From: Christian Brauner <brauner@kernel.org>
To: linux-fsdevel@vger.kernel.org
Cc: Linus Torvalds <torvalds@linux-foundation.org>,
Chris Mason <mason@kernel.org>,
Alexander Viro <viro@zeniv.linux.org.uk>,
Jan Kara <jack@suse.cz>, Jeff Layton <jlayton@kernel.org>,
Aleksa Sarai <cyphar@cyphar.com>,
Amir Goldstein <amir73il@gmail.com>,
bpf@vger.kernel.org,
"Christian Brauner (Amutable)" <brauner@kernel.org>,
stable@vger.kernel.org
Subject: [PATCH 00/17] mount: more bugfixes, the Oprah edition
Date: Wed, 30 Sep 2026 15:31:52 +0200 [thread overview]
Message-ID: <20260930-work-mount-fixes-3-v1-0-be34c83956ae@kernel.org> (raw)
Yet more bugfixes falling out of my recent work in this area:
- don't let a pseudo dentry become the root of a mount
- don't drop active namespace references that were never taken
- don't put a mountpoint on a dentry that's being removed
- detach the fsnotify connector before destroying its marks
- remove the fsnotify marks of a mount namespace in process context
- don't reconfigure internal superblocks via remount and umount
- check the mounts before reading their parents in pivot_root()
- look at the topmost mount for a mount namespace file
- keep covered mounts covered in OPEN_TREE_NAMESPACE
- check a recursive bind mount for mount namespace loops
- check a submount for references right before unmounting it
- queue a mount only once for mount notifications
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
---
Christian Brauner (17):
namespace: queue a mount only once for mount notifications
namespace: check a submount for references right before unmounting it
selftests/filesystems: check that a busy submount survives a synchronous umount
namespace: check a recursive bind mount for mount namespace loops
selftests/filesystems: check that a recursive bind mount can't pin the caller's mount namespace
namespace: keep covered mounts covered in OPEN_TREE_NAMESPACE
selftests/filesystems: check that OPEN_TREE_NAMESPACE keeps mounts covered
namespace: look at the topmost mount for a mount namespace file
selftests/filesystems: check that a mount namespace file on top doesn't bury a mount
namespace: check the mounts before reading their parents in pivot_root()
namespace: don't reconfigure internal superblocks via remount and umount
selftests/filesystems: check that the nullfs root can't be reconfigured
namespace: remove the fsnotify marks of a mount namespace in process context
fsnotify: detach the connector before destroying its marks
dcache: don't put a mountpoint on a dentry that's being removed
unshare: don't drop active namespace references that were never taken
namespace: don't let a pseudo dentry become the root of a mount
fs/dcache.c | 4 +-
fs/fs_context.c | 4 +
fs/fsopen.c | 3 -
fs/mount.h | 3 +
fs/namespace.c | 133 +++++++++----
fs/notify/mark.c | 16 +-
include/linux/nsproxy.h | 1 +
kernel/fork.c | 3 +-
kernel/nsproxy.c | 2 +-
.../selftests/filesystems/empty_mntns/.gitignore | 1 +
.../selftests/filesystems/empty_mntns/Makefile | 2 +
.../empty_mntns/internal_sb_reconfigure_test.c | 108 +++++++++++
.../selftests/filesystems/mount_cycle/.gitignore | 2 +
.../selftests/filesystems/mount_cycle/Makefile | 1 +
.../filesystems/mount_cycle/nsfs_rbind_loop_test.c | 193 +++++++++++++++++++
.../mount_cycle/overmount_ns_file_test.c | 187 +++++++++++++++++++
.../selftests/filesystems/open_tree_ns/.gitignore | 1 +
.../selftests/filesystems/open_tree_ns/Makefile | 2 +-
.../open_tree_ns/open_tree_ns_covered_test.c | 183 ++++++++++++++++++
.../filesystems/umount_propagation/Makefile | 2 +-
.../umount_propagation/shrink_submounts_test.c | 205 +++++++++++++++++++++
21 files changed, 1008 insertions(+), 48 deletions(-)
---
base-commit: b4698e50d4601f43d21759203be5b0b3c123e383
change-id: 20260930-work-mount-fixes-3-47562ce9b80d
next reply other threads:[~2026-09-30 13:32 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 13:31 Christian Brauner [this message]
2026-09-30 13:31 ` [PATCH 01/17] namespace: queue a mount only once for mount notifications Christian Brauner
2026-09-30 13:31 ` [PATCH 02/17] namespace: check a submount for references right before unmounting it Christian Brauner
2026-09-30 13:31 ` [PATCH 03/17] selftests/filesystems: check that a busy submount survives a synchronous umount Christian Brauner
2026-09-30 13:44 ` sashiko-bot
2026-09-30 13:31 ` [PATCH 04/17] namespace: check a recursive bind mount for mount namespace loops Christian Brauner
2026-09-30 13:31 ` [PATCH 05/17] selftests/filesystems: check that a recursive bind mount can't pin the caller's mount namespace Christian Brauner
2026-09-30 13:31 ` [PATCH 06/17] namespace: keep covered mounts covered in OPEN_TREE_NAMESPACE Christian Brauner
2026-09-30 13:31 ` [PATCH 07/17] selftests/filesystems: check that OPEN_TREE_NAMESPACE keeps mounts covered Christian Brauner
2026-09-30 13:43 ` sashiko-bot
2026-09-30 13:32 ` [PATCH 08/17] namespace: look at the topmost mount for a mount namespace file Christian Brauner
2026-09-30 13:32 ` [PATCH 09/17] selftests/filesystems: check that a mount namespace file on top doesn't bury a mount Christian Brauner
2026-09-30 13:40 ` sashiko-bot
2026-09-30 13:32 ` [PATCH 10/17] namespace: check the mounts before reading their parents in pivot_root() Christian Brauner
2026-09-30 13:32 ` [PATCH 11/17] namespace: don't reconfigure internal superblocks via remount and umount Christian Brauner
2026-09-30 13:32 ` [PATCH 12/17] selftests/filesystems: check that the nullfs root can't be reconfigured Christian Brauner
2026-09-30 13:32 ` [PATCH 13/17] namespace: remove the fsnotify marks of a mount namespace in process context Christian Brauner
2026-09-30 15:07 ` Amir Goldstein
2026-09-30 13:32 ` [PATCH 14/17] fsnotify: detach the connector before destroying its marks Christian Brauner
2026-09-30 13:57 ` sashiko-bot
2026-10-01 9:31 ` Christian Brauner
2026-10-01 10:58 ` Amir Goldstein
2026-10-01 12:06 ` Christian Brauner
2026-09-30 13:32 ` [PATCH 15/17] dcache: don't put a mountpoint on a dentry that's being removed Christian Brauner
2026-09-30 13:32 ` [PATCH 16/17] unshare: don't drop active namespace references that were never taken Christian Brauner
2026-09-30 13:32 ` [PATCH 17/17] namespace: don't let a pseudo dentry become the root of a mount Christian Brauner
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930-work-mount-fixes-3-v1-0-be34c83956ae@kernel.org \
--to=brauner@kernel.org \
--cc=amir73il@gmail.com \
--cc=bpf@vger.kernel.org \
--cc=cyphar@cyphar.com \
--cc=jack@suse.cz \
--cc=jlayton@kernel.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=mason@kernel.org \
--cc=stable@vger.kernel.org \
--cc=torvalds@linux-foundation.org \
--cc=viro@zeniv.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.