[RFC PATCH bpf-next 08/12] fs: add mnt_undo_legitimize()
sashiko-bot at kernel.org
sashiko-bot at kernel.org
Tue Oct 6 00:28:20 UTC 2026
> A failed __legitimize_mnt() can oblige its caller to mntput() the
> mount, which may be the final put and so may sleep: legitimize_mnt()
> leaves the RCU read-side critical section it ran under to do it. A
> caller that cannot leave its critical section - a BPF program driving
> a lockless walk, which only the verifier ends - needs that put to be
> callable from inside it.
>
> Add mnt_undo_legitimize(), which drops the count and, when the count
> turns out to be the mount's last, keeps it and hands the mount to
> delayed_mntput() for the sleepable final put. delayed_mntput() then
> tells the two queue populations apart by MNT_DOOMED rather than by an
> unlocked mnt_get_count() read, which a concurrent failed
> __legitimize_mnt() could transiently inflate. legitimize_mnt()
> switches to it as well, retiring its
> rcu_read_unlock/mntput/rcu_read_lock dance.
>
> Unlike mntput(), mnt_expiry_mark is left alone: a walker that failed
> to legitimize a mount never used it.
>
> Signed-off-by: Justin Suess <utilityemal77 at gmail.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261006002020.2890858-1-utilityemal77@gmail.com?part=8
More information about the Linux-security-module-archive
mailing list