From: "Darrick J. Wong" <djwong@kernel.org>
To: bernd@bsbernd.com
Cc: fuse-devel@lists.linux.dev, neal@gompa.dev
Subject: Re: [PATCH v2 04/14] mount_service: use openat to OPEN paths
Date: Mon, 28 Sep 2026 19:27:18 -0700 [thread overview]
Message-ID: <20260929022718.GD6253@frogsfrogsfrogs> (raw)
In-Reply-To: <20260928-mount-service-bound-open-v2-4-0f9f501d05ce@bsbernd.com>
On Mon, Sep 28, 2026 at 01:02:06PM +0200, Bernd Schubert via B4 Relay wrote:
> From: Bernd Schubert <bernd@bsbernd.com>
>
> The fuse server sends fuservicemount3 a series of requests: OPEN for
> its backing file, MNTPT to name the mount point, then MOUNT. The server
> chooses the order. For a directory mount point, attach_to_mountpoint()
> changes the working directory of the helper to the mount point. The
> helper then mounts on ".", so a rename of the path cannot redirect the
> mount.
>
> A relative path in an OPEN request after MNTPT resolved inside the
> mount point. For "fuservicemount3 disk.img /mnt -t fuse.service_ll",
> an OPEN of "disk.img" matched the command line argument, but the helper
> opened /mnt/disk.img, not disk.img in the user's working directory. The
> helper now opens OPEN paths with openat() on the working directory it
> started in.
>
> Assisted-by: LLM
> Signed-off-by: Bernd Schubert <bernd@bsbernd.com>
Looks good!
Reviewed-by: "Darrick J. Wong" <djwong@kernel.org>
--D
> ---
> util/mount_service.c | 20 +++++++++++++++++++-
> 1 file changed, 19 insertions(+), 1 deletion(-)
>
> diff --git a/util/mount_service.c b/util/mount_service.c
> index b4081d53273e..84e9d831ce03 100644
> --- a/util/mount_service.c
> +++ b/util/mount_service.c
> @@ -84,6 +84,9 @@ struct mount_service {
> /* fd for fsopen */
> int fsopenfd;
>
> + /* fd for the initial working directory */
> + int cwdfd;
> +
> /* did we actually mount successfully? */
> bool mounted;
>
> @@ -247,6 +250,18 @@ static int mount_service_init(struct mount_service *mo, int argc, char *argv[])
> return -1;
> }
>
> + drop_privs();
> + mo->cwdfd = open(".", O_PATH | O_CLOEXEC);
> + if (mo->cwdfd < 0) {
> + int error = errno;
> +
> + restore_privs();
> + fprintf(stderr, "%s: cannot open working directory: %s\n",
> + mo->msgtag, strerror(error));
> + return -1;
> + }
> + restore_privs();
> +
> return 0;
> }
>
> @@ -859,8 +874,9 @@ static int mount_service_open_path(const struct mount_service *mo,
> }
>
> open_flags = ntohl(oc->open_flags) | O_CLOEXEC;
> + /* After fchdir to the mountpoint, a relative path would resolve there */
> drop_privs();
> - fd = open(oc->path, open_flags, ntohl(oc->create_mode));
> + fd = openat(mo->cwdfd, oc->path, open_flags, ntohl(oc->create_mode));
> if (fd < 0) {
> int error = errno;
>
> @@ -1807,6 +1823,7 @@ static void mount_service_destroy(struct mount_service *mo)
> close(mo->fusedevfd);
> close(mo->argvfd);
> close(mo->fsopenfd);
> + close(mo->cwdfd);
> shutdown(mo->sockfd, SHUT_RDWR);
> close(mo->sockfd);
>
> @@ -1824,6 +1841,7 @@ static void mount_service_destroy(struct mount_service *mo)
> mo->fusedevfd = -1;
> mo->mountfd = -1;
> mo->fsopenfd = -1;
> + mo->cwdfd = -1;
> }
>
> int mount_service_main(int argc, char *argv[])
>
> --
> 2.53.0
>
>
>
next prev parent reply other threads:[~2026-09-29 2:27 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 11:02 [PATCH v2 00/14] libfuse: Add mount service safety checks and tests Bernd Schubert via B4 Relay
2026-09-28 11:02 ` [PATCH v2 01/14] mount_service: move the command line check into arg_in_cmdline() Bernd Schubert via B4 Relay
2026-09-28 11:02 ` [PATCH v2 02/14] mount_service: warn about paths not named on the command line Bernd Schubert via B4 Relay
2026-09-29 2:10 ` Darrick J. Wong
2026-09-30 11:06 ` Bernd Schubert
2026-09-28 11:02 ` [PATCH v2 03/14] mount_service: refuse paths the user did not name Bernd Schubert via B4 Relay
2026-09-29 2:26 ` Darrick J. Wong
2026-09-30 11:46 ` Bernd Schubert
2026-09-28 11:02 ` [PATCH v2 04/14] mount_service: use openat to OPEN paths Bernd Schubert via B4 Relay
2026-09-29 2:27 ` Darrick J. Wong [this message]
2026-09-28 11:02 ` [PATCH v2 05/14] util: give fuservicemount3 an absolute build-tree runpath Bernd Schubert via B4 Relay
2026-09-28 11:02 ` [PATCH v2 06/14] mount.fuse: free the options on the service mount return path Bernd Schubert via B4 Relay
2026-09-28 11:02 ` [PATCH v2 07/14] example/single_file: take no sector size from a regular backing file Bernd Schubert via B4 Relay
2026-09-28 11:02 ` [PATCH v2 08/14] test: check which files fuservicemount3 opens for the server Bernd Schubert via B4 Relay
2026-09-29 3:52 ` Darrick J. Wong
2026-09-28 11:02 ` [PATCH v2 09/14] test: check what fuservicemount3 refuses Bernd Schubert via B4 Relay
2026-09-29 3:55 ` Darrick J. Wong
2026-09-28 11:02 ` [PATCH v2 10/14] test: mount the service examples through fuservicemount3 Bernd Schubert via B4 Relay
2026-09-28 11:02 ` [PATCH v2 11/14] test: run mkfs.ext4 through the service examples Bernd Schubert via B4 Relay
2026-09-28 11:02 ` [PATCH v2 12/14] fuse_service: bound argc and arg len read from the args memfd Bernd Schubert via B4 Relay
2026-09-29 2:33 ` Darrick J. Wong
2026-09-28 11:02 ` [PATCH v2 13/14] build: move the default service socket directory to /run/fuse Bernd Schubert via B4 Relay
2026-09-29 2:34 ` Darrick J. Wong
2026-09-28 11:02 ` [PATCH v2 14/14] Improve documentation for fuse service mount Bernd Schubert via B4 Relay
2026-09-29 2:43 ` Darrick J. Wong
2026-09-30 13:09 ` Bernd Schubert
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929022718.GD6253@frogsfrogsfrogs \
--to=djwong@kernel.org \
--cc=bernd@bsbernd.com \
--cc=fuse-devel@lists.linux.dev \
--cc=neal@gompa.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox