From: Al Viro <viro@zeniv.linux.org.uk>
To: linux-fsdevel@vger.kernel.org
Cc: torvalds@linux-foundation.org, brauner@kernel.org, jack@suse.cz,
mjguzik@gmail.com, paul@paul-moore.com, axboe@kernel.dk,
audit@vger.kernel.org, io-uring@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: [PATCH v4 00/59] struct filename series
Date: Thu, 8 Jan 2026 07:37:04 +0000 [thread overview]
Message-ID: <20260108073803.425343-1-viro@zeniv.linux.org.uk> (raw)
[See https://lore.kernel.org/all/20251216035518.4037331-1-viro@zeniv.linux.org.uk/
for previous variant]
Changes compared to v3:
* rebased to v6.19-rc4
* the size of embedded name is increased to the point where struct filename
is 192 bytes long
* introduction of CLASS machinery moved up by several commits, so
that "allow incomplete imports of filenames" could make use of it immediately;
as the result, a couple of followups in io_uring/* fold into it.
* __getname_maybe_null() makes use of CLASS(filename_flags)
* calls of refname() (all 3 of them, all in kernel/auditsc.c) expanded.
* convert init_mkdir() et.al. to use of do_mkdirat() and friends, similar
to how init_rmdir() and init_unlink() are done.
Practically all destructor calls are done via CLASS(filename...) now;
only 3 explicit calls left (one in audit, dropping the references it has
grabbed for itself, two in the vicinity of fsconfig - separate story).
No uses of __free(putname) remain; I haven't removed DEFINE_FREE yet,
but it's really tempting.
I've got some continuations for that series (non-consuming variants of
do_renameat2() and friends, now that it can be done with minimal PITA
in the callers; with that added we get almost all constructors done via
CLASS(...); the only exceptions are around fsconfig), but that's in
a separate branch (#experimental.filename) on top of this one.
The branch lives in
git://git.kernel.org/pub/scm/linux/kernel/git/viro/vfs.git #work.filename
now; individual patches in followups.
Please, review; if nobody objects, I'm putting that in #for-next on Saturday.
Rough overview:
1--9:
moving pathname import out of retry loops
10:
now we can get rid of "reuse the struct filename if
we'd just imported it from the same address _and_ audit is
enabled" logics.
11:
get rid of names_cachep abuse in ntfs
12--15:
embed reasonably short pathnames into struct filename,
*always* get struct filename out names_cachep, take the long
names into explicitly kmalloc'ed objects.
16:
runtime_const machinery for names_cachep; there's
a potentially better variant (statically allocated kmem_cache),
but that's a separate series.
17:
infrastructure for CLASS(filename...)
18:
switch __getname_maybe_null() to that.
19:
delayed_filename machinery, solves the audit vs. io_uring
problems.
20:
now we don't need filename->refcnt to be atomic.
21--25:
simplify checks in callers of pathwalk primitives -
they (with exception of do_filp_open()) will do
the right thing if given ERR_PTR() for name.
26--32: ... get rid of that one exception and simplify
more callers.
33--56:
conversions to CLASS(filename...), cleanups
57, 58:
... and these should not have been using getname().
59:
trimming fs/init.c down - doing to init_mkdir() et.al. what's
already been done to init_rmdir() and init_unlink().
