From: Christian Brauner <brauner@kernel.org>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Jann Horn <jannh@google.com>, Jan Kara <jack@suse.cz>,
Amir Goldstein <amir73il@gmail.com>,
linux-fsdevel@vger.kernel.org,
Alexander Viro <viro@zeniv.linux.org.uk>,
"Christian Brauner (Amutable)" <brauner@kernel.org>
Subject: [PATCH RFC v2 3/8] fs: put the old fs_struct before the old namespaces in unshare()
Date: Fri, 25 Sep 2026 00:35:43 +0200 [thread overview]
Message-ID: <20260925-work-mount-knullfs-v2-3-c4aebaa186e9@kernel.org> (raw)
In-Reply-To: <20260925-work-mount-knullfs-v2-0-c4aebaa186e9@kernel.org>
unshare(CLONE_NEWNS) always copies the fs_struct and copy_mnt_ns()
points root and pwd of that copy into the new mount namespace. The old
fs_struct pins the old root and pwd until ksys_unshare() frees it at the
end and switch_task_namespaces() will already put the old mount
namespace before.
This causes pointless work in user namespaces because the copied mounts
are locked and stay connected. Switch and free the fs_struct before
switching the namespaces. The old root and pwd are wasted while their
mount namespace is still alive which also keeps both puts on the
mntput() fast path.
setns() already does this right as it updates root and pwd before the
namespaces are switched.
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
---
kernel/fork.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
diff --git a/kernel/fork.c b/kernel/fork.c
index 416758c8a3d4..da48168c504f 100644
--- a/kernel/fork.c
+++ b/kernel/fork.c
@@ -3312,14 +3312,17 @@ int ksys_unshare(unsigned long unshare_flags)
shm_init_task(current);
}
+ if (new_fs) {
+ new_fs = switch_fs_struct(new_fs);
+ if (new_fs)
+ free_fs_struct(no_free_ptr(new_fs));
+ }
+
if (new_nsproxy) {
switch_task_namespaces(current, new_nsproxy);
new_nsproxy = NULL;
}
- if (new_fs)
- new_fs = switch_fs_struct(new_fs);
-
if (new_fd) {
guard(task_lock)(current);
swap(current->files, new_fd);
--
2.53.0
next prev parent reply other threads:[~2026-09-24 22:35 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 22:35 [PATCH RFC v2 0/8] namespace: prevent UMOUNT_CONNECTED reference count cycles Christian Brauner
2026-09-24 22:35 ` [PATCH RFC v2 1/8] fs: refuse fspick() on internal superblocks Christian Brauner
2026-09-24 22:35 ` [PATCH RFC v2 2/8] fsnotify: record the superblock a connector is accounted on Christian Brauner
2026-09-24 22:35 ` Christian Brauner [this message]
2026-09-24 22:35 ` [PATCH RFC v2 4/8] namespace: drop the file's reference first in dissolve_on_fput() Christian Brauner
2026-09-24 22:35 ` [PATCH RFC v2 5/8] namespace: prevent UMOUNT_CONNECTED reference count cycles Christian Brauner
2026-09-24 22:35 ` [PATCH RFC v2 6/8] selftests/filesystems: check that a loop mount below a dead mount is released Christian Brauner
2026-09-24 22:35 ` [PATCH RFC v2 7/8] selftests/filesystems: check the two-step cycle over crossed loop images Christian Brauner
2026-09-24 22:35 ` [PATCH RFC v2 8/8] selftests/filesystems: check that the holders let go of a dead mount Christian Brauner
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260925-work-mount-knullfs-v2-3-c4aebaa186e9@kernel.org \
--to=brauner@kernel.org \
--cc=amir73il@gmail.com \
--cc=jack@suse.cz \
--cc=jannh@google.com \
--cc=linux-fsdevel@vger.kernel.org \
--cc=torvalds@linux-foundation.org \
--cc=viro@zeniv.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox