All of lore.kernel.org
 help / color / mirror / Atom feed
From: Bernd Schubert via B4 Relay <devnull+bernd.bsbernd.com@kernel.org>
To: fuse-devel@lists.linux.dev
Cc: "Darrick J. Wong" <djwong@kernel.org>,
	neal@gompa.dev,  Bernd Schubert <bernd@bsbernd.com>,
	 Keerthana KT <keerthana@labs.digiscrypt.com>
Subject: [PATCH v3 00/15] libfuse: Add mount service safety checks and tests
Date: Wed, 30 Sep 2026 15:10:54 +0200	[thread overview]
Message-ID: <20260930-mount-service-bound-open-v3-0-e26c5e4eca4c@bsbernd.com> (raw)

That was noticed by AI on comparison to systemd storage provider
and fuse service mount tests were missing as well.

To: fuse-devel@lists.linux.dev
Cc: Darrick J. Wong <djwong@kernel.org>
Cc: neal@gompa.dev

Signed-off-by: Bernd Schubert <bernd@bsbernd.com>
---
Changes in v3:
- Address all Darricks review comments
	- Allow "*" as subtype for service_open_path config option
	- Use sysconf(_SC_ARG_MAX)
	- Also check that pos + len do not exceed memdfd file size
	- Slight documentation wording improvement
- Move fuse_service_priv.h from include/ to lib/
- Link to v2: https://patch.msgid.link/20260928-mount-service-bound-open-v2-0-0f9f501d05ce@bsbernd.com

Changes in v2:
- Add more parsing logic to detect files to open from the command
  line and add admin overrides if the logic failed
- Allow open after mount, but use openat(), which avoids that
  files from the mount point are taken
- Add in '-d path' for mkfs.ext4 to copy in files for improved
  testing
- Add another sanity commit to limit max arg comand size
  (previously https://github.com/libfuse/libfuse/pull/1552)
- Change path to /run/fuse
- Add the documention patch
  (previously https://github.com/libfuse/libfuse/pull/1530)
- libfuse PR: https://github.com/libfuse/libfuse/pull/1638
- Link to v1: https://patch.msgid.link/20260925-mount-service-bound-open-v1-0-bbf1a84c7995@bsbernd.com

---
Bernd Schubert (14):
      mount_service: move the command line check into arg_in_cmdline()
      mount_service: warn about paths not named on the command line
      mount_service: refuse paths the user did not name
      mount_service: use openat to OPEN paths
      util: give fuservicemount3 an absolute build-tree runpath
      mount.fuse: free the options on the service mount return path
      example/single_file: take no sector size from a regular backing file
      test: check which files fuservicemount3 opens for the server
      test: check what fuservicemount3 refuses
      test: mount the service examples through fuservicemount3
      test: run mkfs.ext4 through the service examples
      build: move the default service socket directory to /run/fuse
      Improve documentation for fuse service mount
      move fuse_service_priv.h from include/ to lib/

Keerthana KT (1):
      fuse_service: bound argc and arg len read from the args memfd

 .gitignore                              |   1 +
 doc/README.service-mount                | 312 ++++++++++++++++++++++
 doc/README.service-mount-dev            | 456 ++++++++++++++++++++++++++++++++
 doc/README.service-mount-flow           | 201 ++++++++++++++
 doc/fuservicemount3.8                   | 164 +++++++++++-
 doc/mainpage.dox                        |  13 +
 doc/mount.fuse3.8                       |  25 ++
 example/service_ll.c                    |   5 +
 example/single_file.c                   |   3 +-
 include/fuse_service.h                  |   4 +-
 lib/fuse_service.c                      |  40 +++
 {include => lib}/fuse_service_priv.h    |  10 +
 meson.build                             |   2 +-
 meson_options.txt                       |   2 +-
 test/cases/lib/service-example.sh       | 112 ++++++++
 test/cases/lib/service.sh               |  95 +++++++
 test/cases/lib/socket_activate.py       |  42 +++
 test/cases/mount/service-caps.sh        |  20 ++
 test/cases/mount/service-check.sh       |  38 +++
 test/cases/mount/service-hl-mkfs.sh     |   8 +
 test/cases/mount/service-hl.sh          |   7 +
 test/cases/mount/service-ll-mkfs.sh     |   8 +
 test/cases/mount/service-ll.sh          |   7 +
 test/cases/mount/service-mount-fuse.sh  |  31 +++
 test/cases/mount/service-mountpoint.sh  |  36 +++
 test/cases/mount/service-nonroot.sh     |  54 ++++
 test/cases/mount/service-null.sh        |  33 +++
 test/cases/mount/service-open-bound.sh  |  61 +++++
 test/cases/mount/service-server-exit.sh |  22 ++
 test/meson.build                        |   6 +
 test/test_fuser_conf.c                  |  59 +++++
 test/test_service.c                     | 232 ++++++++++++++++
 util/fuse.conf                          |  12 +
 util/fuser_conf.c                       | 106 ++++++++
 util/fuser_conf.h                       |   3 +
 util/meson.build                        |   2 +
 util/mount.fuse.c                       |  42 +--
 util/mount_service.c                    | 128 +++++++--
 38 files changed, 2360 insertions(+), 42 deletions(-)
---
base-commit: bf4fdf9df8e2d33393894d0789f89e17520944f0
change-id: 20260924-mount-service-bound-open-739b16236bfa

Best regards,
--  
Bernd Schubert <bernd@bsbernd.com>



WARNING: multiple messages have this Message-ID (diff)
From: Bernd Schubert <bernd@bsbernd.com>
To: fuse-devel@lists.linux.dev
Cc: "Darrick J. Wong" <djwong@kernel.org>,
	neal@gompa.dev,  Bernd Schubert <bernd@bsbernd.com>,
	 Keerthana KT <keerthana@labs.digiscrypt.com>
Subject: [PATCH v3 00/15] libfuse: Add mount service safety checks and tests
Date: Wed, 30 Sep 2026 15:10:54 +0200	[thread overview]
Message-ID: <20260930-mount-service-bound-open-v3-0-e26c5e4eca4c@bsbernd.com> (raw)

That was noticed by AI on comparison to systemd storage provider
and fuse service mount tests were missing as well.

To: fuse-devel@lists.linux.dev
Cc: Darrick J. Wong <djwong@kernel.org>
Cc: neal@gompa.dev

Signed-off-by: Bernd Schubert <bernd@bsbernd.com>
---
Changes in v3:
- Address all Darricks review comments
	- Allow "*" as subtype for service_open_path config option
	- Use sysconf(_SC_ARG_MAX)
	- Also check that pos + len do not exceed memdfd file size
	- Slight documentation wording improvement
- Move fuse_service_priv.h from include/ to lib/
- Link to v2: https://patch.msgid.link/20260928-mount-service-bound-open-v2-0-0f9f501d05ce@bsbernd.com

Changes in v2:
- Add more parsing logic to detect files to open from the command
  line and add admin overrides if the logic failed
- Allow open after mount, but use openat(), which avoids that
  files from the mount point are taken
- Add in '-d path' for mkfs.ext4 to copy in files for improved
  testing
- Add another sanity commit to limit max arg comand size
  (previously https://github.com/libfuse/libfuse/pull/1552)
- Change path to /run/fuse
- Add the documention patch
  (previously https://github.com/libfuse/libfuse/pull/1530)
- libfuse PR: https://github.com/libfuse/libfuse/pull/1638
- Link to v1: https://patch.msgid.link/20260925-mount-service-bound-open-v1-0-bbf1a84c7995@bsbernd.com

---
Bernd Schubert (14):
      mount_service: move the command line check into arg_in_cmdline()
      mount_service: warn about paths not named on the command line
      mount_service: refuse paths the user did not name
      mount_service: use openat to OPEN paths
      util: give fuservicemount3 an absolute build-tree runpath
      mount.fuse: free the options on the service mount return path
      example/single_file: take no sector size from a regular backing file
      test: check which files fuservicemount3 opens for the server
      test: check what fuservicemount3 refuses
      test: mount the service examples through fuservicemount3
      test: run mkfs.ext4 through the service examples
      build: move the default service socket directory to /run/fuse
      Improve documentation for fuse service mount
      move fuse_service_priv.h from include/ to lib/

Keerthana KT (1):
      fuse_service: bound argc and arg len read from the args memfd

 .gitignore                              |   1 +
 doc/README.service-mount                | 312 ++++++++++++++++++++++
 doc/README.service-mount-dev            | 456 ++++++++++++++++++++++++++++++++
 doc/README.service-mount-flow           | 201 ++++++++++++++
 doc/fuservicemount3.8                   | 164 +++++++++++-
 doc/mainpage.dox                        |  13 +
 doc/mount.fuse3.8                       |  25 ++
 example/service_ll.c                    |   5 +
 example/single_file.c                   |   3 +-
 include/fuse_service.h                  |   4 +-
 lib/fuse_service.c                      |  40 +++
 {include => lib}/fuse_service_priv.h    |  10 +
 meson.build                             |   2 +-
 meson_options.txt                       |   2 +-
 test/cases/lib/service-example.sh       | 112 ++++++++
 test/cases/lib/service.sh               |  95 +++++++
 test/cases/lib/socket_activate.py       |  42 +++
 test/cases/mount/service-caps.sh        |  20 ++
 test/cases/mount/service-check.sh       |  38 +++
 test/cases/mount/service-hl-mkfs.sh     |   8 +
 test/cases/mount/service-hl.sh          |   7 +
 test/cases/mount/service-ll-mkfs.sh     |   8 +
 test/cases/mount/service-ll.sh          |   7 +
 test/cases/mount/service-mount-fuse.sh  |  31 +++
 test/cases/mount/service-mountpoint.sh  |  36 +++
 test/cases/mount/service-nonroot.sh     |  54 ++++
 test/cases/mount/service-null.sh        |  33 +++
 test/cases/mount/service-open-bound.sh  |  61 +++++
 test/cases/mount/service-server-exit.sh |  22 ++
 test/meson.build                        |   6 +
 test/test_fuser_conf.c                  |  59 +++++
 test/test_service.c                     | 232 ++++++++++++++++
 util/fuse.conf                          |  12 +
 util/fuser_conf.c                       | 106 ++++++++
 util/fuser_conf.h                       |   3 +
 util/meson.build                        |   2 +
 util/mount.fuse.c                       |  42 +--
 util/mount_service.c                    | 128 +++++++--
 38 files changed, 2360 insertions(+), 42 deletions(-)
---
base-commit: bf4fdf9df8e2d33393894d0789f89e17520944f0
change-id: 20260924-mount-service-bound-open-739b16236bfa

