summaryrefslogtreecommitdiffstats
path: root/ChangeLog
Commit message (Collapse)AuthorAgeFilesLines
...
* User-selectable idmapping cache lifetimeneilbrown2006-03-261-0/+6
| | | | | Read and process new configuration option, Cache-Expiration, and use the value to determine how long idmapping entries are cached.
* Set libnfsidmap library debugging level and logging function.neilbrown2006-03-261-0/+7
| | | | | | This patch adds a call to the new libnfsidmap library function nfs4_set_debug(), which defines the verbosity level libnfsidmap should use as well as the logging function.
* Don't close file descriptor until after calling event_del().neilbrown2006-03-261-0/+6
| | | | | Delete event processing for a file descriptor before closing it. This was causing hangs when used in combination with libevent-1.0b.
* Find krb5-config on SuSE 10neilbrown2006-03-261-0/+6
| | | | | SuSE 10.0 puts krb5-config in yet another obscure location. Look for it there and use it if found.
* Update debian package information.neilbrown2006-03-261-0/+3
|
* Install /var/lib/nfs files using DESTDIR and add rpcsec headers to distributionneilbrown2006-03-261-0/+8
| | | | | | | Add "$(DESTDIR)" to the paths for the "$(statedir)" files so they are put in the right place when DESTDIR is defined. Add the rpcsec header files to EXTRA_DIST list.
* head/tail fixesneilbrown2005-12-211-1/+4
|
* Handle new-style quotactl.neilbrown2005-12-211-0/+4
|
* release 1.0.8-rc2neilbrown2005-12-201-0/+2
|
* Complete makefile/configure updateneilbrown2005-12-201-0/+7
|
* Correct documentation of defautl export optionsneilbrown2005-12-201-0/+2
|
* Set default hostname to '*' rather than leaving it emptyneilbrown2005-12-201-0/+5
|
* utils/gssd/gssd_proc.c(create_auth_rpc_client): Use serviceneilbrown2005-12-191-0/+7
| | | | portion of clp->servicename rather than hard-coding "nfs".
* Updates from Kevin Coffman at UMichneilbrown2005-12-161-0/+105
|
* Fix rpc_init so it isn't confused by sshneilbrown2005-12-121-0/+5
|
* idmapd update from Steve Dicksonneilbrown2005-11-031-0/+46
|
* Understand type 2 and type 3 filesystem identifiers.neilbrown2005-10-141-0/+5
|
* Small nfs-utils patch from Olaf Kirchneilbrown2005-10-071-0/+8
|
* Assorted changes from Steve Dicksonneilbrown2005-10-061-0/+32
|
* rquota fixneilbrown2005-10-061-0/+5
|
* Add option to set rpcsec_gss debugging level (if available)neilbrown2005-08-261-0/+8
| | | | | | | Changes to allow gssd/svcgssd to build when using Hiemdal Kerberos libraries. Note that there are still run-time issues preventing this from working when shared libraries for libgssapi and librpcsecgss are used.
* Remove the rpcsec_gss code and rely on an external library instead.neilbrown2005-08-261-0/+3
|
* 2005-08-26 Kevin Coffman <kwc@citi.umich.edu>neilbrown2005-08-261-0/+37
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | *utils/mountd/mountd.c: mountd currently always returns AUTH_NULL and AUTH_SYS as the allowable flavors in mount replies. We want it to also return gss flavors when appropriate. For now as a hack we just have it always return the KRB5 flavors as well. *utils/mountd/cache.c: When attempting to mount an NFSv4 pseudofilesystem (fsid=0) and the actual exported directory does not exist on the server, rpc.mountd doesn't check the directory exists (when fsidtype=1, i.e. using fsid, but does check for fsidtype=0, i.e. using dev/ino). The non-existent exported directory path with fsid=0 is written to the kernel via /proc/net/rpc/nfsd.export/channel, which leads to path_lookup() to return ENOENT (seems appropriate). Unfortunately, the new_cache approach ignores errors returned when writing via the channel file so that particular error is lost and the mount request is silently ignored. Assuming it doesn't make sense to revamp the new_cache/up-call method to not ignore returned errors, it seems appropriate to fix the case where rpc.mountd doesn't check for the existence of an exported directory with fsid= semantics. The following patch does this by moving the stat() up so it is done for both fsidtype's. I'm not certain whether the other tests need to be executed for fsidtype=1, but it doesn't appear to hurt [Not exactly true: the comparison of inode numbers caused problems so now it's kept for fsidtype=0 only]. Would it be also desirable to log a warning for every error, if any, returned by a write to any of the /proc/net/rpc/*/channel files which would otherwise be ignored (maybe under a debug flag)? * gssd/mountd/svcgssd: Changes gssd, svcgssd, and mountd to ignore a SIGHUP rather than dying. * many: Remove the gssapi code and rely on an external library instead.
