* [PATCH] erofs: reuse superblock for file-backed mounts
@ 2026-07-30 12:41 Giuseppe Scrivano
2026-07-30 12:57 ` Pedro Falcato
0 siblings, 1 reply; 7+ messages in thread
From: Giuseppe Scrivano @ 2026-07-30 12:41 UTC (permalink / raw)
To: linux-erofs; +Cc: xiang, linux-fsdevel, amir73il, gscrivan
When the same file is mounted multiple times (via path or fd), reuse
the existing superblock instead of creating a new one. This allows
multiple mounts of the same image to share in-kernel data structures
more efficiently.
The backing file is identified by its inode and fsoffset. If mount
options conflict, a separate superblock is created transparently as
a fallback.
Tested by mounting a 177M Fedora EROFS image 20 times with full
traversal:
```
\#!/bin/sh
IMG=${1:-/root/fedora.erofs}
N=20
DIR=$(mktemp -d)
trap "umount $DIR/m* 2>/dev/null; rm -rf $DIR" EXIT
sync; echo 3 > /proc/sys/vm/drop_caches
INODES_BEFORE=$(grep erofs_inode /proc/slabinfo | awk '{print $2}')
MEM_BEFORE=$(grep ^Slab: /proc/meminfo | awk '{print $2}')
for i in $(seq 1 $N); do mkdir $DIR/m$i && mount -t erofs "$IMG" $DIR/m$i && find $DIR/m$i > /dev/null; done
echo "Superblocks: $(grep $DIR /proc/self/mountinfo | awk '{print $3}' | sort -u | wc -l)"
echo "erofs_inode delta: +$(( $(grep erofs_inode /proc/slabinfo | awk '{print $2}') - INODES_BEFORE ))"
echo "Slab delta: +$(( $(grep ^Slab: /proc/meminfo | awk '{print $2}') - MEM_BEFORE )) kB"
```
unpatched kernel:
Superblocks: 20
erofs_inode delta: +46368
Slab delta: +39952 kB
0.08user 0.82system 0:00.98elapsed 93%CPU (0avgtext+0avgdata 4796maxresident)k
19168inputs+10304outputs (24major+16672minor)pagefaults 0swaps
patched kernel:
Superblocks: 1
erofs_inode delta: +2044
Slab delta: +1088 kB
0.07user 0.21system 0:00.31elapsed 91%CPU (0avgtext+0avgdata 4848maxresident)k
19024inputs+6784outputs (25major+16810minor)pagefaults 0swaps
The time difference shows that sharing the superblock also benefits
the page cache and inode cache, as subsequent mounts of the same image
avoid re-reading the backing file. This is particularly useful for
container hosts running multiple containers from the same base image.
Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
---
Documentation/filesystems/erofs.rst | 4 +++
fs/erofs/super.c | 44 +++++++++++++++++++++++++++--
2 files changed, 46 insertions(+), 2 deletions(-)
diff --git a/Documentation/filesystems/erofs.rst b/Documentation/filesystems/erofs.rst
index 774e8b236d09..ef6785035b26 100644
--- a/Documentation/filesystems/erofs.rst
+++ b/Documentation/filesystems/erofs.rst
@@ -154,6 +154,10 @@ Only regular files are accepted as backing files; to mount an image that
resides on a block device, use the traditional block device mount path
instead.
+When the same backing file is mounted more than once with compatible
+mount options, the kernel reuses the existing superblock. If mount
+options conflict, a separate superblock is created transparently.
