Glossary

Nprotocols

NFS

A POSIX file-share protocol, common between Unix hosts, that mounts a remote directory.

How it works

Like SMB, NFS is a live share. Writes can be partial to a reader. Export rules decide who may mount. A snapshot or a copy to object storage is the transfer you can hash. A mount is not.

A render farm reads shots from an NFS export. A writer renames a finished 6 GB frame into the export. Readers never see the temp name. An export that allowed every address on the VLAN also allowed a laptop that copied the whole tree. Narrowing the export stops that.

How it differs

NFS is not FTP. There is no STOR command. Identity is often host-based, which is weak off a trusted LAN.

Root squash exists because a remote root should not own your files. Leave it on unless you have a reason.

Operators who skip the written rule end up debugging the file when the door was the problem.

On the ticket

  • The practical close is a log line: time, actor, byte count, result.
  • Without that line the transfer is a story.
  • With it, the next person can see whether this door did what the ticket claimed.
  • If the path is shared, say so in the partner profile so a later change does not silently pick a different limit, key, or region.
  • On a real ticket, write down the door, the byte count, and the clock.
  • For nfs, that means naming the host or bucket, the expected size, and the time the other side must have a complete file.
  • A progress bar is not that record.
  • A 200 response that arrives before the complete call is not that record.
  • If a retry is allowed, say how many and whether it resumes.
  • If a person must approve the send, name the person.
  • Partners who receive nfs files should match on hash or size before they import.
  • A same-length corrupt file passes a size check and fails a hash.
  • Keep the published hash off the only channel an attacker can edit, or treat it as a corruption check rather than a substitution check.
  • When the path changes, new key, new region, new cap, update the profile the same day so the next run does not use a stale limit.

Related

Sources

  1. RFC 7530, NFSv4

    NFSv4 as a file-share protocol