Linux Audio

Check our new training course

Loading...
v6.8
  1// SPDX-License-Identifier: GPL-2.0-only
  2/*
  3 * linux/fs/lockd/svc.c
  4 *
  5 * This is the central lockd service.
  6 *
  7 * FIXME: Separate the lockd NFS server functionality from the lockd NFS
  8 * 	  client functionality. Oh why didn't Sun create two separate
  9 *	  services in the first place?
 10 *
 11 * Authors:	Olaf Kirch (okir@monad.swb.de)
 12 *
 13 * Copyright (C) 1995, 1996 Olaf Kirch <okir@monad.swb.de>
 14 */
 15
 16#include <linux/module.h>
 17#include <linux/init.h>
 18#include <linux/sysctl.h>
 19#include <linux/moduleparam.h>
 20
 21#include <linux/sched/signal.h>
 22#include <linux/errno.h>
 23#include <linux/in.h>
 24#include <linux/uio.h>
 25#include <linux/smp.h>
 26#include <linux/mutex.h>
 
 27#include <linux/freezer.h>
 28#include <linux/inetdevice.h>
 29
 30#include <linux/sunrpc/types.h>
 31#include <linux/sunrpc/stats.h>
 32#include <linux/sunrpc/clnt.h>
 33#include <linux/sunrpc/svc.h>
 34#include <linux/sunrpc/svcsock.h>
 35#include <linux/sunrpc/svc_xprt.h>
 36#include <net/ip.h>
 37#include <net/addrconf.h>
 38#include <net/ipv6.h>
 39#include <linux/lockd/lockd.h>
 40#include <linux/nfs.h>
 41
 42#include "netns.h"
 43#include "procfs.h"
 44
 45#define NLMDBG_FACILITY		NLMDBG_SVC
 46#define LOCKD_BUFSIZE		(1024 + NLMSVC_XDRSIZE)
 
 47
 48static struct svc_program	nlmsvc_program;
 49
 50const struct nlmsvc_binding	*nlmsvc_ops;
 51EXPORT_SYMBOL_GPL(nlmsvc_ops);
 52
 53static DEFINE_MUTEX(nlmsvc_mutex);
 54static unsigned int		nlmsvc_users;
 55static struct svc_serv		*nlmsvc_serv;
 
 56unsigned long			nlmsvc_timeout;
 57
 58static void nlmsvc_request_retry(struct timer_list *tl)
 59{
 60	svc_wake_up(nlmsvc_serv);
 61}
 62DEFINE_TIMER(nlmsvc_retry, nlmsvc_request_retry);
 63
 64unsigned int lockd_net_id;
 65
 66/*
 67 * These can be set at insmod time (useful for NFS as root filesystem),
 68 * and also changed through the sysctl interface.  -- Jamie Lokier, Aug 2003
 69 */
 70static unsigned long		nlm_grace_period;
 71static unsigned long		nlm_timeout = LOCKD_DFLT_TIMEO;
 72static int			nlm_udpport, nlm_tcpport;
 73
 74/* RLIM_NOFILE defaults to 1024. That seems like a reasonable default here. */
 75static unsigned int		nlm_max_connections = 1024;
 76
 77/*
 78 * Constants needed for the sysctl interface.
 79 */
 80static const unsigned long	nlm_grace_period_min = 0;
 81static const unsigned long	nlm_grace_period_max = 240;
 82static const unsigned long	nlm_timeout_min = 3;
 83static const unsigned long	nlm_timeout_max = 20;
 
 84
 85#ifdef CONFIG_SYSCTL
 86static const int		nlm_port_min = 0, nlm_port_max = 65535;
 87static struct ctl_table_header * nlm_sysctl_table;
 88#endif
 89
 90static unsigned long get_lockd_grace_period(void)
 91{
 92	/* Note: nlm_timeout should always be nonzero */
 93	if (nlm_grace_period)
 94		return roundup(nlm_grace_period, nlm_timeout) * HZ;
 95	else
 96		return nlm_timeout * 5 * HZ;
 97}
 98
 99static void grace_ender(struct work_struct *grace)
100{
101	struct delayed_work *dwork = to_delayed_work(grace);
 
102	struct lockd_net *ln = container_of(dwork, struct lockd_net,
103					    grace_period_end);
104
105	locks_end_grace(&ln->lockd_manager);
106}
107
108static void set_grace_period(struct net *net)
109{
110	unsigned long grace_period = get_lockd_grace_period();
111	struct lockd_net *ln = net_generic(net, lockd_net_id);
112
113	locks_start_grace(net, &ln->lockd_manager);
114	cancel_delayed_work_sync(&ln->grace_period_end);
115	schedule_delayed_work(&ln->grace_period_end, grace_period);
116}
117
 
 
 
 
 
 
 
 
 
 
 
 
 
118/*
119 * This is the lockd kernel thread
120 */
121static int
122lockd(void *vrqstp)
123{
 
124	struct svc_rqst *rqstp = vrqstp;
125	struct net *net = &init_net;
126	struct lockd_net *ln = net_generic(net, lockd_net_id);
127
128	/* try_to_freeze() is called from svc_recv() */
129	set_freezable();
130
 
 
 
131	dprintk("NFS locking service started (ver " LOCKD_VERSION ").\n");
132
 
 
 
 
133	/*
134	 * The main request loop. We don't terminate until the last
135	 * NFS mount or NFS daemon has gone away.
136	 */
137	while (!svc_thread_should_stop(rqstp)) {
 
 
 
138		/* update sv_maxconn if it has changed */
139		rqstp->rq_server->sv_maxconn = nlm_max_connections;
140
141		nlmsvc_retry_blocked(rqstp);
142		svc_recv(rqstp);
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
143	}
 
144	if (nlmsvc_ops)
145		nlmsvc_invalidate_all();
146	nlm_shutdown_hosts();
147	cancel_delayed_work_sync(&ln->grace_period_end);
148	locks_end_grace(&ln->lockd_manager);
149
150	dprintk("lockd_down: service stopped\n");
151
152	svc_exit_thread(rqstp);
153	return 0;
154}
155
156static int create_lockd_listener(struct svc_serv *serv, const char *name,
157				 struct net *net, const int family,
158				 const unsigned short port,
159				 const struct cred *cred)
160{
161	struct svc_xprt *xprt;
162
163	xprt = svc_find_xprt(serv, name, net, family, 0);
164	if (xprt == NULL)
165		return svc_xprt_create(serv, name, net, family, port,
166				       SVC_SOCK_DEFAULTS, cred);
167	svc_xprt_put(xprt);
168	return 0;
169}
170
171static int create_lockd_family(struct svc_serv *serv, struct net *net,
172			       const int family, const struct cred *cred)
173{
174	int err;
175
176	err = create_lockd_listener(serv, "udp", net, family, nlm_udpport,
177			cred);
178	if (err < 0)
179		return err;
180
181	return create_lockd_listener(serv, "tcp", net, family, nlm_tcpport,
182			cred);
183}
184
185/*
186 * Ensure there are active UDP and TCP listeners for lockd.
187 *
188 * Even if we have only TCP NFS mounts and/or TCP NFSDs, some
189 * local services (such as rpc.statd) still require UDP, and
190 * some NFS servers do not yet support NLM over TCP.
191 *
192 * Returns zero if all listeners are available; otherwise a
193 * negative errno value is returned.
194 */
195static int make_socks(struct svc_serv *serv, struct net *net,
196		const struct cred *cred)
197{
198	static int warned;
199	int err;
200
201	err = create_lockd_family(serv, net, PF_INET, cred);
202	if (err < 0)
203		goto out_err;
204
205	err = create_lockd_family(serv, net, PF_INET6, cred);
206	if (err < 0 && err != -EAFNOSUPPORT)
207		goto out_err;
208
209	warned = 0;
210	return 0;
211
212out_err:
213	if (warned++ == 0)
214		printk(KERN_WARNING
215			"lockd_up: makesock failed, error=%d\n", err);
216	svc_xprt_destroy_all(serv, net);
217	svc_rpcb_cleanup(serv, net);
218	return err;
219}
220
221static int lockd_up_net(struct svc_serv *serv, struct net *net,
222		const struct cred *cred)
223{
224	struct lockd_net *ln = net_generic(net, lockd_net_id);
225	int error;
226
227	if (ln->nlmsvc_users++)
228		return 0;
229
230	error = svc_bind(serv, net);
231	if (error)
232		goto err_bind;
233
234	error = make_socks(serv, net, cred);
235	if (error < 0)
236		goto err_bind;
237	set_grace_period(net);
238	dprintk("%s: per-net data created; net=%x\n", __func__, net->ns.inum);
239	return 0;
240
 
 
241err_bind:
242	ln->nlmsvc_users--;
243	return error;
244}
245
246static void lockd_down_net(struct svc_serv *serv, struct net *net)
247{
248	struct lockd_net *ln = net_generic(net, lockd_net_id);
249
250	if (ln->nlmsvc_users) {
251		if (--ln->nlmsvc_users == 0) {
252			nlm_shutdown_hosts_net(net);
253			cancel_delayed_work_sync(&ln->grace_period_end);
254			locks_end_grace(&ln->lockd_manager);
255			svc_xprt_destroy_all(serv, net);
256			svc_rpcb_cleanup(serv, net);
257		}
258	} else {
259		pr_err("%s: no users! net=%x\n",
260			__func__, net->ns.inum);
261		BUG();
262	}
263}
264
265static int lockd_inetaddr_event(struct notifier_block *this,
266	unsigned long event, void *ptr)
267{
268	struct in_ifaddr *ifa = (struct in_ifaddr *)ptr;
269	struct sockaddr_in sin;
270
271	if (event != NETDEV_DOWN)
272		goto out;
273
274	if (nlmsvc_serv) {
275		dprintk("lockd_inetaddr_event: removed %pI4\n",
276			&ifa->ifa_local);
277		sin.sin_family = AF_INET;
278		sin.sin_addr.s_addr = ifa->ifa_local;
279		svc_age_temp_xprts_now(nlmsvc_serv, (struct sockaddr *)&sin);
 
 
 
 
280	}
281
282out:
283	return NOTIFY_DONE;
284}
285
286static struct notifier_block lockd_inetaddr_notifier = {
287	.notifier_call = lockd_inetaddr_event,
288};
289
290#if IS_ENABLED(CONFIG_IPV6)
291static int lockd_inet6addr_event(struct notifier_block *this,
292	unsigned long event, void *ptr)
293{
294	struct inet6_ifaddr *ifa = (struct inet6_ifaddr *)ptr;
295	struct sockaddr_in6 sin6;
296
297	if (event != NETDEV_DOWN)
298		goto out;
299
300	if (nlmsvc_serv) {
301		dprintk("lockd_inet6addr_event: removed %pI6\n", &ifa->addr);
302		sin6.sin6_family = AF_INET6;
303		sin6.sin6_addr = ifa->addr;
304		if (ipv6_addr_type(&sin6.sin6_addr) & IPV6_ADDR_LINKLOCAL)
305			sin6.sin6_scope_id = ifa->idev->dev->ifindex;
306		svc_age_temp_xprts_now(nlmsvc_serv, (struct sockaddr *)&sin6);
307	}
 
 
308
309out:
310	return NOTIFY_DONE;
 
 
 
 
311}
312
313static struct notifier_block lockd_inet6addr_notifier = {
314	.notifier_call = lockd_inet6addr_event,
315};
316#endif
317
318static int lockd_get(void)
319{
320	struct svc_serv *serv;
321	int error;
322
323	if (nlmsvc_serv) {
324		nlmsvc_users++;
325		return 0;
 
 
 
 
 
 
 