+
Sysfs Entries
=============
diff --git a/fs/erofs/super.c b/fs/erofs/super.c
index 558041011398..cbd76727f0d3 100644
--- a/fs/erofs/super.c
+++ b/fs/erofs/super.c
@@ -788,6 +788,46 @@ static int erofs_fc_fill_super(struct super_block *sb, struct fs_context *fc)
return 0;
}
+static int erofs_fc_test_file_super(struct super_block *sb,
+ struct fs_context *fc)
+{
+ struct erofs_sb_info *sbi = EROFS_SB(sb);
+ struct erofs_sb_info *new_sbi = fc->s_fs_info;
+
+ if (sb->s_iflags & SB_I_RETIRED)
+ return 0;
+ if (!sbi->dif0.file || !new_sbi->dif0.file)
+ return 0;
+ return file_inode(sbi->dif0.file) == file_inode(new_sbi->dif0.file) &&
+ sbi->dif0.fsoff == new_sbi->dif0.fsoff &&
+ sbi->opt.mount_opt == new_sbi->opt.mount_opt &&
+ sbi->opt.cache_strategy == new_sbi->opt.cache_strategy;
+}
+
+static int erofs_fc_get_tree_file(struct fs_context *fc)
+{
+ struct super_block *sb;
+ int err;
+
+ sb = sget_fc(fc, erofs_fc_test_file_super, set_anon_super_fc);
+ if (IS_ERR(sb))
+ return PTR_ERR(sb);
+
+ if (!sb->s_root) {
+ err = erofs_fc_fill_super(sb, fc);
+ if (err) {
+ deactivate_locked_super(sb);
+ return err;
+ }
+ sb->s_flags |= SB_ACTIVE;
+ } else {
+ erofs_info(sb, "sharing superblock for the same backing file");
+ }
+
+ fc->root = dget(sb->s_root);
+ return 0;
+}
+
static int erofs_fc_get_tree(struct fs_context *fc)
{
struct erofs_sb_info *sbi = fc->s_fs_info;
@@ -803,7 +843,7 @@ static int erofs_fc_get_tree(struct fs_context *fc)
errorfc(fc, "source is unsupported");
return -EINVAL;
}
- return get_tree_nodev(fc, erofs_fc_fill_super);
+ return erofs_fc_get_tree_file(fc);
}
ret = get_tree_bdev_flags(fc, erofs_fc_fill_super,
@@ -821,7 +861,7 @@ static int erofs_fc_get_tree(struct fs_context *fc)
if (S_ISREG(file_inode(sbi->dif0.file)->i_mode) &&
sbi->dif0.file->f_mapping->a_ops->read_folio)
- return get_tree_nodev(fc, erofs_fc_fill_super);
+ return erofs_fc_get_tree_file(fc);
}
return ret;
}
--
2.55.0
^ permalink raw reply related [flat|nested] 7+ messages in thread* Re: [PATCH] erofs: reuse superblock for file-backed mounts 2026-07-30 12:41 [PATCH] erofs: reuse superblock for file-backed mounts Giuseppe Scrivano @ 2026-07-30 12:57 ` Pedro Falcato 2026-07-30 13:49 ` Giuseppe Scrivano 0 siblings, 1 reply; 7+ messages in thread From: Pedro Falcato @ 2026-07-30 12:57 UTC (permalink / raw) To: Giuseppe Scrivano; +Cc: linux-erofs, xiang, linux-fsdevel, amir73il On Thu, Jul 30, 2026 at 02:41:20PM +0200, Giuseppe Scrivano wrote: > When the same file is mounted multiple times (via path or fd), reuse > the existing superblock instead of creating a new one. This allows > multiple mounts of the same image to share in-kernel data structures > more efficiently. > > The backing file is identified by its inode and fsoffset. If mount > options conflict, a separate superblock is created transparently as > a fallback. > > Tested by mounting a 177M Fedora EROFS image 20 times with full > traversal: > > ``` > \#!/bin/sh > IMG=${1:-/root/fedora.erofs} > N=20 > DIR=$(mktemp -d) > trap "umount $DIR/m* 2>/dev/null; rm -rf $DIR" EXIT > > sync; echo 3 > /proc/sys/vm/drop_caches > INODES_BEFORE=$(grep erofs_inode /proc/slabinfo | awk '{print $2}') > MEM_BEFORE=$(grep ^Slab: /proc/meminfo | awk '{print $2}') > > for i in $(seq 1 $N); do mkdir $DIR/m$i && mount -t erofs "$IMG" $DIR/m$i && find $DIR/m$i > /dev/null; done > > echo "Superblocks: $(grep $DIR /proc/self/mountinfo | awk '{print $3}' | sort -u | wc -l)" > echo "erofs_inode delta: +$(( $(grep erofs_inode /proc/slabinfo | awk '{print $2}') - INODES_BEFORE ))" > echo "Slab delta: +$(( $(grep ^Slab: /proc/meminfo | awk '{print $2}') - MEM_BEFORE )) kB" > ``` > > unpatched kernel: > > Superblocks: 20 > erofs_inode delta: +46368 > Slab delta: +39952 kB > 0.08user 0.82system 0:00.98elapsed 93%CPU (0avgtext+0avgdata 4796maxresident)k > 19168inputs+10304outputs (24major+16672minor)pagefaults 0swaps > > patched kernel: > > Superblocks: 1 > erofs_inode delta: +2044 > Slab delta: +1088 kB > 0.07user 0.21system 0:00.31elapsed 91%CPU (0avgtext+0avgdata 4848maxresident)k > 19024inputs+6784outputs (25major+16810minor)pagefaults 0swaps > > The time difference shows that sharing the superblock also benefits > the page cache and inode cache, as subsequent mounts of the same image > avoid re-reading the backing file. This is particularly useful for > container hosts running multiple containers from the same base image. Doesn't this approach break-down as soon as you get to change SB flags (through e.g mount -o remount)? It will change superblock flags for all of them, right? (I don't think you can switch off the superblock transparently on a reconfigure?) -- Pedro ^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH] erofs: reuse superblock for file-backed mounts 2026-07-30 12:57 ` Pedro Falcato @ 2026-07-30 13:49 ` Giuseppe Scrivano 2026-07-30 16:13 ` Giuseppe Scrivano 0 siblings, 1 reply; 7+ messages in thread From: Giuseppe Scrivano @ 2026-07-30 13:49 UTC (permalink / raw) To: Pedro Falcato; +Cc: linux-erofs, xiang, linux-fsdevel, amir73il Pedro Falcato <pfalcato@suse.de> writes: > On Thu, Jul 30, 2026 at 02:41:20PM +0200, Giuseppe Scrivano wrote: >> When the same file is mounted multiple times (via path or fd), reuse >> the existing superblock instead of creating a new one. This allows >> multiple mounts of the same image to share in-kernel data structures >> more efficiently. >> >> The backing file is identified by its inode and fsoffset. If mount >> options conflict, a separate superblock is created transparently as >> a fallback. >> >> Tested by mounting a 177M Fedora EROFS image 20 times with full >> traversal: >> >> ``` >> \#!/bin/sh >> IMG=${1:-/root/fedora.erofs} >> N=20 >> DIR=$(mktemp -d) >> trap "umount $DIR/m* 2>/dev/null; rm -rf $DIR" EXIT >> >> sync; echo 3 > /proc/sys/vm/drop_caches >> INODES_BEFORE=$(grep erofs_inode /proc/slabinfo | awk '{print $2}') >> MEM_BEFORE=$(grep ^Slab: /proc/meminfo | awk '{print $2}') >> >> for i in $(seq 1 $N); do mkdir $DIR/m$i && mount -t erofs "$IMG" >> $DIR/m$i && find $DIR/m$i > /dev/null; done >> >> echo "Superblocks: $(grep $DIR /proc/self/mountinfo | awk '{print $3}' | sort -u | wc -l)" >> echo "erofs_inode delta: +$(( $(grep erofs_inode /proc/slabinfo | awk '{print $2}') - INODES_BEFORE ))" >> echo "Slab delta: +$(( $(grep ^Slab: /proc/meminfo | awk '{print $2}') - MEM_BEFORE )) kB" >> ``` >> >> unpatched kernel: >> >> Superblocks: 20 >> erofs_inode delta: +46368 >> Slab delta: +39952 kB >> 0.08user 0.82system 0:00.98elapsed 93%CPU (0avgtext+0avgdata 4796maxresident)k >> 19168inputs+10304outputs (24major+16672minor)pagefaults 0swaps >> >> patched kernel: >> >> Superblocks: 1 >> erofs_inode delta: +2044 >> Slab delta: +1088 kB >> 0.07user 0.21system 0:00.31elapsed 91%CPU (0avgtext+0avgdata 4848maxresident)k >> 19024inputs+6784outputs (25major+16810minor)pagefaults 0swaps >> >> The time difference shows that sharing the superblock also benefits >> the page cache and inode cache, as subsequent mounts of the same image >> avoid re-reading the backing file. This is particularly useful for >> container hosts running multiple containers from the same base image. > > Doesn't this approach break-down as soon as you get to change SB flags (through > e.g mount -o remount)? It will change superblock flags for all of them, right? > > (I don't think you can switch off the superblock transparently on a > reconfigure?) This is the same preexisting behavior for block device mounts. That said, I realize this can feel confusing since EROFS is not a block device and allowed this so far. One way to solve this could be an explicit mount option "share_sb" that is opt-in and, once set, blocks any remount operations. Would that work? Regards, Giuseppe ^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH] erofs: reuse superblock for file-backed mounts 2026-07-30 13:49 ` Giuseppe Scrivano @ 2026-07-30 