NFSv4: Disallow security negotiation for lookups when 'sec=' is specified
Ensure that nfs4_proc_lookup_common respects the NFS_MOUNT_SECFLAVOUR flag. Signed-off-by: Trond Myklebust <Trond.Myklebust@netapp.com>
This commit is contained in:
@@ -3154,7 +3154,9 @@ static int nfs4_proc_lookup_common(struct rpc_clnt **clnt, struct inode *dir,
|
|||||||
err = -EPERM;
|
err = -EPERM;
|
||||||
if (client != *clnt)
|
if (client != *clnt)
|
||||||
goto out;
|
goto out;
|
||||||
|
/* No security negotiation if the user specified 'sec=' */
|
||||||
|
if (NFS_SERVER(dir)->flags & NFS_MOUNT_SECFLAVOUR)
|
||||||
|
goto out;
|
||||||
client = nfs4_create_sec_client(client, dir, name);
|
client = nfs4_create_sec_client(client, dir, name);
|
||||||
if (IS_ERR(client))
|
if (IS_ERR(client))
|
||||||
return PTR_ERR(client);
|
return PTR_ERR(client);
|
||||||
|
Reference in New Issue
Block a user