FILESYSTEM IN USERSPACE (FUSE) development
 help / color / mirror / Atom feed
From: "Darrick J. Wong" <djwong@kernel.org>
To: bernd@bsbernd.com
Cc: fuse-devel@lists.linux.dev, neal@gompa.dev
Subject: Re: [PATCH v2 04/14] mount_service: use openat to OPEN paths
Date: Mon, 28 Sep 2026 19:27:18 -0700	[thread overview]
Message-ID: <20260929022718.GD6253@frogsfrogsfrogs> (raw)
In-Reply-To: <20260928-mount-service-bound-open-v2-4-0f9f501d05ce@bsbernd.com>

On Mon, Sep 28, 2026 at 01:02:06PM +0200, Bernd Schubert via B4 Relay wrote:
> From: Bernd Schubert <bernd@bsbernd.com>
> 
> The fuse server sends fuservicemount3 a series of requests: OPEN for
> its backing file, MNTPT to name the mount point, then MOUNT. The server
> chooses the order. For a directory mount point, attach_to_mountpoint()
> changes the working directory of the helper to the mount point. The
> helper then mounts on ".", so a rename of the path cannot redirect the
> mount.
> 
> A relative path in an OPEN request after MNTPT resolved inside the
> mount point. For "fuservicemount3 disk.img /mnt -t fuse.service_ll",
> an OPEN of "disk.img" matched the command line argument, but the helper
> opened /mnt/disk.img, not disk.img in the user's working directory. The
> helper now opens OPEN paths with openat() on the working directory it
> started in.
> 
> Assisted-by: LLM
> Signed-off-by: Bernd Schubert <bernd@bsbernd.com>

Looks good!
Reviewed-by: "Darrick J. Wong" <djwong@kernel.org>

--D

> ---
>  util/mount_service.c | 20 +++++++++++++++++++-
>  1 file changed, 19 insertions(+), 1 deletion(-)
> 
> diff --git a/util/mount_service.c b/util/mount_service.c
> index b4081d53273e..84e9d831ce03 100644
> --- a/util/mount_service.c
> +++ b/util/mount_service.c
> @@ -84,6 +84,9 @@ struct mount_service {
>  	/* fd for fsopen */
>  	int fsopenfd;
>  
> +	/* fd for the initial working directory */
> +	int cwdfd;
> +
>  	/* did we actually mount successfully? */
>  	bool mounted;
>  
> @@ -247,6 +250,18 @@ static int mount_service_init(struct mount_service *mo, int argc, char *argv[])
>  		return -1;
>  	}
>  
> +	drop_privs();
> +	mo->cwdfd = open(".", O_PATH | O_CLOEXEC);
> +	if (mo->cwdfd < 0) {
> +		int error = errno;
> +
> +		restore_privs();
> +		fprintf(stderr, "%s: cannot open working directory: %s\n",
> +			mo->msgtag, strerror(error));
> +		return -1;
> +	}
> +	restore_privs();
> +
>  	return 0;
>  }
>  
> @@ -859,8 +874,9 @@ static int mount_service_open_path(const struct mount_service *mo,
>  	}
>  
>  	open_flags = ntohl(oc->open_flags) | O_CLOEXEC;
> +	/* After fchdir to the mountpoint, a relative path would resolve there */
>  	drop_privs();
> -	fd = open(oc->path, open_flags, ntohl(oc->create_mode));
> +	fd = openat(mo->cwdfd, oc->path, open_flags, ntohl(oc->create_mode));
>  	if (fd < 0) {
>  		int error = errno;
>  
> @@ -1807,6 +1823,7 @@ static void mount_service_destroy(struct mount_service *mo)
>  	close(mo->fusedevfd);
>  	close(mo->argvfd);
>  	close(mo->fsopenfd);
> +	close(mo->cwdfd);
>  	shutdown(mo->sockfd, SHUT_RDWR);
>  	close(mo->sockfd);
>  
> @@ -1824,6 +1841,7 @@ static void mount_service_destroy(struct mount_service *mo)
>  	mo->fusedevfd = -1;
>  	mo->mountfd = -1;
>  	mo->fsopenfd = -1;
> +	mo->cwdfd = -1;
>  }
>  
>  int mount_service_main(int argc, char *argv[])
> 
> -- 
> 2.53.0
> 
> 
> 

  reply	other threads:[~2026-09-29  2:27 UTC|newest]

Thread overview: 26+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28 11:02 [PATCH v2 00/14] libfuse: Add mount service safety checks and tests Bernd Schubert via B4 Relay
2026-09-28 11:02 ` [PATCH v2 01/14] mount_service: move the command line check into arg_in_cmdline() Bernd Schubert via B4 Relay
2026-09-28 11:02 ` [PATCH v2 02/14] mount_service: warn about paths not named on the command line Bernd Schubert via B4 Relay
2026-09-29  2:10   ` Darrick J. Wong
2026-09-30 11:06     ` Bernd Schubert
2026-09-28 11:02 ` [PATCH v2 03/14] mount_service: refuse paths the user did not name Bernd Schubert via B4 Relay
2026-09-29  2:26   ` Darrick J. Wong
2026-09-30 11:46     ` Bernd Schubert
2026-09-28 11:02 ` [PATCH v2 04/14] mount_service: use openat to OPEN paths Bernd Schubert via B4 Relay
2026-09-29  2:27   ` Darrick J. Wong [this message]
2026-09-28 11:02 ` [PATCH v2 05/14] util: give fuservicemount3 an absolute build-tree runpath Bernd Schubert via B4 Relay
2026-09-28 11:02 ` [PATCH v2 06/14] mount.fuse: free the options on the service mount return path Bernd Schubert via B4 Relay
2026-09-28 11:02 ` [PATCH v2 07/14] example/single_file: take no sector size from a regular backing file Bernd Schubert via B4 Relay
2026-09-28 11:02 ` [PATCH v2 08/14] test: check which files fuservicemount3 opens for the server Bernd Schubert via B4 Relay
2026-09-29  3:52   ` Darrick J. Wong
2026-09-28 11:02 ` [PATCH v2 09/14] test: check what fuservicemount3 refuses Bernd Schubert via B4 Relay
2026-09-29  3:55   ` Darrick J. Wong
2026-09-28 11:02 ` [PATCH v2 10/14] test: mount the service examples through fuservicemount3 Bernd Schubert via B4 Relay
2026-09-28 11:02 ` [PATCH v2 11/14] test: run mkfs.ext4 through the service examples Bernd Schubert via B4 Relay
2026-09-28 11:02 ` [PATCH v2 12/14] fuse_service: bound argc and arg len read from the args memfd Bernd Schubert via B4 Relay
2026-09-29  2:33   ` Darrick J. Wong
2026-09-28 11:02 ` [PATCH v2 13/14] build: move the default service socket directory to /run/fuse Bernd Schubert via B4 Relay
2026-09-29  2:34   ` Darrick J. Wong
2026-09-28 11:02 ` [PATCH v2 14/14] Improve documentation for fuse service mount Bernd Schubert via B4 Relay
2026-09-29  2:43   ` Darrick J. Wong
2026-09-30 13:09     ` Bernd Schubert

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929022718.GD6253@frogsfrogsfrogs \
    --to=djwong@kernel.org \
    --cc=bernd@bsbernd.com \
    --cc=fuse-devel@lists.linux.dev \
    --cc=neal@gompa.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox