[PATCH 15/21] namespace: nothing is mounted on or written through knullfs
From: Christian Brauner
Date: Fri Oct 02 2026 - 09:56:35 EST
Mark the root of knullfs with dont_mount(). Nothing is ever mounted on
the root of a kernel thread and the following patches make that root
reachable from userspace, so say it on the dentry where it doesn't
depend on the mount being in no namespace. Let do_lock_mount() refuse
such a target before it takes the inode lock and namespace_sem. The
flag is sticky so the check needs no lock. The one under the locks
stays for a mountpoint that is being removed.
Make the mount read-only as well. Its one inode is immutable so nothing
could be changed through it anyway, but MNT_READONLY makes that visible
the usual way: EROFS instead of EPERM and ST_RDONLY in statvfs().
Signed-off-by: Christian Brauner (Amutable) <brauner@xxxxxxxxxx>
---
fs/namespace.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/fs/namespace.c b/fs/namespace.c
index d1e83cda57e6..e1b0ade95b0d 100644
--- a/fs/namespace.c
+++ b/fs/namespace.c
@@ -2814,6 +2814,11 @@ static void do_lock_mount(const struct path *path,
scoped_guard(mount_locked_reader) {
m = where_to_mount(path, &dentry, beneath);
+ /* sticky, so it takes no locks to refuse it */
+ if (unlikely(cant_mount(dentry))) {
+ res->parent = ERR_PTR(-ENOENT);
+ return;
+ }
if (&m->mnt != path->mnt) {
mntget(&m->mnt);
dget(dentry);
@@ -6374,6 +6379,10 @@ static void __init init_mount_tree(void)
knullfs = kern_mount(&nullfs_fs_type);
if (IS_ERR(knullfs))
panic("VFS: Failed to create private nullfs instance");
+ /* nothing is ever mounted on the root of a kernel thread */
+ dont_mount(knullfs->mnt_root);
+ /* and nothing is ever written through it */
+ knullfs->mnt_flags |= MNT_READONLY;
root.mnt = knullfs;
root.dentry = knullfs->mnt_root;
--
2.53.0