From nobody Tue Sep 29 00:33:20 2026 Received: from mail-pf1-f179.google.com (mail-pf1-f179.google.com [209.85.210.179]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D8BAB468C2F for ; Fri, 14 Aug 2026 11:47:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.179 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786708025; cv=none; b=a77UNv/sblEf61Dl54/MmoRHrBEZG7po9EHlXmhPyp3CqC0J2CI3txdDCKXqjdG6D1DcPxXPCrhoKK/eOYYOUYes/hlX/yusKYl7II5spKi9NPopIdRkSaoWMiuA1wC4HBbsvJobMdVcsrSW3GzRZOd8g7NiUw9t2he0y1yhGHw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786708025; c=relaxed/simple; bh=+2iizW267rS48I87lDAJbDJ6lsKdwz04TyNcyAaFHJI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=B2bCIzClBy8w9SlIeYVOgo5xUD+XICedZwkj/qE23Gl9PKi99WXAzRdVbw+ekDMM7ROt4MaX002OQ44+7ahZh7x95LuvFpqIotsvqOwZj4tEJFn9iIWMpaHo9nzGRcJeK6fYz3tKhbooPd8uIgSf1MR4/PoneHgEJkv9fNHXRw4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=KKUQb01Z; arc=none smtp.client-ip=209.85.210.179 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="KKUQb01Z" Received: by mail-pf1-f179.google.com with SMTP id d2e1a72fcca58-84a652535dcso531846b3a.3 for ; Fri, 14 Aug 2026 04:47:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786708022; x=1787312822; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=P4USnQ+SH4S6o6UUa3QazIlBZ1RxVg3Vv6Ro4+AqyBQ=; b=KKUQb01ZCQK0Z39hBZilJRApmQx8mzHGJtWVf6lFkijGKDk0GgcJQ6C5/qPtj2AMqt VVj5+54lMtbVnVbGDB4NflKjlx7kfYK24Z0NkybDlH9FQdIGbyc4Va3TS6kF2CCqBhL/ SmiVsWz1u5vwXSYqNAKo4j4KwRKrrRFFwyeiyEfSivvjaJYmennBkOoN9V09n9Sp7YQk NVX8YhZCKdr6PFdClxLMCc4x11edLzwco6yYvHqD09bSckrFf8yeoQHs16Lq5Nvrunw+ O6PW63eIjwJX1sGWR5JaNl+xFNTAnR7bRqMEhukW0DoqwjgA4hnsIWCwtsLoX72GQ58d dklQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786708022; x=1787312822; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=P4USnQ+SH4S6o6UUa3QazIlBZ1RxVg3Vv6Ro4+AqyBQ=; b=qfHCyhHTAoaZ99E2IgbuD/kOjMJpJh0FBl0gsLm7jFPsSxLyyBvSvFds2aGKwQxvGi 6bm9hjBoP2+RMjYC3SlvQ6laNHnfvxlEo3TWxLuCCHX3X4eHoAH5ZCAn6+uo7K1HX6kP V9hbZMSheIQ+9UR6Jm58ztGa2JAhUJuxJSqZNVWmcOoajNBsaQBndCghGZ5CkhjWAMXU IqaT242K41sUCK0V25Nz3u1RNHmzyHhM9PGE3YpwdbI2dl4W5hJBKnJCW492scOBw5zj Jd2cIVyipACQufe4x+5M7pVOLBs0HbGZ5cScOAQRuJabHSeOjOYu70QSEFU1VFi9g7o7 8xOQ== X-Forwarded-Encrypted: i=1; AHgh+RrMufsm156horB/bowNsDcO2/+LRbOm/cqqpjcTK4xUbn18oRWeDuQoi2ywG6O+gaTDh/7TjeWaXvSLkBA=@vger.kernel.org X-Gm-Message-State: AOJu0YyId1tKdXdkDpy7sK6VEyCX3MO4PxWl2Zybsnfjin4K0O84KR9p HRu/m03HQxMQ90q5txPmuOI506YHRKDIapPwZ7SD8l6pRSMsyXVJJmVn X-Gm-Gg: AR+sD12rupJ8w8zUdeqlHZom0qdm7dw53nYy4Vp+N6wkGEDn3lSZZm7EQHwlGFcNfs8 L2nEKXdO0LojDkqrb4GPJElJut0h9cQvbE8Qjk+JCyWHRl3g4HKAFaDWHfniHy881Zim7Smc0XD a4NKYykYExpVKg/rR/Eg202cranCculNiHJ4TySW38FWOUTFu6GPRpN160eaNwwYFK8+S6gCsST VpEzm376LRLNYsTR/vJcLm6wIZ3wP67/2kSkq60oCnIyQx7+PJiU6OV7cQyKCD824xpZYL1dAsm p8guX1rN2rLHfGDippjdHJ4veYKo7sE7QE5vo7AtQbDFO6ZT/8eSK1u4QkBx7lci4GSZr1JTRJW lG3dYxdlM+kfQ7GwCkxbDngI0l0CJXldM6NBQEEymqafseZtehKhJwqCp4wubk4hle4itcJfCNM NsqLch+LQWCu0LEYyMDlB6BjTw++xJBghpRG/8ZeGL7wosTS8xPgXVUpCWEIy46PrwOoikNPSr6 EDHq4MsaglDARI= X-Received: by 2002:a05:6a00:bb0f:b0:84e:2722:5da4 with SMTP id d2e1a72fcca58-84fde2e8c7emr4787148b3a.20.1786708021747; Fri, 