Re: [LSF/MM/BPF TOPIC] Namespace-aware upcalls from kernel filesystems
"Chuck Lever" <[email protected]>
| Newsgroups | org.kernel.vger.keyrings,org.kernel.vger.linux-cifs,org.kernel.vger.linux-fsdevel,org.kernel.vger.linux-nfs |
|---|---|
| Message-ID | <[email protected]> |
On Mon, Feb 16, 2026, at 11:14 PM, Shyam Prasad N wrote: > On Sat, Feb 14, 2026 at 9:10 PM Chuck Lever <[email protected]> wrote: >> >> >> On Sat, Feb 14, 2026, at 5:06 AM, Shyam Prasad N wrote: >> > Kernel filesystems sometimes need to upcall to userspace to get some >> > work done, which cannot be achieved in kernel code (or rather it is >> > better to be done in userspace). Some examples are DNS resolutions, >> > user authentication, ID mapping etc. >> > >> > Filesystems like SMB and NFS clients use the kernel keys subsystem for >> > some of these, which has an upcall facility that can exec a binary in >> > userspace. However, this upcall mechanism is not namespace aware and >> > upcalls to the host namespaces (namespaces of the init process). >> >> Hello Shyam, we've been introducing netlink control interfaces, which >> are namespace-aware. The kernel TLS handshake mechanism now uses >> this approach, as does the new NFSD netlink protocol. >> >> >> -- >> Chuck Lever > > Hi Chuck, > > Interesting. Let me explore this a bit more. > I'm assuming that this is the file that I should be looking into: > fs/nfsd/nfsctl.c Yes, clustered towards the end of the file. NFSD's use of netlink is as a downcall-style administrative control plane. net/handshake/netlink.c uses netlink as an upcall for driving kernel-initiated TLS handshake requests up to a user daemon. This mechanism has been adopted by NFSD, the NFS client, and the NVMe over TCP drivers. An in-kernel QUIC implementation is planned and will also be using this. > And that there would be a corresponding handler in nfs-utils? For NFSD, nfs-utils has a new tool called nfsdctl. The TLS handshake user space components are in ktls-utils. See: https://github.com/oracle/ktls-utils -- Chuck Lever