326	}
327
328	/*
329	 * Sanity check: if there's no pid,
330	 * we should be the first user ...
331	 */
332	if (nlmsvc_users)
333		printk(KERN_WARNING
334			"lockd_up: no pid, %d users??\n", nlmsvc_users);
335
336	if (!nlm_timeout)
337		nlm_timeout = LOCKD_DFLT_TIMEO;
338	nlmsvc_timeout = nlm_timeout * HZ;
339
340	serv = svc_create(&nlmsvc_program, LOCKD_BUFSIZE, lockd);
341	if (!serv) {
342		printk(KERN_WARNING "lockd_up: create service failed\n");
343		return -ENOMEM;
344	}
345
346	serv->sv_maxconn = nlm_max_connections;
347	error = svc_set_num_threads(serv, NULL, 1);
348	if (error < 0) {
349		svc_destroy(&serv);
350		return error;
351	}
352
353	nlmsvc_serv = serv;
354	register_inetaddr_notifier(&lockd_inetaddr_notifier);
355#if IS_ENABLED(CONFIG_IPV6)
356	register_inet6addr_notifier(&lockd_inet6addr_notifier);
357#endif
358	dprintk("lockd_up: service created\n");
359	nlmsvc_users++;
360	return 0;
361}
362
363static void lockd_put(void)
364{
365	if (WARN(nlmsvc_users <= 0, "lockd_down: no users!\n"))
366		return;
367	if (--nlmsvc_users)
368		return;
369
370	unregister_inetaddr_notifier(&lockd_inetaddr_notifier);
371#if IS_ENABLED(CONFIG_IPV6)
372	unregister_inet6addr_notifier(&lockd_inet6addr_notifier);
373#endif
374
375	svc_set_num_threads(nlmsvc_serv, NULL, 0);
376	timer_delete_sync(&nlmsvc_retry);
377	svc_destroy(&nlmsvc_serv);
378	dprintk("lockd_down: service destroyed\n");
379}
380
381/*
382 * Bring up the lockd process if it's not already up.
383 */
384int lockd_up(struct net *net, const struct cred *cred)
385{
 
386	int error;
387
388	mutex_lock(&nlmsvc_mutex);
389
390	error = lockd_get();
391	if (error)
392		goto err;
393
394	error = lockd_up_net(nlmsvc_serv, net, cred);
395	if (error < 0) {
396		lockd_put();
397		goto err;
398	}
399
400err:
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
401	mutex_unlock(&nlmsvc_mutex);
402	return error;
 
 
 
 
403}
404EXPORT_SYMBOL_GPL(lockd_up);
405
406/*
407 * Decrement the user count and bring down lockd if we're the last.
408 */
409void
410lockd_down(struct net *net)
411{
412	mutex_lock(&nlmsvc_mutex);
413	lockd_down_net(nlmsvc_serv, net);
414	lockd_put();
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
415	mutex_unlock(&nlmsvc_mutex);
416}
417EXPORT_SYMBOL_GPL(lockd_down);
418
419#ifdef CONFIG_SYSCTL
420
421/*
422 * Sysctl parameters (same as module parameters, different interface).
423 */
424
425static struct ctl_table nlm_sysctls[] = {
426	{
427		.procname	= "nlm_grace_period",
428		.data		= &nlm_grace_period,
429		.maxlen		= sizeof(unsigned long),
430		.mode		= 0644,
431		.proc_handler	= proc_doulongvec_minmax,
432		.extra1		= (unsigned long *) &nlm_grace_period_min,
433		.extra2		= (unsigned long *) &nlm_grace_period_max,
434	},
435	{
436		.procname	= "nlm_timeout",
437		.data		= &nlm_timeout,
438		.maxlen		= sizeof(unsigned long),
439		.mode		= 0644,
440		.proc_handler	= proc_doulongvec_minmax,
441		.extra1		= (unsigned long *) &nlm_timeout_min,
442		.extra2		= (unsigned long *) &nlm_timeout_max,
443	},
444	{
445		.procname	= "nlm_udpport",
446		.data		= &nlm_udpport,
447		.maxlen		= sizeof(int),
448		.mode		= 0644,
449		.proc_handler	= proc_dointvec_minmax,
450		.extra1		= (int *) &nlm_port_min,
451		.extra2		= (int *) &nlm_port_max,
452	},
453	{
454		.procname	= "nlm_tcpport",
455		.data		= &nlm_tcpport,
456		.maxlen		= sizeof(int),
457		.mode		= 0644,
458		.proc_handler	= proc_dointvec_minmax,
459		.extra1		= (int *) &nlm_port_min,
460		.extra2		= (int *) &nlm_port_max,
461	},
462	{
463		.procname	= "nsm_use_hostnames",
464		.data		= &nsm_use_hostnames,
465		.maxlen		= sizeof(bool),
466		.mode		= 0644,
467		.proc_handler	= proc_dobool,
468	},
469	{
470		.procname	= "nsm_local_state",
471		.data		= &nsm_local_state,
472		.maxlen		= sizeof(int),
473		.mode		= 0644,
474		.proc_handler	= proc_dointvec,
475	},
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
476};
477
478#endif	/* CONFIG_SYSCTL */
479
480/*
481 * Module (and sysfs) parameters.
482 */
483
484#define param_set_min_max(name, type, which_strtol, min, max)		\
485static int param_set_##name(const char *val, const struct kernel_param *kp) \
486{									\
487	char *endp;							\
488	__typeof__(type) num = which_strtol(val, &endp, 0);		\
489	if (endp == val || *endp || num < (min) || num > (max))		\
490		return -EINVAL;						\
491	*((type *) kp->arg) = num;					\
492	return 0;							\
493}
494
495static inline int is_callback(u32 proc)
496{
497	return proc == NLMPROC_GRANTED
498		|| proc == NLMPROC_GRANTED_MSG
499		|| proc == NLMPROC_TEST_RES
500		|| proc == NLMPROC_LOCK_RES
501		|| proc == NLMPROC_CANCEL_RES
502		|| proc == NLMPROC_UNLOCK_RES
503		|| proc == NLMPROC_NSM_NOTIFY;
504}
505
506
507static enum svc_auth_status lockd_authenticate(struct svc_rqst *rqstp)
508{
509	rqstp->rq_client = NULL;
510	switch (rqstp->rq_authop->flavour) {
511		case RPC_AUTH_NULL:
512		case RPC_AUTH_UNIX:
513			rqstp->rq_auth_stat = rpc_auth_ok;
514			if (rqstp->rq_proc == 0)
515				return SVC_OK;
516			if (is_callback(rqstp->rq_proc)) {
517				/* Leave it to individual procedures to
518				 * call nlmsvc_lookup_host(rqstp)
519				 */
520				return SVC_OK;
521			}
522			return svc_set_client(rqstp);
523	}
524	rqstp->rq_auth_stat = rpc_autherr_badcred;
525	return SVC_DENIED;
526}
527
528
529param_set_min_max(port, int, simple_strtol, 0, 65535)
530param_set_min_max(grace_period, unsigned long, simple_strtoul,
531		  nlm_grace_period_min, nlm_grace_period_max)
532param_set_min_max(timeout, unsigned long, simple_strtoul,
533		  nlm_timeout_min, nlm_timeout_max)
534
535MODULE_AUTHOR("Olaf Kirch <okir@monad.swb.de>");
536MODULE_DESCRIPTION("NFS file locking service version " LOCKD_VERSION ".");
537MODULE_LICENSE("GPL");
538
539module_param_call(nlm_grace_period, param_set_grace_period, param_get_ulong,
540		  &nlm_grace_period, 0644);
541module_param_call(nlm_timeout, param_set_timeout, param_get_ulong,
542		  &nlm_timeout, 0644);
543module_param_call(nlm_udpport, param_set_port, param_get_int,
544		  &nlm_udpport, 0644);
545module_param_call(nlm_tcpport, param_set_port, param_get_int,
546		  &nlm_tcpport, 0644);
547module_param(nsm_use_hostnames, bool, 0644);
548module_param(nlm_max_connections, uint, 0644);
549
550static int lockd_init_net(struct net *net)
551{
552	struct lockd_net *ln = net_generic(net, lockd_net_id);
553
554	INIT_DELAYED_WORK(&ln->grace_period_end, grace_ender);
555	INIT_LIST_HEAD(&ln->lockd_manager.list);
556	ln->lockd_manager.block_opens = false;
557	INIT_LIST_HEAD(&ln->nsm_handles);
558	return 0;
559}
560
561static void lockd_exit_net(struct net *net)
562{
563	struct lockd_net *ln = net_generic(net, lockd_net_id);
564
565	WARN_ONCE(!list_empty(&ln->lockd_manager.list),
566		  "net %x %s: lockd_manager.list is not empty\n",
567		  net->ns.inum, __func__);
568	WARN_ONCE(!list_empty(&ln->nsm_handles),
569		  "net %x %s: nsm_handles list is not empty\n",
570		  net->ns.inum, __func__);
571	WARN_ONCE(delayed_work_pending(&ln->grace_period_end),
572		  "net %x %s: grace_period_end was not cancelled\n",
573		  net->ns.inum, __func__);
574}
575
576static struct pernet_operations lockd_net_ops = {
577	.init = lockd_init_net,
578	.exit = lockd_exit_net,
579	.id = &lockd_net_id,
580	.size = sizeof(struct lockd_net),
581};
582
583
584/*
585 * Initialising and terminating the module.
586 */
587
588static int __init init_nlm(void)
589{
590	int err;
591
592#ifdef CONFIG_SYSCTL
593	err = -ENOMEM;
594	nlm_sysctl_table = register_sysctl("fs/nfs", nlm_sysctls);
595	if (nlm_sysctl_table == NULL)
596		goto err_sysctl;
597#endif
598	err = register_pernet_subsys(&lockd_net_ops);
599	if (err)
600		goto err_pernet;
601
602	err = lockd_create_procfs();
603	if (err)
604		goto err_procfs;
605
606	return 0;
607
608err_procfs:
609	unregister_pernet_subsys(&lockd_net_ops);
610err_pernet:
611#ifdef CONFIG_SYSCTL
612	unregister_sysctl_table(nlm_sysctl_table);
613err_sysctl:
614#endif
 
