[PATCH RFC v3 0/5] NFS: isolate mTLS client credentials by network namespace
flat view
WARM1d
From: Chuck Lever <cel@kernel.org>
Date: 2026-10-06 15:24:28
Also in:
keyrings, linux-doc, linux-nfs
An xprtsec=mtls mount names its client certificate and private key by keyring serial number. tlshd reads those keys with its own credentials. Each key has to grant user read permission, and any tlshd on the host that learns a serial number can read it. The RFC thread asked whether the user or mount namespace is a better binding than the network namespace. tlshd services the handshake socket of one network namespace, so that is the namespace tlshd already lives in. https://lore.kernel.org/linux-nfs/20260602154740.49861-1-cel@kernel.org/ (local) After this series each network namespace has its own .nfs keyring, and the keyring's serial number travels with each handshake (patches 3-4). Possessing that keyring lets tlshd read a key that does not grant user read permission. tls_handshake_accept() and tlshd already link a keyring named in the handshake. The handshake genetlink ABI and the cert_serial= and privkey_serial= mount options are not changed. The owner of the network namespace's user namespace now owns the keyring, so global root on the host cannot write to a container's keyring from outside. nfstlskey, the provisioning tool that consumes the key type, is in https://github.com/linux-nfs/ktls-utils/ . Tested on v7.3-rc4 plus this series, on one Fedora VM as both NFS client and NFSD, with tlshd from ktls-utils 1.4.0. --- Changes in v3: - Rebased on v7.3-rc6 - No reviews received; stripped the "RFC" Subject prefix - Link to v2: https://patch.msgid.link/20260925-nfs-mtls-identity-v2-0-aa3ad17dd6c8@kernel.org Changes in v2: - Write "serial number" rather than "serial" throughout (Randy) - Give the .nfs keyring to the netns's user_ns owner (sashiko) - Link to v1: https://patch.msgid.link/20260918-nfs-mtls-identity-v1-0-197e568d78a7@kernel.org --- Chuck Lever (5): NFS: name the init_nfs_fs() error labels NFS: allocate the .nfs keyring per network namespace SUNRPC: pass a keyring serial number to the TLS handshake NFS: name the namespace .nfs keyring in the x509 handshake NFS: add a key type that reveals the namespace .nfs keyring serial number Documentation/filesystems/nfs/index.rst | 1 + Documentation/filesystems/nfs/keyring.rst | 69 ++++++++++ fs/nfs/client.c | 9 +- fs/nfs/fs_context.c | 1 + fs/nfs/inode.c | 211 ++++++++++++++++++++++-------- fs/nfs/netns.h | 9 ++ fs/nfs/nfs3client.c | 1 + fs/nfs/nfs4client.c | 1 + include/linux/sunrpc/xprt.h | 1 + net/sunrpc/xprtsock.c | 1 + 10 files changed, 248 insertions(+), 56 deletions(-) --- base-commit: a90ee4305c4a5df72c11b31dacfdc76e00fcf78a change-id: 20260917-nfs-mtls-identity-04c14f6f348d Best regards, -- Chuck Lever [off-list ref]