Subject: Re: exporting -ro nfs
To: Pavel Cahyna <pavel@NetBSD.org>
From: Thor Lancelot Simon <tls@rek.tjls.com>
List: tech-kern
Date: 01/26/2007 06:46:36
On Thu, Jan 25, 2007 at 09:07:27PM +0100, Pavel Cahyna wrote:
> 
> Could nullfs encrypt the filehandles of the underlying filesystem and use
> those encrypted filehandles for NFS?

What should actually happen is what e.g. Solaris does: the filehandle
given to the client should *always* be generated from the exported
directory and underlying filesystem specific data, rather than the
underlying data alone.  This would allow export of arbitrary directories
with different permissions.

No, I am not volunteering to do this.  The code could possibly be lifted
from a userspace NFS server such as amd, however.

-- 
Thor Lancelot Simon	                               tls@rek.tjls.com
  "All of my opinions are consistent, but I cannot present them all
   at once."	-Jean-Jacques Rousseau, On The Social Contract