From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.openvz.org (unknown [69.168.225.77]) by lore.virtuozzo.com (Postfix) with ESMTPS id DDA8980069 for ; Wed, 26 Aug 2026 15:40:01 +0000 (UTC) Received: from mail.openvz.org (localhost [127.0.0.1]) by mail.openvz.org (8.14.4/8.14.4) with ESMTP id 67QFchP4010137; Wed, 26 Aug 2026 18:38:44 +0300 DKIM-Filter: OpenDKIM Filter v2.11.0 mail.openvz.org 67QFchP4010137 Authentication-Results: mail.openvz.org; dkim=fail reason="signature verification failed" (2048-bit key) header.d=virtuozzo.com header.i=@virtuozzo.com header.b="Zeq/bnoJ" Received: from mail-ed1-f69.google.com (mail-ed1-f69.google.com [209.85.208.69]) by mail.openvz.org (8.14.4/8.14.4) with ESMTP id 67QFcgos010132 (version=TLSv1/SSLv3 cipher=AES128-GCM-SHA256 bits=128 verify=FAIL) for ; Wed, 26 Aug 2026 18:38:42 +0300 DKIM-Filter: OpenDKIM Filter v2.11.0 mail.openvz.org 67QFcgos010132 Received: by mail-ed1-f69.google.com with SMTP id 4fb4d7f45d1cf-6a0a4a22bf0so1298725a12.0 for ; Wed, 26 Aug 2026 08:38:42 -0700 (PDT) X-Gm-Message-State: AFuF++nfymc0kkoTrvdpFm1PFxJrPZePT4dd77URaz4cIEcuDWFidhWL lvO1LrHapj2l8KzTWTEUekQXZA91DejdWrg0Idiv700Xh/goYoGRv2dKZMABpWdF6y7sBN140Js S1uCWESQ5/ep3PCVbEjwU7DfpJ9uofqmKhRhUcTSxmSCHIbNs1Tr6jg== X-Gm-Gg: AR+sD132VC/fjKnY9JRrpok7mcfPYROWWRAJ0LPrU8MEmc0qX1v4w9dE4jYqpiHvMXx +FWx0GttCqRltGjGEWXUxSlqZ01NnLE8Wd9DBSg70D6eBsjSddQ/VVYov3GQ2zYhCisw0kKrh2R gYr3HGIe5b96m8qk9fZmUvRpNSgkb5rvibLqNpcrw1mlCLgD8rNyPSDync+nusU1kwNnKvPemUq Yw+8Kcv0wpSpj6yWmj2ggxJARwbjxD1M2F0Wv82BQtmRGHIEo7LCNmwNckxMGcFhPLQoEhPxIgt e0HeIor+EK8a6Iwe1v15RPQX9Oo2vy+fK2se2S42gCN7F7uydlPe4Nd2WNmHVZOKeL+12G9hOxn 0vJYK3unQAspOdTfF X-Received: by 2002:a05:6402:52dc:b0:69a:a4cb:2882 with SMTP id 4fb4d7f45d1cf-6a5df6209bdmr10167910a12.9.1787758721981; Wed, 26 Aug 2026 08:38:41 -0700 (PDT) X-Received: by 2002:a05:6402:52dc:b0:69a:a4cb:2882 with SMTP id 4fb4d7f45d1cf-6a5df6209bdmr10167842a12.9.1787758721460; Wed, 26 Aug 2026 08:38:41 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1787758721; cv=none; d=google.com; s=arc-20260327; b=QCqenBn0VPnF6r02LGUDWIpkRw1zIVfyYQCOR0nFUi2OrALHQM1F5K0wIx7QRm2GVJ Np3Y6NQ9KsYctH9DOy+JQNRU9NmibjiPp5y7eUXDe8LVp5L63AJBOR06lq5TYWARNw5H xGnBJH/bAegzatUX9izwjQ1j11+9C3Co4u3RJvFqh4ve0t3AyL3N2n0rEfCoIhq2i4fD D3esycVHdWf+6pGIKoDi+GiR+3VG2lGMnthuhGK6IcquWPoYVdhdmHMYLL6y43P/cmL0 0NJiwAMGLeZ7kaoaRq6tvwm4veefw+G2q9ylRlz4ZvPQg4/0CiH4C/AZRczwT/qJC1g9 JA6Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=subject:in-reply-to:cc:to:from:message-id:date:dkim-signature; bh=WZeywQNx9Qmn2DAsUjnaS2PumifAk39lQkG9YdIk4ZI=; fh=6WaLqqjLrnoBYT6o6L3rXzHBtCCDnrtj0IcE19DsjNk=; b=WnRffj5xx9NpSGItuMEqyw7MZVlOzSxtYUXPJPeLFrIxS10w5MJFoOnvdj70iJsJlZ 4Qm8Bds97Cy0PfeRdl74hotocpTc62tfwx3tiMt62v8D7Yv/avzuqqqaDxTs36bBEprI b2Mbmr5V/nfuqC97X8RC6VhO4iDZ3myCaB92j//BrSGb4X+9jG8A7SGYFQiF2ByYGYQ6 IktuNDLCchlBoMvJphOm0MS2ZUY8BiIDVAL7jhVQH0ZNphJVN6+rlh+t/SJx1XLBbKZ3 vCMQeOblcwyAgG8yOlkQplvyrsnJ1tFhrbKP76Whz3B1tyeO9OWee1AkdCDpOqifF7cc q5hA==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@virtuozzo.com header.s=relay header.b="Zeq/bnoJ"; spf=pass (google.com: domain of khorenko@virtuozzo.com designates 130.117.225.111 as permitted sender) smtp.mailfrom=khorenko@virtuozzo.com; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=virtuozzo.com Received: from relay.virtuozzo.com (relay.virtuozzo.com. [130.117.225.111]) by mx.google.com with ESMTPS id 4fb4d7f45d1cf-6a5eddff193si1976670a12.92.2026.08.26.08.38.41 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 26 Aug 2026 08:38:41 -0700 (PDT) Received-SPF: pass (google.com: domain of khorenko@virtuozzo.com designates 130.117.225.111 as permitted sender) client-ip=130.117.225.111; Authentication-Results: mx.google.com; dkim=pass header.i=@virtuozzo.com header.s=relay header.b="Zeq/bnoJ"; spf=pass (google.com: domain of khorenko@virtuozzo.com designates 130.117.225.111 as permitted sender) smtp.mailfrom=khorenko@virtuozzo.com; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=virtuozzo.com DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=virtuozzo.com; s=relay; h=Subject:From:Message-Id:Date:Content-Type: MIME-Version; bh=WZeywQNx9Qmn2DAsUjnaS2PumifAk39lQkG9YdIk4ZI=; b=Zeq/bnoJZjNs p9HnaOdB3nloMrMM5Y39ZY1md1qD6Twtozo+q/Sm/A1xHASdF2uRh737+hMtvpeKmUqxaluIx4wJF Ph/L2TYdTpAhxNFLxhzTIzwm3HUeoQuf6WWXntb2SuMi4xNUXG0tsSuTUFf2gzvHy6g9vFgk210zd FYLXj0q1yTpLWlEv4uRFGE1anhbPcDAVWs+Ty2+w7xWXfgb/nvZTgO/YPkSt+oOfSus1fFfJ9T1cb EpF9CkgxQG3HTTuOBaI0Y1K/kUqXVXvFzFNIyieY32nRaH69BmmTsuv+REangbpmxDX8DyvCdodyG p0Mkg3HGGP+rIb2mCFB63g==; Received: from ch-demo-asa.virtuozzo.com ([130.117.225.8] helo=f0.sw.ru) by relay.virtuozzo.com with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wzFfq-004iUx-0t; Wed, 26 Aug 2026 17:38:40 +0200 Received: from f0.sw.ru (localhost [127.0.0.1]) by f0.sw.ru (8.18.1/8.18.1/Debian-2) with ESMTP id 67QFcePK907505; Wed, 26 Aug 2026 17:38:40 +0200 Received: (from kostja@localhost) by f0.sw.ru (8.18.1/8.18.1/Submit) id 67QFcd7Z907504; Wed, 26 Aug 2026 17:38:39 +0200 Date: Wed, 26 Aug 2026 17:38:39 +0200 Message-Id: <202608261538.67QFcd7Z907504@f0.sw.ru> X-Authentication-Warning: f0.sw.ru: kostja set sender to khorenko@virtuozzo.com using -f From: Konstantin Khorenko To: Mirian Shilakadze In-Reply-to: <2c65bce961b8be0c34e3714181c3bdc533e82b51.1786950779.git.mirian.shilakadze@virtuozzo.com> X-OZ-Fwd: true Cc: OpenVZ devel Subject: Re: [Devel] [PATCH RHEL10 COMMIT] ve/fs: unlink the mount namespace on the copy_mnt_ns() error path X-BeenThere: devel@openvz.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: OpenVZ development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: devel-bounces@openvz.org Errors-To: devel-bounces@openvz.org The commit is pushed to "branch-rh10-6.12.0-211.39.1.16.x.vz10-ovz" and will appear at git@bitbucket.org:openvz/vzkernel.git after rh10-6.12.0-211.39.1.16.10.vz10 ------> commit 5e3e3c3facbcd29dfa49f7f6ab5aabb39a60d1f9 Author: Mirian Shilakadze Date: Mon Aug 17 11:16:39 2026 +0400 ve/fs: unlink the mount namespace on the copy_mnt_ns() error path alloc_mnt_ns() does two things upstream does not: it links the namespace onto all_mntns_list and takes a reference on its owning VE. Both are undone in free_mnt_ns(), which holds the only list_del() of mntns_list and the only put_ve(ns->ve_owner) in the file. copy_mnt_ns() does not call it when copy_tree() fails. It open codes the teardown and finishes with mnt_ns_release(), which drops the passive count and kfree()s the namespace without unlinking it, so the namespace is freed while all_mntns_list still points at it and the VE reference is leaked. The next namespace creation runs list_add_tail() through the dangling entry. A container reaches this deterministically. alloc_vfsmnt() returns NULL when !ve_mount_allowed(), that is when the VE is at sysctl_ve_mount_nr, clone_mnt() turns that into -ENOMEM and copy_tree() propagates it. So a container sitting at its own mount limit that calls unshare(CLONE_NEWNS) takes the error path every time, with no memory pressure and nothing beyond CAP_SYS_ADMIN in its own user namespace, and panics the host: list_add corruption. prev->next should be next (ffffffffa9ca77f0), but was ff2834a3cdfaeed0. (prev=ff2834a3cdfaeed0). kernel BUG at lib/list_debug.c:32! CPU: 94 UID: 0 PID: 7139 Comm: unshare ve: 900 alloc_mnt_ns+0xd5/0x210 copy_mnt_ns+0x82/0x3c0 create_new_namespaces+0x5d/0x2f0 unshare_nsproxy_namespaces+0x69/0xc0 ksys_unshare+0x213/0x3f0 prev->next == prev is INIT_LIST_HEAD() on reallocated memory, the freed namespace reused while the list still referenced it. CONFIG_DEBUG_LIST is only what makes it a clean BUG, without it the same list_add_tail() writes through the dangling pointer silently. The path used to call free_mnt_ns() and was correct. Upstream replaced that with the open coded sequence because free_mnt_ns() reaches mnt_ns_tree_remove(), which rb_erase()s a node that copy_mnt_ns() has not inserted yet, mnt_ns_tree_add() running only after the copy succeeds. Upstream is unaffected by the replacement because its free_mnt_ns() carries nothing else. Ours does. So do not restore the free_mnt_ns() call, that would reintroduce the rb_erase() upstream fixed. Split the part that is ours into mnt_ns_unlink() and call it from both places, so a future addition to namespace teardown has one home rather than two that can drift apart, which is how this happened. Fixes: 229fd15908fe ("fs: don't try and remove empty rbtree node") Fixes: 1db60e545f65 ("ve/mntns: add ve_owner to struct mnt_namespace") https://virtuozzo.atlassian.net/browse/VSTOR-141545 Feature: ve: ve generic structures Signed-off-by: Mirian Shilakadze Reviewed-by: Vasileios Almpanis Reviewed-by: Konstantin Khorenko --- fs/namespace.c | 24 +++++++++++++++++++----- 1 file changed, 19 insertions(+), 5 deletions(-) diff --git a/fs/namespace.c b/fs/namespace.c index 4d4dc52903508..7e27537dcdaf9 100644 --- a/fs/namespace.c +++ b/fs/namespace.c @@ -4243,17 +4243,30 @@ static void dec_mnt_namespaces(struct ucounts *ucounts) static LIST_HEAD(all_mntns_list); static DEFINE_SPINLOCK(all_mntns_list_lock); -static void free_mnt_ns(struct mnt_namespace *ns) +/* + * Undo the bookkeeping alloc_mnt_ns() sets up beyond what upstream does: the + * entry on all_mntns_list and the reference on the owning VE. + * + * Kept separate from free_mnt_ns() because copy_mnt_ns() has to unwind a + * namespace that is not in mnt_ns_tree yet, so it cannot use free_mnt_ns() + * without rb_erase()ing a node that was never inserted. + */ +static void mnt_ns_unlink(struct mnt_namespace *ns) { - if (!is_anon_ns(ns)) - ns_free_inum(&ns->ns); - dec_mnt_namespaces(ns->ucounts); - spin_lock(&all_mntns_list_lock); list_del(&ns->mntns_list); spin_unlock(&all_mntns_list_lock); put_ve(ns->ve_owner); +} + +static void free_mnt_ns(struct mnt_namespace *ns) +{ + if (!is_anon_ns(ns)) + ns_free_inum(&ns->ns); + dec_mnt_namespaces(ns->ucounts); + + mnt_ns_unlink(ns); mnt_ns_tree_remove(ns); } @@ -4347,6 +4360,7 @@ struct mnt_namespace *copy_mnt_ns(unsigned long flags, struct mnt_namespace *ns, namespace_unlock(); ns_free_inum(&new_ns->ns); dec_mnt_namespaces(new_ns->ucounts); + mnt_ns_unlink(new_ns); mnt_ns_release(new_ns); return ERR_CAST(new); } _______________________________________________ Devel mailing list Devel@openvz.org https://lists.openvz.org/mailman/listinfo/devel