615	return err;
616}
617
618static void __exit exit_nlm(void)
619{
620	/* FIXME: delete all NLM clients */
621	nlm_shutdown_hosts();
622	lockd_remove_procfs();
623	unregister_pernet_subsys(&lockd_net_ops);
624#ifdef CONFIG_SYSCTL
625	unregister_sysctl_table(nlm_sysctl_table);
626#endif
627}
628
629module_init(init_nlm);
630module_exit(exit_nlm);
631
632/**
633 * nlmsvc_dispatch - Process an NLM Request
634 * @rqstp: incoming request
635 *
636 * Return values:
637 *  %0: Processing complete; do not send a Reply
638 *  %1: Processing complete; send Reply in rqstp->rq_res
639 */
640static int nlmsvc_dispatch(struct svc_rqst *rqstp)
641{
642	const struct svc_procedure *procp = rqstp->rq_procinfo;
643	__be32 *statp = rqstp->rq_accept_statp;
644
645	if (!procp->pc_decode(rqstp, &rqstp->rq_arg_stream))
646		goto out_decode_err;
647
648	*statp = procp->pc_func(rqstp);
649	if (*statp == rpc_drop_reply)
650		return 0;
651	if (*statp != rpc_success)
652		return 1;
653
654	if (!procp->pc_encode(rqstp, &rqstp->rq_res_stream))
655		goto out_encode_err;
656
657	return 1;
658
659out_decode_err:
660	*statp = rpc_garbage_args;
661	return 1;
662
663out_encode_err:
664	*statp = rpc_system_err;
665	return 1;
666}
667
668/*
669 * Define NLM program and procedures
670 */
671static DEFINE_PER_CPU_ALIGNED(unsigned long, nlmsvc_version1_count[17]);
672static const struct svc_version	nlmsvc_version1 = {
673	.vs_vers	= 1,
674	.vs_nproc	= 17,
675	.vs_proc	= nlmsvc_procedures,
676	.vs_count	= nlmsvc_version1_count,
677	.vs_dispatch	= nlmsvc_dispatch,
678	.vs_xdrsize	= NLMSVC_XDRSIZE,
679};
680
681static DEFINE_PER_CPU_ALIGNED(unsigned long,
682			      nlmsvc_version3_count[ARRAY_SIZE(nlmsvc_procedures)]);
683static const struct svc_version	nlmsvc_version3 = {
684	.vs_vers	= 3,
685	.vs_nproc	= ARRAY_SIZE(nlmsvc_procedures),
686	.vs_proc	= nlmsvc_procedures,
687	.vs_count	= nlmsvc_version3_count,
688	.vs_dispatch	= nlmsvc_dispatch,
689	.vs_xdrsize	= NLMSVC_XDRSIZE,
690};
691
692#ifdef CONFIG_LOCKD_V4
693static DEFINE_PER_CPU_ALIGNED(unsigned long,
694			      nlmsvc_version4_count[ARRAY_SIZE(nlmsvc_procedures4)]);
695static const struct svc_version	nlmsvc_version4 = {
696	.vs_vers	= 4,
697	.vs_nproc	= ARRAY_SIZE(nlmsvc_procedures4),
698	.vs_proc	= nlmsvc_procedures4,
699	.vs_count	= nlmsvc_version4_count,
700	.vs_dispatch	= nlmsvc_dispatch,
701	.vs_xdrsize	= NLMSVC_XDRSIZE,
702};
703#endif
704
705static const struct svc_version *nlmsvc_version[] = {
706	[1] = &nlmsvc_version1,
707	[3] = &nlmsvc_version3,
708#ifdef CONFIG_LOCKD_V4
709	[4] = &nlmsvc_version4,
710#endif
711};
712
713static struct svc_stat		nlmsvc_stats;
714
715#define NLM_NRVERS	ARRAY_SIZE(nlmsvc_version)
716static struct svc_program	nlmsvc_program = {
717	.pg_prog		= NLM_PROGRAM,		/* program number */
718	.pg_nvers		= NLM_NRVERS,		/* number of entries in nlmsvc_version */
719	.pg_vers		= nlmsvc_version,	/* version table */
720	.pg_name		= "lockd",		/* service name */
721	.pg_class		= "nfsd",		/* share authentication with nfsd */
722	.pg_stats		= &nlmsvc_stats,	/* stats table */
723	.pg_authenticate	= &lockd_authenticate,	/* export authentication */
724	.pg_init_request	= svc_generic_init_request,
725	.pg_rpcbind_set		= svc_generic_rpcbind_set,
726};
v3.15
 
