From: Christian Brauner <brauner@kernel.org>
To: linux-fsdevel@vger.kernel.org
Cc: Linus Torvalds <torvalds@linux-foundation.org>,
Jann Horn <jannh@google.com>, Jan Kara <jack@suse.cz>,
Amir Goldstein <amir73il@gmail.com>,
Alexander Viro <viro@zeniv.linux.org.uk>,
"Christian Brauner (Amutable)" <brauner@kernel.org>
Subject: [PATCH 1/3] nullfs: add an empty immutable regular file
Date: Fri, 02 Oct 2026 16:14:27 +0200 [thread overview]
Message-ID: <20261002-work-mount-cover-v1-1-232a8f52b43c@kernel.org> (raw)
In-Reply-To: <20261002-work-mount-cover-v1-0-232a8f52b43c@kernel.org>
Add nullfs_new_file() to allocate an empty immutable regular file on a
nullfs instance as a dentry of its own. It is never hashed under the
root and so can't be found by lookup. Reads return nothing, changes are
refused, file locks, leases and delegations are refused as.
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
---
fs/mount.h | 1 +
fs/namespace.c | 25 +++++++++++++++++++++++++
fs/nullfs.c | 46 ++++++++++++++++++++++++++++++++++++++++++++++
3 files changed, 72 insertions(+)
diff --git a/fs/mount.h b/fs/mount.h
index 4e68e5cbc254..2e29cdbaeb74 100644
--- a/fs/mount.h
+++ b/fs/mount.h
@@ -6,6 +6,7 @@
#include <linux/fs_pin.h>
extern struct file_system_type nullfs_fs_type;
+extern struct dentry *nullfs_new_file(struct super_block *sb);
extern struct vfsmount *knullfs;
extern struct list_head notify_list;
diff --git a/fs/namespace.c b/fs/namespace.c
index e1b0ade95b0d..ff21e0440fae 100644
--- a/fs/namespace.c
+++ b/fs/namespace.c
@@ -81,6 +81,7 @@ static struct hlist_head *mount_hashtable __ro_after_init;
static struct hlist_head *mountpoint_hashtable __ro_after_init;
static struct kmem_cache *mnt_cache __ro_after_init;
struct vfsmount *knullfs __ro_after_init; /* private nullfs instance */
+static struct vfsmount *knullfs_file __ro_after_init; /* its regular file */
static DECLARE_RWSEM(namespace_sem);
static HLIST_HEAD(unmounted); /* protected by namespace_sem */
static LIST_HEAD(ex_mountpoints); /* protected by namespace_sem */
@@ -6330,6 +6331,25 @@ static void __init mount_rootfs_on_nullfs(struct vfsmount *mnt,
attach_mnt(real_mount(mnt), mp.parent, mp.mp);
}
+static struct vfsmount *__init knullfs_file_mount(void)
+{
+ struct dentry *file;
+ struct mount *mnt;
+
+ file = nullfs_new_file(knullfs->mnt_sb);
+ if (IS_ERR(file))
+ return ERR_CAST(file);
+ mnt = clone_mnt(real_mount(knullfs), file, CL_PRIVATE);
+ dput(file);
+ if (IS_ERR(mnt))
+ return ERR_CAST(mnt);
+ mnt->mnt_ns = MNT_NS_INTERNAL;
+ mnt->mnt.mnt_flags |= MNT_INTERNAL | MNT_READONLY;
+ /* nothing is ever mounted on it either */
+ dont_mount(mnt->mnt.mnt_root);
+ return &mnt->mnt;
+}
+
static void __init init_mount_tree(void)
{
struct vfsmount *mnt, *nullfs_mnt;
@@ -6342,6 +6362,8 @@ static void __init init_mount_tree(void)
* (1) nullfs with mount id 1
* (2) mutable rootfs with mount id 2
* (3) private nullfs for kthreads (SB_KERNMOUNT), kept in knullfs
+ * (4) a second mount of (3) rooted on a regular file, kept in
+ * knullfs_file
*
* with (2) mounted on top of (1). The init_task's root and pwd
* are pointed at (3) so all kthreads start isolated in nullfs.
@@ -6383,6 +6405,9 @@ static void __init init_mount_tree(void)
dont_mount(knullfs->mnt_root);
/* and nothing is ever written through it */
knullfs->mnt_flags |= MNT_READONLY;
+ knullfs_file = knullfs_file_mount();
+ if (IS_ERR(knullfs_file))
+ panic("VFS: Failed to create the nullfs file stand-in");
root.mnt = knullfs;
root.dentry = knullfs->mnt_root;
diff --git a/fs/nullfs.c b/fs/nullfs.c
index bfc04bca3940..b1469e49b2d1 100644
--- a/fs/nullfs.c
+++ b/fs/nullfs.c
@@ -47,6 +47,52 @@ static const struct file_operations nullfs_dir_operations = {
.fop_flags = FOP_IMMUTABLE,
};
+/* a file of nullfs is permanently empty */
+static ssize_t nullfs_file_read_iter(struct kiocb *iocb, struct iov_iter *to)
+{
+ return 0;
+}
+
+/* an empty regular file, with the same refusals as the directory */
+static const struct file_operations nullfs_file_operations = {
+ .llseek = generic_file_llseek,
+ .read_iter = nullfs_file_read_iter,
+ .fsync = noop_fsync,
+ .lock = nullfs_nolock,
+ .flock = nullfs_nolock,
+ .setlease = nullfs_nolease,
+};
+
+/*
+ * An empty immutable regular file on @sb as a dentry of its own. It is
+ * never hashed under the root so no lookup finds it.
+ */
+struct dentry *nullfs_new_file(struct super_block *sb)
+{
+ struct dentry *dentry;
+ struct inode *inode;
+
+ inode = new_inode(sb);
+ if (!inode)
+ return ERR_PTR(-ENOMEM);
+
+ /* the root directory is 1 */
+ inode->i_ino = 2;
+ inode->i_mode = S_IFREG | 0444;
+ inode->i_fop = &nullfs_file_operations;
+ simple_inode_init_ts(inode);
+ /* ... and immutable, reading it leaves no trace either */
+ inode->i_flags |= S_IMMUTABLE | S_NOATIME;
+
+ dentry = d_alloc_anon(sb);
+ if (!dentry) {
+ iput(inode);
+ return ERR_PTR(-ENOMEM);
+ }
+ d_instantiate(dentry, inode);
+ return dentry;
+}
+
static int nullfs_fs_fill_super(struct super_block *s, struct fs_context *fc)
{
struct inode *inode;
--
2.53.0
next prev parent reply other threads:[~2026-10-02 14:14 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-02 14:14 [PATCH 0/3] namespace: rework connected mounts Christian Brauner
2026-10-02 14:14 ` Christian Brauner [this message]
2026-10-02 14:31 ` [PATCH 1/3] nullfs: add an empty immutable regular file Jann Horn
2026-10-05 10:33 ` Christian Brauner
2026-10-02 14:14 ` [PATCH 2/3] namespace: rework connected mounts Christian Brauner
2026-10-02 14:14 ` [PATCH 3/3] selftests/filesystems: test covered mounts Christian Brauner
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261002-work-mount-cover-v1-1-232a8f52b43c@kernel.org \
--to=brauner@kernel.org \
--cc=amir73il@gmail.com \
--cc=jack@suse.cz \
--cc=jannh@google.com \
--cc=linux-fsdevel@vger.kernel.org \
--cc=torvalds@linux-foundation.org \
--cc=viro@zeniv.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox