Re: [PATCH 18/21] nullfs: refuse leases and delegations
From: Jeff Layton
Date: Sat Oct 03 2026 - 04:20:45 EST
On Fri, 2026-10-02 at 15:52 +0200, Christian Brauner wrote:
> Refuse leases and delegations on nullfs as well. generic_setlease()
> grants read leases and directory delegations on directories, so the
> owner of the shared inode, or anyone with CAP_LEASE, could put one on
> the directory that stands in for every unmounted mount and F_GETLEASE
> and F_GETDELEG would show it to every other holder. Nothing on nullfs
> ever changes, so a lease on it would never be broken and never tell
> anyone anything.
>
> Signed-off-by: Christian Brauner (Amutable) <brauner@xxxxxxxxxx>
> ---
> fs/nullfs.c | 8 ++++++++
> 1 file changed, 8 insertions(+)
>
> diff --git a/fs/nullfs.c b/fs/nullfs.c
> index d90c71f5eece..f76b87cf1841 100644
> --- a/fs/nullfs.c
> +++ b/fs/nullfs.c
> @@ -28,6 +28,13 @@ static int nullfs_nolock(struct file *file, int cmd, struct file_lock *fl)
> return -ENOLCK;
> }
>
> +/* and no leases or delegations */
> +static int nullfs_nolease(struct file *file, int arg, struct file_lease **flp,
> + void **priv)
> +{
> + return -EINVAL;
> +}
> +
> /* what libfs gives an empty directory, plus the refusal of file locks */
> static const struct file_operations nullfs_dir_operations = {
> .llseek = nullfs_dir_llseek,
> @@ -36,6 +43,7 @@ static const struct file_operations nullfs_dir_operations = {
> .fsync = noop_fsync,
> .lock = nullfs_nolock,
> .flock = nullfs_nolock,
> + .setlease = nullfs_nolease,
> };
>
> static int nullfs_fs_fill_super(struct super_block *s, struct fs_context *fc)
I don't think this patch is necessary. Commit 2b10994be716 made it so
that filesystems with a NULL ->setlease pointer already return -EINVAL.
--
Jeff Layton <jlayton@xxxxxxxxxx>