[PATCH 18/21] nullfs: refuse leases and delegations

From: Christian Brauner

Date: Fri Oct 02 2026 - 09:57:37 EST


Refuse leases and delegations on nullfs as well. generic_setlease()
grants read leases and directory delegations on directories, so the
owner of the shared inode, or anyone with CAP_LEASE, could put one on
the directory that stands in for every unmounted mount and F_GETLEASE
and F_GETDELEG would show it to every other holder. Nothing on nullfs
ever changes, so a lease on it would never be broken and never tell
anyone anything.

Signed-off-by: Christian Brauner (Amutable) <brauner@xxxxxxxxxx>
---
fs/nullfs.c | 8 ++++++++
1 file changed, 8 insertions(+)

diff --git a/fs/nullfs.c b/fs/nullfs.c
index d90c71f5eece..f76b87cf1841 100644
--- a/fs/nullfs.c
+++ b/fs/nullfs.c
@@ -28,6 +28,13 @@ static int nullfs_nolock(struct file *file, int cmd, struct file_lock *fl)
return -ENOLCK;
}

+/* and no leases or delegations */
+static int nullfs_nolease(struct file *file, int arg, struct file_lease **flp,
+ void **priv)
+{
+ return -EINVAL;
+}
+
/* what libfs gives an empty directory, plus the refusal of file locks */
static const struct file_operations nullfs_dir_operations = {
.llseek = nullfs_dir_llseek,
@@ -36,6 +43,7 @@ static const struct file_operations nullfs_dir_operations = {
.fsync = noop_fsync,
.lock = nullfs_nolock,
.flock = nullfs_nolock,
+ .setlease = nullfs_nolease,
};

static int nullfs_fs_fill_super(struct super_block *s, struct fs_context *fc)

--
2.53.0