com [209.85.128.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 52DC137AA7E for ; Fri, 14 Aug 2026 20:35:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.44 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786739705; cv=none; b=hL3B2yrGbd0PnM7ILJc4BmodIhyRA8WLFs1V7u+KnrAoOPzDc+NleklTL6akOEwrosJ+eIqDeuu789rNN2mxnlXWy46UpI4FF/a+7McMt6GrL87fMQCmT5paGy0m+hFMNmUeyd9eOrHles7ytZOdZyjf1Jk4MrNqbyGgrkyxbQA= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786739705; c=relaxed/simple; bh=Y0DnnLCKrn4UR+viD2LnHKNQzSrMQ4oyX6cKdGqCwBk=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=X2yqMmLm6N7x9rlXfqIx0jigf1BbMLE1RT3bz9wN4NRwsFkFV/gtgelIwv4fxTBRTV5zUd26/3Fol6Zt8u+JbgIeXvfEm/C6Mwskin/bu/FxrCUfIP1S3qctchxpyTKPGBaBe5pWAl/Kjkm1+oNkboQZYIoL9BUIKdth6HPCinA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=truenas.com; spf=pass smtp.mailfrom=truenas.com; dkim=pass (2048-bit key) header.d=truenas.com header.i=@truenas.com header.b=Xr5OP1UJ; arc=none smtp.client-ip=209.85.128.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=truenas.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=truenas.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=truenas.com header.i=@truenas.com header.b="Xr5OP1UJ" Received: by mail-wm1-f44.google.com with SMTP id 5b1f17b1804b1-49800c6a846so15663235e9.3 for ; Fri, 14 Aug 2026 13:35:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=truenas.com; s=google; t=1786739701; x=1787344501; darn=vger.kernel.org; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=Uakh9dheobahKr2bQxAdnTzBionUCo0AbbTF93Cw6r0=; b=Xr5OP1UJzA/Qg4sPxYWRqc61DA+MPQclWcU0DzI180sS8Z9jjcUOyrtZjOXPIR+/5w ZmGXl5yfh15o71PohxKv1l4dtOYDD2VaxjSBUCUgkLa/PhHv4QJkqbyULvmoyZR8Xhbh oKPADuu7FKF7lCEdU+Cap0H13Jt694XKQYRFutEOMhh4jsrQfZpInUWGhP6L2hIf8RGi +CiOgi6ZA6bUPnOHe+ZBQzoncnpzL1KdpsSqNR3rcm8U5VxJJAdsi8VWe4LvNHxxBvk6 OwW6DqPLdDG1EPr+A41/Pa20kMWWfd90bLiOZHzK9SShNhLRO4i+V8amTHifh7SQ8FUS cC8g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786739701; x=1787344501; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Uakh9dheobahKr2bQxAdnTzBionUCo0AbbTF93Cw6r0=; b=g9cuVmVNsmw05jnkcESGvAPDfxy5vOI3VhFfrcuo2enXScnYQe2boDoEI4wolU9ou7 PsDH0ZraPH/r4oV/m1rLlndQfbdN/HAdrVCeR2+8dkperLXDzDjLsk74ThKvJLebLmWJ u0fu5FaJ4PzxUIiilRAvSFChzVwrPPSJ2wE8g4DDdbYPv8UntgIccvMsSsRR6kWNw7tt ihomp6K+0XL2CqkVQLHJXrbN7NhRNOQLgqPTLNc0ip6NBdYdhU/bdUVBbfRVtN2QqFCO JtGE5CAaBbvMDIAufnkywVxYHpV5F7MjJeebHYY2LHRXEegadnrLxDPnEq63VgpZt17G CvhA== X-Forwarded-Encrypted: i=1; AHgh+RoeAI6zQjfWF/rpQ051s98MK4SNx7afH3eAybyu7aLKbi4eViH5cKjU5+8LFAOEXXQSyw02xfjCzFcg3vw=@vger.kernel.org X-Gm-Message-State: AOJu0Yyz7LpI0F6EZX5LmyUIW2eQwF7DUu/k6JQB8j/gSl88ucOX+dN0 9O9iIlM0t1KfU4MB6jYZjYIh4LnPM5AvULdwgh/8CRCXfhe6Gd+FAqjdB4fgevib7Q== X-Gm-Gg: AR+sD102ymH4Vw7ahWwzUmSPNVZmn2Bf6f6p6ckVB8MZidCPDzH6gEm8sIGQi+ErxDX OmXlXiEUUcz+L703ccVj8bJPpauf+VZnU7amPk6AJVAmv//xtZRtzRzQh86ISfLF1tvHfZwn4Mp 0G1G3WaNV6j2UR1TpZacpDxV8UKBt1V2L4JxsANBCo6Z1fGFYaqtld4om0FGOrLzJubfRnQ9Xvf M1w3lJYUb/VtfbflmRm9m+GOVVSMALJ9NXpVMalDO6FkJNe1WsWUxDKi648x7JdUGA9JaIJlCmC NzFDL7N3dgNBdURDndD2EYkLT8Dh43ltHRKyixISPm/mEnlAbE1xkSK1WD+Pm66x3AiUd4Ue0PX FLlIhmWWLhSVk57jieNHFpAB+smL6YeqmG5uoDfnYoMOAbcOMfOZGWmx5FkDqG9T4iZUz7xYNPB mzD2Dd42+Ghk2dpjZq6Hr4yRvmLcBccvfJFINRSg0hlhI8iQJerjs= X-Received: by 2002:a05:600d:8489:20b0:499:8b13:3a98 with SMTP id 5b1f17b1804b1-4998b133b3dmr44499635e9.4.1786739701433; Fri, 14 Aug 2026 13:35:01 -0700 (PDT) Received: from hamza-PC ([2400:adc1:158:c700::1]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4998777d428sm51134315e9.0.2026.08.14.13.34.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 14 Aug 2026 13:35:00 -0700 (PDT) Date: Sat, 15 Aug 2026 01:34:56 +0500 From: Ameer Hamza To: Chuck Lever Cc: Jeff Layton , NeilBrown , Olga Kornievskaia , Dai Ngo , Tom Talpey , linux-nfs@vger.kernel.org, linux-kernel@vger.kernel.org, alexander.motin@truenas.com, caleb.stjohn@truenas.com Subject: Re: [PATCH] sunrpc: treat empty auth.unix.gid replies as negative entries Message-ID: References: <20260814172507.1474519-1-ameer.hamza@truenas.com> <032eae35-e958-4c87-9185-3896250eb7e1@app.fastmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <032eae35-e958-4c87-9185-3896250eb7e1@app.fastmail.com> On Fri, Aug 14, 2026 at 04:02:23PM -0400, Chuck Lever wrote: > > > On Fri, Aug 14, 2026, at 1:25 PM, Ameer Hamza wrote: > > When rpc.mountd cannot resolve a uid (getpwuid() or getgrouplist() > > failure, e.g. while winbind or sssd is briefly unreachable), it > > answers the auth.unix.gid upcall with zero groups. unix_gid_parse() > > installs that as a valid positive entry, and svcauth_unix_set_client() > > then replaces the credential's group list with the empty one on > > every request, RPCSEC_GSS included via svcauth_gss_set_client(). > > One failed lookup strips that uid of all supplementary groups on > > every export for up to mountd's configured TTL (30 minutes by > > default), long after the NSS backend has recovered. > > > > mountd cannot send an empty list for a successful lookup, since > > getgrouplist(3) always includes at least the user's primary group, > > so a zero-group reply can only mean the lookup failed. Record it as > > a negative entry: unix_gid_find() then returns -ENOENT and > > svcauth_unix_set_client() keeps the groups the RPC credential > > already carries. This is the fallback that > > commit 3fc605a2aa38 ("[PATCH] knfsd: allow the server to provide a > > gid list when using AUTH_UNIX authentication") promised when no > > answer is available, and the same state try_to_negate_entry() > > already creates when no listener holds the channel open. > > > > Fixes: 3fc605a2aa38 ("[PATCH] knfsd: allow the server to provide a gid > > list when using AUTH_UNIX authentication") > > Assisted-by: Claude:claude-fable-5 > > Signed-off-by: Ameer Hamza > > Looks like the same bug exists for the new mountd netlink > mechanism. Since that instance of the bug arrived in a > different commit, that fix needs to be a separate patch > with its own Fixes: tag. > > Can you make this a two-patch series? > > > -- > Chuck Lever Sure, will send v2 with the netlink fix as a separate patch. Thanks for taking a look.