From nobody Mon Sep 28 23:56:09 2026 Received: from mail-yw1-f171.google.com (mail-yw1-f171.google.com [209.85.128.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1D97031813A for ; Fri, 14 Aug 2026 22:25:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.171 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786746350; cv=none; b=NZ2bT2tkYD2z8/nBEPRws0VqRRGTxcImFzO//4Ux6ox1FR5Dc6MpGI6UZtm0fYM39Ax14pXAoJnnJR/kRw5EL+7/j2GpnQ2fl1/lxKoXnfC+t6wmtLXt1zuz6nk5Y5N7p8hYiLB3Z7mQ4DKIzx3d68PEjyiTEhlePUzipuiIpCw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786746350; c=relaxed/simple; bh=DMJdiSD5U8AT2cI2O4jUZQHb/eheBbmYTwpW++1+C3M=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=B/cItj3f+RQoP9eeD07BX0rshzaHy1gosatXvEfBddGGiIX43CXo1QYeHNkIun23tEGaMmytkOCHWVVbgfzbk32DZ3Id9skWDkLGzbJ8SowF8kSeBFKIJL83t4+dgjZ711Fi+d/vNhk87vgvaqBUoyZaKPFUcbRrhizxVtVtKeU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=truenas.com; spf=pass smtp.mailfrom=truenas.com; dkim=pass (2048-bit key) header.d=truenas.com header.i=@truenas.com header.b=dnATp4IR; arc=none smtp.client-ip=209.85.128.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=truenas.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=truenas.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=truenas.com header.i=@truenas.com header.b="dnATp4IR" Received: by mail-yw1-f171.google.com with SMTP id 00721157ae682-81f3b227a4aso22966087b3.1 for ; Fri, 14 Aug 2026 15:25:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=truenas.com; s=google; t=1786746344; x=1787351144; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=lrqsLvhg/CxOI86B6O3H4IhUbUiJfTNZpqsBInKvA+A=; b=dnATp4IRrMJVVidPos06Gdj2D7pRoLtzMvvXAVIPxPNb8FLRnHH6QWDcDvmnEZKr3O MnRpvlwUlVEdf+EcJfyTcLkl9LRz422C2Try1P9ztmSIsaED79SfXpHsWQP6VtowQ5op AK2EmopGCNqwVjFTeBp91pj3zv0vlcX3LG2tgKOTNRgWU39labLu61cSsNJ3TY9Lg245 HgwgqA/c9JiB4i0NP6566rY2Q+n7fntODHcT5WpQ3r2tv8Jz1HpgC15wAPXvaMhQ8FOf azTVBBdS1BxdBwo0xOAqPDrqALZtLgmDM4mPEqRZvH6LNnDoFFjauRWQctMwQLd2slTr +R3Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786746344; x=1787351144; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=lrqsLvhg/CxOI86B6O3H4IhUbUiJfTNZpqsBInKvA+A=; b=JXdu8LsO5wrEMWeFBaaT+oZxFJF+K/IdP9EOkCuf+G/5ljx6gl5IidJb2rkGlTCLgv 5AefUYdGSsgf0UKSuSyE2/d71qyexBK2pvNaz8HyLcZLzjTIpfT3n4VgmX9B4V5jzG/c jvxGCWMLf3nyKAUXgQooV9ShKRxzffYCwmTOf2XDhS39efIyPVDh2EIBE9kjdjItAxUh oIEXw/ZrvZnZWZ9atu6EIHYtv3casP401vdggSCw1tRnlP5FpQSj1JyA+MWnGuwETKHv NT7VmfTTxiqqBJCuUDGjLllyCEKJzZ7aS21tb9LpOxVkz6Vk7Deg1Y8OVcZZLtUSfzTV wBkQ== X-Forwarded-Encrypted: i=1; AHgh+Ro3+BImioFTdSNaObKr8vaKtXQHR6lkaq6ZnPq0X601GnmJsL876zPoC2b111Vi3Y8xfkWMBXHmEymIMXI=@vger.kernel.org X-Gm-Message-State: AOJu0YxY6hzizc0C09pqL1L5yJY+99ny0eJHi+QUC8zjwAdXccESQ+1K Tv8qRjGUblTIPC8y3z869yZBZ8coen6MIYncwZfurhcB6/D5ZkEdFgPbEkAJyjHTvQ== X-Gm-Gg: AR+sD11HTJwKO+CWmBNbNYVTWmCyZyNzyqPRzIrkrKSU1xQg0AiFW/zI+yDNGuM9sRk ONQcvntxlH9hrmOPH2McvcTPCr9ilQNVwsHk2CK9iFjJMQit5/B6tMuDeinQW6AKiN1cMRX1h2e qERaNGDyk322rAVXK5LX5rbJNcEdsiFqHY9qwrMNrVcgFaUwzjV3aZTPKGOv2ugjNGdIVU66zAX VYaJeFCEQtXbrB+ovuQDoXLpCs/Zo1JQEyysjWTwm1KuwIHqt7cqHzQXRoeEMkt41UccfN58YzC WZITWP+eGZrLwdlW9ES3MjHxuCSSCGPhZDS6RvLYXXCOVUMieRyxMZPwYdtG2eylWYW1PLRD4Go uSSelAVfUmj8/ERFLGO9H5NbBlBHXB5qPuZ980V/03+QtqgeUqzVHhUJAgDKUhSbfl4VrscKdzv ectw9gOZZ8UTp6FePiAsARAkn7UszQg1Nb9reBHIY1SFMc1HxTF40TVfa2pxOC X-Received: by 2002:a05:690c:e18:b0:81e:514b:1b98 with SMTP id 00721157ae682-8370cc30942mr39322467b3.7.1786746343905; Fri, 14 Aug 2026 15:25:43 -0700 (PDT) Received: from hamza-PC ([124.29.197.38]) by smtp.gmail.com with ESMTPSA id 00721157ae682-836c1777c5esm19859857b3.26.2026.08.14.15.25.38 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 14 Aug 2026 15:25:42 -0700 (PDT) From: Ameer Hamza To: cel@kernel.org, jlayton@kernel.org, neil@brown.name, okorniev@redhat.com, Dai.Ngo@oracle.com, tom@talpey.com Cc: linux-nfs@vger.kernel.org, linux-kernel@vger.kernel.org, alexander.motin@truenas.com, caleb.stjohn@truenas.com, ameer.hamza@truenas.com Subject: [PATCH v2 1/2] sunrpc: treat empty auth.unix.gid replies as negative entries Date: Sat, 15 Aug 2026 03:19:52 +0500 Message-ID: <20260814221953.108837-2-ameer.hamza@truenas.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260814221953.108837-1-ameer.hamza@truenas.com> References: <20260814221953.108837-1-ameer.hamza@truenas.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" When rpc.mountd cannot resolve a uid (getpwuid() or getgrouplist() failure, e.g. while winbind or sssd is briefly unreachable), it answers the auth.unix.gid upcall with zero groups. unix_gid_parse() installs that as a valid positive entry, and svcauth_unix_set_client() then replaces the credential's group list with the empty one on every request, RPCSEC_GSS included via svcauth_gss_set_client(). One failed lookup strips that uid of all supplementary groups on every export for up to mountd's configured TTL (30 minutes by default), long after the NSS backend has recovered. mountd cannot send an empty list for a successful lookup, since getgrouplist(3) always includes at least the user's primary group, so a zero-group reply can only mean the lookup failed. Record it as a negative entry: unix_gid_find() then returns -ENOENT and svcauth_unix_set_client() keeps the groups the RPC credential already carries. This is the fallback that commit 3fc605a2aa38 ("[PATCH] knfsd: allow the server to provide a gid list when using AUTH_UNIX authentication") promised when no answer is available, and the same state try_to_negate_entry() already creates when no listener holds the channel open. Fixes: 3fc605a2aa38 ("[PATCH] knfsd: allow the server to provide a gid list= when using AUTH_UNIX authentication") Assisted-by: Claude:claude-fable-5 Signed-off-by: Ameer Hamza --- Reproducer (any server with rpc.mountd --manage-gids; 'alice' is a member of group 'proj' *supplementary*, /srv/proj is root:proj 0750): runuser -u alice -- cat /mnt/proj/data # ok # the reply mountd sends when getpwuid()/getgrouplist() fail: echo "$(id -u alice) $(( $(date +%s) + 600 )) 0" \ > /proc/net/rpc/auth.unix.gid/channel runuser -u alice -- cat /mnt/proj/data # EACCES until # refresh/flush/expiry Applies unmodified (fuzz 0) to every maintained stable tree, 5.10.y through 7.1.y. Tested on a live 6.12-based server over NFSv3 and v4.0-v4.2, with sec=3Dsys and sec=3Dkrb5. net/sunrpc/svcauth_unix.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/net/sunrpc/svcauth_unix.c b/net/sunrpc/svcauth_unix.c index aebd97e7f66c7..2f592ba54a366 100644 --- a/net/sunrpc/svcauth_unix.c +++ b/net/sunrpc/svcauth_unix.c @@ -540,6 +540,13 @@ static int unix_gid_parse(struct cache_detail *cd, if (ugp) { struct cache_head *ch; ug.h.flags =3D 0; + /* + * mountd sends at least the user's primary group on + * success, so an empty list can only mean the lookup + * failed. Keep the credential's own groups instead. + */ + if (gids =3D=3D 0) + set_bit(CACHE_NEGATIVE, &ug.h.flags); ug.h.expiry_time =3D expiry; ch =3D sunrpc_cache_update(cd, &ug.h, &ugp->h, --=20 2.53.0 From nobody Mon Sep 28 23:56:09 2026 Received: from mail-yw1-f173.google.com (mail-yw1-f173.google.com [209.85.128.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A74693876C5 for ; Fri, 14 Aug 2026 22:25:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.173 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786746352; cv=none; b=f+EOJRK++c8lVY1KAsjSzZvDxXvuTLrkWVCpB9vZTFWfdfiZ2hcboNPcbFV8nnBL1Tc7+G7ymNSLLINeTK6fzRlMO86y/3wHQtXIu39hXDvwSSJWQbsY3s2vFUWz5xJeRqBNWkYQMO0bdaPQga/Cu99KkX9Zt4pcaVOiaZ0u2h8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786746352; c=relaxed/simple; bh=Bv00FDpsRNeRWCLCsp9n8XqpgbExu26SCnvgROenxBw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=R6Yw/Uom6QFLOCfXsZKecrGIHDXXwabaqNhO0NbxeUvCSp91fDJpxKVpaadNwMz4sijHWGH983BZIwv5xjDoGR8vY4gNzoxB2uGUWy1vzWBuUKXrLgvljCKEACSICZdQR6DjyMKzfaelLgOD5APjuKPwGsFmY/C6qwQ3b0yiCSs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=truenas.com; spf=pass smtp.mailfrom=truenas.com; dkim=pass (2048-bit key) header.d=truenas.com header.i=@truenas.com header.b=Io4psCIX; arc=none smtp.client-ip=209.85.128.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=truenas.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=truenas.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=truenas.com header.i=@truenas.com header.b="Io4psCIX" Received: by mail-yw1-f173.google.com with SMTP id 00721157ae682-836c91bd782so23016227b3.0 for ; Fri, 14 Aug 2026 15:25:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=truenas.com; s=google; t=1786746350; x=1787351150; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ZTN+B4kFzqTAI1BrFvQTa93RZ8Fx5/03UErkDUDNG0U=; b=Io4psCIXiCv1H/8dhcCIeKKRcljjknW1QTjGTV0cv+u8v1X2ZCbogSF80GMHRDgcYa ZNDw37iG7JbrJ3jarld7E9urYUhALdwJOIGszcKAk5NJ7uohPREct3LilYpUdhpFruBz xAzEmjHDJYA824DXbZpiJ/Id5gWG55/kPBsr1nUztLxiaxzOoWpLGnIhldGr3utSz5LN rQXAKgW5PvyNuoQKlh3+/5F3hIyjPgvZ/2G/4aF5T8KGGo2CIAZ+cDVBMLZgc36RzLvE aTsQQgRHpcx2w/NqwZNBNoPYz0cdw/RUwP6Vu5L4vikXFLJPNMF6ktJqWcVhVTyFUph0 Z/4A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786746350; x=1787351150; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=ZTN+B4kFzqTAI1BrFvQTa93RZ8Fx5/03UErkDUDNG0U=; b=ehQBi+F6ZU+cgjCckrJA+gGgsZc8xg031l525/E6DvmBlepjwX6lLyc+lK8Mr1sYsZ aGswjy3X5rqJUp7vC7LtQEwNcEXI0aOPVEvKwRaS3DAw85ezkZNCDj6a4cT7L/cEphKW yju5ksnVhNDMzK6Tob0eTx+VOJTjbSUZRvi2BdWQxqL7SdHu/bWXyPCZYehwyRYdet/4 pFM+gajyMeWJg7Qdsf4Ieq6u1Is/IVPIARj1BgTp3f9g31qsPY1tw2B5ULzp0td7fvfj Xhh+iW+hBDu6SibZInNP5oa1YcBuQYdqPwgSqCAw7MDcsz8rfmvb95ubnwbMaGPdOrc3 Yvzw== X-Forwarded-Encrypted: i=1; AHgh+RquRjVZDAns3YjNhcbq11Kmiq+2ngYZCfuEtzrSP6mskwlbeDfV1XxS2cN70SWpK6jOeqJo8nPspz7VtPE=@vger.kernel.org X-Gm-Message-State: AOJu0YwnbT7ZpcweiZE4qoVk4clWpxCIUQW41cDdSLSmVkUu2Vd/j4H3 io0dkkxHRGZTgmB1Js1t2Kjhu6ZeT59FQfXrmJU5nm8AuwAtyjqsWAuceFwmHTLrNQ== X-Gm-Gg: AR+sD12swSO3q9BmKBzyOTgoS81EuyNSg4mM0t8KlTfbE1/PsNtbrCXT3QNymzVvqXP fehPOoPzXe+2lfsj4i/XZTdmV3U5n/n8+Pv9/xhcm+mvMziN59XY0xwFq81UBeQt3gYvc9/ukpU 8CipOjNlxas8/6k4RfTcDrnkThbkGh8qN2l8gXphw+qDoMz5tEGNXiXYU3oCXbGYW//JUxDt/GO gkLMLaC2aKfwG7frvbPMpKD2KLYRQM5WS0F8bdw1Z1S79oGBzkf+ix9hJBGotL2ry0WoUZZTOQf K2jtz/BTBSY835d/+xTtG4NO+1NDjOxbMPiaDD/m85dqCOak1SpAwatijaOVxiK7Xsh+wJD2Xrf aJ6dNDDTWRyRO39pJj+4uouY/wXIdauBDSPnA50cO7vpE0kbZs6O/GXd2keqSN7A5vneg+oGR7f u6HRi5EAJnwkfVFJVqwvO1GCiW/e6VvmLBr7gonb2+irm4laexTpP1Ky9PWpVy X-Received: by 2002:a05:690c:e507:b0:821:e0a:6cd9 with SMTP id 00721157ae682-83712da963bmr32775117b3.17.1786746349699; Fri, 14 Aug 2026 15:25:49 -0700 (PDT) Received: from hamza-PC ([124.29.197.38]) by smtp.gmail.com with ESMTPSA id 00721157ae682-836c1777c5esm19859857b3.26.2026.08.14.15.25.44 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 14 Aug 2026 15:25:48 -0700 (PDT) From: Ameer Hamza To: cel@kernel.org, jlayton@kernel.org, neil@brown.name, okorniev@redhat.com, Dai.Ngo@oracle.com, tom@talpey.com Cc: linux-nfs@vger.kernel.org, linux-kernel@vger.kernel.org, alexander.motin@truenas.com, caleb.stjohn@truenas.com, ameer.hamza@truenas.com Subject: [PATCH v2 2/2] sunrpc: honor the netlink unix_gid NEGATIVE flag Date: Sat, 15 Aug 2026 03:19:53 +0500 Message-ID: <20260814221953.108837-3-ameer.hamza@truenas.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260814221953.108837-1-ameer.hamza@truenas.com> References: <20260814221953.108837-1-ameer.hamza@truenas.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The unix_gid netlink upcall protocol has an explicit SUNRPC_A_UNIX_GID_NEGATIVE attribute for failed group lookups, and mountd sends it, but sunrpc_nl_parse_one_unix_gid() only allocates an empty group list for a flagged reply without propagating the flag into the entry, so it installs a valid positive entry with zero groups. Such an entry strips the uid of all supplementary groups until it is refreshed or expires: the same defect the previous patch fixes on the classic channel, on a transport that can say "lookup failed" explicitly. Set CACHE_NEGATIVE for flagged replies, as the netlink ip_map path already does for its negative flag. An empty GIDS list without the flag remains a positive entry. Fixes: 0850e8603cd7 ("sunrpc: add netlink upcall for the auth.unix.gid cach= e") Assisted-by: Claude:claude-fable-5 Signed-off-by: Ameer Hamza --- net/sunrpc/svcauth_unix.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/net/sunrpc/svcauth_unix.c b/net/sunrpc/svcauth_unix.c index 2f592ba54a366..4dd28749bd5de 100644 --- a/net/sunrpc/svcauth_unix.c +++ b/net/sunrpc/svcauth_unix.c @@ -737,6 +737,8 @@ static int sunrpc_nl_parse_one_unix_gid(struct cache_de= tail *cd, boot.tv_sec; =20 if (tb[SUNRPC_A_UNIX_GID_NEGATIVE]) { + /* failed lookup: keep the credential's own groups */ + set_bit(CACHE_NEGATIVE, &ug.h.flags); ug.gi =3D groups_alloc(0); if (!ug.gi) return -ENOMEM; --=20 2.53.0