From: "Darrick J. Wong" <djwong@kernel.org>
To: Miklos Szeredi <mszeredi@redhat.com>
Cc: linux-fsdevel@vger.kernel.org, Bernd Schubert <bernd@bsbernd.com>
Subject: Re: [PATCH v2 4/6] fuse: clean up device cloning
Date: Fri, 13 Mar 2026 16:59:51 -0700 [thread overview]
Message-ID: <20260313235951.GH1742010@frogsfrogsfrogs> (raw)
In-Reply-To: <20260312194019.3077902-5-mszeredi@redhat.com>
On Thu, Mar 12, 2026 at 08:40:02PM +0100, Miklos Szeredi wrote:
> - fuse_mutex is not needed for device cloning, because fuse_dev_install()
> uses cmpxcg() to set fud->fc, which prevents races between clone/mount
> or clone/clone. This makes the logic simpler
>
> - Drop fc->dev_count. This is only used to check in release if the device
> is the last clone, but checking list_empty(&fc->devices) is equivalent
> after removing the released device from the list. Removing the fuse_dev
> before calling fuse_abort_conn() is okay, since the processing and io
> lists are now empty for this device.
>
> Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
> ---
> fs/fuse/dev.c | 44 ++++++++++++++++----------------------------
> fs/fuse/fuse_i.h | 3 ---
> fs/fuse/inode.c | 1 -
> 3 files changed, 16 insertions(+), 32 deletions(-)
>
> diff --git a/fs/fuse/dev.c b/fs/fuse/dev.c
> index 3adf6bd38c9b..18cc844cf290 100644
> --- a/fs/fuse/dev.c
> +++ b/fs/fuse/dev.c
> @@ -2543,14 +2543,15 @@ int fuse_dev_release(struct inode *inode, struct file *file)
>
> fuse_dev_end_requests(&to_end);
>
> + spin_lock(&fc->lock);
> + list_del(&fud->entry);
> + spin_unlock(&fc->lock);
> +
> /* Are we the last open device? */
> - if (atomic_dec_and_test(&fc->dev_count)) {
> + if (list_empty(&fc->devices)) {
If you have two threads closing their cloned fuse dev fds, can they both
see an empty list here and abort the connection? I think they can, but
it's benign because the abort takes its own spinlock.
Aside from that question, this looks ok to me.
--D
> WARN_ON(fc->iq.fasync != NULL);
> fuse_abort_conn(fc);
> }
> - spin_lock(&fc->lock);
> - list_del(&fud->entry);
> - spin_unlock(&fc->lock);
> fuse_conn_put(fc);
> }
> fuse_dev_put(fud);
> @@ -2569,24 +2570,10 @@ static int fuse_dev_fasync(int fd, struct file *file, int on)
> return fasync_helper(fd, file, on, &fud->fc->iq.fasync);
> }
>
> -static int fuse_device_clone(struct fuse_conn *fc, struct file *new)
> -{
> - struct fuse_dev *new_fud = fuse_file_to_fud(new);
> -
> - if (fuse_dev_fc_get(new_fud))
> - return -EINVAL;
> -
> - fuse_dev_install(new_fud, fc);
> - atomic_inc(&fc->dev_count);
> -
> - return 0;
> -}
> -
> static long fuse_dev_ioctl_clone(struct file *file, __u32 __user *argp)
> {
> - int res;
> int oldfd;
> - struct fuse_dev *fud = NULL;
> + struct fuse_dev *fud, *new_fud;
>
> if (get_user(oldfd, argp))
> return -EFAULT;
> @@ -2599,17 +2586,18 @@ static long fuse_dev_ioctl_clone(struct file *file, __u32 __user *argp)
> * Check against file->f_op because CUSE
> * uses the same ioctl handler.
