[RFC PATCH bpf-next 08/12] fs: add mnt_undo_legitimize()

sashiko-bot at kernel.org sashiko-bot at kernel.org
Tue Oct 6 00:28:20 UTC 2026


> A failed __legitimize_mnt() can oblige its caller to mntput() the
> mount, which may be the final put and so may sleep: legitimize_mnt()
> leaves the RCU read-side critical section it ran under to do it.  A
> caller that cannot leave its critical section - a BPF program driving
> a lockless walk, which only the verifier ends - needs that put to be
> callable from inside it.
> 
> Add mnt_undo_legitimize(), which drops the count and, when the count
> turns out to be the mount's last, keeps it and hands the mount to
> delayed_mntput() for the sleepable final put.  delayed_mntput() then
> tells the two queue populations apart by MNT_DOOMED rather than by an
> unlocked mnt_get_count() read, which a concurrent failed
> __legitimize_mnt() could transiently inflate.  legitimize_mnt()
> switches to it as well, retiring its
> rcu_read_unlock/mntput/rcu_read_lock dance.
> 
> Unlike mntput(), mnt_expiry_mark is left alone: a walker that failed
> to legitimize a mount never used it.
> 
> Signed-off-by: Justin Suess <utilityemal77 at gmail.com>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261006002020.2890858-1-utilityemal77@gmail.com?part=8




More information about the Linux-security-module-archive mailing list