Shortlog:
Al Viro (58):
do_faccessat(): import pathname only once
do_fchmodat(): import pathname only once
do_fchownat(): import pathname only once
do_utimes_path(): import pathname only once
chdir(2): import pathname only once
chroot(2): import pathname only once
user_statfs(): import pathname only once
do_sys_truncate(): import pathname only once
do_readlinkat(): import pathname only once
get rid of audit_reusename()
ntfs: ->d_compare() must not block
getname_flags() massage, part 1
getname_flags() massage, part 2
struct filename: use names_cachep only for getname() and friends
struct filename: saner handling of long names
allow to use CLASS() for struct filename *
switch __getname_maybe_null() to CLASS(filename_flags)
allow incomplete imports of filenames
struct filename ->refcnt doesn't need to be atomic
file_getattr(): filename_lookup() accepts ERR_PTR() as filename
file_setattr(): filename_lookup() accepts ERR_PTR() as filename
move_mount(): filename_lookup() accepts ERR_PTR() as filename
ksmbd_vfs_path_lookup(): vfs_path_parent_lookup() accepts ERR_PTR() as name
ksmbd_vfs_rename(): vfs_path_parent_lookup() accepts ERR_PTR() as name
do_filp_open(): DTRT when getting ERR_PTR() as pathname
rename do_filp_open() to do_file_open()
do_sys_openat2(): get rid of useless check, switch to CLASS(filename)
simplify the callers of file_open_name()
simplify the callers of do_open_execat()
simplify the callers of alloc_bprm()
switch {alloc,free}_bprm() to CLASS()
file_[gs]etattr(2): switch to CLASS(filename_maybe_null)
mount_setattr(2): don't mess with LOOKUP_EMPTY
do_open_execat(): don't care about LOOKUP_EMPTY
vfs_open_tree(): use CLASS(filename_uflags)
name_to_handle_at(): use CLASS(filename_uflags)
fspick(2): use CLASS(filename_flags)
do_fchownat(): unspaghettify a bit...
chdir(2): unspaghettify a bit...
do_utimes_path(): switch to CLASS(filename_uflags)
do_sys_truncate(): switch to CLASS(filename)
do_readlinkat(): switch to CLASS(filename_flags)
do_f{chmod,chown,access}at(): use CLASS(filename_uflags)
do_{renameat2,linkat,symlinkat}(): use CLASS(filename_consume)
do_{mknodat,mkdirat,unlinkat,rmdir}(): use CLASS(filename_consume)
namei.c: convert getname_kernel() callers to CLASS(filename_kernel)
namei.c: switch user pathname imports to CLASS(filename{,_flags})
filename_...xattr(): don't consume filename reference
move_mount(2): switch to CLASS(filename_maybe_null)
chroot(2): switch to CLASS(filename)
quotactl_block(): switch to CLASS(filename)
statx: switch to CLASS(filename_maybe_null)
user_statfs(): switch to CLASS(filename)
mqueue: switch to CLASS(filename)
ksmbd: use CLASS(filename_kernel)
alpha: switch osf_mount() to strndup_user()
sysfs(2): fs_index() argument is _not_ a pathname
switch init_mkdir() to use of do_mkdirat(), etc.
Mateusz Guzik (1):
fs: hide names_cache behind runtime const machinery
Diffstat:
arch/alpha/kernel/osf_sys.c | 34 ++--
fs/dcache.c | 8 +-
fs/exec.c | 99 ++++------
fs/fhandle.c | 5 +-
fs/file_attr.c | 12 +-
fs/filesystems.c | 9 +-
fs/fsopen.c | 6 +-
fs/init.c | 88 +--------
fs/internal.h | 5 +-
fs/namei.c | 370 ++++++++++++++++++++------------------
fs/namespace.c | 22 +--
fs/ntfs3/dir.c | 5 +-
fs/ntfs3/fsntfs.c | 4 +-
fs/ntfs3/inode.c | 13 +-
fs/ntfs3/namei.c | 17 +-
fs/ntfs3/xattr.c | 5 +-
fs/open.c | 119 +++++-------
fs/quota/quota.c | 3 +-
fs/smb/server/vfs.c | 15 +-
fs/stat.c | 28 +--
fs/statfs.c | 3 +-
fs/utimes.c | 8 +-
fs/xattr.c | 33 +---
include/asm-generic/vmlinux.lds.h | 3 +-
include/linux/audit.h | 11 --
include/linux/fs.h | 42 +++--
io_uring/fs.c | 101 ++++++-----
io_uring/openclose.c | 26 +--
io_uring/statx.c | 17 +-
io_uring/xattr.c | 30 ++--
ipc/mqueue.c | 11 +-
kernel/acct.c | 4 +-
kernel/auditsc.c | 29 +--
mm/huge_memory.c | 15 +-
mm/swapfile.c | 21 +--
35 files changed, 483 insertions(+), 738 deletions(-)
next reply other threads:[~2026-01-08 7:36 UTC|newest]
Thread overview: 65+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-01-08 7:37 Al Viro [this message]
2026-01-08 7:37 ` [PATCH v4 01/59] do_faccessat(): import pathname only once Al Viro
2026-01-08 7:37 ` [PATCH v4 02/59] do_fchmodat(): " Al Viro
2026-01-08 7:37 ` [PATCH v4 03/59] do_fchownat(): " Al Viro
2026-01-08 7:37 ` [PATCH v4 04/59] do_utimes_path(): " Al Viro
2026-01-08 7:37 ` [PATCH v4 05/59] chdir(2): " Al Viro
2026-01-08 7:37 ` [PATCH v4 06/59] chroot(2): " Al Viro
2026-01-08 7:37 ` [PATCH v4 07/59] user_statfs(): " Al Viro
2026-01-08 7:37 ` [PATCH v4 08/59] do_sys_truncate(): " Al Viro
2026-01-08 7:37 ` [PATCH v4 09/59] do_readlinkat(): " Al Viro
2026-01-08 7:37 ` [PATCH v4 10/59] get rid of audit_reusename() Al Viro
2026-01-08 7:37 ` [PATCH v4 11/59] ntfs: ->d_compare() must not block Al Viro
2026-01-08 7:37 ` [PATCH v4 12/59] getname_flags() massage, part 1 Al Viro
2026-01-08 7:37 ` [PATCH v4 13/59] getname_flags() massage, part 2 Al Viro
2026-01-08 7:37 ` [PATCH v4 14/59] struct filename: use names_cachep only for getname() and friends Al Viro
2026-01-08 7:37 ` [PATCH v4 15/59] struct filename: saner handling of long names Al Viro
2026-01-13 15:31 ` Mark Brown
2026-01-13 15:39 ` Al Viro
2026-01-13 17:51 ` Mark Brown
2026-01-13 19:07 ` Al Viro
2026-01-13 19:17 ` Al Viro
2026-01-08 7:37 ` [PATCH v4 16/59] fs: hide names_cache behind runtime const machinery Al Viro
2026-01-08 7:37 ` [PATCH v4 17/59] allow to use CLASS() for struct filename * Al Viro
2026-01-08 7:37 ` [PATCH v4 18/59] switch __getname_maybe_null() to CLASS(filename_flags) Al Viro
2026-01-08 7:37 ` [PATCH v4 19/59] allow incomplete imports of filenames Al Viro
2026-01-08 7:37 ` [PATCH v4 20/59] struct filename ->refcnt doesn't need to be atomic Al Viro
2026-01-08 7:37 ` [PATCH v4 21/59] file_getattr(): filename_lookup() accepts ERR_PTR() as filename Al Viro
2026-01-08 7:37 ` [PATCH v4 22/59] file_setattr(): " Al Viro
2026-01-08 7:37 ` [PATCH v4 23/59] move_mount(): " Al Viro
2026-01-08 7:37 ` [PATCH v4 24/59] ksmbd_vfs_path_lookup(): vfs_path_parent_lookup() accepts ERR_PTR() as name Al Viro
2026-01-08 7:37 ` [PATCH v4 25/59] ksmbd_vfs_rename(): " Al Viro
2026-01-08 7:37 ` [PATCH v4 26/59] do_filp_open(): DTRT when getting ERR_PTR() as pathname Al Viro
2026-01-08 7:37 ` [PATCH v4 27/59] rename do_filp_open() to do_file_open() Al Viro