  1/*
  2 * linux/fs/lockd/svc.c
  3 *
  4 * This is the central lockd service.
  5 *
  6 * FIXME: Separate the lockd NFS server functionality from the lockd NFS
  7 * 	  client functionality. Oh why didn't Sun create two separate
  8 *	  services in the first place?
  9 *
 10 * Authors:	Olaf Kirch (okir@monad.swb.de)
 11 *
 12 * Copyright (C) 1995, 1996 Olaf Kirch <okir@monad.swb.de>
 13 */
 14
 15#include <linux/module.h>
 16#include <linux/init.h>
 17#include <linux/sysctl.h>
 18#include <linux/moduleparam.h>
 19
 20#include <linux/sched.h>
 21#include <linux/errno.h>
 22#include <linux/in.h>
 23#include <linux/uio.h>
 24#include <linux/smp.h>
 25#include <linux/mutex.h>
 26#include <linux/kthread.h>
 27#include <linux/freezer.h>
 
 28
 29#include <linux/sunrpc/types.h>
 30#include <linux/sunrpc/stats.h>
 31#include <linux/sunrpc/clnt.h>
 32#include <linux/sunrpc/svc.h>
 33#include <linux/sunrpc/svcsock.h>
 
 34#include <net/ip.h>
 
 
 35#include <linux/lockd/lockd.h>
 36#include <linux/nfs.h>
 37
 38#include "netns.h"
 
 39
 40#define NLMDBG_FACILITY		NLMDBG_SVC
 41#define LOCKD_BUFSIZE		(1024 + NLMSVC_XDRSIZE)
 42#define ALLOWED_SIGS		(sigmask(SIGKILL))
 43
 44static struct svc_program	nlmsvc_program;
 45
 46struct nlmsvc_binding *		nlmsvc_ops;
 47EXPORT_SYMBOL_GPL(nlmsvc_ops);
 48
 49static DEFINE_MUTEX(nlmsvc_mutex);
 50static unsigned int		nlmsvc_users;
 51static struct task_struct	*nlmsvc_task;
 52static struct svc_rqst		*nlmsvc_rqst;
 53unsigned long			nlmsvc_timeout;
 54
 55int lockd_net_id;
 
 
 
 
 
 
 56
 57/*
 58 * These can be set at insmod time (useful for NFS as root filesystem),
 59 * and also changed through the sysctl interface.  -- Jamie Lokier, Aug 2003
 60 */
 61static unsigned long		nlm_grace_period;
 62static unsigned long		nlm_timeout = LOCKD_DFLT_TIMEO;
 63static int			nlm_udpport, nlm_tcpport;
 64
 65/* RLIM_NOFILE defaults to 1024. That seems like a reasonable default here. */
 66static unsigned int		nlm_max_connections = 1024;
 67
 68/*
 69 * Constants needed for the sysctl interface.
 70 */
 71static const unsigned long	nlm_grace_period_min = 0;
 72static const unsigned long	nlm_grace_period_max = 240;
 73static const unsigned long	nlm_timeout_min = 3;
 74static const unsigned long	nlm_timeout_max = 20;
 75static const int		nlm_port_min = 0, nlm_port_max = 65535;
 76
 77#ifdef CONFIG_SYSCTL
 
 78static struct ctl_table_header * nlm_sysctl_table;
 79#endif
 80
 81static unsigned long get_lockd_grace_period(void)
 82{
 83	/* Note: nlm_timeout should always be nonzero */
 84	if (nlm_grace_period)
 85		return roundup(nlm_grace_period, nlm_timeout) * HZ;
 86	else
 87		return nlm_timeout * 5 * HZ;
 88}
 89
 90static void grace_ender(struct work_struct *grace)
 91{
 92	struct delayed_work *dwork = container_of(grace, struct delayed_work,
 93						  work);
 94	struct lockd_net *ln = container_of(dwork, struct lockd_net,
 95					    grace_period_end);
 96
 97	locks_end_grace(&ln->lockd_manager);
 98}
 99
100static void set_grace_period(struct net *net)
101{
102	unsigned long grace_period = get_lockd_grace_period();
103	struct lockd_net *ln = net_generic(net, lockd_net_id);
104
105	locks_start_grace(net, &ln->lockd_manager);
106	cancel_delayed_work_sync(&ln->grace_period_end);
107	schedule_delayed_work(&ln->grace_period_end, grace_period);
108}
109
110static void restart_grace(void)
111{
112	if (nlmsvc_ops) {
113		struct net *net = &init_net;
114		struct lockd_net *ln = net_generic(net, lockd_net_id);
115
116		cancel_delayed_work_sync(&ln->grace_period_end);
117		locks_end_grace(&ln->lockd_manager);
118		nlmsvc_invalidate_all();
119		set_grace_period(net);
120	}
121}
122
123/*
124 * This is the lockd kernel thread
125 */
126static int
127lockd(void *vrqstp)
128{
129	int		err = 0;
130	struct svc_rqst *rqstp = vrqstp;
 