16:13 ` Giuseppe Scrivano 2026-07-31 13:12 ` Christian Brauner 0 siblings, 1 reply; 7+ messages in thread From: Giuseppe Scrivano @ 2026-07-30 16:13 UTC (permalink / raw) To: Pedro Falcato; +Cc: linux-erofs, xiang, linux-fsdevel, amir73il Giuseppe Scrivano <gscrivan@redhat.com> writes: > Pedro Falcato <pfalcato@suse.de> writes: > >> On Thu, Jul 30, 2026 at 02:41:20PM +0200, Giuseppe Scrivano wrote: >>> When the same file is mounted multiple times (via path or fd), reuse >>> the existing superblock instead of creating a new one. This allows >>> multiple mounts of the same image to share in-kernel data structures >>> more efficiently. >>> >>> The backing file is identified by its inode and fsoffset. If mount >>> options conflict, a separate superblock is created transparently as >>> a fallback. >>> >>> Tested by mounting a 177M Fedora EROFS image 20 times with full >>> traversal: >>> >>> ``` >>> \#!/bin/sh >>> IMG=${1:-/root/fedora.erofs} >>> N=20 >>> DIR=$(mktemp -d) >>> trap "umount $DIR/m* 2>/dev/null; rm -rf $DIR" EXIT >>> >>> sync; echo 3 > /proc/sys/vm/drop_caches >>> INODES_BEFORE=$(grep erofs_inode /proc/slabinfo | awk '{print $2}') >>> MEM_BEFORE=$(grep ^Slab: /proc/meminfo | awk '{print $2}') >>> >>> for i in $(seq 1 $N); do mkdir $DIR/m$i && mount -t erofs "$IMG" >>> $DIR/m$i && find $DIR/m$i > /dev/null; done >>> >>> echo "Superblocks: $(grep $DIR /proc/self/mountinfo | awk '{print $3}' | sort -u | wc -l)" >>> echo "erofs_inode delta: +$(( $(grep erofs_inode /proc/slabinfo | awk '{print $2}') - INODES_BEFORE ))" >>> echo "Slab delta: +$(( $(grep ^Slab: /proc/meminfo | awk '{print $2}') - MEM_BEFORE )) kB" >>> ``` >>> >>> unpatched kernel: >>> >>> Superblocks: 20 >>> erofs_inode delta: +46368 >>> Slab delta: +39952 kB >>> 0.08user 0.82system 0:00.98elapsed 93%CPU (0avgtext+0avgdata 4796maxresident)k >>> 19168inputs+10304outputs (24major+16672minor)pagefaults 0swaps >>> >>> patched kernel: >>> >>> Superblocks: 1 >>> erofs_inode delta: +2044 >>> Slab delta: +1088 kB >>> 0.07user 0.21system 0:00.31elapsed 91%CPU (0avgtext+0avgdata 4848maxresident)k >>> 19024inputs+6784outputs (25major+16810minor)pagefaults 0swaps >>> >>> The time difference shows that sharing the superblock also benefits >>> the page cache and inode cache, as subsequent mounts of the same image >>> avoid re-reading the backing file. This is particularly useful for >>> container hosts running multiple containers from the same base image. >> >> Doesn't this approach break-down as soon as you get to change SB flags (through >> e.g mount -o remount)? It will change superblock flags for all of them, right? >> >> (I don't think you can switch off the superblock transparently on a >> reconfigure?) > > This is the same preexisting behavior for block device mounts. That > said, I realize this can feel confusing since EROFS is not a block > device and allowed this so far. > > One way to solve this could be an explicit mount option "share_sb" that > is opt-in and, once set, blocks any remount operations. Would that > work? Would something like the following fixup on top of the previous patch be acceptable (suggestions for better names are welcome)? Thanks, Giuseppe diff --git a/fs/erofs/internal.h b/fs/erofs/internal.h index 580f8d9f14e7..ac26daf4f78a 100644 --- a/fs/erofs/internal.h +++ b/fs/erofs/internal.h @@ -156,6 +156,7 @@ struct erofs_sb_info { #define EROFS_MOUNT_DAX_NEVER 0x00000080 #define EROFS_MOUNT_DIRECT_IO 0x00000100 #define EROFS_MOUNT_INODE_SHARE 0x00000200 +#define EROFS_MOUNT_SHARE_SB 0x00000400 #define clear_opt(opt, option) ((opt)->mount_opt &= ~EROFS_MOUNT_##option) #define set_opt(opt, option) ((opt)->mount_opt |= EROFS_MOUNT_##option) diff --git a/fs/erofs/super.c b/fs/erofs/super.c index cbd76727f0d3..dd2a351811c8 100644 --- a/fs/erofs/super.c +++ b/fs/erofs/super.c @@ -386,7 +386,7 @@ static void erofs_default_options(struct erofs_sb_info *sbi) enum { Opt_user_xattr, Opt_acl, Opt_cache_strategy, Opt_dax, Opt_dax_enum, Opt_device, Opt_domain_id, Opt_directio, Opt_fsoffset, Opt_inode_share, - Opt_source, + Opt_source, Opt_share_sb, }; static const struct constant_table erofs_param_cache_strategy[] = { @@ -414,6 +414,7 @@ static const struct fs_parameter_spec erofs_fs_parameters[] = { fsparam_flag_no("directio", Opt_directio), fsparam_u64("fsoffset", Opt_fsoffset), fsparam_flag("inode_share", Opt_inode_share), + fsparam_flag("share_sb", Opt_share_sb), fsparam_file_or_string("source", Opt_source), {} }; @@ -560,6 +561,12 @@ static int erofs_fc_parse_param(struct fs_context *fc, else set_opt(&sbi->opt, INODE_SHARE); break; + case Opt_share_sb: + if (!IS_ENABLED(CONFIG_EROFS_FS_BACKED_BY_FILE)) + errorfc(fc, "%s option not supported", erofs_fs_parameters[opt].name); + else + set_opt(&sbi->opt, SHARE_SB); + break; case Opt_source: return erofs_fc_parse_source(fc, param); } @@ -798,6 +805,8 @@ static int erofs_fc_test_file_super(struct super_block *sb, return 0; if (!sbi->dif0.file || !new_sbi->dif0.file) return 0; + if (!test_opt(&new_sbi->opt, SHARE_SB)) + return 0; return file_inode(sbi->dif0.file) == file_inode(new_sbi->dif0.file) && sbi->dif0.fsoff == new_sbi->dif0.fsoff && sbi->opt.mount_opt == new_sbi->opt.mount_opt && @@ -874,6 +883,9 @@ static int erofs_fc_reconfigure(struct fs_context *fc) DBG_BUGON(!sb_rdonly(sb)); + if (test_opt(&sbi->opt, SHARE_SB)) + return -EBUSY; + if (new_sbi->domain_id) erofs_info(sb, "ignoring reconfiguration for domain_id."); ^ permalink raw reply related [flat|nested] 7+ messages in thread
* Re: [PATCH] erofs: reuse superblock for file-backed mounts 2026-07-30 16:13 ` Giuseppe Scrivano @ 2026-07-31 13:12 ` Christian Brauner 2026-07-31 13:19 ` Giuseppe Scrivano 0 siblings, 1 reply; 7+ messages in thread From: Christian Brauner @ 2026-07-31 13:12 UTC (permalink / raw) To: Giuseppe Scrivano Cc: Pedro Falcato, linux-erofs, xiang, linux-fsdevel, amir73il > >>> The time difference shows that sharing the superblock also benefits > >>> the page cache and inode cache, as subsequent mounts of the same image > >>> avoid re-reading the backing file. This is particularly useful for > >>> container hosts running multiple containers from the same base image. > >> > >> Doesn't this approach break-down as soon as you get to change SB flags (through > >> e.g mount -o remount)? It will change superblock flags for all of them, right? > >> > >> (I don't think you can switch off the superblock transparently on a > >> reconfigure?) > > > > This is the same preexisting behavior for block device mounts. That Yeah, and it sucks ass. :) Only an incompatible vfs-level RO/RW property causes a silent reuse to fail. Otherwise it not possible to detect that a superblock has been created and requested mount options silently ignore. In other words, doing this unconditionally is incompatible with current userspace. Btw, I added FSCONFIG_CMD_CREATE_EXCL for this reason which refuses to reuse an existing superblock for filesystems that would otherwise end up sharing a superblock. This way userspace is guaranteed to not silently get filesystem options ignored. > > said, I realize this can feel confusing since EROFS is not a block > > device and allowed this so far. > > > > One way to solve this could be an explicit mount option "share_sb" that > > is opt-in and, once set, blocks any remount operations. Would that > > work? > > Would something like the following fixup on top of the previous patch be > acceptable (suggestions for better names are welcome)? The patch as written still means that a task A creates a new erofs mount with for file F and marks it as shared. Another task B creates new erofs mount expecting to get a new superblock and will end up sharing it with task A instead. That is still quite the behavior change and could be used to subvert workloads expectations and be used in (odd) attacks. So if you want sb-sharing you need it to be an admin-level