brintos

brintos / linux-shallow public Read only

0
0
Text · 8.0 KiB · 2aff6d1 Raw
222 lines · plain
1# SPDX-License-Identifier: GPL-2.0-only2config CIFS3	tristate "SMB3 and CIFS support (advanced network filesystem)"4	depends on INET5	select NETFS_SUPPORT6	select NLS7	select NLS_UCS2_UTILS8	select CRYPTO9	select CRYPTO_MD510	select CRYPTO_SHA25611	select CRYPTO_SHA51212	select CRYPTO_CMAC13	select CRYPTO_HMAC14	select CRYPTO_AEAD215	select CRYPTO_CCM16	select CRYPTO_GCM17	select CRYPTO_ECB18	select CRYPTO_AES19	select KEYS20	select DNS_RESOLVER21	select ASN122	select OID_REGISTRY23	select NETFS_SUPPORT24	help25	  This is the client VFS module for the SMB3 family of network file26	  protocols (including the most recent, most secure dialect SMB3.1.1).27	  This module also includes support for earlier dialects such as28	  SMB2.1, SMB2 and even the old Common Internet File System (CIFS)29	  protocol.  CIFS was the successor to the original network filesystem30	  protocol, Server Message Block (SMB ie SMB1), the native file sharing31	  mechanism for most early PC operating systems.32 33	  The SMB3.1.1 protocol is supported by most modern operating systems34	  and NAS appliances (e.g. Samba, Windows 11, Windows Server 2022,35	  MacOS) and even in the cloud (e.g. Microsoft Azure) and also by the36	  Linux kernel server, ksmbd.  Support for the older CIFS protocol was37	  included in Windows NT4, 2000 and XP (and later). Use of dialects38	  older than SMB2.1 is often discouraged on public networks.39	  This module also provides limited support for OS/2 and Windows ME40	  and similar very old servers.41 42	  This module provides an advanced network file system client for43	  mounting to SMB3 (and CIFS) compliant servers.  It includes support44	  for DFS (hierarchical name space), secure per-user session45	  establishment via Kerberos or NTLMv2, RDMA (smbdirect), advanced46	  security features, per-share encryption, packet-signing, snapshots,47	  directory leases, safe distributed caching (leases), multichannel,48	  Unicode and other internationalization improvements.49 50	  In general, the default dialects, SMB3 and later, enable better51	  performance, security and features, than would be possible with CIFS.52 53	  If you need to mount to Samba, Azure, ksmbd, Macs or Windows from this54	  machine, say Y.55 56config CIFS_STATS257	bool "Extended statistics"58	depends on CIFS59	default y60	help61	  Enabling this option will allow more detailed statistics on SMB62	  request timing to be displayed in /proc/fs/cifs/DebugData and also63	  allow optional logging of slow responses to dmesg (depending on the64	  value of /proc/fs/cifs/cifsFYI). See Documentation/admin-guide/cifs/usage.rst65	  for more details. These additional statistics may have a minor effect66	  on performance and memory utilization.67 68	  If unsure, say Y.69 70config CIFS_ALLOW_INSECURE_LEGACY71	bool "Support legacy servers which use less secure dialects"72	depends on CIFS73	default y74	help75	  Modern dialects, SMB2.1 and later (including SMB3 and 3.1.1), have76	  additional security features, including protection against77	  man-in-the-middle attacks and stronger crypto hashes, so the use78	  of legacy dialects (SMB1/CIFS and SMB2.0) is discouraged.79 80	  Disabling this option prevents users from using vers=1.0 or vers=2.081	  on mounts with cifs.ko82 83	  If unsure, say Y.84 85config CIFS_UPCALL86	bool "Kerberos/SPNEGO advanced session setup"87	depends on CIFS88	help89	  Enables an upcall mechanism for CIFS which accesses userspace helper90	  utilities to provide SPNEGO packaged (RFC 4178) Kerberos tickets91	  which are needed to mount to certain secure servers (for which more92	  secure Kerberos authentication is required). If unsure, say Y.93 94config CIFS_XATTR95	bool "CIFS extended attributes"96	depends on CIFS97	help98	  Extended attributes are name:value pairs associated with inodes by99	  the kernel or by users (see the attr(5) manual page for details).100	  CIFS maps the name of extended attributes beginning with the user101	  namespace prefix to SMB/CIFS EAs.  EAs are stored on Windows102	  servers without the user namespace prefix, but their names are103	  seen by Linux cifs clients prefaced by the user namespace prefix.104	  The system namespace (used by some filesystems to store ACLs) is105	  not supported at this time.106 107	  If unsure, say Y.108 109config CIFS_POSIX110	bool "CIFS POSIX Extensions"111	depends on CIFS && CIFS_ALLOW_INSECURE_LEGACY && CIFS_XATTR112	help113	  Enabling this option will cause the cifs client to attempt to114	  negotiate a feature of the older cifs dialect with servers, such as115	  Samba 3.0.5 or later, that optionally can handle more POSIX like116	  (rather than Windows like) file behavior.  It also enables support117	  for POSIX ACLs (getfacl and setfacl) to servers (such as Samba 3.10118	  and later) which can negotiate CIFS POSIX ACL support.  This config119	  option is not needed when mounting with SMB3.1.1. If unsure, say N.120 121config CIFS_DEBUG122	bool "Enable CIFS debugging routines"123	default y124	depends on CIFS125	help126	  Enabling this option adds helpful debugging messages to127	  the cifs code which increases the size of the cifs module.128	  If unsure, say Y.129 130config CIFS_DEBUG2131	bool "Enable additional CIFS debugging routines"132	depends on CIFS_DEBUG133	help134	  Enabling this option adds a few more debugging routines135	  to the cifs code which slightly increases the size of136	  the cifs module and can cause additional logging of debug137	  messages in some error paths, slowing performance. This138	  option can be turned off unless you are debugging139	  cifs problems.  If unsure, say N.140 141config CIFS_DEBUG_DUMP_KEYS142	bool "Dump encryption keys for offline decryption (Unsafe)"143	depends on CIFS_DEBUG144	help145	  Enabling this will dump the encryption and decryption keys146	  used to communicate on an encrypted share connection on the147	  console. This allows Wireshark to decrypt and dissect148	  encrypted network captures. Enable this carefully.149	  If unsure, say N.150 151config CIFS_DFS_UPCALL152	bool "DFS feature support"153	depends on CIFS154	help155	  Distributed File System (DFS) support is used to access shares156	  transparently in an enterprise name space, even if the share157	  moves to a different server.  This feature also enables158	  an upcall mechanism for CIFS which contacts userspace helper159	  utilities to provide server name resolution (host names to160	  IP addresses) which is needed in order to reconnect to161	  servers if their addresses change or for implicit mounts of162	  DFS junction points. If unsure, say Y.163 164config CIFS_SWN_UPCALL165	bool "SWN feature support"166	depends on CIFS167	help168	  The Service Witness Protocol (SWN) is used to get notifications169	  from a highly available server of resource state changes. This170	  feature enables an upcall mechanism for CIFS which contacts a171	  userspace daemon to establish the DCE/RPC connection to retrieve172	  the cluster available interfaces and resource change notifications.173	  If unsure, say Y.174 175config CIFS_NFSD_EXPORT176	bool "Allow nfsd to export CIFS file system"177	depends on CIFS && BROKEN178	help179	  Allows NFS server to export a CIFS mounted share (nfsd over cifs)180 181if CIFS182 183config CIFS_SMB_DIRECT184	bool "SMB Direct support"185	depends on CIFS=m && INFINIBAND && INFINIBAND_ADDR_TRANS || CIFS=y && INFINIBAND=y && INFINIBAND_ADDR_TRANS=y186	help187	  Enables SMB Direct support for SMB 3.0, 3.02 and 3.1.1.188	  SMB Direct allows transferring SMB packets over RDMA. If unsure,189	  say Y.190 191config CIFS_FSCACHE192	bool "Provide CIFS client caching support"193	depends on CIFS=m && FSCACHE || CIFS=y && FSCACHE=y194	help195	  Makes CIFS FS-Cache capable. Say Y here if you want your CIFS data196	  to be cached locally on disk through the general filesystem cache197	  manager. If unsure, say N.198 199config CIFS_ROOT200	bool "SMB root file system (Experimental)"201	depends on CIFS=y && IP_PNP202	help203	  Enables root file system support over SMB protocol.204 205	  Most people say N here.206 207config CIFS_COMPRESSION208	bool "SMB message compression (Experimental)"209	depends on CIFS210	default n211	help212	  Enables over-the-wire message compression for SMB 3.1.1213	  mounts when negotiated with the server.214 215	  Only write requests with data size >= PAGE_SIZE will be216	  compressed to avoid wasting resources.217 218	  Say Y here if you want SMB traffic to be compressed.219	  If unsure, say N.220 221endif222