 
131
132	/* try_to_freeze() is called from svc_recv() */
133	set_freezable();
134
135	/* Allow SIGKILL to tell lockd to drop all of its locks */
136	allow_signal(SIGKILL);
137
138	dprintk("NFS locking service started (ver " LOCKD_VERSION ").\n");
139
140	if (!nlm_timeout)
141		nlm_timeout = LOCKD_DFLT_TIMEO;
142	nlmsvc_timeout = nlm_timeout * HZ;
143
144	/*
145	 * The main request loop. We don't terminate until the last
146	 * NFS mount or NFS daemon has gone away.
147	 */
148	while (!kthread_should_stop()) {
149		long timeout = MAX_SCHEDULE_TIMEOUT;
150		RPC_IFDEBUG(char buf[RPC_MAX_ADDRBUFLEN]);
151
152		/* update sv_maxconn if it has changed */
153		rqstp->rq_server->sv_maxconn = nlm_max_connections;
154
155		if (signalled()) {
156			flush_signals(current);
157			restart_grace();
158			continue;
159		}
160
161		timeout = nlmsvc_retry_blocked();
162
163		/*
164		 * Find a socket with data available and call its
165		 * recvfrom routine.
166		 */
167		err = svc_recv(rqstp, timeout);
168		if (err == -EAGAIN || err == -EINTR)
169			continue;
170		dprintk("lockd: request from %s\n",
171				svc_print_addr(rqstp, buf, sizeof(buf)));
172
173		svc_process(rqstp);
174	}
175	flush_signals(current);
176	if (nlmsvc_ops)
177		nlmsvc_invalidate_all();
178	nlm_shutdown_hosts();
 
 
 
 
 
 
179	return 0;
180}
181
182static int create_lockd_listener(struct svc_serv *serv, const char *name,
183				 struct net *net, const int family,
184				 const unsigned short port)
 
185{
186	struct svc_xprt *xprt;
187
188	xprt = svc_find_xprt(serv, name, net, family, 0);
189	if (xprt == NULL)
190		return svc_create_xprt(serv, name, net, family, port,
191						SVC_SOCK_DEFAULTS);
192	svc_xprt_put(xprt);
193	return 0;
194}
195
196static int create_lockd_family(struct svc_serv *serv, struct net *net,
197			       const int family)
198{
199	int err;
200
201	err = create_lockd_listener(serv, "udp", net, family, nlm_udpport);
 
202	if (err < 0)
203		return err;
204
205	return create_lockd_listener(serv, "tcp", net, family, nlm_tcpport);
 
206}
207
208/*
209 * Ensure there are active UDP and TCP listeners for lockd.
210 *
211 * Even if we have only TCP NFS mounts and/or TCP NFSDs, some
212 * local services (such as rpc.statd) still require UDP, and
213 * some NFS servers do not yet support NLM over TCP.
214 *
215 * Returns zero if all listeners are available; otherwise a
216 * negative errno value is returned.
217 */
218static int make_socks(struct svc_serv *serv, struct net *net)
 
219{
220	static int warned;
221	int err;
222
223	err = create_lockd_family(serv, net, PF_INET);
224	if (err < 0)
225		goto out_err;
226
227	err = create_lockd_family(serv, net, PF_INET6);
228	if (err < 0 && err != -EAFNOSUPPORT)
229		goto out_err;
230
231	warned = 0;
232	return 0;
233
234out_err:
235	if (warned++ == 0)
236		printk(KERN_WARNING
237			"lockd_up: makesock failed, error=%d\n", err);
238	svc_shutdown_net(serv, net);
 
239	return err;
240}
241
242static int lockd_up_net(struct svc_serv *serv, struct net *net)
 
243{
244	struct lockd_net *ln = net_generic(net, lockd_net_id);
245	int error;
246
247	if (ln->nlmsvc_users++)
248		return 0;
249
250	error = svc_bind(serv, net);
251	if (error)
252		goto err_bind;
253
254	error = make_socks(serv, net);
255	if (error < 0)
256		goto err_socks;
257	set_grace_period(net);
258	dprintk("lockd_up_net: per-net data created; net=%p\n", net);
259	return 0;
260
261err_socks:
262	svc_rpcb_cleanup(serv, net);
263err_bind:
264	ln->nlmsvc_users--;
265	return error;
266}
267
268static void lockd_down_net(struct svc_serv *serv, struct net *net)
269{
270	struct lockd_net *ln = net_generic(net, lockd_net_id);
271
272	if (ln->nlmsvc_users) {
273		if (--ln->nlmsvc_users == 0) {
274			nlm_shutdown_hosts_net(net);
275			cancel_delayed_work_sync(&ln->grace_period_end);
276			locks_end_grace(&ln->lockd_manager);
277			svc_shutdown_net(serv, net);
278			dprintk("lockd_down_net: per-net data destroyed; net=%p\n", net);
279		}
280	} else {
281		printk(KERN_ERR "lockd_down_net: no users! task=%p, net=%p\n",
282				nlmsvc_task, net);
283		BUG();
284	}
285}
286
287static int lockd_start_svc(struct svc_serv *serv)
 
288{
289	int error;
 
290
291	if (nlmsvc_rqst)
292		return 0;
293
294	/*
295	 * Create the kernel thread and wait for it to start.
296	 */
297	nlmsvc_rqst = svc_prepare_thread(serv, &serv->sv_pools[0], NUMA_NO_NODE);
298	if (IS_ERR(nlmsvc_rqst)) {
299		error = PTR_ERR(nlmsvc_rqst);
300		printk(KERN_WARNING
301			"lockd_up: svc_rqst allocation failed, error=%d\n",
302			error);
303		goto out_rqst;
304	}
305
306	svc_sock_update_bufs(serv);
307	serv->sv_maxconn = nlm_max_connections;
 
 
 
 
 
308
309	nlmsvc_task = kthread_run(lockd, nlmsvc_rqst, "%s", serv->sv_name);
310	if (IS_ERR(nlmsvc_task)) {
311		error = PTR_ERR(nlmsvc_task);
312		printk(KERN_WARNING
313			"lockd_up: kthread_run failed, error=%d\n", error);
314		goto out_task;
 
 
 
 
 
 
 
 
 
 
 
315	}
316	dprintk("lockd_up: service started\n");
317	return 0;
318
319out_task:
320	svc_exit_thread(nlmsvc_rqst);
321	nlmsvc_task = NULL;
322out_rqst:
323	nlmsvc_rqst = NULL;
324	return error;
325}
326
327static struct svc_serv *lockd_create_svc(void)
 
 
 
 
 
328{
329	struct svc_serv *serv;
 
330
331	/*
332	 * Check whether we're already up and running.
333	 */
334	if (nlmsvc_rqst) {
335		/*
336		 * Note: increase service usage, because later in case of error
337		 * svc_destroy() will be called.
338		 */
339		svc_get(nlmsvc_rqst->rq_server);
340		return nlmsvc_rqst->rq_server;
341	}
342
343	/*
344	 * Sanity check: if there's no pid,
345	 * we should be the first user ...
346	 */
347	if (nlmsvc_users)
348		printk(KERN_WARNING
349			"lockd_up: no pid, %d users??\n", nlmsvc_users);
350
351	serv = svc_create(&nlmsvc_program, LOCKD_BUFSIZE, NULL);
 
 
 
 
352	if (!serv) {
353		printk(KERN_WARNING "lockd_up: create service failed\n");
354		return ERR_PTR(-ENOMEM);
 
 
 
 
 
 
 
355	}
 
 
 
 
 
 
356	dprintk("lockd_up: service created\n");
357	return serv;
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
358}
359
360/*
361 * Bring up the lockd process if it's not already up.
362 */
363int lockd_up(struct net *net)
364{
365	struct svc_serv *serv;
366	int error;
367
368	mutex_lock(&nlmsvc_mutex);
369
370	serv = lockd_create_svc();
371	if (IS_ERR(serv)) {
372		error = PTR_ERR(serv);
373		goto err_create;
 
 
 
 
374	}
375
376	error = lockd_up_net(serv, net);
377	if (error < 0)
378		goto err_net;
379
380	error = lockd_start_svc(serv);
381	if (error < 0)
382		goto err_start;
383
384	nlmsvc_users++;
385	/*
386	 * Note: svc_serv structures have an initial use count of 1,
387	 * so we exit through here on both success and failure.
388	 */
389err_net:
390	svc_destroy(serv);
391err_create:
392	mutex_unlock(&nlmsvc_mutex);
393	return error;
394
395err_start:
396	lockd_down_net(serv, net);
397	goto err_net;
398}
399EXPORT_SYMBOL_GPL(lockd_up);
400
401/*
402 * Decrement the user count and bring down lockd if we're the last.
403 */
404void
405lockd_down(struct net *net)
406{
407	mutex_lock(&nlmsvc_mutex);
408	lockd_down_net(nlmsvc_rqst->rq_server, net);
409	if (nlmsvc_users) {
410		if (--nlmsvc_users)
411			goto out;
412	} else {
413		printk(KERN_ERR "lockd_down: no users! task=%p\n",
414			nlmsvc_task);
415		BUG();
416	}
417
418	if (!nlmsvc_task) {
419		printk(KERN_ERR "lockd_down: no lockd running.\n");
420		BUG();
421	}
422	kthread_stop(nlmsvc_task);
423	dprintk("lockd_down: service stopped\n");
424	svc_exit_thread(nlmsvc_rqst);
425	dprintk("lockd_down: service destroyed\n");
426	nlmsvc_task = NULL;
427	nlmsvc_rqst = NULL;
428out:
429	mutex_unlock(&nlmsvc_mutex);
430}
431EXPORT_SYMBOL_GPL(lockd_down);
432
433#ifdef CONFIG_SYSCTL
434
435/*
436 * Sysctl parameters (same as module parameters, different interface).
437 */
438
439static ctl_table nlm_sysctls[] = {
440	{
441		.procname	= "nlm_grace_period",
442		.data		= &nlm_grace_period,
443		.maxlen		= sizeof(unsigned long),
444		.mode		= 0644,
445		.proc_handler	= proc_doulongvec_minmax,
446		.extra1		= (unsigned long *) &nlm_grace_period_min,
447		.extra2		= (unsigned long *) &nlm_grace_period_max,
448	},
449	{
450		.procname	= "nlm_timeout",
451		.data		= &nlm_timeout,
452		.maxlen		= sizeof(unsigned long),
453		.mode		= 0644,
454		.proc_handler	= proc_doulongvec_minmax,
455		.extra1		= (unsigned long *) &nlm_timeout_min,
456		.extra2		= (unsigned long *) &nlm_timeout_max,
457	},
458	{
459		.procname	= "nlm_udpport",
460		.data		= &nlm_udpport,
461		.maxlen		= sizeof(int),
462		.mode		= 0644,
463		.proc_handler	= proc_dointvec_minmax,
464		.extra1		= (int *) &nlm_port_min,
465		.extra2		= (int *) &nlm_port_max,
466	},
467	{
468		.procname	= "nlm_tcpport",
469		.data		= &nlm_tcpport,
470		.maxlen		= sizeof(int),
471		.mode		= 0644,
472		.proc_handler	= proc_dointvec_minmax,
473		.extra1		= (int *) &nlm_port_min,
474		.extra2		= (int *) &nlm_port_max,
475	},
476	{
477		.procname	= "nsm_use_hostnames",
478		.data		= &nsm_use_hostnames,
479		.maxlen		= sizeof(int),
480		.mode		= 0644,
481		.proc_handler	= proc_dointvec,
482	},
483	{
484		.procname	= "nsm_local_state",
485		.data		= &nsm_local_state,
486		.maxlen		= sizeof(int),
487		.mode		= 0644,
488		.proc_handler	= proc_dointvec,
489	},
490	{ }
491};
492
493static ctl_table nlm_sysctl_dir[] = {
494	{
495		.procname	= "nfs",
496		.mode		= 0555,
497		.child		= nlm_sysctls,
498	},
499	{ }
500};
501
502static ctl_table nlm_sysctl_root[] = {
503	{
504		.procname	= "fs",
505		.mode		= 0555,
506		.child		= nlm_sysctl_dir,
507	},
508	{ }
509};
510
511#endif	/* CONFIG_SYSCTL */
512
513/*
514 * Module (and sysfs) parameters.
515 */
516
517#define param_set_min_max(name, type, which_strtol, min, max)		\
518static int param_set_##name(const char *val, struct kernel_param *kp)	\
519{									\
520	char *endp;							\
521	__typeof__(type) num = which_strtol(val, &endp, 0);		\
522	if (endp == val || *endp || num < (min) || num > (max))		\
523		return -EINVAL;						\
524	*((type *) kp->arg) = num;					\
525	return 0;							\
526}
527
528static inline int is_callback(u32 proc)
529{
530	return proc == NLMPROC_GRANTED
531		|| proc == NLMPROC_GRANTED_MSG
532		|| proc == NLMPROC_TEST_RES
533		|| proc == NLMPROC_LOCK_RES
534		|| proc == NLMPROC_CANCEL_RES
535		|| proc == NLMPROC_UNLOCK_RES
536		|| proc == NLMPROC_NSM_NOTIFY;
537}
538
539
540static int lockd_authenticate(struct svc_rqst *rqstp)
541{
542	rqstp->rq_client = NULL;
543	switch (rqstp->rq_authop->flavour) {
544		case RPC_AUTH_NULL:
545		case RPC_AUTH_UNIX:
 
