Received: by 2002:a05:6358:3188:b0:123:57c1:9b43 with SMTP id q8csp1167400rwd; Tue, 16 May 2023 12:51:55 -0700 (PDT) X-Google-Smtp-Source: ACHHUZ7vycxsCiJebPnb8DsOEC6DHZVkb3DsOBxEFO1oZaycabAUEttcFEzy1lo3NsXWgjRtmyLD X-Received: by 2002:a17:90b:11cd:b0:250:aaea:4306 with SMTP id gv13-20020a17090b11cd00b00250aaea4306mr26739693pjb.21.1684266714987; Tue, 16 May 2023 12:51:54 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1684266714; cv=none; d=google.com; s=arc-20160816; b=Tlve15FWqXYpEQ/HC+s+Vko3zGfY9Lzzb0kJXpWdWiP0Xvf5g5YgVL1vO1zgdFw78Q Ex3czoyqmPGxDXMiWoUDZGpMiDPMkLBhs0n8QeQZxh3Z/BPaGRu94bIQkuBZxlIUtKcx Cl3VcyUeJkt+la5jxTizEY7VvH2bA+u7aBjh6LGzu3QwV/FWzZp8ziZCNoHdpMlwGVns nJRm794o4JnHzyd7n/bVaP7+tySDPJXQHFl+K27yzQTJ//7IpCZfjReqB5zBgqZRT5pJ 3tZsHKLBPigHGC/uSm4KIhudFXZwJDapmZbEbVV0d02b2t1uGmu06xSZe7b9Ml+DKpd4 Fc5A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :user-agent:references:in-reply-to:message-id:date:cc:to:from :subject:dkim-signature; bh=L2F8ToCDuQw+a89s3ejc1yGvX+iUz5YuMCWN/pbsNMY=; b=Yettzx3Ppa5rhSLWmVkuTqYKu11wVp44TEEBdw8EImGA3CxpoTRNpBdWw+vvRdgsha ZO7r8IIptjJ5bG4XnvvfYM9wkVEFZjtFR5B1TOhoqnM/2DNt0ny6WztUYUM91cAXlHSM P3ItsvNxbKfVmkwqiW4wVOdImUv5o2YEKnMK43xuyjpesrC9weN3bHeS44wn04tEWHn3 XgpKy/LhtszXCDijL8Sv8jFIiPa5tmLjas6UB/mUVGgJCPsBxqfWVUHII/dRYPw8izA7 qvHRGoZDjpxPdovaBIL74Rd05LHq46XWtjQ+c18KILbYIqa82X69FA/aFNCMji14oriF slEg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=qTvv1r5H; spf=pass (google.com: domain of linux-nfs-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-nfs-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id cq21-20020a17090af99500b00252f4ca40c4si191259pjb.34.2023.05.16.12.51.43; Tue, 16 May 2023 12:51:54 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-nfs-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=qTvv1r5H; spf=pass (google.com: domain of linux-nfs-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-nfs-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S229456AbjEPTnX (ORCPT + 99 others); Tue, 16 May 2023 15:43:23 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:37826 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229913AbjEPTnX (ORCPT ); Tue, 16 May 2023 15:43:23 -0400 Received: from dfw.source.kernel.org (dfw.source.kernel.org [IPv6:2604:1380:4641:c500::1]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 06050DC46 for ; Tue, 16 May 2023 12:43:00 -0700 (PDT) Received: from smtp.kernel.org (relay.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by dfw.source.kernel.org (Postfix) with ESMTPS id A1CCE6340C for ; Tue, 16 May 2023 19:42:57 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id B0BD8C433EF; Tue, 16 May 2023 19:42:56 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1684266177; bh=vcjrEnERJLjeZ1eWbL7eCvmWtj0HQV4kugyziIkFrhc=; h=Subject:From:To:Cc:Date:In-Reply-To:References:From; b=qTvv1r5HWbshaebtCL7x32eWLPeXFKY/nvFnqs8xXi5BYCI7y8bikjhEc+P1/zX9H fStBbJmCU+5n6U0JDDoUlY8KeQDGHaG7YkwCcBWsTuJGzAkQPJNnBRLoIn5PydFqh4 N31Yq5/mkzFGQg5G+xQ+IXn66lutyHLP5+IrTDw6HFtKEstMZV/hUzHhZDkE3FaeDI jH4aHzzh09Kudb7zZrS8S9qkKkxV0J4Wl6POgxNRDaQhstMqoh1o9g/SnJnN1w4Pei gTACE+LDGOfHZip+j63mINN+UggWAfvusxtqAbtwfNkxVIh6U3EIVwhJoLlZ8Mpg3F oxxWCqSnI0i1Q== Subject: [PATCH RFC 10/12] SUNRPC: Add RPC-with-TLS tracepoints From: Chuck Lever To: anna.schumaker@netapp.com, trondmy@hammerspace.com Cc: Chuck Lever , linux-nfs@vger.kernel.org, kernel-tls-handshake@lists.linux.dev Date: Tue, 16 May 2023 15:42:45 -0400 Message-ID: <168426615568.74246.14196813436403192718.stgit@oracle-102.nfsv4bat.org> In-Reply-To: <168426587118.74246.214357450560967997.stgit@oracle-102.nfsv4bat.org> References: <168426587118.74246.214357450560967997.stgit@oracle-102.nfsv4bat.org> User-Agent: StGit/1.5 MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit X-Spam-Status: No, score=-4.4 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_MED, SPF_HELO_NONE,SPF_PASS,T_SCC_BODY_TEXT_LINE autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-nfs@vger.kernel.org From: Chuck Lever RFC 9289 makes auditing TLS handshakes mandatory-to-implement. Signed-off-by: Chuck Lever --- include/trace/events/sunrpc.h | 44 +++++++++++++++++++++++++++++++++++++++++ net/sunrpc/xprtsock.c | 5 ++++- 2 files changed, 48 insertions(+), 1 deletion(-) diff --git a/include/trace/events/sunrpc.h b/include/trace/events/sunrpc.h index 34784f29a63d..7cd4bbd6904c 100644 --- a/include/trace/events/sunrpc.h +++ b/include/trace/events/sunrpc.h @@ -1525,6 +1525,50 @@ TRACE_EVENT(rpcb_unregister, ) ); +/** + ** RPC-over-TLS tracepoints + **/ + +DECLARE_EVENT_CLASS(rpc_tls_class, + TP_PROTO( + const struct rpc_clnt *clnt, + const struct rpc_xprt *xprt + ), + + TP_ARGS(clnt, xprt), + + TP_STRUCT__entry( + __field(unsigned long, requested_policy) + __field(u32, version) + __string(servername, xprt->servername) + __string(progname, clnt->cl_program->name) + ), + + TP_fast_assign( + __entry->requested_policy = clnt->cl_xprtsec.policy; + __entry->version = clnt->cl_vers; + __assign_str(servername, xprt->servername); + __assign_str(progname, clnt->cl_program->name) + ), + + TP_printk("server=%s %sv%u requested_policy=%s", + __get_str(servername), __get_str(progname), __entry->version, + rpc_show_xprtsec_policy(__entry->requested_policy) + ) +); + +#define DEFINE_RPC_TLS_EVENT(name) \ + DEFINE_EVENT(rpc_tls_class, rpc_tls_##name, \ + TP_PROTO( \ + const struct rpc_clnt *clnt, \ + const struct rpc_xprt *xprt \ + ), \ + TP_ARGS(clnt, xprt)) + +DEFINE_RPC_TLS_EVENT(unavailable); +DEFINE_RPC_TLS_EVENT(not_started); + + /* Record an xdr_buf containing a fully-formed RPC message */ DECLARE_EVENT_CLASS(svc_xdr_msg_class, TP_PROTO( diff --git a/net/sunrpc/xprtsock.c b/net/sunrpc/xprtsock.c index 686dd313f89f..7ade414aa1cb 100644 --- a/net/sunrpc/xprtsock.c +++ b/net/sunrpc/xprtsock.c @@ -2630,6 +2630,7 @@ static void xs_tls_connect(struct work_struct *work) /* This implicitly sends an RPC_AUTH_TLS probe */ lower_clnt = rpc_create(&args); if (IS_ERR(lower_clnt)) { + trace_rpc_tls_unavailable(upper_clnt, upper_xprt); clear_bit(XPRT_SOCK_CONNECTING, &upper_transport->sock_state); xprt_clear_connecting(upper_xprt); xprt_wake_pending_tasks(upper_xprt, PTR_ERR(lower_clnt)); @@ -2645,8 +2646,10 @@ static void xs_tls_connect(struct work_struct *work) lower_xprt = rcu_dereference(lower_clnt->cl_xprt); rcu_read_unlock(); status = xs_tls_handshake_sync(lower_xprt, &upper_xprt->xprtsec); - if (status) + if (status) { + trace_rpc_tls_not_started(upper_clnt, upper_xprt); goto out_close; + } status = xs_tls_finish_connecting(lower_xprt, upper_transport); if (status)