From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.openvz.org (unknown [69.168.225.77]) by lore.virtuozzo.com (Postfix) with ESMTPS id C7D4480068 for ; Wed, 26 Aug 2026 11:05:50 +0000 (UTC) Received: from mail.openvz.org (localhost [127.0.0.1]) by mail.openvz.org (8.14.4/8.14.4) with ESMTP id 67QB4VpP007033; Wed, 26 Aug 2026 14:04:32 +0300 DKIM-Filter: OpenDKIM Filter v2.11.0 mail.openvz.org 67QB4VpP007033 Authentication-Results: mail.openvz.org; dkim=fail reason="signature verification failed" (2048-bit key) header.d=virtuozzo.com header.i=@virtuozzo.com header.b="Zhfd84mV" Received: from mail-wr1-f70.google.com (mail-wr1-f70.google.com [209.85.221.70]) by mail.openvz.org (8.14.4/8.14.4) with ESMTP id 67QB4Mpw007015 (version=TLSv1/SSLv3 cipher=AES128-GCM-SHA256 bits=128 verify=FAIL) for ; Wed, 26 Aug 2026 14:04:22 +0300 DKIM-Filter: OpenDKIM Filter v2.11.0 mail.openvz.org 67QB4Mpw007015 Received: by mail-wr1-f70.google.com with SMTP id ffacd0b85a97d-482e5323310so410970f8f.3 for ; Wed, 26 Aug 2026 04:04:22 -0700 (PDT) X-Gm-Message-State: AFuF++n6xtGN4jqfM+quGwcvtDEWRMHJWgl5Yhg1/H+HgALDj1m4xjQx O+6FfBR8HzLFuWbKyFjEhGqvBexIhSophopXFPDg89tHGHaG1GXcdZtTLzsAykJu4+Hfmuu5NQ5 mFs6HbIcUgU94joh81RRFsO5D3ywn7i7RIzDWR6iVnGzbn9VUOsyDfg== X-Gm-Gg: AR+sD12Ugzhh10YwYaTwMYPy+pTE8N5em56s+e4vMfw/RTyq7QSYMRymiYsL+Emimbq LSLH+SyzU4G+TPUMvjV4AL8k7+QRdxVK3Z1D8B6FgvMHGz6ZImECw8qfpLDnncww374xYgsiISp jnZ6mgk7OClMtL996p2lISLIkxX3Oh4VCC5DgFesCJ26XhGuMTDw2xhVkF8UXsV13oyH4jhfAai phhHlYhJQS1RCcM8eqneh5zQktd+Uj4SBv9ZEmdZY2EcXtzhqY0+ErSPf5wMt8E4LC3+KgKkJPs AAKITHZexhvVsY3zVDdjz0emVANxesiU5pt8VKBMriDmlzkFGWpg4otf+0PKLq6A5VunrRXtAkg 0QqkFSmfsqTGf/U7wvpgQmOYyzQqN X-Received: by 2002:adf:e191:0:b0:482:c7a0:6b64 with SMTP id ffacd0b85a97d-482e26eda9amr6586463f8f.19.1787742261981; Wed, 26 Aug 2026 04:04:21 -0700 (PDT) X-Received: by 2002:adf:e191:0:b0:482:c7a0:6b64 with SMTP id ffacd0b85a97d-482e26eda9amr6586353f8f.19.1787742261283; Wed, 26 Aug 2026 04:04:21 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1787742261; cv=none; d=google.com; s=arc-20260327; b=RAi37JbbY5SfSGlOez3nGn4Gs6wlpJQkz+DA0NvrKJOeLQJUAUfkt11yXvEnmeOqlg uBlxc08HVM8FAkylqWAufYq44qoE/aIrG+nsYeYfSpz2uh2ha1z8ENTMxLUHSCPiqDZ7 mq2GiszxywCwJulJWz2W6EO/ZzHGW1wA8q3JBR53w0P6aA5s2anqK0+D/NiuFnpg2Ev+ 8AQo7f9KJkk4r3uoHDtB3ayCN9ULM6nOcd4vu0nkuDFuNTrmschZ3BkMP52reY8E2o0e q0z9c1Xt2Yyf6PMvEP9x7IGksscfItZImm5AvUfU8PNKo0M8DLscJGmLDzw3ULLI61v8 /Z3g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:dkim-signature; bh=fM39jY6eds97Sb8xqS9WagUwdFU5ZAi/JHWbOZOPHkg=; fh=HgZU6gWxVSDFWCEWiGWrMzzoxLctZeZ+0Da/uTKKnNs=; b=VV/VKsKK1lKT7qfcHzF7yZ5aS+gDdQnrcgDESMMZrt1ukVmOeX0xMlqde97HDEcNoq w73O7ToeTHGNRrsCsrutHzqrZmooM6VDy9YyQuPoIlW8Ngg8n5Lps+N2fS57091fpK/a XmID47SUSRQt0kaN5VQ7mdCr94CnFjUeNdO6NSoSvtIASreQy4HSAWaVrW4N0YFyl8Ei m0q+Cms1dvGxCvLdmvXjt67EVhzKEBb7l3dtxbgKm2939pGU/q4DTAEUIQesEUomqk1o gUzd/xV5vl983wVT67SoU2X+jE2T/Ib7h7Bl2LTLyUA78XxMJ5mzBpXXy2F9Lde4jrV3 KwUg==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@virtuozzo.com header.s=relay header.b=Zhfd84mV; spf=pass (google.com: domain of mirian.shilakadze@virtuozzo.com designates 130.117.225.111 as permitted sender) smtp.mailfrom=mirian.shilakadze@virtuozzo.com; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=virtuozzo.com Received: from relay.virtuozzo.com (relay.virtuozzo.com. [130.117.225.111]) by mx.google.com with ESMTPS id ffacd0b85a97d-482e2787b6fsi2275824f8f.3.2026.08.26.04.04.21 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 26 Aug 2026 04:04:21 -0700 (PDT) Received-SPF: pass (google.com: domain of mirian.shilakadze@virtuozzo.com designates 130.117.225.111 as permitted sender) client-ip=130.117.225.111; Authentication-Results: mx.google.com; dkim=pass header.i=@virtuozzo.com header.s=relay header.b=Zhfd84mV; spf=pass (google.com: domain of mirian.shilakadze@virtuozzo.com designates 130.117.225.111 as permitted sender) smtp.mailfrom=mirian.shilakadze@virtuozzo.com; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=virtuozzo.com DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=virtuozzo.com; s=relay; h=MIME-Version:Message-ID:Date:Subject:From: Content-Type; bh=fM39jY6eds97Sb8xqS9WagUwdFU5ZAi/JHWbOZOPHkg=; b=Zhfd84mVovT3 yGnJ25H1VLZXqhsASp+43n18o9q8u/dwVn+56TvbMNdnLdoIp6CUp4iF9mQtHeLCEeQ3dSrNtYPXR oMQcKABt0HCrpq6lPyxuVMjgXPUPFgxItY6nD1KvYOJOWtanjtLIY2NTysceWPf5VhqJLjG5i9Kj4 eF5f0qeRlwjXfG0nzuOmkB48Nk1CbsJI32Q5HGO/fj1YST6c5+ANQ1COPNYeNkqpU+f1s0WTqHjgd CgWn+XSfuFbqDxNGnKyGUnKn6jQk3einRfj5Q8gZb/Z23gVHMWrOkzJl05GNqHkg2GbecVZprgWUA 6HyNJF0hPW/EEA7CV4Gxpg==; Received: from ch-demo-asa.virtuozzo.com ([130.117.225.8] helo=localhost.localdomain) by relay.virtuozzo.com with esmtp (Exim 4.96) (envelope-from ) id 1wzBOM-00H4OO-0O; Wed, 26 Aug 2026 13:04:20 +0200 From: Mirian Shilakadze To: khorenko@virtuozzo.com, ptikhomirov@virtuozzo.com Date: Wed, 26 Aug 2026 15:04:10 +0400 Message-ID: <20260826110415.41119-2-mirian.shilakadze@virtuozzo.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260826110415.41119-1-mirian.shilakadze@virtuozzo.com> References: <20260826110415.41119-1-mirian.shilakadze@virtuozzo.com> MIME-Version: 1.0 X-OZ-Fwd: true Cc: devel@openvz.org Subject: [Devel] [PATCH vz10 v2 1/2] fs/kernfs, ve: hide entries from a VE without invalidating the dentry X-BeenThere: devel@openvz.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: OpenVZ development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: devel-bounces@openvz.org Errors-To: devel-bounces@openvz.org kernfs_dop_revalidate() ends with a per VE visibility check and answers it with the same "return 0" that the staleness checks above it use. Those checks are properties of the kernfs node and hold for every observer: the node was deactivated, moved, renamed, or retagged. Visibility is a property of the calling task's VE, so one host dentry answers "valid" to a ve0 task and "stale" to a task inside a Container. The VFS reads 0 as a global fact and calls d_invalidate(), which walks the subtree and hands every mountpoint it finds to __detach_mounts(). The mountpoint hash is not scoped to a mount namespace, and m_list holds every mount attached at that dentry in any of them, so a Container's lookup unmounts the host's mounts. One lookup of /sys/fs/bpf from a task that only did setns() into a Container's ve namespace, staying in the host mount namespace, both hides the entry from the caller and destroys the host's bpffs. A Container start reaches the same path on its own: libvzctl stats every mount point in the namespace to collect the mount flags of a bindmount source, and does it after CLONE_NEWVE and before pivot_root, so the host loses bpffs and tracefs on the way. libvzctl needs bpffs for the cgroup v2 device controller, so no Container on the node can be managed afterwards, and the damage outlives the failed start. Report the name as missing instead, except on a kernfs instance that this VE created, where the dentry is dropped as before. Everywhere else, the host's sysfs above all, the caller that cannot see the entry is told the name is missing, which is what the check is for, and the dentry stays valid for everyone else. No caller of ->d_revalidate() reaches d_invalidate() with a negative return: lookup_dcache(), lookup_fast(), __lookup_slow() and lookup_open() in fs/namei.c all gate it on exactly 0, ovl_revalidate_real() gates it the same way, and ecryptfs_d_revalidate() hands the value back without invalidating anything itself. kernfs_iop_lookup() already answers this same condition with a plain "not found". Feature: kernfs: per-CT entries visibility and permissions configuration https://virtuozzo.atlassian.net/browse/VSTOR-142552 Fixes: 3dd8c2499df6 ("ve/kernfs: hide forbidden entries in container") Signed-off-by: Mirian Shilakadze --- fs/kernfs/dir.c | 17 +++++++++++++++-- 1 file changed, 15 insertions(+), 2 deletions(-) diff --git a/fs/kernfs/dir.c b/fs/kernfs/dir.c index be680eb98ed4..4a5ee299a94e 100644 --- a/fs/kernfs/dir.c +++ b/fs/kernfs/dir.c @@ -1199,8 +1199,21 @@ static int kernfs_dop_revalidate(struct dentry *dentry, unsigned int flags) kernfs_info(dentry->d_sb)->ns != kn->ns) goto out_bad; - if (!kernfs_d_visible(kn, kernfs_info(dentry->d_sb))) - goto out_bad; + if (!kernfs_d_visible(kn, kernfs_info(dentry->d_sb))) { + /* + * On an instance this VE created, drop the dentry as before. + * Anywhere else the node is fine and is only outside this + * VE's view: returning 0 would tell the VFS that the dentry + * is stale, and it answers that with d_invalidate(), which + * detaches every mount on that dentry in every mount + * namespace. Report the name as missing to this caller + * instead. + */ + if (kernfs_info(dentry->d_sb)->ve == get_exec_env()) + goto out_bad; + up_read(&root->kernfs_rwsem); + return -ENOENT; + } up_read(&root->kernfs_rwsem); return 1; -- 2.43.0 _______________________________________________ Devel mailing list Devel@openvz.org https://lists.openvz.org/mailman/listinfo/devel