546			if (rqstp->rq_proc == 0)
547				return SVC_OK;
548			if (is_callback(rqstp->rq_proc)) {
549				/* Leave it to individual procedures to
550				 * call nlmsvc_lookup_host(rqstp)
551				 */
552				return SVC_OK;
553			}
554			return svc_set_client(rqstp);
555	}
 
556	return SVC_DENIED;
557}
558
559
560param_set_min_max(port, int, simple_strtol, 0, 65535)
561param_set_min_max(grace_period, unsigned long, simple_strtoul,
562		  nlm_grace_period_min, nlm_grace_period_max)
563param_set_min_max(timeout, unsigned long, simple_strtoul,
564		  nlm_timeout_min, nlm_timeout_max)
565
566MODULE_AUTHOR("Olaf Kirch <okir@monad.swb.de>");
567MODULE_DESCRIPTION("NFS file locking service version " LOCKD_VERSION ".");
568MODULE_LICENSE("GPL");
569
570module_param_call(nlm_grace_period, param_set_grace_period, param_get_ulong,
571		  &nlm_grace_period, 0644);
572module_param_call(nlm_timeout, param_set_timeout, param_get_ulong,
573		  &nlm_timeout, 0644);
574module_param_call(nlm_udpport, param_set_port, param_get_int,
575		  &nlm_udpport, 0644);
576module_param_call(nlm_tcpport, param_set_port, param_get_int,
577		  &nlm_tcpport, 0644);
578module_param(nsm_use_hostnames, bool, 0644);
579module_param(nlm_max_connections, uint, 0644);
580
581static int lockd_init_net(struct net *net)
582{
583	struct lockd_net *ln = net_generic(net, lockd_net_id);
584
585	INIT_DELAYED_WORK(&ln->grace_period_end, grace_ender);
586	INIT_LIST_HEAD(&ln->grace_list);
587	spin_lock_init(&ln->nsm_clnt_lock);
 
588	return 0;
589}
590
591static void lockd_exit_net(struct net *net)
592{
 
 
 
 
 
 
 
 
 
 
 
593}
594
595static struct pernet_operations lockd_net_ops = {
596	.init = lockd_init_net,
597	.exit = lockd_exit_net,
598	.id = &lockd_net_id,
599	.size = sizeof(struct lockd_net),
600};
601
602
603/*
604 * Initialising and terminating the module.
605 */
606
607static int __init init_nlm(void)
608{
609	int err;
610
611#ifdef CONFIG_SYSCTL
612	err = -ENOMEM;
613	nlm_sysctl_table = register_sysctl_table(nlm_sysctl_root);
614	if (nlm_sysctl_table == NULL)
615		goto err_sysctl;
616#endif
617	err = register_pernet_subsys(&lockd_net_ops);
618	if (err)
619		goto err_pernet;
 
 
 
 
 
620	return 0;
621
 
 
622err_pernet:
623#ifdef CONFIG_SYSCTL
624	unregister_sysctl_table(nlm_sysctl_table);
 
625#endif
626err_sysctl:
627	return err;
628}
629
630static void __exit exit_nlm(void)
631{
632	/* FIXME: delete all NLM clients */
633	nlm_shutdown_hosts();
 
634	unregister_pernet_subsys(&lockd_net_ops);
635#ifdef CONFIG_SYSCTL
636	unregister_sysctl_table(nlm_sysctl_table);
637#endif
638}
639
640module_init(init_nlm);
641module_exit(exit_nlm);
642
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
643/*
644 * Define NLM program and procedures
645 */
646static struct svc_version	nlmsvc_version1 = {
647		.vs_vers	= 1,
648		.vs_nproc	= 17,
649		.vs_proc	= nlmsvc_procedures,
650		.vs_xdrsize	= NLMSVC_XDRSIZE,
 
 
 
651};
652static struct svc_version	nlmsvc_version3 = {
653		.vs_vers	= 3,
654		.vs_nproc	= 24,
655		.vs_proc	= nlmsvc_procedures,
656		.vs_xdrsize	= NLMSVC_XDRSIZE,
 
 
 
 
 
657};
 
658#ifdef CONFIG_LOCKD_V4
659static struct svc_version	nlmsvc_version4 = {
660		.vs_vers	= 4,
661		.vs_nproc	= 24,
662		.vs_proc	= nlmsvc_procedures4,
663		.vs_xdrsize	= NLMSVC_XDRSIZE,
 
 
 
 
664};
665#endif
666static struct svc_version *	nlmsvc_version[] = {
 
667	[1] = &nlmsvc_version1,
668	[3] = &nlmsvc_version3,
669#ifdef CONFIG_LOCKD_V4
670	[4] = &nlmsvc_version4,
671#endif
672};
673
674static struct svc_stat		nlmsvc_stats;
675
676#define NLM_NRVERS	ARRAY_SIZE(nlmsvc_version)
677static struct svc_program	nlmsvc_program = {
678	.pg_prog		= NLM_PROGRAM,		/* program number */
679	.pg_nvers		= NLM_NRVERS,		/* number of entries in nlmsvc_version */
680	.pg_vers		= nlmsvc_version,	/* version table */
681	.pg_name		= "lockd",		/* service name */
682	.pg_class		= "nfsd",		/* share authentication with nfsd */
683	.pg_stats		= &nlmsvc_stats,	/* stats table */
684	.pg_authenticate = &lockd_authenticate	/* export authentication */
 
 
685};