Run rpc.rquotad Safely for NFS Remote Quotas
You will finish with a read-only rpc.rquotad configuration for serving quota information to NFS clients, a version check, and a short verification plan. The examples match quota 4.06-1build6 and its installed rpc.rquotad(8) manual on this machine.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about twenty minutes, plus time to check the host's NFS service manager and access-control files. You need root access on the NFS server, an exported filesystem with quotas already configured, and a client that mounts that export. This guide does not create quota files, edit an NFS export, or start a service automatically.
1. Confirm the installed daemon
Run these read-only checks as an ordinary user. They identify the binary and the package version before you change a service configuration:
$ command -v rpc.rquotad
/usr/sbin/rpc.rquotad
$ dpkg-query -W -f='${Package} ${Version}\n' quota
quota 4.06-1build6
$ rpc.rquotad --version
Quota utilities version 4.06.
Compiled with: USE_LDAP_MAIL_LOOKUP EXT2_DIRECT HOSTS_ACCESS RPC RPC_SETQUOTA BSD_BEHAVIOUR
The exact package version will differ on another distribution. Record it with your change notes because option availability and service integration are package-specific.
Checkpoint: the command must be /usr/sbin/rpc.rquotad, and the installed output must identify quota tools. If it is missing, install the distribution's quota package through its normal package-management process; do not copy a daemon binary from another host.
2. Understand the safe default
rpc.rquotad answers RPC requests for quotas on local filesystems that a remote machine reaches over NFS. The quota client uses the results to display usage, while edquota can use the service for remote quota changes when the daemon and build support allow it.
The default is --no-setquota, also written -s. Keep that default for ordinary reporting. It prevents remote requests from setting quotas. This binary was compiled with RPC_SETQUOTA, so the enabling option exists here, but that is not a reason to use it.
Security checkpoint
Do not add --setquota or -S unless you have a documented administrative requirement, a tested authorisation boundary, and a rollback plan. Enabling it changes the service from a read-only reporting endpoint into a remote quota administration endpoint.
3. Check the local quota data before starting anything
On the NFS server, inspect mounted filesystems and quota files as root. These commands do not enable or alter quotas:
# findmnt -t ext4,xfs,btrfs
# find / -maxdepth 3 \( -name aquota.user -o -name aquota.group -o -name quota.user -o -name quota.group \) -print 2>/dev/null
The manual names aquota.user and aquota.group for version 2 quota files on non-XFS filesystems, and quota.user and quota.group for version 1. It also names /etc/mtab as the default filesystems source. Do not infer that a quota filename proves quotas are active: check the filesystem and your distribution's quota status tools as well.
Stop here if the exported filesystem has no working quota configuration. Starting rpc.rquotad will not create quota files or repair filesystem quota accounting.
4. Keep the daemon in read-only mode
When you need to run the daemon under a service manager, use its normal unit or startup integration and pass only the read-only option if an explicit setting is required. The command shape is:
# /usr/sbin/rpc.rquotad --no-setquota
Do not paste that command into a production shell while troubleshooting unless you know how your host registers RPC services. A foreground process may conflict with an existing instance, and a manually started daemon may be missed by boot recovery and monitoring. First inspect the service definition:
# systemctl status rpc-rquotad.service
# systemctl cat rpc-rquotad.service
If that unit name does not exist, find the package's installed service integration rather than guessing a replacement:
# systemctl list-unit-files | grep -i quota
# ps -ef | grep '[r]pc.rquotad'
The service name and unit name are not specified by rpc.rquotad(8); they depend on the distribution. Preserve any existing administrator-approved arguments, and make sure the final command still contains --no-setquota or -s.
5. Restrict who can call it
This build uses TCP wrappers. The daemon uses the service name rquotad, so the host access files can allow or deny clients. Review the current files before editing them:
# grep -nE '(^|[[:space:]])rquotad([[:space:]]|:|$)' /etc/hosts.allow /etc/hosts.deny 2>/dev/null || true
Apply the narrowest rule that matches your NFS management network. For example, an existing policy might contain a line such as this, but the network is only a placeholder:
rquotad: 192.0.2.0/24
Do not copy that example as a real network. Confirm your distribution's hosts.allow(5) syntax and the addresses used by the NFS clients. A wrapper rule is an additional boundary, not a replacement for firewall rules, NFS export restrictions, or authentication.
Change warning: editing access-control files can immediately disconnect clients from the quota service. Save a root-readable backup and keep an existing session open while testing:
# cp --preserve=mode,ownership,timestamps /etc/hosts.allow /etc/hosts.allow.bak
# cp --preserve=mode,ownership,timestamps /etc/hosts.deny /etc/hosts.deny.bak
To undo only this backup operation, restore the relevant file after confirming that no other administrator has changed it:
# cp --preserve=mode,ownership,timestamps /etc/hosts.allow.bak /etc/hosts.allow
6. Handle NFSv4 paths deliberately
If you serve NFSv4 exports, the daemon may need the same export-table view used by the NFS server. The --xtab PATH or -x PATH option selects an alternative NFSD export table. It is used to determine the NFSv4 pseudoroot, which is prepended to relative paths in quota requests.
Do not invent a path for this option. Inspect the NFS service configuration and its running arguments, then use the path your distribution actually manages. A wrong export table can make valid client requests resolve to the wrong filesystem or fail to resolve at all.
Use --autofs or -I only when your deployment intentionally needs automounted filesystems included. The normal behaviour ignores autofs mountpoints. Adding this option can cause quota lookups to trigger mounts, so test it outside a busy production window.
7. Choose a fixed port only when required
--port PORT or -p PORT makes the daemon listen on an alternate port. Leave the default alone unless your firewall, RPC registration, or deployment design requires a fixed alternative. The port must be a valid numeric port; the installed command rejects invalid values.
If you change the port, update the firewall and any RPC client or service-discovery configuration as one planned change. Verify the port from the service manager's effective command line and from the host's listening-socket tools. Do not expose a newly chosen port to the whole network while testing.
8. Verify from the client
After the service manager has started the daemon, check its status on the server, then mount the NFS export from an approved client and ask the quota client to report it:
# systemctl status rpc-rquotad.service
$ quota -s
The unit name and quota output are host-specific. A successful client report should show the mounted NFS filesystem and its quota figures, not merely a clean exit from the daemon. If it fails, check the NFS mount, the client address allowed by TCP wrappers, the server's export table, and the daemon logs in that order.
For a read-only deployment, a useful negative check is to confirm that the effective service command contains --no-setquota or -s and does not contain --setquota or -S:
# systemctl show rpc-rquotad.service --property=ExecStart
# ps -ef | grep '[r]pc.rquotad'
Do not test quota writes against a production filesystem merely to prove that they are disabled. If remote quota administration is genuinely required, design and test that change separately with explicit approvals.
Done means
rpc.rquotadis the expected installed binary and its quota-tools version is recorded.- The server has working filesystem quotas before the RPC daemon is considered useful.
- The service runs with the documented read-only default,
--no-setquota. - TCP-wrapper access is limited to the intended NFS clients, with a tested recovery copy.
- Any NFSv4
--xtab, autofs, or alternate-port setting matches the host's real service configuration. - An approved client can query quota information, and the service's effective command line has been checked.