So, could we just have a global run-time configuration option? Maybe a module parameter, defaulting to off. Then an admin can decide to turn it on, or to turn it on only after installing some firewall rules to restrict the source of copies. Another odd option might be to restrict to copies from files on filesystems that server already has mounted. Maybe that would simplify the copy code too. I think that's too inflexible, though. --b. -- To unsubscribe from this list: send the line "unsubscribe linux-nfs" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html