* 2005-08-26 Kevin Coffman <kwc@citi.umich.edu>neilbrown2005-08-261-0/+45
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * utils/exportfs/exports.man: Document the "crossmnt" export export option * utils/gssd/krb5_util.c: Add better debugging and partially revert the function check for gss_krb5_ccache_name. For MIT Kerberos releases up to and including 1.3.1, we *must* use the routine gss_krb5_ccache_name to get the K5 gssapi code to use a different credentials cache. For releases 1.3.2 and on, we want to use the KRB5CCNAME environment variable to tell it what to use. (A problem was reported where 1.3.5 was being used, our code was using gss_krb5_ccache_name, but the underlying code continued to use the first (or default?) credentials cache. Switching to using the env variable fixed the problem. I cannot recreate this problem. *utils/gssd/krb5_util.c: Andrew Mahone <andrew.mahone@gmail.com> reported that reiser4 always has DT_UNKNOWN. He supplied patch to move the check for regular files after the stat() call to correctly find ccache files in reiser4 filesystem. Also change the name comparison so that the wrong file is not selected when the substring comparison is done. *utils/gssd/krb5_util.c: Limit the set of encryption types that can be negotiated by the Kerberos library to those that the kernel code currently supports. This should eventually query the kernel for the list of supported enctypes. *utils/gssd/gss_util.c, utils/svcgssd/svcgssd_main_loop.c: Print more information in error messages to help debugging failures. *utils/svcgssd/svcgssd_proc.c: Increase token buffer size and update error handling so that a response is always sent. *utils/svcgssd/svcgssd_proc.c: Add support to retrieve supplementary groups.
* 2005-08-26 Kevin Coffman <kwc@citi.umich.edu>neilbrown2005-08-261-0/+14
| | | | | | | | | | | | | | | | | | | | | | | | * configure.in etc Consolidate some of the Kerberos checking instead of repeating the same things for MIT and Heimdal. Also adds more checks to distinguish 32-bit from 64-bit (mainly for gssapi.h) Fix svcgssd Makefile so make TOP=../../ works correctly there. Enable running a modern autoheader. * utils/gssd/gss_oids.c: Use correct OID value for SPKM-3 * utils/gssd/gss_util.c: Fix build with older MIT releases that do not define GSS_C_NT_HOSTBASED_SERVICE * utils/gssd/write_bytes.h, support/include/gssapi/gssapi.h: Length of gss_buffer_desc is a size_t which is 64-bits on a 64-bit machine. Kernel code expects 32-bit integer for length. Coerce length value into a 32-bit value when reading from or writing to the kernel. Change gssapi.h to use datatype size values obtained from configure rather than hard-coded values. * utils/idmapd/idmapd.c: The EV_INIT check here was wrong, and was causing idmapd to become unresponsive to server requests after receiving a sighup. * utils/idmapd/idmapd.c: Idmapd should flush the server id<->name caches when its started.
* From: Kevin Coffman <kwc@citi.umich.edu>neilbrown2005-08-261-0/+9
| | | | | | | | | | | Consolidate some of the Kerberos checking instead of repeating the same things for MIT and Heimdal. Also adds more checks to distinguish 32-bit from 64-bit (mainly for gssapi.h) Fix svcgssd Makefile so make TOP=../../ works correctly there. Enable running a modern autoheader. (Requires that autoconf be run to regenerate configure script.)
* See Changeloggmorris2005-04-121-0/+12
|
* Debian version 1.0.7-2.chip2005-04-071-0/+4
|
* Update config.sub and config.guess.chip2005-04-061-0/+2
|
* Don't use cast as lvaluechip2005-04-061-0/+3
|
* Support "acl" and "no_acl" export options.chip2005-04-061-0/+10
|
* treat N.N.N.N as a special case of MCL_SUBNETWORK instead ofneilbrown2005-03-141-1/+7
| | | | MCL_FQDN
* Changes to utils/exportfs/exports.man and support/nfs/cacheio.cgmorris2005-03-111-0/+6
|
* Make statd_get_socket actually honour the 'port' parameter.neilbrown2005-02-281-0/+4
|
* Debian 1.0.7-1.chip2005-01-121-0/+12
|
* release 1.0.7neilbrown2004-12-171-0/+6
|
* release 1.0.7-pre2neilbrown2004-12-101-0/+5
|
* ha-callout ands sigchldneilbrown2004-12-101-0/+2
|
* configure improvementsneilbrown2004-12-101-0/+6
|
* HA statd updatesneilbrown2004-12-061-1/+9
|
* statd fixesneilbrown2004-12-061-0/+7
|
* auth_reload fixneilbrown2004-12-061-0/+4
|
* set version to 1.0.7-pre1neilbrown2004-12-031-0/+5
|
* Ignore SIGPIPE in statdneilbrown2004-12-031-0/+4
|
* *** empty log message ***neilbrown2004-11-221-0/+8
|
* *** empty log message ***neilbrown2004-11-221-0/+2
|
* *** empty log message ***neilbrown2004-11-221-0/+2
|
* further idmapd updateneilbrown2004-11-221-0/+3
|
* more idmapd updatesneilbrown2004-11-221-0/+4
|
* idmapd updatesneilbrown2004-11-221-0/+3
|