From: "André Almeida" <andrealmeid@igalia.com>
To: linux-kernel@vger.kernel.org, linux-btrfs@vger.kernel.org,
linux-unionfs@vger.kernel.org, linux-fsdevel@vger.kernel.org
Cc: kernel-dev@igalia.com, "Miklos Szeredi" <miklos@szeredi.hu>,
"Amir Goldstein" <amir73il@gmail.com>, "Chris Mason" <clm@fb.com>,
"David Sterba" <dsterba@suse.com>,
"Anand Jain" <anand.jain@oracle.com>,
"Guilherme G . Piccoli" <gpiccoli@igalia.com>,
"André Almeida" <andrealmeid@igalia.com>
Subject: [RFC PATCH 1/1] ovl: Use fsid as unique identifier for trusted origin
Date: Mon, 13 Oct 2025 22:57:07 -0300 [thread overview]
Message-ID: <20251014015707.129013-2-andrealmeid@igalia.com> (raw)
In-Reply-To: <20251014015707.129013-1-andrealmeid@igalia.com>
Some filesystem have non-persistent UUIDs, that can change between
mounting, even if the filesystem is not modified. To prevent
false-positives when mounting overlayfs with index enabled, use the fsid
reported from statfs that is persistent across mounts.
Signed-off-by: André Almeida <andrealmeid@igalia.com>
---
This patch is just for illustrative purposes and doesn't work.
---
fs/overlayfs/copy_up.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/fs/overlayfs/copy_up.c b/fs/overlayfs/copy_up.c
index aac7e34f56c1..633d9470a089 100644
--- a/fs/overlayfs/copy_up.c
+++ b/fs/overlayfs/copy_up.c
@@ -8,6 +8,7 @@
#include <linux/fs.h>
#include <linux/slab.h>
#include <linux/file.h>
+#include <linux/statfs.h>
#include <linux/fileattr.h>
#include <linux/splice.h>
#include <linux/xattr.h>
@@ -421,9 +422,14 @@ struct ovl_fh *ovl_encode_real_fh(struct ovl_fs *ofs, struct inode *realinode,
struct ovl_fh *fh;
int fh_type, dwords;
int buflen = MAX_HANDLE_SZ;
- uuid_t *uuid = &realinode->i_sb->s_uuid;
+ uuid_t uuid;
+ struct kstatfs ks;
int err;
+ // RFC: dentry can't be NULL, uuid needs a type cast
+ realinode->i_sb->s_op->statfs(NULL, &ks);
+ uuid.b = ks.f_fsid;
+
/* Make sure the real fid stays 32bit aligned */
BUILD_BUG_ON(OVL_FH_FID_OFFSET % 4);
BUILD_BUG_ON(MAX_HANDLE_SZ + OVL_FH_FID_OFFSET > 255);
--
2.51.0
next prev parent reply other threads:[~2025-10-14 1:57 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-10-14 1:57 [RFC PATCH 0/1] ovl: brtfs' temp_fsid doesn't work with ovl index=on André Almeida
2025-10-14 1:57 ` André Almeida [this message]
2025-10-14 4:39 ` [RFC PATCH 1/1] ovl: Use fsid as unique identifier for trusted origin Christoph Hellwig
2025-10-14 5:13 ` Qu Wenruo
2025-10-14 17:40 ` David Sterba
2025-10-14 17:55 ` André Almeida
2025-10-14 23:46 ` Anand Jain
2025-10-15 1:22 ` Christoph Hellwig
2025-10-20 21:43 ` Dave Chinner
2025-10-21 1:16 ` Anand Jain
2025-10-15 10:52 ` Amir Goldstein
2025-10-14 5:26 ` [RFC PATCH 0/1] ovl: brtfs' temp_fsid doesn't work with ovl index=on Qu Wenruo
2025-10-14 18:24 ` David Sterba
2025-10-14 21:08 ` Qu Wenruo
2025-10-15 0:05 ` Anand Jain
2025-10-15 4:18 ` Qu Wenruo
2025-10-14 22:04 ` Anand Jain
2025-10-15 11:09 ` Amir Goldstein
2025-10-16 4:57 ` Christoph Hellwig
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20251014015707.129013-2-andrealmeid@igalia.com \
--to=andrealmeid@igalia.com \
--cc=amir73il@gmail.com \
--cc=anand.jain@oracle.com \
--cc=clm@fb.com \
--cc=dsterba@suse.com \
--cc=gpiccoli@igalia.com \
--cc=kernel-dev@igalia.com \
--cc=linux-btrfs@vger.kernel.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-unionfs@vger.kernel.org \
--cc=miklos@szeredi.hu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox