nfsd: let "insecure" flag vary by pseudoflavor
[deliverable/linux.git] / include / linux / nfsd / export.h
CommitLineData
1da177e4
LT
1/*
2 * include/linux/nfsd/export.h
3 *
4 * Public declarations for NFS exports. The definitions for the
5 * syscall interface are in nfsctl.h
6 *
7 * Copyright (C) 1995-1997 Olaf Kirch <okir@monad.swb.de>
8 */
9
10#ifndef NFSD_EXPORT_H
11#define NFSD_EXPORT_H
12
1da177e4 13# include <linux/types.h>
3187cedf 14#ifdef __KERNEL__
72579ac9 15# include <linux/nfsd/nfsfh.h>
1da177e4
LT
16#endif
17
18/*
19 * Important limits for the exports stuff.
20 */
21#define NFSCLNT_IDMAX 1024
22#define NFSCLNT_ADDRMAX 16
23#define NFSCLNT_KEYMAX 32
24
25/*
26 * Export flags.
27 */
28#define NFSEXP_READONLY 0x0001
29#define NFSEXP_INSECURE_PORT 0x0002
30#define NFSEXP_ROOTSQUASH 0x0004
31#define NFSEXP_ALLSQUASH 0x0008
32#define NFSEXP_ASYNC 0x0010
33#define NFSEXP_GATHERED_WRITES 0x0020
34/* 40 80 100 currently unused */
35#define NFSEXP_NOHIDE 0x0200
36#define NFSEXP_NOSUBTREECHECK 0x0400
37#define NFSEXP_NOAUTHNLM 0x0800 /* Don't authenticate NLM requests - just trust */
38#define NFSEXP_MSNFS 0x1000 /* do silly things that MS clients expect */
39#define NFSEXP_FSID 0x2000
40#define NFSEXP_CROSSMOUNT 0x4000
41#define NFSEXP_NOACL 0x8000 /* reserved for possible ACL related use */
e8e8753f
BF
42/* All flags that we claim to support. (Note we don't support NOACL.) */
43#define NFSEXP_ALLFLAGS 0x7E3F
1da177e4 44
e677bfe4 45/* The flags that may vary depending on security flavor: */
1269bc69 46#define NFSEXP_SECINFO_FLAGS (NFSEXP_READONLY | NFSEXP_ROOTSQUASH \
12045a6e
BF
47 | NFSEXP_ALLSQUASH \
48 | NFSEXP_INSECURE_PORT)
1da177e4
LT
49
50#ifdef __KERNEL__
51
93346919
MN
52/*
53 * FS Locations
54 */
55
56#define MAX_FS_LOCATIONS 128
57
58struct nfsd4_fs_location {
59 char *hosts; /* colon separated list of hosts */
60 char *path; /* slash separated list of path components */
61};
62
63struct nfsd4_fs_locations {
64 uint32_t locations_count;
65 struct nfsd4_fs_location *locations;
66/* If we're not actually serving this data ourselves (only providing a
67 * list of replicas that do serve it) then we set "migrated": */
68 int migrated;
69};
70
e677bfe4
AA
71/*
72 * We keep an array of pseudoflavors with the export, in order from most
73 * to least preferred. For the forseeable future, we don't expect more
74 * than the eight pseudoflavors null, unix, krb5, krb5i, krb5p, skpm3,
75 * spkm3i, and spkm3p (and using all 8 at once should be rare).
76 */
77#define MAX_SECINFO_LIST 8
78
79struct exp_flavor_info {
80 u32 pseudoflavor;
81 u32 flags;
82};
83
1da177e4
LT
84struct svc_export {
85 struct cache_head h;
86 struct auth_domain * ex_client;
87 int ex_flags;
54775491
JB
88 struct path ex_path;
89 char *ex_pathname;
1da177e4
LT
90 uid_t ex_anon_uid;
91 gid_t ex_anon_gid;
92 int ex_fsid;
af6a4e28 93 unsigned char * ex_uuid; /* 16 byte fsid */
93346919 94 struct nfsd4_fs_locations ex_fslocs;
e677bfe4
AA
95 int ex_nflavors;
96 struct exp_flavor_info ex_flavors[MAX_SECINFO_LIST];
1da177e4
LT
97};
98
99/* an "export key" (expkey) maps a filehandlefragement to an
af6a4e28
N
100 * svc_export for a given client. There can be several per export,
101 * for the different fsid types.
1da177e4
LT
102 */
103struct svc_expkey {
104 struct cache_head h;
105
106 struct auth_domain * ek_client;
107 int ek_fsidtype;
af6a4e28 108 u32 ek_fsid[6];
1da177e4 109
e83aece3 110 struct path ek_path;
1da177e4
LT
111};
112
1da177e4 113#define EX_ISSYNC(exp) (!((exp)->ex_flags & NFSEXP_ASYNC))
1da177e4
LT
114#define EX_NOHIDE(exp) ((exp)->ex_flags & NFSEXP_NOHIDE)
115#define EX_WGATHER(exp) ((exp)->ex_flags & NFSEXP_GATHERED_WRITES)
116
c7d51402 117int nfsexp_flags(struct svc_rqst *rqstp, struct svc_export *exp);
32c1eb0c 118__be32 check_nfsd_access(struct svc_export *exp, struct svc_rqst *rqstp);
1da177e4
LT
119
120/*
121 * Function declarations
122 */
dbf847ec 123int nfsd_export_init(void);
1da177e4
LT
124void nfsd_export_shutdown(void);
125void nfsd_export_flush(void);
126void exp_readlock(void);
127void exp_readunlock(void);
0989a788 128struct svc_export * rqst_exp_get_by_name(struct svc_rqst *,
91c9fa8f 129 struct path *);
0989a788 130struct svc_export * rqst_exp_parent(struct svc_rqst *,
e64c390c 131 struct path *);
1da177e4
LT
132int exp_rootfh(struct auth_domain *,
133 char *path, struct knfsd_fh *, int maxsize);
df547efb 134__be32 exp_pseudoroot(struct svc_rqst *, struct svc_fh *);
63f10311 135__be32 nfserrno(int errno);
1da177e4 136
74cae61a 137extern struct cache_detail svc_export_cache;
1da177e4
LT
138
139static inline void exp_put(struct svc_export *exp)
140{
baab935f 141 cache_put(&exp->h, &svc_export_cache);
1da177e4
LT
142}
143
144static inline void exp_get(struct svc_export *exp)
145{
146 cache_get(&exp->h);
147}
0989a788 148struct svc_export * rqst_exp_find(struct svc_rqst *, int, u32 *);
1da177e4
LT
149
150#endif /* __KERNEL__ */
151
152#endif /* NFSD_EXPORT_H */
153
This page took 0.645082 seconds and 5 git commands to generate.