2026-01-08 7:37 ` [PATCH v4 28/59] do_sys_openat2(): get rid of useless check, switch to CLASS(filename) Al Viro
2026-01-08 7:37 ` [PATCH v4 29/59] simplify the callers of file_open_name() Al Viro
2026-01-08 7:37 ` [PATCH v4 30/59] simplify the callers of do_open_execat() Al Viro
2026-01-08 7:37 ` [PATCH v4 31/59] simplify the callers of alloc_bprm() Al Viro
2026-01-08 7:37 ` [PATCH v4 32/59] switch {alloc,free}_bprm() to CLASS() Al Viro
2026-01-08 7:37 ` [PATCH v4 33/59] file_[gs]etattr(2): switch to CLASS(filename_maybe_null) Al Viro
2026-01-08 7:37 ` [PATCH v4 34/59] mount_setattr(2): don't mess with LOOKUP_EMPTY Al Viro
2026-01-08 7:37 ` [PATCH v4 35/59] do_open_execat(): don't care about LOOKUP_EMPTY Al Viro
2026-01-08 7:37 ` [PATCH v4 36/59] vfs_open_tree(): use CLASS(filename_uflags) Al Viro
2026-01-08 7:37 ` [PATCH v4 37/59] name_to_handle_at(): " Al Viro
2026-01-08 7:37 ` [PATCH v4 38/59] fspick(2): use CLASS(filename_flags) Al Viro
2026-01-08 7:37 ` [PATCH v4 39/59] do_fchownat(): unspaghettify a bit Al Viro
2026-01-08 7:37 ` [PATCH v4 40/59] chdir(2): " Al Viro
2026-01-08 7:37 ` [PATCH v4 41/59] do_utimes_path(): switch to CLASS(filename_uflags) Al Viro
2026-01-08 7:37 ` [PATCH v4 42/59] do_sys_truncate(): switch to CLASS(filename) Al Viro
2026-01-08 7:37 ` [PATCH v4 43/59] do_readlinkat(): switch to CLASS(filename_flags) Al Viro
2026-01-08 7:37 ` [PATCH v4 44/59] do_f{chmod,chown,access}at(): use CLASS(filename_uflags) Al Viro
2026-01-08 7:37 ` [PATCH v4 45/59] do_{renameat2,linkat,symlinkat}(): use CLASS(filename_consume) Al Viro
2026-01-08 7:37 ` [PATCH v4 46/59] do_{mknodat,mkdirat,unlinkat,rmdir}(): " Al Viro
2026-01-08 7:37 ` [PATCH v4 47/59] namei.c: convert getname_kernel() callers to CLASS(filename_kernel) Al Viro
2026-01-08 7:37 ` [PATCH v4 48/59] namei.c: switch user pathname imports to CLASS(filename{,_flags}) Al Viro
2026-01-08 7:37 ` [PATCH v4 49/59] filename_...xattr(): don't consume filename reference Al Viro
2026-01-08 7:37 ` [PATCH v4 50/59] move_mount(2): switch to CLASS(filename_maybe_null) Al Viro
2026-01-08 7:37 ` [PATCH v4 51/59] chroot(2): switch to CLASS(filename) Al Viro
2026-01-08 7:37 ` [PATCH v4 52/59] quotactl_block(): " Al Viro
2026-01-08 7:37 ` [PATCH v4 53/59] statx: switch to CLASS(filename_maybe_null) Al Viro
2026-01-08 7:37 ` [PATCH v4 54/59] user_statfs(): switch to CLASS(filename) Al Viro
2026-01-08 7:37 ` [PATCH v4 55/59] mqueue: " Al Viro
2026-01-08 7:38 ` [PATCH v4 56/59] ksmbd: use CLASS(filename_kernel) Al Viro
2026-01-08 7:38 ` [PATCH v4 57/59] alpha: switch osf_mount() to strndup_user() Al Viro
2026-01-08 7:38 ` [PATCH v4 58/59] sysfs(2): fs_index() argument is _not_ a pathname Al Viro
2026-01-08 7:38 ` [PATCH v4 59/59] switch init_mkdir() to use of do_mkdirat(), etc Al Viro
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260108073803.425343-1-viro@zeniv.linux.org.uk \
--to=viro@zeniv.linux.org.uk \
--cc=audit@vger.kernel.org \
--cc=axboe@kernel.dk \
--cc=brauner@kernel.org \
--cc=io-uring@vger.kernel.org \
--cc=jack@suse.cz \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mjguzik@gmail.com \
--cc=paul@paul-moore.com \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.