Best regards,
--  
Bernd Schubert <bernd@bsbernd.com>


             reply	other threads:[~2026-09-30 13:11 UTC|newest]

Thread overview: 38+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-30 13:10 Bernd Schubert via B4 Relay [this message]
2026-09-30 13:10 ` [PATCH v3 00/15] libfuse: Add mount service safety checks and tests Bernd Schubert
2026-09-30 13:10 ` [PATCH v3 01/15] mount_service: move the command line check into arg_in_cmdline() Bernd Schubert via B4 Relay
2026-09-30 13:10   ` Bernd Schubert
2026-09-30 13:10 ` [PATCH v3 02/15] mount_service: warn about paths not named on the command line Bernd Schubert via B4 Relay
2026-09-30 13:10   ` Bernd Schubert
2026-09-30 13:10 ` [PATCH v3 03/15] mount_service: refuse paths the user did not name Bernd Schubert via B4 Relay
2026-09-30 13:10   ` Bernd Schubert
2026-09-30 15:07   ` Darrick J. Wong
2026-09-30 13:10 ` [PATCH v3 04/15] mount_service: use openat to OPEN paths Bernd Schubert via B4 Relay
2026-09-30 13:10   ` Bernd Schubert
2026-09-30 13:10 ` [PATCH v3 05/15] util: give fuservicemount3 an absolute build-tree runpath Bernd Schubert via B4 Relay
2026-09-30 13:10   ` Bernd Schubert
2026-09-30 13:11 ` [PATCH v3 06/15] mount.fuse: free the options on the service mount return path Bernd Schubert via B4 Relay
2026-09-30 13:11   ` Bernd Schubert
2026-09-30 13:11 ` [PATCH v3 07/15] example/single_file: take no sector size from a regular backing file Bernd Schubert via B4 Relay
2026-09-30 13:11   ` Bernd Schubert
2026-09-30 13:11 ` [PATCH v3 08/15] test: check which files fuservicemount3 opens for the server Bernd Schubert via B4 Relay
2026-09-30 13:11   ` Bernd Schubert
2026-09-30 13:11 ` [PATCH v3 09/15] test: check what fuservicemount3 refuses Bernd Schubert via B4 Relay
2026-09-30 13:11   ` Bernd Schubert
2026-09-30 13:11 ` [PATCH v3 10/15] test: mount the service examples through fuservicemount3 Bernd Schubert via B4 Relay
2026-09-30 13:11   ` Bernd Schubert
2026-09-30 13:11 ` [PATCH v3 11/15] test: run mkfs.ext4 through the service examples Bernd Schubert via B4 Relay
2026-09-30 13:11   ` Bernd Schubert
2026-09-30 13:11 ` [PATCH v3 12/15] fuse_service: bound argc and arg len read from the args memfd Bernd Schubert via B4 Relay
2026-09-30 13:11   ` Bernd Schubert
2026-09-30 14:03   ` Bernd Schubert
2026-09-30 15:09   ` Darrick J. Wong
2026-09-30 13:11 ` [PATCH v3 13/15] build: move the default service socket directory to /run/fuse Bernd Schubert via B4 Relay
2026-09-30 13:11   ` Bernd Schubert
2026-09-30 15:09   ` Darrick J. Wong
2026-09-30 13:11 ` [PATCH v3 14/15] Improve documentation for fuse service mount Bernd Schubert via B4 Relay
2026-09-30 13:11   ` Bernd Schubert
2026-09-30 15:44   ` Darrick J. Wong
2026-09-30 13:11 ` [PATCH v3 15/15] move fuse_service_priv.h from include/ to lib/ Bernd Schubert via B4 Relay
2026-09-30 13:11   ` Bernd Schubert
2026-09-30 15:10   ` Darrick J. Wong

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260930-mount-service-bound-open-v3-0-e26c5e4eca4c@bsbernd.com \
    --to=devnull+bernd.bsbernd.com@kernel.org \
    --cc=bernd@bsbernd.com \
    --cc=djwong@kernel.org \
    --cc=fuse-devel@lists.linux.dev \
    --cc=keerthana@labs.digiscrypt.com \
    --cc=neal@gompa.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.