From: Christian Brauner <brauner@kernel.org>
To: linux-fsdevel@vger.kernel.org
Cc: Linus Torvalds <torvalds@linux-foundation.org>,
Alexander Viro <viro@zeniv.linux.org.uk>,
Jan Kara <jack@suse.cz>,
"Christian Brauner (Amutable)" <brauner@kernel.org>,
stable@vger.kernel.org
Subject: [PATCH 0/8] mount: a few gnarly fixes
Date: Wed, 23 Sep 2026 14:27:52 +0200 [thread overview]
Message-ID: <20260923-work-mount-fixes-v1-0-f424cf8d3242@kernel.org> (raw)
Hey,
A short while ago I received a bug report about problematic behavior in
the mount code and that let me to review and model a few corner cases
including reference counting. The result is the following set of fixes:
- Ensure that copies of unbindable mounts remain unbindable
- Ensure that MOVE_MOUNT_SET_GROUP doesn't operate on unbindable mounts
so we don't create an undefined state where a mount is both unbindable
and a slave mount.
- Ensure that we don't silently unmount busy mounts. This is nasty
because it's an old bug from v4.13 where calculation of whether a
synchronous (non-MNT_DETACH) umount would succeed drifted apart from
the actual codepath that did the unmount.
- Ensure that we don't silently unmount busy mounts. Same class,
different mechanism. There's a race between the reference count check
in propagate_mount_busy() (summing up per-cpu counters) and mntget().
Fixes and test for all. No test for the mntget() race because that needs
aritifical delays.
And fwiw, I think I another vomitorious series in the pipes.
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
---
Christian Brauner (8):
mount: keep a copied mount unbindable
selftests/filesystems: check that a copied mount namespace keeps unbindable
mount: refuse MOVE_MOUNT_SET_GROUP on an unbindable mount
selftests/move_mount_set_group: check that an unbindable target is refused
fs: don't silently unmount busy mounts
selftests/filesystems: check that a busy propagated copy blocks a synchronous umount
fs: don't let a migrating task hide its reference from do_umount()
docs: update the unmount propagation rule
Documentation/filesystems/sharedsubtree.rst | 20 +-
fs/mount.h | 3 +-
fs/namespace.c | 51 +++--
fs/pnode.c | 108 ++++++++--
tools/testing/selftests/Makefile | 2 +
.../filesystems/mntns_unbindable/Makefile | 6 +
.../mntns_unbindable/mntns_unbindable_test.c | 227 +++++++++++++++++++++
.../filesystems/umount_propagation/Makefile | 6 +
.../umount_propagation/umount_propagation_test.c | 226 ++++++++++++++++++++
.../move_mount_set_group_test.c | 74 ++++++-
10 files changed, 673 insertions(+), 50 deletions(-)
---
base-commit: 2d2a2d7aa98741b58f54cacc99b52024e4d865f9
change-id: 20260923-work-mount-fixes-c9f19fb484eb
next reply other threads:[~2026-09-23 12:28 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-23 12:27 Christian Brauner [this message]
2026-09-23 12:27 ` [PATCH 1/8] mount: keep a copied mount unbindable Christian Brauner
2026-09-23 12:27 ` [PATCH 2/8] selftests/filesystems: check that a copied mount namespace keeps unbindable Christian Brauner
2026-09-23 12:27 ` [PATCH 3/8] mount: refuse MOVE_MOUNT_SET_GROUP on an unbindable mount Christian Brauner
2026-09-23 12:27 ` [PATCH 4/8] selftests/move_mount_set_group: check that an unbindable target is refused Christian Brauner
2026-09-23 12:27 ` [PATCH 5/8] fs: don't silently unmount busy mounts Christian Brauner
2026-09-23 12:27 ` [PATCH 6/8] selftests/filesystems: check that a busy propagated copy blocks a synchronous umount Christian Brauner
2026-09-23 12:27 ` [PATCH 7/8] fs: don't let a migrating task hide its reference from do_umount() Christian Brauner
2026-09-23 12:28 ` [PATCH 8/8] docs: update the unmount propagation rule Christian Brauner
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260923-work-mount-fixes-v1-0-f424cf8d3242@kernel.org \
--to=brauner@kernel.org \
--cc=jack@suse.cz \
--cc=linux-fsdevel@vger.kernel.org \
--cc=stable@vger.kernel.org \
--cc=torvalds@linux-foundation.org \
--cc=viro@zeniv.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox