[PATCH 16/21] fsnotify: let a filesystem refuse marks on its objects
From: Christian Brauner
Date: Fri Oct 02 2026 - 10:01:26 EST
Don't let nullfs be watched. fanotify refuses mount and filesystem marks
on SB_NOUSER superblocks but inode marks of inotify, fanotify and
dnotify go through. The one inode of knullfs is the root of every
kernel thread and the following patches make it reachable from
userspace as the directory that stands in for an unmounted mount. A
watch placed through one such directory would report the opens through
all the others, across users.
Add FS_DISALLOW_NOTIFY next to FS_DISALLOW_NOTIFY_PERM, refuse a mark on
any object of such a filesystem in fsnotify_add_mark_list() where every
backend ends up and set it for nullfs. There's nothing to watch on a
permanently empty and immutable filesystem.
Signed-off-by: Christian Brauner (Amutable) <brauner@xxxxxxxxxx>
---
fs/notify/mark.c | 4 ++++
fs/nullfs.c | 1 +
include/linux/fs.h | 1 +
3 files changed, 6 insertions(+)
diff --git a/fs/notify/mark.c b/fs/notify/mark.c
index b2640d836a71..d17628580a57 100644
--- a/fs/notify/mark.c
+++ b/fs/notify/mark.c
@@ -903,6 +903,10 @@ static int fsnotify_add_mark_list(struct fsnotify_mark *mark, void *obj,
if (WARN_ON(!fsnotify_valid_obj_type(obj_type)))
return -EINVAL;
+ /* the filesystem doesn't want its objects watched */
+ if (sb && (sb->s_type->fs_flags & FS_DISALLOW_NOTIFY))
+ return -EINVAL;
+
/*
* Attach the sb info before attaching a connector to any object on sb.
* The sb info will remain attached as long as sb lives.
diff --git a/fs/nullfs.c b/fs/nullfs.c
index 40aa228bd81a..55a04f2d7761 100644
--- a/fs/nullfs.c
+++ b/fs/nullfs.c
@@ -61,6 +61,7 @@ static int nullfs_init_fs_context(struct fs_context *fc)
struct file_system_type nullfs_fs_type = {
.name = "nullfs",
+ .fs_flags = FS_DISALLOW_NOTIFY,
.init_fs_context = nullfs_init_fs_context,
.kill_sb = kill_anon_super,
};
diff --git a/include/linux/fs.h b/include/linux/fs.h
index f9d1e05e8ae6..784fa20217c4 100644
--- a/include/linux/fs.h
+++ b/include/linux/fs.h
@@ -2296,6 +2296,7 @@ struct file_system_type {
#define FS_POWER_FREEZE 256 /* Always freeze on suspend/hibernate */
#define FS_USERNS_MOUNT_RESTRICTED 512 /* Restrict mount in userns if not already visible */
#define FS_USERNS_DELEGATABLE 1024 /* Can be mounted inside userns from outside */
+#define FS_DISALLOW_NOTIFY 2048 /* No fsnotify marks on its objects */
#define FS_RENAME_DOES_D_MOVE 32768 /* FS will handle d_move() during rename() internally. */
int (*init_fs_context)(struct fs_context *);
const struct fs_parameter_spec *parameters;
--
2.53.0