14 Aug 2026 04:47:01 -0700 (PDT) Received: from localhost.localdomain ([219.251.253.167]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-8517d223e4bsm339450b3a.30.2026.08.14.04.47.00 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Fri, 14 Aug 2026 04:47:01 -0700 (PDT) From: Kitae Yoo To: Jan Kara Cc: linux-fsdevel@vger.kernel.org, linux-ext4@vger.kernel.org, linux-kernel@vger.kernel.org, Kitae Yoo Subject: [RFC PATCH 1/2] quota: allow DQF_ROOT_SQUASH on all quota formats Date: Fri, 14 Aug 2026 20:46:48 +0900 Message-ID: <20260814114649.51253-2-kitaeyoo777@gmail.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260814114649.51253-1-kitaeyoo777@gmail.com> References: <20260814114649.51253-1-kitaeyoo777@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" ignore_hardlimit() exempts CAP_SYS_RESOURCE holders from enforcement of hard limits and of soft limits whose grace time expired. DQF_ROOT_SQUASH disables that exemption, but it has been confined to the old v1 quota format since the quota format abstraction was introduced, and commit ca6cb0918e87 ("quota: Verify flags passed to Q_SETINFO") later made Q_SETINFO reject it explicitly on other formats. That confinement predates generic project quota support. Project limits bound the size of a directory tree rather than restrict a user, and are commonly used for capacity isolation of container volumes and NFS exports. There the exemption defeats the purpose: knfsd raises CAP_SYS_RESOURCE for requests mapped to root on no_root_squash exports (CAP_NFSD_SET), so any remote root write silently exceeds project hard limits. XFS enforces project limits regardless of capabilities. Lift the format restriction so the flag can be set per quota type through Q_SETINFO on journaled quota as well. Existing setups keep their behaviour: the flag stays clear unless explicitly set, and setting it was previously rejected with -EINVAL on anything but QFMT_VFS_OLD - accepting it there is the user-visible ABI change this patch makes. Signed-off-by: Kitae Yoo --- fs/quota/dquot.c | 8 +------- include/uapi/linux/quota.h | 2 +- 2 files changed, 2 insertions(+), 8 deletions(-) diff --git a/fs/quota/dquot.c b/fs/quota/dquot.c index 9850de3955..e431e72dfe 100644 --- a/fs/quota/dquot.c +++ b/fs/quota/dquot.c @@ -1309,8 +1309,7 @@ static int ignore_hardlimit(struct dquot *dquot) struct mem_dqinfo *info =3D &sb_dqopt(dquot->dq_sb)->info[dquot->dq_id.ty= pe]; =20 return capable(CAP_SYS_RESOURCE) && - (info->dqi_format->qf_fmt_id !=3D QFMT_VFS_OLD || - !(info->dqi_flags & DQF_ROOT_SQUASH)); + !(info->dqi_flags & DQF_ROOT_SQUASH); } =20 static int dquot_add_inodes(struct dquot *dquot, qsize_t inodes, @@ -2900,11 +2899,6 @@ int dquot_set_dqinfo(struct super_block *sb, int typ= e, struct qc_info *ii) if (!sb_has_quota_active(sb, type)) return -ESRCH; mi =3D sb_dqopt(sb)->info + type; - if (ii->i_fieldmask & QC_FLAGS) { - if ((ii->i_flags & QCI_ROOT_SQUASH && - mi->dqi_format->qf_fmt_id !