> */
> - if (fd_file(f)->f_op == file->f_op)
> - fud = __fuse_get_dev(fd_file(f));
> + if (fd_file(f)->f_op != file->f_op)
> + return -EINVAL;
>
> - res = -EINVAL;
> - if (fud) {
> - mutex_lock(&fuse_mutex);
> - res = fuse_device_clone(fud->fc, file);
> - mutex_unlock(&fuse_mutex);
> - }
> + fud = __fuse_get_dev(fd_file(f));
> + if (!fud)
> + return -EINVAL;
>
> - return res;
> + new_fud = fuse_file_to_fud(file);
> + if (!fuse_dev_install(new_fud, fud->fc))
> + return -EINVAL;
> +
> + return 0;
> }
>
> static long fuse_dev_ioctl_backing_open(struct file *file,
> diff --git a/fs/fuse/fuse_i.h b/fs/fuse/fuse_i.h
> index b77b384b0385..92576e28f8ac 100644
> --- a/fs/fuse/fuse_i.h
> +++ b/fs/fuse/fuse_i.h
> @@ -647,9 +647,6 @@ struct fuse_conn {
> /** Refcount */
> refcount_t count;
>
> - /** Number of fuse_dev's */
> - atomic_t dev_count;
> -
> /** Current epoch for up-to-date dentries */
> atomic_t epoch;
>
> diff --git a/fs/fuse/inode.c b/fs/fuse/inode.c
> index 45abcfec03a4..e42356d60f7a 100644
> --- a/fs/fuse/inode.c
> +++ b/fs/fuse/inode.c
> @@ -995,7 +995,6 @@ void fuse_conn_init(struct fuse_conn *fc, struct fuse_mount *fm,
> spin_lock_init(&fc->bg_lock);
> init_rwsem(&fc->killsb);
> refcount_set(&fc->count, 1);
> - atomic_set(&fc->dev_count, 1);
> atomic_set(&fc->epoch, 1);
> INIT_WORK(&fc->epoch_work, fuse_epoch_work);
> init_waitqueue_head(&fc->blocked_waitq);
> --
> 2.53.0
>
>
next prev parent reply other threads:[~2026-03-13 23:59 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-03-12 19:39 [PATCH v2 0/6] fuse: fix hang with sync init Miklos Szeredi
2026-03-12 19:39 ` [PATCH v2 1/6] fuse: create fuse_dev on /dev/fuse open instead of mount Miklos Szeredi
2026-03-13 22:05 ` Darrick J. Wong
2026-03-16 10:04 ` Miklos Szeredi
2026-03-19 23:36 ` Mark Brown
2026-03-12 19:40 ` [PATCH v2 2/6] fuse: add refcount to fuse_dev Miklos Szeredi
2026-03-13 22:28 ` Darrick J. Wong
2026-03-16 10:50 ` Miklos Szeredi
2026-03-12 19:40 ` [PATCH v2 3/6] fuse: don't require /dev/fuse fd to be kept open during mount Miklos Szeredi
2026-03-13 23:09 ` Darrick J. Wong
2026-03-16 11:29 ` Miklos Szeredi
2026-03-17 23:39 ` Darrick J. Wong
2026-03-17 23:49 ` Joanne Koong
2026-03-18 22:15 ` Bernd Schubert
2026-03-18 23:18 ` Joanne Koong
2026-03-12 19:40 ` [PATCH v2 4/6] fuse: clean up device cloning Miklos Szeredi
2026-03-13 23:59 ` Darrick J. Wong [this message]
2026-03-16 11:40 ` Miklos Szeredi
2026-03-12 19:40 ` [PATCH v2 5/6] fuse: alloc pqueue before installing fc Miklos Szeredi
2026-03-12 19:40 ` [PATCH v2 6/6] fuse: support FSCONFIG_SET_FD for "fd" option Miklos Szeredi
2026-03-13 12:03 ` kernel test robot
2026-03-14 0:10 ` Darrick J. Wong
2026-03-14 17:22 ` kernel test robot
2026-03-12 23:04 ` [PATCH v2 0/6] fuse: fix hang with sync init Bernd Schubert
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260313235951.GH1742010@frogsfrogsfrogs \
--to=djwong@kernel.org \
--cc=bernd@bsbernd.com \
--cc=linux-fsdevel@vger.kernel.org \
--cc=mszeredi@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox