From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.openvz.org (unknown [69.168.225.77]) by lore.virtuozzo.com (Postfix) with ESMTPS id 8CE0880024 for ; Wed, 26 Aug 2026 16:17:11 +0000 (UTC) Received: from mail.openvz.org (localhost [127.0.0.1]) by mail.openvz.org (8.14.4/8.14.4) with ESMTP id 67QGFtkc010665; Wed, 26 Aug 2026 19:15:56 +0300 DKIM-Filter: OpenDKIM Filter v2.11.0 mail.openvz.org 67QGFtkc010665 Authentication-Results: mail.openvz.org; dkim=fail reason="signature verification failed" (2048-bit key) header.d=virtuozzo.com header.i=@virtuozzo.com header.b="g1HesmDR" Received: from mail-ej1-f72.google.com (mail-ej1-f72.google.com [209.85.218.72]) by mail.openvz.org (8.14.4/8.14.4) with ESMTP id 67QGFp4G010657 (version=TLSv1/SSLv3 cipher=AES128-GCM-SHA256 bits=128 verify=FAIL) for ; Wed, 26 Aug 2026 19:15:51 +0300 DKIM-Filter: OpenDKIM Filter v2.11.0 mail.openvz.org 67QGFp4G010657 Received: by mail-ej1-f72.google.com with SMTP id a640c23a62f3a-c252c2ffeb8so78148766b.2 for ; Wed, 26 Aug 2026 09:15:51 -0700 (PDT) X-Gm-Message-State: AFuF++lHOYOZG5T2/SC2yfxG4LwuqEEpR5BHHyrng3Z77XBHX78gr8bv T7ef5QLMIV7YRcST6r3A3oz6oWZwu4ijYBFjqr99nDOJkHX8DHvByzclTLHBbrQfKuUbL0PFBZN r3ZGnVsbENQJXrNMFGvnLw6FmP5DUNO3T/IV3k1QsxvrSD6gOsXFD2w== X-Gm-Gg: AR+sD13JdtTqjcldbxuET9L7JRwoeQ1e82nw4Zfn7CqsGrIe+FPiRogJzLuTQ9DTMeI RRE1e48qU1DIsklgRjIQ5zdrzifjhEgQuqgRmEV537wnuiMwEdRcePTZNAlBvx6Kt06nmiCCDHU ovzMdVyWXDbPQhZclICk1JE3ID9NasWDEf+sui9D5LfUyji6Qv1CewO++P2ta2nXNueq0s7dpQU SorAXQahVZw0B5E5LCbh9vyXHqu2WqXKFXjYniW0XO6OYvlzwUpT5KjP6+4vAGjEUO9avHc6695 k3Pj7le4n02cjx67CpOJQE2pZ90a3PhywfBvac4DwsxNgBiX0sVB/AMKhFi9QZ1ffnAPLB81AIB Tci8YD/Dpy+LmimNP X-Received: by 2002:a17:906:9f86:b0:c24:e0dc:8b66 with SMTP id a640c23a62f3a-c250c485f66mr940849866b.6.1787760951192; Wed, 26 Aug 2026 09:15:51 -0700 (PDT) X-Received: by 2002:a17:906:9f86:b0:c24:e0dc:8b66 with SMTP id a640c23a62f3a-c250c485f66mr940842466b.6.1787760950649; Wed, 26 Aug 2026 09:15:50 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1787760950; cv=none; d=google.com; s=arc-20260327; b=EUlSkNWtyvYEzT67G8YDmtf+obpkUt+5TnidJ8U9SlOuFuQy8h2VgRftMJeAWZPiRQ Itqvu9iQdsxYyHMROdQxCA3EjutVOY31wg+Y4wvwLfpaiL/GQaYYdMLjyo1MYn803L8M 1vZqDtwJfxGVrYPTdW7cS/LeawexrKwgKQHSkJMgkZMZHaCjzP4FWUpoQHqTcBhy/LtU B9YMj+Qi+yovTgoGXVrHS6J1jtsC3OfWc3YzbY0/gdR7m/Jhd4hTwnwMPsO7IzmSriHV TRWjYgZ+xZiy0jv9vKu3m0a7tigPOZDt4ZHseTYjFrsmwTjG0TiCKbhwhrW3Gl/50R8E sreA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=subject:in-reply-to:cc:to:from:message-id:date:dkim-signature; bh=l6mv+YKImq/cl0qD8Sd2dvDh7Gtls0bdzahf95gG83s=; fh=6WaLqqjLrnoBYT6o6L3rXzHBtCCDnrtj0IcE19DsjNk=; b=mUKpbGyeE4yjK8nVPVmcauscZkQEv1yhj5a6xtfR1jYxfy6VqRAKSuqNrEVfxDqRCw lUNfl1+7dNEyUI8FOU6rViRPj8yVD4cWhDjMtTacCKnYMR73kqsN49cimRQllwWrAggf hjcdeX7GIifKzJH5G7I+VeDNWUqTOQPaul8ysFGbixFVPdY3PVMzZkzkEnFYa9vjeBOg eGKUOt3pIIH7Fizi743Y6axzMW/XUeq7rkrbieXklu5FGZn8AQJSMMGTiDitF8hAZOeC TLsOpkvk/bnnrtCFG366Dz7t45h0TW2yKBerALceFfDrqqKsC4KCGXl3zEMvfmAk9STU NLkg==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@virtuozzo.com header.s=relay header.b=g1HesmDR; spf=pass (google.com: domain of khorenko@virtuozzo.com designates 130.117.225.111 as permitted sender) smtp.mailfrom=khorenko@virtuozzo.com; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=virtuozzo.com Received: from relay.virtuozzo.com (relay.virtuozzo.com. [130.117.225.111]) by mx.google.com with ESMTPS id a640c23a62f3a-c2529b29d20si222438966b.32.2026.08.26.09.15.50 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 26 Aug 2026 09:15:50 -0700 (PDT) Received-SPF: pass (google.com: domain of khorenko@virtuozzo.com designates 130.117.225.111 as permitted sender) client-ip=130.117.225.111; Authentication-Results: mx.google.com; dkim=pass header.i=@virtuozzo.com header.s=relay header.b=g1HesmDR; spf=pass (google.com: domain of khorenko@virtuozzo.com designates 130.117.225.111 as permitted sender) smtp.mailfrom=khorenko@virtuozzo.com; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=virtuozzo.com DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=virtuozzo.com; s=relay; h=Subject:From:Message-Id:Date:Content-Type: MIME-Version; bh=l6mv+YKImq/cl0qD8Sd2dvDh7Gtls0bdzahf95gG83s=; b=g1HesmDR7THC UI+L7lazNU7Z8I0bikHv3VpEjFUk+BEdpGrI0Tb/Q8kf/zKZAxnlAn0FuNui5W89bqUTVSI9PXRnA v6fuQYkqsuLBDFbACYCFcE5CL8nS1QTHQm775Xo3WDI0kYOGPbr8XPPDKely5nDfrCjcrCt85ZrL9 Lh/tr1EltJzbMXwea89bU6aZ6cirQcMXuDh0667KdmKjk33pNzm5cwcw4IPZ3KWin+oI0VvZMWBOY W3NK6Lms2T/4Dl1Jdkq26fPVRsUtu3xyto9fdrKp//K0P9jjZ/4ksateXuM0aEAQXZIbNMx5C9qXX K6owAEbg0A6TmqVYvGm90g==; Received: from ch-demo-asa.virtuozzo.com ([130.117.225.8] helo=f0.sw.ru) by relay.virtuozzo.com with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wzGFn-005QQu-1u; Wed, 26 Aug 2026 18:15:49 +0200 Received: from f0.sw.ru (localhost [127.0.0.1]) by f0.sw.ru (8.18.1/8.18.1/Debian-2) with ESMTP id 67QGFnlh913675; Wed, 26 Aug 2026 18:15:49 +0200 Received: (from kostja@localhost) by f0.sw.ru (8.18.1/8.18.1/Submit) id 67QGFngB913674; Wed, 26 Aug 2026 18:15:49 +0200 Date: Wed, 26 Aug 2026 18:15:49 +0200 Message-Id: <202608261615.67QGFngB913674@f0.sw.ru> X-Authentication-Warning: f0.sw.ru: kostja set sender to khorenko@virtuozzo.com using -f From: Konstantin Khorenko To: Mirian Shilakadze In-Reply-to: <20260826110415.41119-2-mirian.shilakadze@virtuozzo.com> X-OZ-Fwd: true Cc: OpenVZ devel Subject: Re: [Devel] [PATCH RHEL10 COMMIT] fs/kernfs, ve: hide entries from a VE without invalidating the dentry X-BeenThere: devel@openvz.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: OpenVZ development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: devel-bounces@openvz.org Errors-To: devel-bounces@openvz.org The commit is pushed to "branch-rh10-6.12.0-211.39.1.16.x.vz10-ovz" and will appear at git@bitbucket.org:openvz/vzkernel.git after rh10-6.12.0-211.39.1.16.10.vz10 ------> commit d57b4b66477bc8f4afed0a532fc40ee19f31e286 Author: Mirian Shilakadze Date: Wed Aug 26 15:04:10 2026 +0400 fs/kernfs, ve: hide entries from a VE without invalidating the dentry kernfs_dop_revalidate() ends with a per VE visibility check and answers it with the same "return 0" that the staleness checks above it use. Those checks are properties of the kernfs node and hold for every observer: the node was deactivated, moved, renamed, or retagged. Visibility is a property of the calling task's VE, so one host dentry answers "valid" to a ve0 task and "stale" to a task inside a Container. The VFS reads 0 as a global fact and calls d_invalidate(), which walks the subtree and hands every mountpoint it finds to __detach_mounts(). The mountpoint hash is not scoped to a mount namespace, and m_list holds every mount attached at that dentry in any of them, so a Container's lookup unmounts the host's mounts. One lookup of /sys/fs/bpf from a task that only did setns() into a Container's ve namespace, staying in the host mount namespace, both hides the entry from the caller and destroys the host's bpffs. A Container start reaches the same path on its own: libvzctl stats every mount point in the namespace to collect the mount flags of a bindmount source, and does it after CLONE_NEWVE and before pivot_root, so the host loses bpffs and tracefs on the way. libvzctl needs bpffs for the cgroup v2 device controller, so no Container on the node can be managed afterwards, and the damage outlives the failed start. Report the name as missing instead, except on a kernfs instance that this VE created, where the dentry is dropped as before. Everywhere else, the host's sysfs above all, the caller that cannot see the entry is told the name is missing, which is what the check is for, and the dentry stays valid for everyone else. No caller of ->d_revalidate() reaches d_invalidate() with a negative return: lookup_dcache(), lookup_fast(), __lookup_slow() and lookup_open() in fs/namei.c all gate it on exactly 0, ovl_revalidate_real() gates it the same way, and ecryptfs_d_revalidate() hands the value back without invalidating anything itself. kernfs_iop_lookup() already answers this same condition with a plain "not found". Feature: kernfs: per-CT entries visibility and permissions configuration https://virtuozzo.atlassian.net/browse/VSTOR-142552 Fixes: 3dd8c2499df6 ("ve/kernfs: hide forbidden entries in container") Signed-off-by: Mirian Shilakadze Reviewed-by: Pavel Tikhomirov Reviewed-by: Konstantin Khorenko --- fs/kernfs/dir.c | 17 +++++++++++++++-- 1 file changed, 15 insertions(+), 2 deletions(-) diff --git a/fs/kernfs/dir.c b/fs/kernfs/dir.c index be680eb98ed4f..4a5ee299a94eb 100644 --- a/fs/kernfs/dir.c +++ b/fs/kernfs/dir.c @@ -1199,8 +1199,21 @@ static int kernfs_dop_revalidate(struct dentry *dentry, unsigned int flags) kernfs_info(dentry->d_sb)->ns != kn->ns) goto out_bad; - if (!kernfs_d_visible(kn, kernfs_info(dentry->d_sb))) - goto out_bad; + if (!kernfs_d_visible(kn, kernfs_info(dentry->d_sb))) { + /* + * On an instance this VE created, drop the dentry as before. + * Anywhere else the node is fine and is only outside this + * VE's view: returning 0 would tell the VFS that the dentry + * is stale, and it answers that with d_invalidate(), which + * detaches every mount on that dentry in every mount + * namespace. Report the name as missing to this caller + * instead. + */ + if (kernfs_info(dentry->d_sb)->ve == get_exec_env()) + goto out_bad; + up_read(&root->kernfs_rwsem); + return -ENOENT; + } up_read(&root->kernfs_rwsem); return 1; _______________________________________________ Devel mailing list Devel@openvz.org https://lists.openvz.org/mailman/listinfo/devel