=3D QFMT_VFS_OLD)) - return -EINVAL; - } spin_lock(&dq_data_lock); if (ii->i_fieldmask & QC_SPC_TIMER) mi->dqi_bgrace =3D ii->i_spc_timelimit; diff --git a/include/uapi/linux/quota.h b/include/uapi/linux/quota.h index 52090105b8..a34f43519a 100644 --- a/include/uapi/linux/quota.h +++ b/include/uapi/linux/quota.h @@ -149,7 +149,7 @@ enum { DQF_PRIVATE }; =20 -/* Root squash enabled (for v1 quota format) */ +/* Enforce limits also for CAP_SYS_RESOURCE processes */ #define DQF_ROOT_SQUASH (1 << DQF_ROOT_SQUASH_B) /* Quota stored in a system file */ #define DQF_SYS_FILE (1 << DQF_SYS_FILE_B) --=20 2.50.1 (Apple Git-155) From nobody Tue Sep 29 00:33:20 2026 Received: from mail-pg1-f171.google.com (mail-pg1-f171.google.com [209.85.215.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B67AB3C1F54 for ; Fri, 14 Aug 2026 11:47:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.171 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786708031; cv=none; b=sfSAuDBy+Ul80zqsGuKNzb4cW1LOvOOrXg6t6sOnViz4yXDbpTF7ONJaiDta4AnkX8jyhnF44ZNOFaPKL8nsJgh8VnAmjPJkiRi3tXOQRhaJ12oC1uo/Kdlzsoi5yaSOA7AU/qy9AX/KVzvibzcdR6NDvC2AC0IZgdWgTZod/04= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786708031; c=relaxed/simple; bh=VO2yLfzSLmMaYW9bXlGe7RAs1ThpIK7rKaLFhEEFtwY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=auwiTkyIHbOpE9F2fN2ByhUcpNTTPNXnUuBlCyl722ZiFK9W1XsB5+aqHRQtzfVH+/QkCEMbGdwcl20jq1/Hw+zy9LL0yrsJZe5tQd3E9wcvlkqf9qAmfU+SoFC/w26HEUSANf18a0UQzqMIJo0stuqygwFF0L3OSKEcZglLOBg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=fOjzj2YY; arc=none smtp.client-ip=209.85.215.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="fOjzj2YY" Received: by mail-pg1-f171.google.com with SMTP id 41be03b00d2f7-c966b9ee9cbso525545a12.1 for ; Fri, 14 Aug 2026 04:47:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786708029; x=1787312829; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=u3LwVqpB2dcFP1kfnn5N55VXaVAN5Cf9mnID9lWYeK8=; b=fOjzj2YY8vnXxh88edeGMt/B2kHcmQ97etJcojbxmDXEgg3Z0lhfgkbI7DBjKQoU1o TiTdtKlL3OhR7WITUF+szdY2KC//Lya2wlHhvKhIEfitRhNSh+BHfFcQg4SQj6lIF7af 1R1vCgiFZaAtZ+IYC3dKR/nJi7KmA7PRIibXX6Ws4en56TWNtlpPpEC9CYx+usk794SS /LviqCeIgtVwYbAFMlW/haOSRhcEZ08U9NI8iY146twGZgHAG3iWKNBcT2UiA4u+GVyo kVgre0Q20qwm1+cETDokd5LiF+LmLB+Gef33zPeCV5DtkHzwIpXdNzlnThe2g2F8hq18 cHvw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786708029; x=1787312829; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=u3LwVqpB2dcFP1kfnn5N55VXaVAN5Cf9mnID9lWYeK8=; b=gfoYI/JW0s9imhTpK1r/fyij736G+I0cktHMsHZUoSSMNNHNV5lme7jGyKQXZqGzib j2b8Zvr+vd2igtumX3K4icukpYyY6hPCvL+X4xyQ5OHp9yEnfXgTjCG68ig+RIWFVK/6 IttWS4EG9bYXuYzJJA640Q/8ZNBNfElfyXoxWEABfjrBS4j5pjRqltdTq1L6m2nlt9Z0 AWkBI+fmcL00wXJ+AbT3KPMt4tScn4cGYfCQF4z8q3hifkCivhMEclkpMiQFl212V/Oh NW5q171j/sPBPZ/INRmBvMXJXCD/QgLoDKt0MWfHUI/bqvtmjKJFi5ZCrToB8O6j5AXO WZwg== X-Forwarded-Encrypted: i=1; AHgh+RqTfQyl8R3jiKn4Gtncz9qNf7L7a/yj09kfYnytNikcbdoY+A5U+ys4GL73U7ni/BCXCameYA8outVibEI=@vger.kernel.org X-Gm-Message-State: AOJu0Yxlg8E1j9SD4zMTuzUT+eB4FVu4e+w0zqX+7uF8zXD8F/z2tFyf qCzkmgg0IOyI4k35aYZ72aqKsRcHI0j6zQOXPEwF5xYkUcgLcRCnHz2A X-Gm-Gg: AR+sD13enq+nhgPlNq0O7fC/BP2qgmjDfKwia5l32wiaBexlFGRiu5Q0mJkcpXCdog+ 5seP3E6sZ1GWBEMYujPwAPYWC+d5sD55UIhuJTYGuHg7lRuUR8iVjidYdGU+I8MXgq+KpYPcWlW 6ohJxewQ2VuD94aSk4CJlFiUJ31V5W+O57RshaLVjHM6HIIYpRkSWjIvhnTzZTKcETvnmh4CM0E LFBQW5cVlUVRD/R/CEjNl9CveGfIThq1yPEmfr121cFVm/Vx5T5Ct1ROERpWbAEiWEBXuULmog2 IustEarbAfkLxZzR/uZBUp4nLv4wO+IVxoGWDrFXwRGaIrPTT36kkpxqxdND8E+M2vFeXt16P/h ify9hXT6om6oxa9jVHR5lWceP+z7HCcz/PPkA0lDBrv1w27/j1tLeVrNrfkexUML1Dm5vZsVg96 W12KZvKtfFBQuTWiihqx23X8sOtk5Z8b5HQ4tgc0jYQBRkfiiKdmodfK1letyJDm2rZ6zk+vlev qfAzwjfbJ6ZkQw= X-Received: by 2002:a05:6a00:4f88:b0:848:700d:c950 with SMTP id d2e1a72fcca58-84fde7d054cmr5303714b3a.37.1786708028898; Fri, 14 Aug 2026 04:47:08 -0700 (PDT) Received: from localhost.localdomain ([219.251.253.167]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-8517d223e4bsm339450b3a.30.2026.08.14.04.47.07 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Fri, 14 Aug 2026 04:47:08 -0700 (PDT) From: Kitae Yoo To: Jan Kara Cc: linux-fsdevel@vger.kernel.org, linux-ext4@vger.kernel.org, linux-kernel@vger.kernel.org, Kitae Yoo Subject: [RFC PATCH 2/2] quota_v2: persist DQF_ROOT_SQUASH Date: Fri, 14 Aug 2026 20:46:49 +0900 Message-ID: <20260814114649.51253-3-kitaeyoo777@gmail.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260814114649.51253-1-kitaeyoo777@gmail.com> References: <20260814114649.51253-1-kitaeyoo777@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Commit c119c5b9749e ("quota: Don't store flags for v2 quota format") stopped persisting dqi_flags because no v2 flag was supported and on-disk flags could contain unvalidated garbage. Now that DQF_ROOT_SQUASH is settable on v2, losing it across quotaoff/quotaon or remount would silently re-enable the CAP_SYS_RESOURCE exemption - a poor property for an enforcement policy. Store the flag in the existing on-disk dqi_flags field and mask on read so only the supported flag is ever accepted from disk, which also keeps pre-existing garbage bits out of the in-memory flags. An older kernel rewriting quota info still clears the stored flag; strict enforcement then needs to be set up again after booting back. Signed-off-by: Kitae Yoo --- fs/quota/quota_v2.c | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/fs/quota/quota_v2.c b/fs/quota/quota_v2.c index a24fab5f9f..814db61681 100644 --- a/fs/quota/quota_v2.c +++ b/fs/quota/quota_v2.c @@ -142,8 +142,7 @@ static int v2_read_file_info(struct super_block *sb, in= t type) } info->dqi_bgrace =3D le32_to_cpu(dinfo.dqi_bgrace); info->dqi_igrace =3D le32_to_cpu(dinfo.dqi_igrace); - /* No flags currently supported */ - info->dqi_flags =3D 0; + info->dqi_flags =3D le32_to_cpu(dinfo.dqi_flags) & DQF_ROOT_SQUASH; qinfo->dqi_sb =3D sb; qinfo->dqi_type =3D type; qinfo->dqi_blocks =3D le32_to_cpu(dinfo.dqi_blocks); @@ -209,8 +208,7 @@ static int v2_write_file_info(struct super_block *sb, i= nt type) info->dqi_flags &=3D ~DQF_INFO_DIRTY; dinfo.dqi_bgrace =3D cpu_to_le32(info->dqi_bgrace); dinfo.dqi_igrace =3D cpu_to_le32(info->dqi_igrace); - /* No flags currently supported */ - dinfo.dqi_flags =3D cpu_to_le32(0); + dinfo.dqi_flags =3D cpu_to_le32(info->dqi_flags & DQF_ROOT_SQUASH); spin_unlock(&dq_data_lock); dinfo.dqi_blocks =3D cpu_to_le32(qinfo->dqi_blocks); dinfo.dqi_free_blk =3D cpu_to_le32(qinfo->dqi_free_blk); --=20 2.50.1 (Apple Git-155)