setting or you need to make it a domain the same way page cache sharing for erofs is a domain. IOW, only task that mount with the same domain end up sharing superblocks. Or it's a global setting. But doing it this way seems problematic to me. > Thanks, > Giuseppe > > diff --git a/fs/erofs/internal.h b/fs/erofs/internal.h > index 580f8d9f14e7..ac26daf4f78a 100644 > --- a/fs/erofs/internal.h > +++ b/fs/erofs/internal.h > @@ -156,6 +156,7 @@ struct erofs_sb_info { > #define EROFS_MOUNT_DAX_NEVER 0x00000080 > #define EROFS_MOUNT_DIRECT_IO 0x00000100 > #define EROFS_MOUNT_INODE_SHARE 0x00000200 > +#define EROFS_MOUNT_SHARE_SB 0x00000400 > > #define clear_opt(opt, option) ((opt)->mount_opt &= ~EROFS_MOUNT_##option) > #define set_opt(opt, option) ((opt)->mount_opt |= EROFS_MOUNT_##option) > diff --git a/fs/erofs/super.c b/fs/erofs/super.c > index cbd76727f0d3..dd2a351811c8 100644 > --- a/fs/erofs/super.c > +++ b/fs/erofs/super.c > @@ -386,7 +386,7 @@ static void erofs_default_options(struct erofs_sb_info *sbi) > enum { > Opt_user_xattr, Opt_acl, Opt_cache_strategy, Opt_dax, Opt_dax_enum, > Opt_device, Opt_domain_id, Opt_directio, Opt_fsoffset, Opt_inode_share, > - Opt_source, > + Opt_source, Opt_share_sb, > }; > > static const struct constant_table erofs_param_cache_strategy[] = { > @@ -414,6 +414,7 @@ static const struct fs_parameter_spec erofs_fs_parameters[] = { > fsparam_flag_no("directio", Opt_directio), > fsparam_u64("fsoffset", Opt_fsoffset), > fsparam_flag("inode_share", Opt_inode_share), > + fsparam_flag("share_sb", Opt_share_sb), > fsparam_file_or_string("source", Opt_source), > {} > }; > @@ -560,6 +561,12 @@ static int erofs_fc_parse_param(struct fs_context *fc, > else > set_opt(&sbi->opt, INODE_SHARE); > break; > + case Opt_share_sb: > + if (!IS_ENABLED(CONFIG_EROFS_FS_BACKED_BY_FILE)) > + errorfc(fc, "%s option not supported", erofs_fs_parameters[opt].name); > + else > + set_opt(&sbi->opt, SHARE_SB); > + break; > case Opt_source: > return erofs_fc_parse_source(fc, param); > } > @@ -798,6 +805,8 @@ static int erofs_fc_test_file_super(struct super_block *sb, > return 0; > if (!sbi->dif0.file || !new_sbi->dif0.file) > return 0; > + if (!test_opt(&new_sbi->opt, SHARE_SB)) > + return 0; > return file_inode(sbi->dif0.file) == file_inode(new_sbi->dif0.file) && > sbi->dif0.fsoff == new_sbi->dif0.fsoff && > sbi->opt.mount_opt == new_sbi->opt.mount_opt && > @@ -874,6 +883,9 @@ static int erofs_fc_reconfigure(struct fs_context *fc) > > DBG_BUGON(!sb_rdonly(sb)); > > + if (test_opt(&sbi->opt, SHARE_SB)) > + return -EBUSY; > + > if (new_sbi->domain_id) > erofs_info(sb, "ignoring reconfiguration for domain_id."); > > > > ^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH] erofs: reuse superblock for file-backed mounts 2026-07-31 13:12 ` Christian Brauner @ 2026-07-31 13:19 ` Giuseppe Scrivano 2026-07-31 13:32 ` Christian Brauner 0 siblings, 1 reply; 7+ messages in thread From: Giuseppe Scrivano @ 2026-07-31 13:19 UTC (permalink / raw) To: Christian Brauner Cc: Pedro Falcato, linux-erofs, xiang, linux-fsdevel, amir73il Christian Brauner <brauner@kernel.org> writes: >> >>> The time difference shows that sharing the superblock also benefits >> >>> the page cache and inode cache, as subsequent mounts of the same image >> >>> avoid re-reading the backing file. This is particularly useful for >> >>> container hosts running multiple containers from the same base image. >> >> >> >> Doesn't this approach break-down as soon as you get to change SB flags (through >> >> e.g mount -o remount)? It will change superblock flags for all of them, right? >> >> >> >> (I don't think you can switch off the superblock transparently on a >> >> reconfigure?) >> > >> > This is the same preexisting behavior for block device mounts. That > > Yeah, and it sucks ass. :) > Only an incompatible vfs-level RO/RW property causes a silent reuse to > fail. Otherwise it not possible to detect that a superblock has been > created and requested mount options silently ignore. > > In other words, doing this unconditionally is incompatible with current > userspace. > > Btw, I added FSCONFIG_CMD_CREATE_EXCL for this reason which refuses to > reuse an existing superblock for filesystems that would otherwise end up > sharing a superblock. This way userspace is guaranteed to not silently > get filesystem options ignored. > >> > said, I realize this can feel confusing since EROFS is not a block >> > device and allowed this so far. >> > >> > One way to solve this could be an explicit mount option "share_sb" that >> > is opt-in and, once set, blocks any remount operations. Would that >> > work? >> >> Would something like the following fixup on top of the previous patch be >> acceptable (suggestions for better names are welcome)? > > The patch as written still means that a task A creates a new erofs mount > with for file F and marks it as shared. Another task B creates new erofs > mount expecting to get a new superblock and will end up sharing it with > task A instead. > > That is still quite the behavior change and could be used to subvert > workloads expectations and be used in (odd) attacks. no, my suggestion is that task B gets the same superblock created by A only if it also specifies share_sb. If the option is not specified, as is the case for existing workloads, then it gets a new superblock even if A is already mounted with share_sb. The tasks A and B will get the same superblock only if they both specify share_sb. It is fully opt-in, it doesn't affect any other user that doesn't want this behavior. Regards, Giuseppe > > So if you want sb-sharing you need it to be an admin-level setting or > you need to make it a domain the same way page cache sharing for erofs > is a domain. IOW, only task that mount with the same domain end up > sharing superblocks. Or it's a global setting. > > But doing it this way seems problematic to me. > >> Thanks, >> Giuseppe >> >> diff --git a/fs/erofs/internal.h b/fs/erofs/internal.h >> index 580f8d9f14e7..ac26daf4f78a 100644 >> --- a/fs/erofs/internal.h >> +++ b/fs/erofs/internal.h >> @@ -156,6 +156,7 @@ struct erofs_sb_info { >> #define EROFS_MOUNT_DAX_NEVER 0x00000080 >> #define EROFS_MOUNT_DIRECT_IO 0x00000100 >> #define EROFS_MOUNT_INODE_SHARE 0x00000200 >> +#define EROFS_MOUNT_SHARE_SB 0x00000400 >> >> #define clear_opt(opt, option) ((opt)->mount_opt &= ~EROFS_MOUNT_##option) >> #define set_opt(opt, option) ((opt)->mount_opt |= EROFS_MOUNT_##option) >> diff --git a/fs/erofs/super.c b/fs/erofs/super.c >> index cbd76727f0d3..dd2a351811c8 100644 >> --- a/fs/erofs/super.c >> +++ b/fs/erofs/super.c >> @@ -386,7 +386,7 @@ static void erofs_default_options(struct erofs_sb_info *sbi) >> enum { >> Opt_user_xattr, Opt_acl, Opt_cache_strategy, Opt_dax, Opt_dax_enum, >> Opt_device, Opt_domain_id, Opt_directio, Opt_fsoffset, Opt_inode_share, >> - Opt_source, >> + Opt_source, Opt_share_sb, >> }; >> >> static const struct constant_table erofs_param_cache_strategy[] = { >> @@ -414,6 +414,7 @@ static const struct fs_parameter_spec erofs_fs_parameters[] = { >> fsparam_flag_no("directio", Opt_directio), >> fsparam_u64("fsoffset", Opt_fsoffset), >> fsparam_flag("inode_share", Opt_inode_share), >> + fsparam_flag("share_sb", Opt_share_sb), >> fsparam_file_or_string("source", Opt_source), >> {} >> }; >> @@ -560,6 +561,12 @@ static int erofs_fc_parse_param(struct fs_context *fc, >> else >> set_opt(&sbi->opt, INODE_SHARE); >> break; >> + case Opt_share_sb: >> + if (!IS_ENABLED(CONFIG_EROFS_FS_BACKED_BY_FILE)) >> + errorfc(fc, "%s option not supported", erofs_fs_parameters[opt].name); >> + else >> + set_opt(&sbi->opt, SHARE_SB); >> + break; >> case Opt_source: >> return erofs_fc_parse_source(fc, param); >> } >> @@ -798,6 +805,8 @@ static int erofs_fc_test_file_super(struct super_block *sb, >> return 0; >> if (!sbi->dif0.file || !new_sbi->dif0.file) >> return 0; >> + if (!test_opt(&new_sbi->opt, SHARE_SB)) >> + return 0; >> return file_inode(sbi->dif0.file) == file_inode(new_sbi->dif0.file) && >> sbi->dif0.fsoff == new_sbi->dif0.fsoff && >> sbi->opt.mount_opt == new_sbi->opt.mount_opt && >> @@ -874,6 +883,9 @@ static int erofs_fc_reconfigure(struct fs_context *fc) >> >> DBG_BUGON(!sb_rdonly(sb)); >> >> + if (test_opt(&sbi->opt, SHARE_SB)) >> + return -EBUSY; >> + >> if (new_sbi->domain_id) >> erofs_info(sb, "ignoring reconfiguration for domain_id."); >> >> >> >> ^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH] erofs: reuse superblock for file-backed mounts 2026-07-31 13:19 ` Giuseppe Scrivano @ 2026-07-31 13:32 ` Christian Brauner 0 siblings, 0 replies; 7+ messages in thread From: Christian Brauner @ 2026-07-31 13:32 UTC (permalink / raw) To: Giuseppe Scrivano Cc: Pedro Falcato, linux-erofs, xiang, linux-fsdevel, amir73il On Fri, Jul 31, 2026 at 03:19:58PM +0200, Giuseppe Scrivano wrote: > Christian Brauner <brauner@kernel.org> writes: > > >> >>> The time difference shows that sharing the superblock also benefits > >> >>> the page cache and inode cache, as subsequent mounts of the same image > >> >>> avoid re-reading the backing file. This is particularly useful for > >> >>> container hosts running multiple containers from the same base image. > >> >> > >> >> Doesn't this approach break-down as soon as you get to change SB flags (through > >> >> e.g mount -o remount)? It will change superblock flags for all of them, right? > >> >> > >> >> (I don't think you can switch off the superblock transparently on a > >> >> reconfigure?) > >> > > >> > This is the same preexisting behavior for block device mounts. That > > > > Yeah, and it sucks ass. :) > > Only an incompatible vfs-level RO/RW property causes a silent reuse to > > fail. Otherwise it not possible to detect that a superblock has been > > created and requested mount options silently ignore. > > > > In other words, doing this unconditionally is incompatible with current > > userspace. > > > > Btw, I added FSCONFIG_CMD_CREATE_EXCL for this reason which refuses to > > reuse an existing superblock for filesystems that would otherwise end up > > sharing a superblock. This way userspace is guaranteed to not silently > > get filesystem options ignored. > > > >> > said, I realize this can feel confusing since EROFS is not a block > >> > device and allowed this so far. > >> > > >> > One way to solve this could be an explicit mount option "share_sb" that > >> > is opt-in and, once set, blocks any remount operations. Would that > >> > work? > >> > >> Would something like the following fixup on top of the previous patch be > >> acceptable (suggestions for better names are welcome)? > > > > The patch as written still means that a task A creates a new erofs mount > > with for file F and marks it as shared. Another task B creates new erofs > > mount expecting to get a new superblock and will end up sharing it with > > task A instead. > > > > That is still quite the behavior change and could be used to subvert > > workloads expectations and be used in (odd) attacks. > > no, my suggestion is that task B gets the same superblock created by A > only if it also specifies share_sb. Yeah, that works. > If the option is not specified, as is the case for existing workloads, > then it gets a new superblock even if A is already mounted with > share_sb. Sounds good! Ship it. ^ permalink raw reply [flat|nested] 7+ messages in thread
end of thread, other threads:[~2026-07-31 13:32 UTC | newest] Thread overview: 7+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-07-30 12:41 [PATCH] erofs: reuse superblock for file-backed mounts Giuseppe Scrivano 2026-07-30 12:57 ` Pedro Falcato 2026-07-30 13:49 ` Giuseppe Scrivano 2026-07-30 16:13 ` Giuseppe Scrivano 2026-07-31 13:12 ` Christian Brauner 2026-07-31 13:19 ` Giuseppe Scrivano 2026-07-31 13:32 ` Christian Brauner
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox