From nobody Mon Sep 28 10:00:07 2026 Received: from ewsoutbound.kpnmail.nl (ewsoutbound.kpnmail.nl [195.121.94.183]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5696C37E5C4 for ; Sun, 23 Aug 2026 16:07:08 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=195.121.94.183 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501229; cv=none; b=UnTZK4CYMyLLqUWRBynodEuA7Ez4bWZ336Nz/9t+h1Fkcbqqfc1LRgY/nAsweNKqfOKAuGCeEvWHW+EX/Ac9263d2jpP3XjUZYHTIG5Ow/aaliReQRUDBfWogfbuTzQIBkf/Sm1Cjt3cMfNgnJKAkwVrRMs8owRMUvuorihNhRs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501229; c=relaxed/simple; bh=lYHNhghDqhHsjjnzaKnpHZ1Yj+9CZfCiOT3Sdjnr29M=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=UNLwSkzgDpqBthDRJsemkOr1NLKtnXZm0GdMYCY0xcRfxs+pZQe6lLj6sBIOJ9JxqfDwSx50ZRfdxVj3E2iT+vlzONx3ay+wXcVxk5jHwASqXVJBjXJh9Q7clCG+SFggxdWPohvYnfHEyBFPvKWVvLPm4uww/GmYyU+ArJITLnI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xs4all.nl; spf=pass smtp.mailfrom=xs4all.nl; dkim=pass (2048-bit key) header.d=xs4all.nl header.i=@xs4all.nl header.b=vStKSY4V; arc=none smtp.client-ip=195.121.94.183 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xs4all.nl Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=xs4all.nl Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=xs4all.nl header.i=@xs4all.nl header.b="vStKSY4V" X-KPN-MessageId: 872ec057-9f0c-11f1-8f56-005056992ed3 Received: from smtp.kpnmail.nl (unknown [10.31.155.8]) by ewsoutbound.so.kpn.org (Halon) with ESMTPS id 872ec057-9f0c-11f1-8f56-005056992ed3; Sun, 23 Aug 2026 18:05:58 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=xs4all.nl; s=xs4all01; h=mime-version:message-id:date:subject:to:from; bh=vNEE7ynNmmy0RLTjcVOI7+EkabxMyxI+8yp5sxRccrg=; b=vStKSY4VQtiTM9hjCt+jhY3YKIAH8KTTxMi2+6CwNTmEWE5vpMvWjpI9nHEJPGsyo/864t+//vHwH 5tr8Id1XiQQfMqNfkvbjHidaIENHFuPN79iEdfk8RmC935PIDMjXky9i56kdhP+xLfABZpXMhK9BEn HSMNEREbE64qguB+TI/tq6NPzhSc1XMpUs1CTcpG9HYy0LDlda71ZdzLi5wlCY72JIisxedXrGrvyk uwZc0TYWS+igAOXJPTJW3u03yhV6qbsObTpAJxfN+I+cK+rsvxC+2nMjGOe8g3k/WALceQcqELjCmh zq4MuYiPgGRumapH9WiSxxBjZk4K8wg== X-KPN-MID: 33|uDSyLnk/QUtbS32wqcmPI+9zIWKKnB4AHxXEel5sjRb6A+Eq5IhoIDgAo4oZ9RT flzGIUpt1R4U617rL7TaryRlYbTB35pZUsyAX15fiQNw= X-KPN-VerifiedSender: Yes X-CMASSUN: 33|GqqSZk1x9goRfoBYy8arhJ2qv85Gk90Hw86U0+Jm3cphDMhWbvIs5PLQuFYBOLe 8eqzC7a4EVonTpznsm0SdRg== Received: from daedalus.home (unknown [178.231.250.211]) by smtp.xs4all.nl (Halon) with ESMTPSA id 86f629b4-9f0c-11f1-8ddb-00505699d6e5; Sun, 23 Aug 2026 18:05:58 +0200 (CEST) From: Jori Koolstra To: Jeff Layton , Christian Brauner , Al Viro , Aleksa Sarai , NeilBrown , Amir Goldstein , Jan Kara Cc: linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, Jori Koolstra Subject: [PATCH v5 01/10] fs/namei.c: use trailing_slashes() Date: Sun, 23 Aug 2026 18:06:57 +0200 Message-ID: <20260823160706.358293-2-jkoolstra@xs4all.nl> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260823160706.358293-1-jkoolstra@xs4all.nl> References: <20260823160706.358293-1-jkoolstra@xs4all.nl> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" There are several places in fs/namei.c that can use the trailing_slashes() function to improve context. To allow this broader use its signature is changed to take a struct qstr instead of a struct nameidata. Reviewed-by: NeilBrown Signed-off-by: Jori Koolstra --- fs/namei.c | 28 +++++++++++++++------------- 1 file changed, 15 insertions(+), 13 deletions(-) diff --git a/fs/namei.c b/fs/namei.c index 20a6534ea3ef..ab1302b38f46 100644 --- a/fs/namei.c +++ b/fs/namei.c @@ -2781,9 +2781,16 @@ static const char *path_init(struct nameidata *nd, u= nsigned flags) return s; } =20 +static inline bool trailing_slashes(const struct qstr *last) +{ + /* last->len is set by hash_name() to the length of the current + * component ->name, terminating with '/' or a NUL character. */ + return (bool)last->name[last->len]; +} + static inline const char *lookup_last(struct nameidata *nd) { - if (nd->last_type =3D=3D LAST_NORM && nd->last.name[nd->last.len]) + if (nd->last_type =3D=3D LAST_NORM && trailing_slashes(&nd->last)) nd->flags |=3D LOOKUP_FOLLOW | LOOKUP_DIRECTORY; =20 return walk_component(nd, WALK_TRAILING); @@ -4695,17 +4702,12 @@ struct file *vfs_lookup_open(struct path *parent, s= truct qstr *last, } EXPORT_SYMBOL_FOR_MODULES(vfs_lookup_open, "nfsd"); =20 -static inline bool trailing_slashes(struct nameidata *nd) -{ - return (bool)nd->last.name[nd->last.len]; -} - static struct dentry *lookup_fast_for_open(struct nameidata *nd, int open_= flag) { struct dentry *dentry; =20 if (open_flag & O_CREAT) { - if (trailing_slashes(nd)) + if (trailing_slashes(&nd->last)) return ERR_PTR(-EISDIR); =20 /* Don't bother on an O_EXCL create */ @@ -4713,7 +4715,7 @@ static struct dentry *lookup_fast_for_open(struct nam= eidata *nd, int open_flag) return NULL; } =20 - if (trailing_slashes(nd)) + if (trailing_slashes(&nd->last)) nd->flags |=3D LOOKUP_FOLLOW | LOOKUP_DIRECTORY; =20 dentry =3D lookup_fast(nd); @@ -5087,7 +5089,7 @@ static struct dentry *filename_create(int dfd, struct= filename *name, * Do the final lookup. Suppress 'create' if there is a trailing * '/', and a directory wasn't requested. */ - if (last.name[last.len] && !want_dir) + if (trailing_slashes(&last) && !want_dir) create_flags &=3D ~LOOKUP_CREATE; dentry =3D start_dirop(path->dentry, &last, reval_flag | create_flags); if (IS_ERR(dentry)) @@ -5703,7 +5705,7 @@ int filename_unlinkat(int dfd, struct filename *name) goto exit_drop_write; =20 /* Why not before? Because we want correct error value */ - if (unlikely(last.name[last.len])) { + if (unlikely(trailing_slashes(&last))) { if (d_is_dir(dentry)) error =3D -EISDIR; else @@ -6305,16 +6307,16 @@ int filename_renameat2(int olddfd, struct filename = *from, if (flags & RENAME_EXCHANGE) { if (!d_is_dir(rd.new_dentry)) { error =3D -ENOTDIR; - if (new_last.name[new_last.len]) + if (trailing_slashes(&new_last)) goto exit_unlock; } } /* unless the source is a directory trailing slashes give -ENOTDIR */ if (!d_is_dir(rd.old_dentry)) { error =3D -ENOTDIR; - if (old_last.name[old_last.len]) + if (trailing_slashes(&old_last)) goto exit_unlock; - if (!(flags & RENAME_EXCHANGE) && new_last.name[new_last.len]) + if (!(flags & RENAME_EXCHANGE) && trailing_slashes(&new_last)) goto exit_unlock; } =20 --=20 2.55.0 From nobody Mon Sep 28 10:00:07 2026 Received: from ewsoutbound.kpnmail.nl (ewsoutbound.kpnmail.nl [195.121.94.184]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BDC88310645 for ; Sun, 23 Aug 2026 16:07:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=195.121.94.184 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501232; cv=none; b=FVPoOyfJ6NsXCtc5wNH2a/Y6HdOq1y69xzeoF/6KKLOl4sjDWL6mFgw6CiDZuhRAeSsenidBlsq9pX4T9Xh6k9X/vrwMAD8nFnyuvnBiAfbo1hAKxiX63an4016NTUkaXfG/bMsskR+h0aYBXa+NMh7W2lMTgE+l4T5pHZZcUN8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501232; c=relaxed/simple; bh=ze3mtFyHXBfW/BgZf5/VZHXDXjbkyJ+My7CiAwzNgsA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=s0fAR5aihK5jkx5fa7TLVXhnus1eiswOZTp/cz1DetX7VW6PMshp7EV45fX8y6Iy9K6GeK9tXvUCy5fPJc6F0M2lyM2GOg7IHKFVLVcYmKPLzlZV8rwIsS3VJNawzcbnWWvcs4y++vp3rzAEsPv4DJPltsHpkwEY68MfTMGpJFI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xs4all.nl; spf=pass smtp.mailfrom=xs4all.nl; dkim=pass (2048-bit key) header.d=xs4all.nl header.i=@xs4all.nl header.b=Hm3nqk9K; arc=none smtp.client-ip=195.121.94.184 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xs4all.nl Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=xs4all.nl Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=xs4all.nl header.i=@xs4all.nl header.b="Hm3nqk9K" X-KPN-MessageId: 880f8cfc-9f0c-11f1-a5a2-005056994fde Received: from smtp.kpnmail.nl (unknown [10.31.155.8]) by ewsoutbound.so.kpn.org (Halon) with ESMTPS id 880f8cfc-9f0c-11f1-a5a2-005056994fde; Sun, 23 Aug 2026 18:05:59 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=xs4all.nl; s=xs4all01; h=mime-version:message-id:date:subject:to:from; bh=iOkGSXunanUbl+67XJPMYRsFwQtLcl/hNXplO8NPaxQ=; b=Hm3nqk9KRx++BjvuQBJTQjr22AwNPONbx7wwMX+Pw0YO20MmeWEppQ2Bjsxf+6u6X2F4r1/2ht/i7 hzXOS5fwGB2ZBWbmLSm1TBDUqCQfPmYEpUSDw/gzcwP5CSCxylfAmBOee1Y2iAh9C+MfeVhWLRrLyj iTTyZcQ7yyey6+3H4BjRgITZKplWO5rfi3WCUqyxet6YbFjkDNtYBOMYzpv8BYX5/Bl+lunfT1qb+s N1GX49dET+upH/bwDf8GnMWUEIeiaS/XENTHP1l9+gC6i4wGKvTillHKT6Gt1hz0LtkbWGMNbQyA4e RF2SuSwMSxGDDkMpnIUmtfmr4DUxs3A== X-KPN-MID: 33|IulYgCOnjHLGuZf09mt2qLZlN8HVSH2gt08nWb8bWvxuaOxeN/RQlnDMcvLMVgl ScIS92Zdq9RA25HvLJL+UigU4uL+RHlmdOG6KhKEznLI= X-KPN-VerifiedSender: Yes X-CMASSUN: 33|Fc16PkErUP0RgWxxNWgOgKYEPxtg+oi7u3YZCgY4srlAdBgiQy28oM8YlYsvw2K LcCUOS4akeHbmnBevrbSlRw== Received: from daedalus.home (unknown [178.231.250.211]) by smtp.xs4all.nl (Halon) with ESMTPSA id 87d63060-9f0c-11f1-8ddb-00505699d6e5; Sun, 23 Aug 2026 18:05:59 +0200 (CEST) From: Jori Koolstra To: Jeff Layton , Christian Brauner , Al Viro , Aleksa Sarai , NeilBrown , Amir Goldstein , Jan Kara Cc: linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, Jori Koolstra Subject: [PATCH v5 02/10] vfs: prepare vfs_creat|mkdir_no_perm for reuse in lookup_open() Date: Sun, 23 Aug 2026 18:06:58 +0200 Message-ID: <20260823160706.358293-3-jkoolstra@xs4all.nl> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260823160706.358293-1-jkoolstra@xs4all.nl> References: <20260823160706.358293-1-jkoolstra@xs4all.nl> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" To implement O_CREAT|O_DIRECTORY we will have to repeat some of the logic that is now in vfs_mkdir() (e.g. do error checks in the same order). Separate this out in vfs_mkdir_no_perm(), which does all the non-permission related work of vfs_mkdir(). Permission checking for the lookup_open() path is timed differently because we may just be doing an open and no create. Similar considerations give rise to vfs_create_no_perm(). Reviewed-by: NeilBrown Signed-off-by: Jori Koolstra --- fs/namei.c | 78 +++++++++++++++++++++++++++++++++++++----------------- 1 file changed, 54 insertions(+), 24 deletions(-) diff --git a/fs/namei.c b/fs/namei.c index ab1302b38f46..229a5f7329f0 100644 --- a/fs/namei.c +++ b/fs/namei.c @@ -4166,6 +4166,24 @@ static inline umode_t vfs_prepare_mode(struct mnt_id= map *idmap, return mode; } =20 +static inline +int vfs_create_no_perm(struct mnt_idmap *idmap, struct dentry *dentry, + umode_t mode, struct delegated_inode *di) +{ + struct inode *dir =3D d_inode(dentry->d_parent); + int error; + + error =3D try_break_deleg(dir, LEASE_BREAK_DIR_CREATE, di); + if (error) + return error; + + error =3D dir->i_op->create(idmap, dir, dentry, mode); + if (!error) + fsnotify_create(dir, dentry); + + return error; +} + /** * vfs_create - create new file * @idmap: idmap of the mount the inode was found from @@ -4198,13 +4216,8 @@ int vfs_create(struct mnt_idmap *idmap, struct dentr= y *dentry, umode_t mode, error =3D security_inode_create(dir, dentry, mode); if (error) return error; - error =3D try_break_deleg(dir, LEASE_BREAK_DIR_CREATE, di); - if (error) - return error; - error =3D dir->i_op->create(idmap, dir, dentry, mode); - if (!error) - fsnotify_create(dir, dentry); - return error; + + return vfs_create_no_perm(idmap, dentry, mode, di); } EXPORT_SYMBOL(vfs_create); =20 @@ -4418,6 +4431,7 @@ static struct dentry *atomic_open(const struct path *= path, struct dentry *dentry dput(dentry); dentry =3D ERR_PTR(error); } + return dentry; } =20 @@ -4544,6 +4558,7 @@ static struct dentry *lookup_open(struct nameidata *n= d, struct file *file, dentry =3D res; } } + if (dentry->d_inode || !(op->open_flag & O_CREAT)) { /* * No need to create a file. If lookup returned a positive @@ -5358,6 +5373,34 @@ SYSCALL_DEFINE3(mknod, const char __user *, filename= , umode_t, mode, unsigned, d return filename_mknodat(AT_FDCWD, name, mode, dev); } =20 +/* Returns the dentry to use (not NULL) or -E on error */ +static inline +struct dentry *vfs_mkdir_no_perm(struct mnt_idmap *idmap, struct inode *di= r, + struct dentry *dentry, umode_t mode, + struct delegated_inode *di) +{ + int error; + struct dentry *de; + unsigned max_links =3D dir->i_sb->s_max_links; + + if (max_links && dir->i_nlink >=3D max_links) + return ERR_PTR(-EMLINK); + + error =3D try_break_deleg(dir, LEASE_BREAK_DIR_CREATE, di); + if (error) + return ERR_PTR(error); + + de =3D dir->i_op->mkdir(idmap, dir, dentry, mode); + if (IS_ERR(de)) + return de; + if (de) { + dput(dentry); + dentry =3D de; + } + fsnotify_mkdir(dir, dentry); + return dentry; +} + /** * vfs_mkdir - create directory returning correct dentry if possible * @idmap: idmap of the mount the inode was found from @@ -5385,7 +5428,6 @@ struct dentry *vfs_mkdir(struct mnt_idmap *idmap, str= uct inode *dir, struct delegated_inode *delegated_inode) { int error; - unsigned max_links =3D dir->i_sb->s_max_links; struct dentry *de; =20 error =3D may_create_dentry(idmap, dir, dentry); @@ -5401,24 +5443,12 @@ struct dentry *vfs_mkdir(struct mnt_idmap *idmap, s= truct inode *dir, if (error) goto err; =20 - error =3D -EMLINK; - if (max_links && dir->i_nlink >=3D max_links) - goto err; - - error =3D try_break_deleg(dir, LEASE_BREAK_DIR_CREATE, delegated_inode); - if (error) + de =3D vfs_mkdir_no_perm(idmap, dir, dentry, mode, delegated_inode); + if (IS_ERR(de)) { + error =3D PTR_ERR(de); goto err; - - de =3D dir->i_op->mkdir(idmap, dir, dentry, mode); - error =3D PTR_ERR(de); - if (IS_ERR(de)) - goto err; - if (de) { - dput(dentry); - dentry =3D de; } - fsnotify_mkdir(dir, dentry); - return dentry; + return de; =20 err: end_creating(dentry); --=20 2.55.0 From nobody Mon Sep 28 10:00:07 2026 Received: from ewsoutbound.kpnmail.nl (ewsoutbound.kpnmail.nl [195.121.94.184]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C888A344DBD for ; Sun, 23 Aug 2026 16:07:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=195.121.94.184 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501233; cv=none; b=erINJCG2Esi+K2lDEx2Yjmfu+olC52wG2fHLpUAJloFzthn61oIwIBpsNf5oghcNv2eObuNCdhUGDZ/gB0U3z/Blrt9KOIFvryGVEEnK6ame/cngylTDWK0J6+n1kRlEi32r9yDnPhIEIxjzzZXEnJMhpjHpiw0huL7K6X+J6I4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501233; c=relaxed/simple; bh=VZ/4WHNbzM6xNGhIe35vCBWGLs9hrCLQFLL+ZkyZtJc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=tOIbvS5qv/lSYVVGOixmv6kFgQ05ZSNVoR02qyB58c3clUSqBLc0GSZc+ul80AD1mf0bC8TeaPgpLlNtDDKtQpJz3H0MEUMBenscLnhq4DVP5esc6gWA3nN1sX/rbQS/Wo9HIH5gfxD8uYzIaStcqkJGGSzgcIe5D4IHa669Hw8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xs4all.nl; spf=pass smtp.mailfrom=xs4all.nl; dkim=pass (2048-bit key) header.d=xs4all.nl header.i=@xs4all.nl header.b=nnjAp6Nk; arc=none smtp.client-ip=195.121.94.184 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xs4all.nl Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=xs4all.nl Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=xs4all.nl header.i=@xs4all.nl header.b="nnjAp6Nk" X-KPN-MessageId: 892d0393-9f0c-11f1-a5a2-005056994fde Received: from smtp.kpnmail.nl (unknown [10.31.155.8]) by ewsoutbound.so.kpn.org (Halon) with ESMTPS id 892d0393-9f0c-11f1-a5a2-005056994fde; Sun, 23 Aug 2026 18:06:01 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=xs4all.nl; s=xs4all01; h=mime-version:message-id:date:subject:to:from; bh=QRYHuTVinpWCYh5YAfIpvY+f806/zbpBDKQkZPXhsa4=; b=nnjAp6Nkb3yzsBZK9nf3x7DQmnsr/wXRhmEsvzyuIRNZ0KGA8e6x1EPO/CHESmucAcOEWoV2l/xgU E84fbOp1N6kBe8suF3x9QIoFbqf9pTyjLEA/tQDB+xoEqNyLy2/0p9eyrFuuXNpmsXCCzGMu8tTnav txgPMOmQd/Sq9nJ78dhf4lZjSwX91j1+mh4fBv2Lp3xbGZZ1EY6wc5jLgj/2dvcHcmJU9IJdEJy24Z e3/I/F4SmeVtmCjPFyEtiJBrLOxCV5YcRiwinaQ/xWF3yrUOEkaCu86zPJu7xRpzHil0oUEFpDQFbz OC0te4KnSY3C8F4eyIvrNqt/YF/bYDw== X-KPN-MID: 33|cplPyGLLuVHVshPjedRKXwZq9Ikmg0mf8u/u8LepF5X1ygskgEZUghCFC5I6zUm arTWnyNLTzPXS/d8lMJB4Cg== X-KPN-VerifiedSender: Yes X-CMASSUN: 33|v+DNFZ7RyBU0G7mNvhY30nL70zcDicIcFZ/jMGv4Ll0wm5a/qw/S+EVEAl6hh6I OhUFJX/FxeoyC6e9rreMatw== Received: from daedalus.home (unknown [178.231.250.211]) by smtp.xs4all.nl (Halon) with ESMTPSA id 88f29b37-9f0c-11f1-8ddb-00505699d6e5; Sun, 23 Aug 2026 18:06:01 +0200 (CEST) From: Jori Koolstra To: Jeff Layton , Christian Brauner , Al Viro , Aleksa Sarai , NeilBrown , Amir Goldstein , Jan Kara Cc: linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, Jori Koolstra Subject: [PATCH v5 03/10] vfs: lookup_open(): move setting FMODE_CREATED down Date: Sun, 23 Aug 2026 18:06:59 +0200 Message-ID: <20260823160706.358293-4-jkoolstra@xs4all.nl> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260823160706.358293-1-jkoolstra@xs4all.nl> References: <20260823160706.358293-1-jkoolstra@xs4all.nl> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" In preparation for using vfs_create_no_perm() in lookup_open() we need to move setting FMODE_CREATED on the file mode to either before or after that call, as currently it is in the middle. If try_break_deleg() fails it is currently not set, but vfs_create_no_perm() includes a try_break_deleg(). Going up the call chain of lookup_open() we see that it is only used in open_last_lookups() if no error is returned from lookup_open(), so we can safely move it to after the filesystem create() call. This also makes more sense when reading the code as you don't have to wonder what the implications are of setting FMODE_CREATED before the create() call. Reviewed-by: NeilBrown Signed-off-by: Jori Koolstra --- fs/namei.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/fs/namei.c b/fs/namei.c index 229a5f7329f0..2aa18efa4e04 100644 --- a/fs/namei.c +++ b/fs/namei.c @@ -4580,7 +4580,6 @@ static struct dentry *lookup_open(struct nameidata *n= d, struct file *file, if (error) goto out_dput; =20 - file->f_mode |=3D FMODE_CREATED; if (!dir_inode->i_op->create) { error =3D -EACCES; goto out_dput; @@ -4589,6 +4588,8 @@ static struct dentry *lookup_open(struct nameidata *n= d, struct file *file, error =3D dir_inode->i_op->create(idmap, dir_inode, dentry, mode); if (error) goto out_dput; + + file->f_mode |=3D FMODE_CREATED; out: if (!IS_ERR(dentry)) { if (file->f_mode & FMODE_CREATED) --=20 2.55.0 From nobody Mon Sep 28 10:00:07 2026 Received: from ewsoutbound.kpnmail.nl (ewsoutbound.kpnmail.nl [195.121.94.186]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7C91738D686 for ; Sun, 23 Aug 2026 16:07:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=195.121.94.186 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501239; cv=none; b=hYEB+X1/2aCgdiMfkwiow32jduTxuzhJRm/e2SQDV0f+Phz4fLowBTvJeN+ylLvTc8SNZ5joecmTDmTwcq97lor8fJ/wt8WyBFmH4uS9e+ZiEpUD9MUgKAFjAODGqCfABaJquj9TbQYIq1BWGIgGogG9kUgqmcl3GMmBe3CvdBI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501239; c=relaxed/simple; bh=Gt7onBZYdsy3Yfo0sqgPFGC6QywXWs1vSnStSHJwcdc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=aCAYMFXFlffhOJrOR44OmDh6tnBP2z4DwlHXV/YeooeMy+DOMXtQjCvOHFQN82IYOkmQ/ZmIs7nT01JXEPwxLSUK9HlD1B4kMj7Q7sbdCfXbV5utbamlOsgEIayv/e43+DFUWRUJNhjKcH1y9ao3VizX/lu2aZB/rYfS676V08g= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xs4all.nl; spf=pass smtp.mailfrom=xs4all.nl; dkim=pass (2048-bit key) header.d=xs4all.nl header.i=@xs4all.nl header.b=QrGDaGVt; arc=none smtp.client-ip=195.121.94.186 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xs4all.nl Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=xs4all.nl Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=xs4all.nl header.i=@xs4all.nl header.b="QrGDaGVt" X-KPN-MessageId: 8a8036bf-9f0c-11f1-bfbb-00505699b430 Received: from smtp.kpnmail.nl (unknown [10.31.155.8]) by ewsoutbound.so.kpn.org (Halon) with ESMTPS id 8a8036bf-9f0c-11f1-bfbb-00505699b430; Sun, 23 Aug 2026 18:06:03 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=xs4all.nl; s=xs4all01; h=mime-version:message-id:date:subject:to:from; bh=8PZtSq/HzqhQUrRAn5vv8dn6sAMc4aVq0EPLcAO5uts=; b=QrGDaGVtnd6OD+Fh0RpwJfVdYc5SxbZnZYzho/AtpvKjOKWqTWEjjO+kB58OOUaeibgiv9BkvT3I8 xq4NWWMbnycuKscNKepPB2Iqt6c3Z9d12RD6Jz/r1ZM5QB8DgyS1VUH3GCguQy8TSlBlu88RcFi4VE D9c89KYY4aUxh0vieedWYRMlPmKWZZwkkQrv9PMnYRJVIzRqs6B0kTWZTq5IxzmZNR/5cAsULtojCA M2Ekx0LR12+PJR1C91N77gYsoBipllWt3s2tpooj7vtjyyPx/RymaLkPVWQDnuEj8efHKL1bCmkvV4 n/1Z6bHDGQEvwzFFrUFVCrg2GyiTEew== X-KPN-MID: 33|NWSVPxN5p+oPHBLhuIH0zet2uNRK6N6aeanbxOCc+lHXvDP3DBquXez943+kou1 IFhgdScBiHF3+pShPW6Pt2mJdi/fvF9XwYNr5aAu9Pz8= X-KPN-VerifiedSender: Yes X-CMASSUN: 33|pVczlwtz4mTe/fZGcFWPLoYPVk6RnkKBZ6uoF+E9d0/oA8F3430V4HNgVeRInED xCR0kdM2hh238fEvCjkWSRg== Received: from daedalus.home (unknown [178.231.250.211]) by smtp.xs4all.nl (Halon) with ESMTPSA id 8a499a4a-9f0c-11f1-8ddb-00505699d6e5; Sun, 23 Aug 2026 18:06:03 +0200 (CEST) From: Jori Koolstra To: Jeff Layton , Christian Brauner , Al Viro , Aleksa Sarai , NeilBrown , Amir Goldstein , Jan Kara Cc: linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, Jori Koolstra Subject: [PATCH v5 04/10] vfs: move ->create check in lookup_open() to before try_break_deleg() Date: Sun, 23 Aug 2026 18:07:00 +0200 Message-ID: <20260823160706.358293-5-jkoolstra@xs4all.nl> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260823160706.358293-1-jkoolstra@xs4all.nl> References: <20260823160706.358293-1-jkoolstra@xs4all.nl> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The i_op->create check in lookup_open() takes place after the try_break_deleg() call. This does not match the order when doing a regular file create via mknod(2). There the call order is: filename_mknodat() vfs_create() i_op->create check try_break_deleg() Move the i_op->create check to before try_break_deleg() in lookup_open(). Reviewed-by: NeilBrown Signed-off-by: Jori Koolstra --- fs/namei.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/fs/namei.c b/fs/namei.c index 2aa18efa4e04..55ba23f95c5b 100644 --- a/fs/namei.c +++ b/fs/namei.c @@ -4576,15 +4576,15 @@ static struct dentry *lookup_open(struct nameidata = *nd, struct file *file, goto out_dput; } =20 - error =3D try_break_deleg(dir_inode, LEASE_BREAK_DIR_CREATE, &delegated_i= node); - if (error) - goto out_dput; - if (!dir_inode->i_op->create) { error =3D -EACCES; goto out_dput; } =20 + error =3D try_break_deleg(dir_inode, LEASE_BREAK_DIR_CREATE, &delegated_i= node); + if (error) + goto out_dput; + error =3D dir_inode->i_op->create(idmap, dir_inode, dentry, mode); if (error) goto out_dput; --=20 2.55.0 From nobody Mon Sep 28 10:00:07 2026 Received: from ewsoutbound.kpnmail.nl (ewsoutbound.kpnmail.nl [195.121.94.186]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2252E31B80E for ; Sun, 23 Aug 2026 16:07:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=195.121.94.186 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501239; cv=none; b=LhYqGTkgh9AMs+gtX/qCcP7ntqYytu8qn0UxPW3IxXxmGPSxSxi/gT0N8ClslECjv9u2eYvBYPzwpT7V2ZzbJXFotKtiSPaJoHCMLu4OjjhTIJJ2eD0BSBYM19ziizPBWFmy+MIyLX/S5d6ICjpjqSJrQwzOPvS2V6t1AHtVR+A= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501239; c=relaxed/simple; bh=DenZvGPHyO13gxRxhTT+l0jfZ14awd/jX35HccXOnRw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=inY6FVyAddi935gbovSKyZsxSk/47USmHs3q8KDBGtXqd3wds15D/K6rNhfirIz3EGKmw84cjaKSkI4qz4QW3NuMed8UJLwb9PF3fyDJ+p5ZLPv7zBrOEaOZc8Q43tEbAXRkMLQTOHvZMcc+FvMS4E6T9z6WGwIrcX182UjjNGw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xs4all.nl; spf=pass smtp.mailfrom=xs4all.nl; dkim=pass (2048-bit key) header.d=xs4all.nl header.i=@xs4all.nl header.b=PsaW7jLE; arc=none smtp.client-ip=195.121.94.186 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xs4all.nl Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=xs4all.nl Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=xs4all.nl header.i=@xs4all.nl header.b="PsaW7jLE" X-KPN-MessageId: 8bce24c4-9f0c-11f1-bfbb-00505699b430 Received: from smtp.kpnmail.nl (unknown [10.31.155.8]) by ewsoutbound.so.kpn.org (Halon) with ESMTPS id 8bce24c4-9f0c-11f1-bfbb-00505699b430; Sun, 23 Aug 2026 18:06:05 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=xs4all.nl; s=xs4all01; h=mime-version:message-id:date:subject:to:from; bh=cPPN17Vt5blltHnoRmL4pqMxURJAQRAmUbIE0xyBclc=; b=PsaW7jLEkduhrtD66DEMaV9Bi9VOWyecm/Va/ohbjNuKtmgFt4GuUACshUXG4Z2L7MLcTYFQkgJja jDe91m3tNjVNGmjsBJ+K0ZgisqnwvKtj+hOD5NWsd6LCltoieeT/7sQuc5THiMzGsmO7YZeg7MH+Kh AxrdWfUMBCdppRkKwX1tITQQ/Zz6Tyld+6KbnPjgzGrI91pHhCZhW7a82Lygs57OopovHUn/AHaXbB Bt0HBh8WO7IKazGs1CZ/tFkn2VLJ4xECHj+vkj/A98jhhFVddfq2XsxOvDbSbdt++BD9inBFfHYVEC NNkg7QBEoMpxbdbgpkvQ2TauTN2XMWA== X-KPN-MID: 33|ubHhYK5RryFvsy0bZe5j1Cg9dkvDRUDQdcR+oNQ6VYL1TyEcI6pTis5WWaXUyvx fEM792AurXDNjL952s2lggvDxnLmilGVyaEQjeshaKCw= X-KPN-VerifiedSender: Yes X-CMASSUN: 33|J2AfV2v4Ile4U7Hkm81He3YYbYGKqgFZj59d4L3hqlvjKiBlFMlqAYhcJ6Tf7p8 Ycwwt5orKg5JbPp+kWwIV4Q== Received: from daedalus.home (unknown [178.231.250.211]) by smtp.xs4all.nl (Halon) with ESMTPSA id 8b91fc56-9f0c-11f1-8ddb-00505699d6e5; Sun, 23 Aug 2026 18:06:05 +0200 (CEST) From: Jori Koolstra To: Jeff Layton , Christian Brauner , Al Viro , Aleksa Sarai , NeilBrown , Amir Goldstein , Jan Kara Cc: linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, Jori Koolstra Subject: [PATCH v5 05/10] vfs: lookup_open(): use vfs_create_no_perm() Date: Sun, 23 Aug 2026 18:07:01 +0200 Message-ID: <20260823160706.358293-6-jkoolstra@xs4all.nl> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260823160706.358293-1-jkoolstra@xs4all.nl> References: <20260823160706.358293-1-jkoolstra@xs4all.nl> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" We can replace the code in the no create_error/negative dentry found from lookup case in lookup_open() with the vfs_create_no_perm() helper. Reviewed-by: NeilBrown Signed-off-by: Jori Koolstra --- fs/namei.c | 20 +++++++------------- 1 file changed, 7 insertions(+), 13 deletions(-) diff --git a/fs/namei.c b/fs/namei.c index 55ba23f95c5b..3afae6e87825 100644 --- a/fs/namei.c +++ b/fs/namei.c @@ -4430,8 +4430,14 @@ static struct dentry *atomic_open(const struct path = *path, struct dentry *dentry } dput(dentry); dentry =3D ERR_PTR(error); + } else { + if (file->f_mode & FMODE_CREATED) + fsnotify_create(dir_inode, dentry); + if (file->f_mode & FMODE_OPENED) + fsnotify_open(file); } =20 + return dentry; } =20 @@ -4581,22 +4587,10 @@ static struct dentry *lookup_open(struct nameidata = *nd, struct file *file, goto out_dput; } =20 - error =3D try_break_deleg(dir_inode, LEASE_BREAK_DIR_CREATE, &delegated_i= node); - if (error) - goto out_dput; - - error =3D dir_inode->i_op->create(idmap, dir_inode, dentry, mode); - if (error) - goto out_dput; + error =3D vfs_create_no_perm(idmap, dentry, mode, &delegated_inode); =20 file->f_mode |=3D FMODE_CREATED; out: - if (!IS_ERR(dentry)) { - if (file->f_mode & FMODE_CREATED) - fsnotify_create(dir_inode, dentry); - if (file->f_mode & FMODE_OPENED) - fsnotify_open(file); - } if ((open_flag & O_CREAT) || create_error) inode_unlock(dir_inode); else --=20 2.55.0 From nobody Mon Sep 28 10:00:07 2026 Received: from ewsoutbound.kpnmail.nl (ewsoutbound.kpnmail.nl [195.121.94.184]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 722D12264DB for ; Sun, 23 Aug 2026 16:06:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=195.121.94.184 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501175; cv=none; b=MYr5ZzbLkTbICah4rfPnxYXaJCRa0TMibavxsEwmB9ol70EyccWmsfKTku2+G0N37qpD/puPsiiGOtslS9TcOjEfUgKEGMg86J5c5gCM4lhSRmZredodaSQRWMmK83L489TWJXUHfv9g0nBR37Nmqj45LgpSA5CJmntSRVZx7g0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501175; c=relaxed/simple; bh=wJic2UAIxBPyZgLC96Z+WSUYmUOLk7qIkYfZE16zJyU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=guRN8JrpkCWGc8M0RGaX7IE7js+2szYb8uqGmOrBdRSHHxIyVCCnQKaoIp3N+oYejgyALEF7MyfXSUuMOEq8T/+KkNjqluYEQcr4UKdPrRoaFjT5MP4HRU6D+oxC5JNUIxCI7K0ZPW7YzLiRRd+3XC466Ka2uK04vTXYfj6zo8g= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xs4all.nl; spf=pass smtp.mailfrom=xs4all.nl; dkim=pass (2048-bit key) header.d=xs4all.nl header.i=@xs4all.nl header.b=N2J6OIxS; arc=none smtp.client-ip=195.121.94.184 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xs4all.nl Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=xs4all.nl Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=xs4all.nl header.i=@xs4all.nl header.b="N2J6OIxS" X-KPN-MessageId: 8d228739-9f0c-11f1-a5a2-005056994fde Received: from smtp.kpnmail.nl (unknown [10.31.155.8]) by ewsoutbound.so.kpn.org (Halon) with ESMTPS id 8d228739-9f0c-11f1-a5a2-005056994fde; Sun, 23 Aug 2026 18:06:08 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=xs4all.nl; s=xs4all01; h=mime-version:message-id:date:subject:to:from; bh=PBexnP9AD6x5gbEnZv5Lm5xsfraWCFmP//CI9dMmy2Y=; b=N2J6OIxSX4jTkOB3o7/kflyO26xam2DC/T0+KC7sRpbacu+G6j4qEy6upG3p1ppD2Vswr3GNzptU2 bsQbne7bgdnpPTPdTrUr7JQ9RSGi2bLPdikIQw5kosyOb3/hJGSWdRg6dD+PYymILS4nHIXhNzOG2F TcgXAhUqReYzgAEXDIbJqyDBlRVIV+fcVuBAOEKpIcRq0Symwe0DtFNyw8ApKCNQizwbeJ5AZgpGu6 vYnyhlP4VqhK1NvizM3250BM/87cFve1MOofnYblrt/GEK51Vj9EtxUAv/VEbw9QHpw9TesD7UZPvX am9gtBNPNvHOGrhOMOWI3/UhZOh2s8w== X-KPN-MID: 33|fH13FB7Kaef42rY0JazBDs5iV1vYXVqrNTzLpJItR7GfMsHPtLkJA9HOsbrcu+J rbUx5gA/G5EtQlnPnHbTMJg== X-KPN-VerifiedSender: Yes X-CMASSUN: 33|fiDKeULooFB3vxQX0+LDNWw24GRuHOJkAg/JGSEkdXDSsD6vfAXBlV9N+tdTT7R nKLD6A66A8ZVONE99x2d89w== Received: from daedalus.home (unknown [178.231.250.211]) by smtp.xs4all.nl (Halon) with ESMTPSA id 8ce72b63-9f0c-11f1-8ddb-00505699d6e5; Sun, 23 Aug 2026 18:06:08 +0200 (CEST) From: Jori Koolstra To: Jeff Layton , Christian Brauner , Al Viro , Aleksa Sarai , NeilBrown , Amir Goldstein , Jan Kara Cc: linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, Jori Koolstra Subject: [PATCH v5 06/10] vfs: add O_CREAT|O_DIRECTORY to open*(2) Date: Sun, 23 Aug 2026 18:07:02 +0200 Message-ID: <20260823160706.358293-7-jkoolstra@xs4all.nl> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260823160706.358293-1-jkoolstra@xs4all.nl> References: <20260823160706.358293-1-jkoolstra@xs4all.nl> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Currently there is no way to race-freely create and open a directory. For regular files we have open(O_CREAT) for creating a new file inode, and returning a pinning fd to it. The lack of such functionality for directories means that when populating a directory tree there's always a race involved: the inodes first need to be created, and then opened to adjust their permissions/ownership/labels/timestamps/acls/xattrs/..., but in the time window between the creation and the opening they might be replaced by something else. Addressing this race without a proper API is only partially possible: the caller can immediately fstat() what was opened to verify that it has the expected inode type, owner and mode. But besides being easy to get wrong, this cannot establish who created the directory: a directory created by another process with identical credentials is indistinguishable from one the caller created itself, so the caller cannot tell whether the directory is its own to manage. Historically, the O_CREAT|O_DIRECTORY behaviour was to return ENOTDIR if a regular file exists at the open path; EISDIR if a directory exists at the path; and to create a regular file if no file exists at the path. This behaviour changed accidentally with 973d4b73fbaf ("do_last(): rejoin the common path even earlier in FMODE_{OPENED,CREATED} case") causing ENOTDIR to return in the last case while still creating the file. As this change was not detected for a long time, Brauner proposed to adopt the more consistent NetBSD behaviour, i.e. to return EINVAL on the O_CREAT|O_DIRECTORY combination. This change was applied in 43b450632676 ("open: return EINVAL for O_DIRECTORY | O_CREAT") in March, 2023. As the EINVAL behaviour has been in the kernel for about 3 years now, no rollback is expected as a result of userspace reliance on old behaviour, leaving us free to reassign the O_CREAT|O_DIRECTORY semantics. O_CREAT|O_DIRECTORY is made to reduce to a lookup on ->atomic_open() filesystems. These filesystems currenly cannot handle O_CREAT|O_DIRECTORY without protocol extensions and therefore are forced into a fallback mode by stripping the O_CREAT bit. This causes existing directories to be succesfully opened, while for targets that should have been created, -ENOENT is returned. The other option of simply returning -EINVAL leads to inconsistent behaviour: before ->atomic_open() is called in lookup_open(), the dcache is queried. So returning -EINVAL there would make O_CREAT|O_DIRECTORY dependent on the cache state of the dentry. There is no separate sysctl for directory creation implemented currently. Therefore, for the S_ISDIR case, disabling sysctl_protected_regular is not enough to allow creating a directory in a sticky folder, because that may surprise users not expecting that O_CREAT|O_DIRECTORY is possible on newer kernels. This feature idea (and some of its description) is taken from the UAPI group: https://github.com/uapi-group/kernel-features?tab=3Dreadme-ov-file#race-fre= e-creation-and-opening-of-non-file-inodes Signed-off-by: Jori Koolstra --- fs/namei.c | 89 ++++++++++++++++++++++++++++++++++--------- fs/open.c | 25 ++++++------ include/linux/fcntl.h | 6 +++ 3 files changed, 92 insertions(+), 28 deletions(-) diff --git a/fs/namei.c b/fs/namei.c index 3afae6e87825..6f18a480665b 100644 --- a/fs/namei.c +++ b/fs/namei.c @@ -1382,13 +1382,13 @@ int may_linkat(struct mnt_idmap *idmap, const struc= t path *link) =20 /** * may_create_in_sticky - Check whether an O_CREAT open in a sticky direct= ory - * should be allowed, or not, on files that already - * exist. + * should be allowed, or not, on files/directories that + * already exist. * @idmap: idmap of the mount the inode was found from * @nd: nameidata pathwalk data * @inode: the inode of the file to open * - * Block an O_CREAT open of a FIFO (or a regular file) when: + * Block an O_CREAT open of a FIFO (or a regular file/directory) when: * - sysctl_protected_fifos (or sysctl_protected_regular) is enabled * - the file already exists * - we are in a sticky directory @@ -1416,6 +1416,14 @@ static int may_create_in_sticky(struct mnt_idmap *id= map, struct nameidata *nd, if (likely(!(dir_mode & S_ISVTX))) return 0; =20 + /* + * There is no separate sysctl for directory creation in sticky + * folders. Therefore, for the S_ISDIR case, disabling + * sysctl_protected_regular is not enough to allow creating a + * directory in a sticky folder, because that may surprise users + * not expecting that O_CREAT|O_DIRECTORY is possible on newer + * kernels. + */ if (S_ISREG(inode->i_mode) && !sysctl_protected_regular) return 0; =20 @@ -1447,6 +1455,12 @@ static int may_create_in_sticky(struct mnt_idmap *id= map, struct nameidata *nd, "sticky_create_regular"); return -EACCES; } + + if (S_ISDIR(inode->i_mode)) { + audit_log_path_denied(AUDIT_ANOM_CREAT, + "sticky_create_dir"); + return -EACCES; + } } =20 return 0; @@ -4334,21 +4348,41 @@ static inline int open_to_namei_flags(int flag) =20 static int may_o_create(struct mnt_idmap *idmap, const struct path *dir, struct dentry *dentry, - umode_t mode) + int open_flag, umode_t mode) { - int error =3D security_path_mknod(dir, dentry, mode, 0); + struct inode *dir_inode =3D dir->dentry->d_inode; + bool create_dir =3D O_IS_MKDIR(open_flag); + int error; + + if (create_dir) + error =3D security_path_mkdir(dir, dentry, mode); + else + error =3D security_path_mknod(dir, dentry, mode, 0); if (error) return error; =20 if (!fsuidgid_has_mapping(dir->dentry->d_sb, idmap)) return -EOVERFLOW; =20 - error =3D inode_permission(idmap, dir->dentry->d_inode, - MAY_WRITE | MAY_EXEC); + error =3D inode_permission(idmap, dir_inode, MAY_WRITE | MAY_EXEC); if (error) return error; =20 - return security_inode_create(dir->dentry->d_inode, dentry, mode); + if (create_dir) + error =3D security_inode_mkdir(dir_inode, dentry, mode); + else + error =3D security_inode_create(dir_inode, dentry, mode); + + return error; +} + +static inline umode_t o_create_mode(struct mnt_idmap *idmap, + const struct inode *dir, int open_flag, umode_t mode) +{ + if (O_IS_MKDIR(open_flag)) + return vfs_prepare_mode(idmap, dir, mode, S_IRWXUGO | S_ISVTX, S_IFDIR); + else + return vfs_prepare_mode(idmap, dir, mode, S_IALLUGO, S_IFREG); } =20 /** @@ -4384,8 +4418,9 @@ static struct dentry *atomic_open(const struct path *= path, struct dentry *dentry =20 file->__f_path.dentry =3D DENTRY_NOT_SET; file->__f_path.mnt =3D path->mnt; + error =3D dir_inode->i_op->atomic_open(dir_inode, dentry, file, - open_to_namei_flags(open_flag), mode); + open_to_namei_flags(open_flag), mode); d_lookup_done(dentry); =20 if (!error) { @@ -4441,6 +4476,10 @@ static struct dentry *atomic_open(const struct path = *path, struct dentry *dentry return dentry; } =20 +static inline +struct dentry *vfs_mkdir_no_perm(struct mnt_idmap *, struct inode *, + struct dentry *, umode_t, + struct delegated_inode *); /* * Look up and maybe create and open the last component. * @@ -4462,6 +4501,7 @@ static struct dentry *lookup_open(struct nameidata *n= d, struct file *file, struct mnt_idmap *idmap; struct dentry *dir =3D nd->path.dentry; struct inode *dir_inode =3D dir->d_inode; + bool create_dir =3D O_IS_MKDIR(op->mode); int open_flag; struct dentry *dentry; int error, create_error; @@ -4482,7 +4522,7 @@ static struct dentry *lookup_open(struct nameidata *n= d, struct file *file, */ } if (open_flag & O_CREAT) - inode_lock(dir_inode); + inode_lock_nested(dir_inode, I_MUTEX_PARENT); else inode_lock_shared(dir_inode); =20 @@ -4491,6 +4531,9 @@ static struct dentry *lookup_open(struct nameidata *n= d, struct file *file, goto out; } =20 + if (create_dir && dir_inode->i_op->atomic_open) + open_flag &=3D ~O_CREAT; + file->f_mode &=3D ~FMODE_CREATED; dentry =3D d_lookup(dir, &nd->last); for (;;) { @@ -4534,10 +4577,10 @@ static struct dentry *lookup_open(struct nameidata = *nd, struct file *file, if (open_flag & O_CREAT) { if (open_flag & O_EXCL) open_flag &=3D ~O_TRUNC; - mode =3D vfs_prepare_mode(idmap, dir_inode, mode, mode, mode); + mode =3D o_create_mode(idmap, dir_inode, open_flag, mode); if (likely(got_write)) create_error =3D may_o_create(idmap, &nd->path, - dentry, mode); + dentry, open_flag, mode); else create_error =3D -EROFS; } @@ -4582,12 +4625,23 @@ static struct dentry *lookup_open(struct nameidata = *nd, struct file *file, goto out_dput; } =20 - if (!dir_inode->i_op->create) { + if ((create_dir && !dir_inode->i_op->mkdir) + || (!create_dir && !dir_inode->i_op->create)) { error =3D -EACCES; goto out_dput; } =20 - error =3D vfs_create_no_perm(idmap, dentry, mode, &delegated_inode); + if (create_dir) { + struct dentry *res =3D vfs_mkdir_no_perm(idmap, dir_inode, dentry, + mode, &delegated_inode); + error =3D PTR_ERR_OR_ZERO(res); + if (!error) + dentry =3D res; + } else { + error =3D vfs_create_no_perm(idmap, dentry, mode, &delegated_inode); + } + if (error) + goto out_dput; =20 file->f_mode |=3D FMODE_CREATED; out: @@ -4717,7 +4771,7 @@ static struct dentry *lookup_fast_for_open(struct nam= eidata *nd, int open_flag) struct dentry *dentry; =20 if (open_flag & O_CREAT) { - if (trailing_slashes(&nd->last)) + if (trailing_slashes(&nd->last) && !(open_flag & O_DIRECTORY)) return ERR_PTR(-EISDIR); =20 /* Don't bother on an O_EXCL create */ @@ -4818,8 +4872,9 @@ static int do_open(struct nameidata *nd, if (open_flag & O_CREAT) { if ((open_flag & O_EXCL) && !(file->f_mode & FMODE_CREATED)) return -EEXIST; - if (d_is_dir(nd->path.dentry)) + if (!(open_flag & O_DIRECTORY) && d_is_dir(nd->path.dentry)) return -EISDIR; + error =3D may_create_in_sticky(idmap, nd, d_backing_inode(nd->path.dentry)); if (unlikely(error)) @@ -5194,7 +5249,7 @@ struct file *dentry_create(struct path *path, int fla= gs, umode_t mode, path->dentry =3D dir; mode =3D vfs_prepare_mode(idmap, dir_inode, mode, S_IALLUGO, S_IFREG); =20 - create_error =3D may_o_create(idmap, path, dentry, mode); + create_error =3D may_o_create(idmap, path, dentry, flags, mode); if (create_error) flags &=3D ~O_CREAT; =20 diff --git a/fs/open.c b/fs/open.c index 6b1c14e684a9..189af02a2425 100644 --- a/fs/open.c +++ b/fs/open.c @@ -1239,29 +1239,30 @@ inline int build_open_flags(const struct open_how *= how, struct open_flags *op) if (WILL_CREATE(flags)) { if (how->mode & ~S_IALLUGO) return -EINVAL; - op->mode =3D how->mode | S_IFREG; + if (O_IS_MKDIR(flags)) + op->mode =3D how->mode | S_IFDIR; + else + op->mode =3D how->mode | S_IFREG; } else { if (how->mode !=3D 0) return -EINVAL; op->mode =3D 0; } =20 - /* - * Block bugs where O_DIRECTORY | O_CREAT created regular files. - * Note, that blocking O_DIRECTORY | O_CREAT here also protects - * O_TMPFILE below which requires O_DIRECTORY being raised. - */ - if ((flags & (O_DIRECTORY | O_CREAT)) =3D=3D (O_DIRECTORY | O_CREAT)) - return -EINVAL; - /* Now handle the creative implementation of O_TMPFILE. */ if (flags & __O_TMPFILE) { /* * In order to ensure programs get explicit errors when trying * to use O_TMPFILE on old kernels we enforce that O_DIRECTORY - * is raised alongside __O_TMPFILE. + * is raised alongside __O_TMPFILE, but without O_CREAT. The + * reason for disallowing O_CREAT|O_TMPFILE is that + * O_DIRECTORY|O_CREAT used to work and created a regular file + * if nothing existed at the open path. Hence, allowing the + * combination would have caused O_CREAT|O_TMPFILE to create a + * regular (non-temporary) file on old kernels, while the caller + * would believe they created an actual O_TMPFILE. */ - if (!(flags & O_DIRECTORY)) + if (!(flags & O_DIRECTORY) || (flags & O_CREAT)) return -EINVAL; if (!(acc_mode & MAY_WRITE)) return -EINVAL; @@ -1319,6 +1320,8 @@ inline int build_open_flags(const struct open_how *ho= w, struct open_flags *op) op->intent =3D flags & O_PATH ? 0 : LOOKUP_OPEN; =20 if (flags & O_CREAT) { + if ((flags & O_DIRECTORY) && (acc_mode & MAY_WRITE)) + return -EISDIR; op->intent |=3D LOOKUP_CREATE; if (flags & O_EXCL) { op->intent |=3D LOOKUP_EXCL; diff --git a/include/linux/fcntl.h b/include/linux/fcntl.h index 6ad6b9e7a226..204e16bbe263 100644 --- a/include/linux/fcntl.h +++ b/include/linux/fcntl.h @@ -30,6 +30,12 @@ */ #define __O_REGULAR (1 << 30) =20 +#define O_MKDIR_MASK (O_CREAT | O_DIRECTORY) +static inline bool O_IS_MKDIR(unsigned int flags) +{ + return (flags & O_MKDIR_MASK) =3D=3D O_MKDIR_MASK; +} + /* List of all valid flags for the how->resolve argument: */ #define VALID_RESOLVE_FLAGS \ (RESOLVE_NO_XDEV | RESOLVE_NO_MAGICLINKS | RESOLVE_NO_SYMLINKS | \ --=20 2.55.0 From nobody Mon Sep 28 10:00:07 2026 Received: from ewsoutbound.kpnmail.nl (ewsoutbound.kpnmail.nl [195.121.94.186]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B3AFF37AA61 for ; Sun, 23 Aug 2026 16:07:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=195.121.94.186 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501245; cv=none; b=gD5s3wPTOwLEni2CTnGm+fvz7qfygYuWwee2oTcfL2hsmoP2vb0Tm6RirIsXdRejvN6i9Yf4E1xpTmvUayCff704m6jvztKbTkF0Wyah+1kaARec7FEQyFrr6vQBkKQdhVVIET4EjdBd4SpYK9/DbcfqAw0L9rztE0CfKqyeU7I= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501245; c=relaxed/simple; bh=H7msf3yI9M5aLnwC5iCcjy/+WO3IohCoTEuXODtmBYA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=bscwXtAOPqt48nH7nHTksXnTZ46MDhX3fJlpntfiNUenxB7fBGNNaWTATxhjo4OTsdzwL6H3Tt/xjUtSgqEHbg8vo5jk7p8ZvO2hZmZVznlfDWCvJJq59sg2uuHB7uWCjDqhf7YIwIqRsyUvuu2iP20AdjaN4LizY+ZXPTY8ndo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xs4all.nl; spf=pass smtp.mailfrom=xs4all.nl; dkim=pass (2048-bit key) header.d=xs4all.nl header.i=@xs4all.nl header.b=MVu6fOYD; arc=none smtp.client-ip=195.121.94.186 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xs4all.nl Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=xs4all.nl Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=xs4all.nl header.i=@xs4all.nl header.b="MVu6fOYD" X-KPN-MessageId: 8e59cae4-9f0c-11f1-bfbb-00505699b430 Received: from smtp.kpnmail.nl (unknown [10.31.155.8]) by ewsoutbound.so.kpn.org (Halon) with ESMTPS id 8e59cae4-9f0c-11f1-bfbb-00505699b430; Sun, 23 Aug 2026 18:06:10 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=xs4all.nl; s=xs4all01; h=mime-version:message-id:date:subject:to:from; bh=B7V1s5RVlb4qOUedRDgd/SrIwd/qrGBdycJP6EIHoVI=; b=MVu6fOYDGM0CV/3FOneDr0bEvMg6AsKrSAru8wJKhRk8alAB0Xn7a2XvBZwpmEvkQ4SxLP/hSx0P2 okAnbqEITRJZKUlWx3gRUifulFhKwy/EF3ipLBPWxxzfO51YlNuspmjdh6PcR1AUjr9jGRh+ILrSb1 WAK8NshVL3Y0T5vtG4HMmYdGfp7ExIR02hwDnqKsN3eZlzi+rTuXbiKGyHiAwOIOTXg2gPkJ9CpwLu pXcNufZAuR628HpHOw4qDGAFY/Jir27IkuLopJS7ZOpiL5QfnwEe1VH++vzPUy0oYYVSQMtw/HoVq1 uIfgAfNSgIMMCf1uBQ7oygZXVt/smrQ== X-KPN-MID: 33|W47J78vGMlThf/uxFte2zdsdRzlJD7EOzXNnVdCacztNQsrRDq7gnlKC+UFDBPP UirTumin8X+wJJ2DqycCk4FdT/71w4QhayXMd2aOWA28= X-KPN-VerifiedSender: Yes X-CMASSUN: 33|zLM95cXXSynrj5xN3ehyXHnOAmGIma0CqbydqGo5If8KWX+BlK+D0ghji/2uQM3 9zjgz4ytoKan2CmiTpDXHZA== Received: from daedalus.home (unknown [178.231.250.211]) by smtp.xs4all.nl (Halon) with ESMTPSA id 8e20498c-9f0c-11f1-8ddb-00505699d6e5; Sun, 23 Aug 2026 18:06:10 +0200 (CEST) From: Jori Koolstra To: Jeff Layton , Christian Brauner , Al Viro , Aleksa Sarai , NeilBrown , Amir Goldstein , Jan Kara Cc: linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, Jori Koolstra Subject: [PATCH v5 07/10] vfs: move O_IS_MKDIR check from lookup_open() into individual filesystems Date: Sun, 23 Aug 2026 18:07:03 +0200 Message-ID: <20260823160706.358293-8-jkoolstra@xs4all.nl> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260823160706.358293-1-jkoolstra@xs4all.nl> References: <20260823160706.358293-1-jkoolstra@xs4all.nl> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Individual filesystems that implement ->atomic_open() need to get the chance to implement O_CREAT|O_DIRECTORY or not, rather than decide this at the VFS level in lookup_open(). Signed-off-by: Jori Koolstra --- fs/9p/vfs_inode.c | 3 +++ fs/9p/vfs_inode_dotl.c | 3 +++ fs/ceph/file.c | 3 +++ fs/fuse/dir.c | 3 +++ fs/gfs2/inode.c | 3 +++ fs/namei.c | 3 --- fs/nfs/dir.c | 6 ++++++ fs/smb/client/dir.c | 3 +++ fs/vboxsf/dir.c | 3 +++ 9 files changed, 27 insertions(+), 3 deletions(-) diff --git a/fs/9p/vfs_inode.c b/fs/9p/vfs_inode.c index 3829554ca369..b1e0823c87b5 100644 --- a/fs/9p/vfs_inode.c +++ b/fs/9p/vfs_inode.c @@ -776,6 +776,9 @@ v9fs_vfs_atomic_open(struct inode *dir, struct dentry *= dentry, struct inode *inode; int p9_omode; =20 + if (O_IS_MKDIR(flags)) + flags &=3D ~O_CREAT; + if (d_in_lookup(dentry)) { struct dentry *res =3D v9fs_vfs_lookup(dir, dentry, 0); if (res || d_really_is_positive(dentry)) diff --git a/fs/9p/vfs_inode_dotl.c b/fs/9p/vfs_inode_dotl.c index 116b29e95f21..64e0aba08da1 100644 --- a/fs/9p/vfs_inode_dotl.c +++ b/fs/9p/vfs_inode_dotl.c @@ -238,6 +238,9 @@ v9fs_vfs_atomic_open_dotl(struct inode *dir, struct den= try *dentry, struct v9fs_session_info *v9ses; struct posix_acl *pacl =3D NULL, *dacl =3D NULL; =20 + if (O_IS_MKDIR(flags)) + flags &=3D ~O_CREAT; + if (d_in_lookup(dentry)) { struct dentry *res =3D v9fs_vfs_lookup(dir, dentry, 0); if (res || d_really_is_positive(dentry)) diff --git a/fs/ceph/file.c b/fs/ceph/file.c index a4a2a4b6a027..62163b7eca5f 100644 --- a/fs/ceph/file.c +++ b/fs/ceph/file.c @@ -812,6 +812,9 @@ int ceph_atomic_open(struct inode *dir, struct dentry *= dentry, dir, ceph_vinop(dir), dentry, dentry, d_unhashed(dentry) ? "unhashed" : "hashed", flags, mode); =20 + if (O_IS_MKDIR(flags)) + flags &=3D ~O_CREAT; + if (dentry->d_name.len > NAME_MAX) return -ENAMETOOLONG; =20 diff --git a/fs/fuse/dir.c b/fs/fuse/dir.c index d4e0029810c0..55d5844e2655 100644 --- a/fs/fuse/dir.c +++ b/fs/fuse/dir.c @@ -935,6 +935,9 @@ static int fuse_atomic_open(struct inode *dir, struct d= entry *entry, struct mnt_idmap *idmap =3D file_mnt_idmap(file); struct fuse_conn *fc =3D get_fuse_conn(dir); =20 + if (O_IS_MKDIR(flags)) + flags &=3D ~O_CREAT; + if (fuse_is_bad(dir)) return -EIO; =20 diff --git a/fs/gfs2/inode.c b/fs/gfs2/inode.c index f361876c5583..3ee1360f1bc2 100644 --- a/fs/gfs2/inode.c +++ b/fs/gfs2/inode.c @@ -1386,6 +1386,9 @@ static int gfs2_atomic_open(struct inode *dir, struct= dentry *dentry, { bool excl =3D !!(flags & O_EXCL); =20 + if (O_IS_MKDIR(flags)) + flags &=3D ~O_CREAT; + if (d_in_lookup(dentry)) { struct dentry *d =3D __gfs2_lookup(dir, dentry, file); if (file->f_mode & FMODE_OPENED) { diff --git a/fs/namei.c b/fs/namei.c index 6f18a480665b..9da91f081c11 100644 --- a/fs/namei.c +++ b/fs/namei.c @@ -4531,9 +4531,6 @@ static struct dentry *lookup_open(struct nameidata *n= d, struct file *file, goto out; } =20 - if (create_dir && dir_inode->i_op->atomic_open) - open_flag &=3D ~O_CREAT; - file->f_mode &=3D ~FMODE_CREATED; dentry =3D d_lookup(dir, &nd->last); for (;;) { diff --git a/fs/nfs/dir.c b/fs/nfs/dir.c index 36f2e8588922..b4db703c9e8c 100644 --- a/fs/nfs/dir.c +++ b/fs/nfs/dir.c @@ -2121,6 +2121,9 @@ int nfs_atomic_open(struct inode *dir, struct dentry = *dentry, dfprintk(VFS, "NFS: atomic_open(%s/%llu), %pd\n", dir->i_sb->s_id, dir->i_ino, dentry); =20 + if (O_IS_MKDIR(open_flags)) + open_flags &=3D ~O_CREAT; + err =3D nfs_check_flags(open_flags); if (err) return err; @@ -2313,6 +2316,9 @@ int nfs_atomic_open_v23(struct inode *dir, struct den= try *dentry, */ int error =3D 0; =20 + if (O_IS_MKDIR(open_flags)) + open_flags &=3D ~O_CREAT; + if (dentry->d_name.len > NFS_SERVER(dir)->namelen) return -ENAMETOOLONG; =20 diff --git a/fs/smb/client/dir.c b/fs/smb/client/dir.c index 7803bd5bd01f..d1af90c981cd 100644 --- a/fs/smb/client/dir.c +++ b/fs/smb/client/dir.c @@ -538,6 +538,9 @@ int cifs_atomic_open(struct inode *dir, struct dentry *= direntry, if (unlikely(cifs_forced_shutdown(cifs_sb))) return smb_EIO(smb_eio_trace_forced_shutdown); =20 + if (O_IS_MKDIR(oflags)) + oflags &=3D ~O_CREAT; + /* * Posix open is only called (at lookup time) for file create now. For * opens (rather than creates), because we do not know if it is a file diff --git a/fs/vboxsf/dir.c b/fs/vboxsf/dir.c index 0b9eab157432..6e306ddd722b 100644 --- a/fs/vboxsf/dir.c +++ b/fs/vboxsf/dir.c @@ -318,6 +318,9 @@ static int vboxsf_dir_atomic_open(struct inode *parent,= struct dentry *dentry, u64 handle; int err; =20 + if (O_IS_MKDIR(flags)) + flags &=3D ~O_CREAT; + if (d_in_lookup(dentry)) { struct dentry *res =3D vboxsf_dir_lookup(parent, dentry, 0); if (res || d_really_is_positive(dentry)) --=20 2.55.0 From nobody Mon Sep 28 10:00:07 2026 Received: from ewsoutbound.kpnmail.nl (ewsoutbound.kpnmail.nl [195.121.94.186]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AD6272BE7AB for ; Sun, 23 Aug 2026 16:06:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=195.121.94.186 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501176; cv=none; b=gVV2oxbeHW1CozW/+77g0urCi59yjKMeP1HMUvCTtRnsBpV8PFuQb2aRY43PEGtem8di7QTP1dqKz4UO4WjVfM/fgV5K1osUcxnS5L3hmf4jiE9auW18UibwTcpASIOVNsc9Rd/M40eynwJyA93vFLtNTsILwDiWFgWywxEx8DY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501176; c=relaxed/simple; bh=K+hE5SIP1DfMrkDoCPFRvzqMCev5XZT58nDKED1tNKU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=iKjL1ST40Ik+D3cl3PFGy9CImkS/3XoeK6dr50dD0LTMqVlODKD+KTFS4Uh7t95RwRPN11OPzLaOii/8OslE63v9FkUjGlbDcExQ141tZ3fg0xSb3ApV3E+Q6hZlzS71x1YeY1jMCQgrXHecbpyucqLFRUhbh1lsNy8ebt4Knj8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xs4all.nl; spf=pass smtp.mailfrom=xs4all.nl; dkim=pass (2048-bit key) header.d=xs4all.nl header.i=@xs4all.nl header.b=XG9K0vfq; arc=none smtp.client-ip=195.121.94.186 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xs4all.nl Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=xs4all.nl Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=xs4all.nl header.i=@xs4all.nl header.b="XG9K0vfq" X-KPN-MessageId: 8f9cce85-9f0c-11f1-bfbb-00505699b430 Received: from smtp.kpnmail.nl (unknown [10.31.155.8]) by ewsoutbound.so.kpn.org (Halon) with ESMTPS id 8f9cce85-9f0c-11f1-bfbb-00505699b430; Sun, 23 Aug 2026 18:06:12 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=xs4all.nl; s=xs4all01; h=mime-version:message-id:date:subject:to:from; bh=WRMkOaicp0dXfWUDHDbhi9ythsDbQ/z5UIeyTt/KkGA=; b=XG9K0vfqQeV3eLxNiPVu73MC+HL3Gef92mD6dszxZAHx6v8nPnVuwVLyQAcb/ZXkAohgjt2WtgTQJ s56c2ovGzZqAD9SnGTAXKgIz6UD0hGBLaftvFbLnyqYyxnBnc3erFrJsBf3iXVoC65elJdE4R1MtIk PBPisaEM/rhoTekV9947fRXRsSQ5hrGkSWimMJkQWkqHG/qz3epfKstXV/qB3wOumlsp6J8fguZjck bm8QutLyIp6fF1qWJ/NGu/ClCobNFlqYdWye34rwF8aLdOlu9bVB2L7U04ONlY8spldD3VhhZmIdHX KkalNUMkmyXAwFDPN28bnMnFQGqob/w== X-KPN-MID: 33|an+U0fqLdWvdXtrM4l6KDirzP1DAB5lpjRlqSRqKhKxKva+0mxNX4wrLth6Dp8a 264DoeRi0da3pAEw2/tBwku68TwrljvgmrGJA2nN3Wqs= X-KPN-VerifiedSender: Yes X-CMASSUN: 33|Igedpa6P/9cghHainCUdkm3BPeGl7dFjbh0vO0dHl4FbmIX4VQPLBX06PIwx+km QOd1zuwiYewn5IlKI6dJ6Ew== Received: from daedalus.home (unknown [178.231.250.211]) by smtp.xs4all.nl (Halon) with ESMTPSA id 8f64fde8-9f0c-11f1-8ddb-00505699d6e5; Sun, 23 Aug 2026 18:06:12 +0200 (CEST) From: Jori Koolstra To: Jeff Layton , Christian Brauner , Al Viro , Aleksa Sarai , NeilBrown , Amir Goldstein , Jan Kara Cc: linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, Jori Koolstra Subject: [PATCH v5 08/10] vfs: refuse O_CREAT for directories through a dangling symlink Date: Sun, 23 Aug 2026 18:07:04 +0200 Message-ID: <20260823160706.358293-9-jkoolstra@xs4all.nl> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260823160706.358293-1-jkoolstra@xs4all.nl> References: <20260823160706.358293-1-jkoolstra@xs4all.nl> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" open(O_CREAT) without O_EXCL follows a trailing symlink and, when the symlink target does not exist, creates it. Refuse to create through a dangling symlink for directories. In lookup_open() a negative target reached with nd->depth > 0 was arrived at by following a trailing symlink; since the dentry is negative the symlink is dangling. Set create_error to -EEXIST in that case (matching the errno returned by mkdir(2).) Reusing the existing create_error path strips O_CREAT for both the generic and ->atomic_open create paths and only reports the error when the target is actually negative. Thus opening an existing target through a symlink, interior symlinks, and O_EXCL (which never follows the trailing link) are all unaffected. Suggested-by: Christian Brauner (Amutable) Reviewed-by: NeilBrown Signed-off-by: Jori Koolstra --- fs/namei.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/fs/namei.c b/fs/namei.c index 9da91f081c11..e1a8f18385a5 100644 --- a/fs/namei.c +++ b/fs/namei.c @@ -4580,6 +4580,11 @@ static struct dentry *lookup_open(struct nameidata *= nd, struct file *file, dentry, open_flag, mode); else create_error =3D -EROFS; + /* Refuse to create a directory through a dangling (trailing) + * symlink. For regular files this has been allowed historically + * on O_CREAT without O_EXCL. */ + if (unlikely(nd->depth) && create_dir && !create_error) + create_error =3D -EEXIST; } if (create_error) open_flag &=3D ~O_CREAT; --=20 2.55.0 From nobody Mon Sep 28 10:00:07 2026 Received: from ewsoutbound.kpnmail.nl (ewsoutbound.kpnmail.nl [195.121.94.186]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6DA23344DBD for ; Sun, 23 Aug 2026 16:06:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=195.121.94.186 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501177; cv=none; b=oEaAQzvZdlIKyAepM6zkOZFOvwaaMl6tM6k4bm4K5UVawv+IxqUD/JlcqWEjwkhlI9iwo6cUhGnDRJ1LUicyssTip5DcOz0CRyotVvKDyqRlesS2MvOPZU+DrnzHHU5gjhfW7E/EgdF+Gn9JZ2S75ZJUMWyP3zHdfy92L1kCgSo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501177; c=relaxed/simple; bh=J36fVG2Gop1jTPTE0Lzk+Nipg8LtgBVKtOm80+fB8JM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=V1MTRbJpql+0X5aU5Slk4h3IR0Swftbq0oJyNuiY0FyKDw0+OcjlTnUnxPMl3bDL+HzE5xkz1JihajkzBMk0zwjo3BBYQsV85djsZll0792/zu3Xyj9/1GIWQK0jt7VFy/iDq0jtwW3rXs5Nh6W1z7gTpgqPW1W5zOv8cfA1/5U= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xs4all.nl; spf=pass smtp.mailfrom=xs4all.nl; dkim=pass (2048-bit key) header.d=xs4all.nl header.i=@xs4all.nl header.b=lfU1gwUT; arc=none smtp.client-ip=195.121.94.186 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xs4all.nl Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=xs4all.nl Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=xs4all.nl header.i=@xs4all.nl header.b="lfU1gwUT" X-KPN-MessageId: 90512e8b-9f0c-11f1-bfbb-00505699b430 Received: from smtp.kpnmail.nl (unknown [10.31.155.8]) by ewsoutbound.so.kpn.org (Halon) with ESMTPS id 90512e8b-9f0c-11f1-bfbb-00505699b430; Sun, 23 Aug 2026 18:06:13 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=xs4all.nl; s=xs4all01; h=mime-version:message-id:date:subject:to:from; bh=I0mBoC0NDW7esUAmw5xGbkSmt0K3Ofsyt4PIap3Vlt8=; b=lfU1gwUTUQ/J1Z8ama4Jcmb3NVruyF261VaIs7JHmKeTPPT50SLFz9AvGI/HpjLOlaBhJ3m5W6CYr xSNq6ym0n/Z1FnXgSSoLfbPRELS3Kd+GWwLUoi9m8Zp8wcfP3GLayHSLvA8riVtI93lvigWUQqpYWQ NSxK9Rm2XX5n1YGyUJFxfCihPe9vkMVnpgVqvhWG4Ll6Anh1StSAPu2lWjua3XV/i2VCvZCVzqY1UQ 9R2bOaqlq02tT90Mtm7VpEwD7DztfQNEZ4q4WaYA9bq/JBPNyPCgIY7LK9ZvrttTgGacXwb5QVp+MU x8DqJh7I40URAcwreaPqOEBUzw/sf2A== X-KPN-MID: 33|MLSMDmiIUqpjUJLjXUU23b1NIkip/N7AFqmQVW3wqjUX+AIMTyWFhH1/0/9t5CL OZoT1X13j2SRAxRQnXpfHXRkA+Qbm30U2ABXi9uI9vfs= X-KPN-VerifiedSender: Yes X-CMASSUN: 33|trvADC78DfaEI+9dDVQRk4aMhhsvoJauKDLsNKnPGNwlRu57NGiyvwuJ1Z9EXnn nYLnp7ynTLqSKYLmz9crBpw== Received: from daedalus.home (unknown [178.231.250.211]) by smtp.xs4all.nl (Halon) with ESMTPSA id 9015fc0c-9f0c-11f1-8ddb-00505699d6e5; Sun, 23 Aug 2026 18:06:13 +0200 (CEST) From: Jori Koolstra To: Jeff Layton , Christian Brauner , Al Viro , Aleksa Sarai , NeilBrown , Amir Goldstein , Jan Kara Cc: linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, Jori Koolstra Subject: [PATCH v5 09/10] vfs: short-circuit MAY_WRITE access for O_DIRECTORY opens Date: Sun, 23 Aug 2026 18:07:05 +0200 Message-ID: <20260823160706.358293-10-jkoolstra@xs4all.nl> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260823160706.358293-1-jkoolstra@xs4all.nl> References: <20260823160706.358293-1-jkoolstra@xs4all.nl> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Requesting write access on a directory can never succeed. Rather than performing a path-walk to determine whether the target is actually a directory (-EISDIR) or not (-ENOTDIR), or does not exist (-ENOENT), etc., we short-circuit to -ENOTDIR. Currently O_WRONLY for directories is only blocked in may_open(), which happens after we have the inode for the target, so after any create via O_CREAT|O_DIRECTORY. The advantage of short-circuiting is that we don't have to add even more logic to lookup_open() to differentiate -EISDIR/-ENOTDIR. Also, for filesystems that define atomic_open(), handling this cannot even be done at the VFS level, as we can't know ahead of calling ->atomic_open() what the result of the lookup is. Suggested-by: Christian Brauner (Amutable) Reviewed-by: NeilBrown Signed-off-by: Jori Koolstra --- fs/open.c | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/fs/open.c b/fs/open.c index 189af02a2425..6cb5e2ad781f 100644 --- a/fs/open.c +++ b/fs/open.c @@ -1319,9 +1319,16 @@ inline int build_open_flags(const struct open_how *h= ow, struct open_flags *op) =20 op->intent =3D flags & O_PATH ? 0 : LOOKUP_OPEN; =20 + /* + * Requesting write access on a directory can never succeed. Rather + * than performing a path-walk to determine whether the target is + * actually a directory (-EISDIR) or not (-ENOTDIR), we short-circuit + * to -ENOTDIR. + */ + if ((flags & O_DIRECTORY) && !(flags & __O_TMPFILE) && (acc_mode & MAY_WR= ITE)) + return -ENOTDIR; + if (flags & O_CREAT) { - if ((flags & O_DIRECTORY) && (acc_mode & MAY_WRITE)) - return -EISDIR; op->intent |=3D LOOKUP_CREATE; if (flags & O_EXCL) { op->intent |=3D LOOKUP_EXCL; --=20 2.55.0 From nobody Mon Sep 28 10:00:07 2026 Received: from ewsoutbound.kpnmail.nl (ewsoutbound.kpnmail.nl [195.121.94.183]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B9B7C38F62F for ; Sun, 23 Aug 2026 16:06:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=195.121.94.183 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501181; cv=none; b=hhmBZQJmM2MViwkIzCq8Fax1oh6ldwN0ZDQ3B91zmEHAHmkbFV6cRquo86bbTGCo4qvoozP7TwMbJhedOR3NTx0InqK2rXwucyHo49CWFq8xT4XILvL2ewhcGunUO+uoQdw0REIKLZZdJnGr0r48n8L3M44buDmIOUj2J57vo9U= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787501181; c=relaxed/simple; bh=spWNZBldw8GMd8inP3VAXkgffgZh1WjutQb7nebFCYc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=A4981qO+5J91V95YUcZGDYOQPyPj+VrInCQSui4ksZewaTT0YRzz0FTxFN4i6JQIVLuN6M+hzyHB1DV9cm1stlsmRcA8T8c5PUG2sOG3+NSLDMF7YziSu0WBhqYRgwWADxI+ThnyliStdOVjT2nOqut9aABekSrq1ElBMZ5F9+8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xs4all.nl; spf=pass smtp.mailfrom=xs4all.nl; dkim=pass (2048-bit key) header.d=xs4all.nl header.i=@xs4all.nl header.b=vaXVx3oa; arc=none smtp.client-ip=195.121.94.183 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xs4all.nl Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=xs4all.nl Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=xs4all.nl header.i=@xs4all.nl header.b="vaXVx3oa" X-KPN-MessageId: 917be2ef-9f0c-11f1-8f56-005056992ed3 Received: from smtp.kpnmail.nl (unknown [10.31.155.8]) by ewsoutbound.so.kpn.org (Halon) with ESMTPS id 917be2ef-9f0c-11f1-8f56-005056992ed3; Sun, 23 Aug 2026 18:06:15 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=xs4all.nl; s=xs4all01; h=mime-version:message-id:date:subject:to:from; bh=NsM81Bi3C4jar7eOgg9FMzVA7MuiHRfVEmSBzan1hHE=; b=vaXVx3oaWIlpm3t2V65nfq83Ph0bsiBXD/rYbwFP6sMbMLGrkH/FnYTBB9eJxkfMmCMf3yfuOSjw+ xVcieEO6OQYrxH0yU8vktrq4joMubW4yKPq+Nz8hu2GpYRxNtdVs7gIy9H8KJYtAgC0+XTvxFuhcax N/xKZuU0d20x5+N7AXmq8qKuhgknx+xd1E6TNaKQHK+r4m/fUola0h7VcEEzMECKFNYU4t5EpqtwqN 6ZaFVHRAMd/o68OkP9lSirZTHepTOFQtajGe2SwGkY5bLo2yWEKGsk+Id3celwgQlALxigauiLpp/o UXu5xjobhSjA5QrhSv1j1HvgxRbZ2gg== X-KPN-MID: 33|PfRWJXFH8m2v643Y1/dJt0k62fDe0lD9/DRoWTKmDKanNV6AszseiEZUZQXqAZT A9G2UXIHfwnRRQrFf/1xALg== X-KPN-VerifiedSender: Yes X-CMASSUN: 33|4GBUKNWG/lkzENgrm/jgHF3VUbBmMn6BkqGM6QslwC5NB5HxbY7vD8r0ino3Iiu i6FNywSZyDTJY0PYDNBV6gQ== Received: from daedalus.home (unknown [178.231.250.211]) by smtp.xs4all.nl (Halon) with ESMTPSA id 91437fdf-9f0c-11f1-8ddb-00505699d6e5; Sun, 23 Aug 2026 18:06:15 +0200 (CEST) From: Jori Koolstra To: Jeff Layton , Christian Brauner , Al Viro , Aleksa Sarai , NeilBrown , Amir Goldstein , Jan Kara Cc: linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, Jori Koolstra Subject: [PATCH v5 10/10] selftest: add tests for open*(O_CREAT|O_DIRECTORY) Date: Sun, 23 Aug 2026 18:07:06 +0200 Message-ID: <20260823160706.358293-11-jkoolstra@xs4all.nl> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260823160706.358293-1-jkoolstra@xs4all.nl> References: <20260823160706.358293-1-jkoolstra@xs4all.nl> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Add some tests for the new valid O_CREAT|O_DIRECTORY flag combination for open*(2) to test compliance and to showcase its behaviour. Signed-off-by: Jori Koolstra --- .../testing/selftests/filesystems/.gitignore | 1 + tools/testing/selftests/filesystems/Makefile | 2 +- .../filesystems/open_o_creat_o_dir.c | 201 ++++++++++++++++++ .../testing/selftests/filesystems/wrappers.h | 11 + 4 files changed, 214 insertions(+), 1 deletion(-) create mode 100644 tools/testing/selftests/filesystems/open_o_creat_o_dir.c diff --git a/tools/testing/selftests/filesystems/.gitignore b/tools/testing= /selftests/filesystems/.gitignore index 9eb185fb2f9d..01c588d4c84f 100644 --- a/tools/testing/selftests/filesystems/.gitignore +++ b/tools/testing/selftests/filesystems/.gitignore @@ -1,4 +1,5 @@ # SPDX-License-Identifier: GPL-2.0-only +open_o_creat_o_dir dnotify_test devpts_pts fclog diff --git a/tools/testing/selftests/filesystems/Makefile b/tools/testing/s= elftests/filesystems/Makefile index 03be337c1f35..0959bd26875a 100644 --- a/tools/testing/selftests/filesystems/Makefile +++ b/tools/testing/selftests/filesystems/Makefile @@ -1,7 +1,7 @@ # SPDX-License-Identifier: GPL-2.0 =20 CFLAGS +=3D $(KHDR_INCLUDES) -TEST_GEN_PROGS :=3D devpts_pts file_stressor anon_inode_test kernfs_test f= clog ustat_test +TEST_GEN_PROGS :=3D open_o_creat_o_dir devpts_pts file_stressor anon_inode= _test kernfs_test fclog ustat_test TEST_GEN_PROGS +=3D idmapped_tmpfile TEST_GEN_PROGS_EXTENDED :=3D dnotify_test =20 diff --git a/tools/testing/selftests/filesystems/open_o_creat_o_dir.c b/too= ls/testing/selftests/filesystems/open_o_creat_o_dir.c new file mode 100644 index 000000000000..be0ab34267e1 --- /dev/null +++ b/tools/testing/selftests/filesystems/open_o_creat_o_dir.c @@ -0,0 +1,201 @@ +// SPDX-License-Identifier: GPL-2.0 +#include +#include +#include +#include + +#include "kselftest_harness.h" +#include "wrappers.h" + +#define openat_o_mkdir_checked_flags(dfd, pathname, flags) ({ \ + struct stat __st; \ + int __fd =3D openat_o_mkdir(dfd, pathname, flags, S_IRWXU); \ + ASSERT_GE(__fd, 0); \ + ASSERT_EQ(fstat(__fd, &__st), 0); \ + EXPECT_TRUE(S_ISDIR(__st.st_mode)); \ + __fd; \ +}) + +#define openat_o_mkdir_checked(dfd, pathname) \ + openat_o_mkdir_checked_flags(dfd, pathname, O_RDONLY) + +FIXTURE(open_o_creat_o_dir) { + char dirpath[PATH_MAX]; + int dfd; +}; + +FIXTURE_SETUP(open_o_creat_o_dir) +{ + strcpy(self->dirpath, "/tmp/open_o_creat_o_dir_test.XXXXXX"); + ASSERT_NE(mkdtemp(self->dirpath), NULL); + self->dfd =3D open(self->dirpath, O_DIRECTORY); + ASSERT_GE(self->dfd, 0); +} + +FIXTURE_TEARDOWN(open_o_creat_o_dir) +{ + close(self->dfd); + rmdir(self->dirpath); +} + +/* Does open_o_creat_o_dir return a fd at all? */ +TEST_F(open_o_creat_o_dir, returns_fd) +{ + int fd =3D openat_o_mkdir_checked(self->dfd, "newdir"); + EXPECT_EQ(close(fd), 0); + EXPECT_EQ(unlinkat(self->dfd, "newdir", AT_REMOVEDIR), 0); +} + +/* The fd must refer to the directory that was just created. */ +TEST_F(open_o_creat_o_dir, fd_is_created_dir) +{ + int fd; + struct stat st_via_fd, st_via_path; + char path[PATH_MAX]; + + fd =3D openat_o_mkdir_checked(self->dfd, "checkdir"); + + ASSERT_EQ(fstat(fd, &st_via_fd), 0); + + snprintf(path, sizeof(path), "%s/checkdir", self->dirpath); + ASSERT_EQ(stat(path, &st_via_path), 0); + + EXPECT_EQ(st_via_fd.st_ino, st_via_path.st_ino); + EXPECT_EQ(st_via_fd.st_dev, st_via_path.st_dev); + + EXPECT_EQ(close(fd), 0); + EXPECT_EQ(rmdir(path), 0); +} + +/* Missing parent component must fail with ENOENT. */ +TEST_F(open_o_creat_o_dir, enoent_missing_parent) +{ + EXPECT_EQ(openat_o_mkdir(self->dfd, "nonexistent/child", O_RDONLY, S_IRWX= U), -1); + EXPECT_EQ(errno, ENOENT); +} + +/* An invalid dfd must fail with EBADF. */ +TEST_F(open_o_creat_o_dir, ebadf) +{ + EXPECT_EQ(openat_o_mkdir(FD_INVALID, "badfdir", O_RDONLY, S_IRWXU), -1); + EXPECT_EQ(errno, EBADF); +} + +/* A dfd that points to a file (not a directory) must fail with ENOTDIR. */ +TEST_F(open_o_creat_o_dir, enotdir_dfd) +{ + int file_fd; + + file_fd =3D openat(self->dfd, "file", + O_CREAT | O_RDONLY, S_IRWXU); + ASSERT_GE(file_fd, 0); + + EXPECT_EQ(openat_o_mkdir(file_fd, "subdir", O_RDONLY, S_IRWXU), -1); + EXPECT_EQ(errno, ENOTDIR); + + EXPECT_EQ(close(file_fd), 0); + EXPECT_EQ(unlinkat(self->dfd, "file", 0), 0); +} + +/* + * O_EXCL together with O_CREAT|O_DIRECTORY should succeed if the target + * directory does not yet exist. After directory creation, repeating this + * call must fail with EEXIST. + */ +TEST_F(open_o_creat_o_dir, o_excl_eexist) +{ + int excldir_fd; + + excldir_fd =3D openat_o_mkdir_checked_flags(self->dfd, "excldir", O_EXCL); + + EXPECT_EQ(openat_o_mkdir(excldir_fd, ".", O_EXCL, S_IRWXU), -1); + EXPECT_EQ(errno, EEXIST); + + EXPECT_EQ(close(excldir_fd), 0); + EXPECT_EQ(unlinkat(self->dfd, "excldir", AT_REMOVEDIR), 0); +} + +/* + * O_CREAT|O_DIRECTORY on a path that already exists as a regular file + * must fail with ENOTDIR. + */ +TEST_F(open_o_creat_o_dir, existing_file_enotdir) +{ + int file_fd; + + file_fd =3D openat(self->dfd, "regfile", + O_CREAT | O_RDONLY, S_IRWXU); + ASSERT_GE(file_fd, 0); + EXPECT_EQ(close(file_fd), 0); + + EXPECT_EQ(openat_o_mkdir(self->dfd, "regfile", O_RDONLY, S_IRWXU), -1); + EXPECT_EQ(errno, ENOTDIR); + + EXPECT_EQ(unlinkat(self->dfd, "regfile", 0), 0); +} + +/* + * O_CREAT|O_DIRECTORY combined with a writable access mode must be + * rejected: a directory cannot be opened for writing. + */ +TEST_F(open_o_creat_o_dir, rejects_writable_acc_mode) +{ + EXPECT_EQ(openat_o_mkdir(self->dfd, "rdwrdir", O_RDWR, S_IRWXU), -1); + EXPECT_EQ(errno, ENOTDIR); + /* Clean up if the kernel created the directory anyway. */ + unlinkat(self->dfd, "rdwrdir", AT_REMOVEDIR); +} + +/* + * openat(O_CREAT|O_DIRECTORY) with a trailing slash should work. + */ +TEST_F(open_o_creat_o_dir, trailing_slash) +{ + int fd =3D openat_o_mkdir_checked(self->dfd, "newdir/"); + EXPECT_EQ(close(fd), 0); + EXPECT_EQ(unlinkat(self->dfd, "newdir", AT_REMOVEDIR), 0); +} + +/* + * openat(O_CREAT) with a trailing slash but without O_DIRECTORY + * must fail with EISDIR and must not create anything at the path. + */ +TEST_F(open_o_creat_o_dir, trailing_slash_no_o_dir) +{ + int fd; + struct stat st; + + fd =3D openat(self->dfd, "trailing/", O_CREAT | O_RDONLY, S_IRWXU); + EXPECT_EQ(fd, -1); + EXPECT_EQ(errno, EISDIR); + + EXPECT_EQ(fstatat(self->dfd, "trailing", &st, 0), -1); + EXPECT_EQ(errno, ENOENT); + + /* Best-effort cleanup in case the kernel left a file behind. */ + if (fd >=3D 0) + close(fd); + unlinkat(self->dfd, "trailing", 0); +} + +/* + * The returned fd must be usable as a dfd for further *at() calls. + */ +TEST_F(open_o_creat_o_dir, fd_usable_as_dfd) +{ + int parent_fd, child_fd; + char path[PATH_MAX]; + + parent_fd =3D openat_o_mkdir_checked(self->dfd, "parent"); + child_fd =3D openat_o_mkdir_checked(parent_fd, "child"); + + EXPECT_EQ(close(child_fd), 0); + EXPECT_EQ(close(parent_fd), 0); + + snprintf(path, sizeof(path), "%s/parent/child", self->dirpath); + EXPECT_EQ(rmdir(path), 0); + snprintf(path, sizeof(path), "%s/parent", self->dirpath); + EXPECT_EQ(rmdir(path), 0); +} + +TEST_HARNESS_MAIN diff --git a/tools/testing/selftests/filesystems/wrappers.h b/tools/testing= /selftests/filesystems/wrappers.h index 420ae4f908cf..abe5b85cebdc 100644 --- a/tools/testing/selftests/filesystems/wrappers.h +++ b/tools/testing/selftests/filesystems/wrappers.h @@ -13,6 +13,10 @@ #define STATX_MNT_ID_UNIQUE 0x00004000U /* Want/got extended stx_mount_id = */ #endif =20 +#ifndef FD_INVALID +#define FD_INVALID -10009 +#endif + static inline int sys_fsopen(const char *fsname, unsigned int flags) { return syscall(__NR_fsopen, fsname, flags); @@ -105,4 +109,11 @@ static inline int sys_open_tree(int dfd, const char *f= ilename, unsigned int flag return syscall(__NR_open_tree, dfd, filename, flags); } =20 +static inline int openat_o_mkdir(int dfd, const char *pathname, + unsigned int flags, mode_t mode) +{ + return syscall(__NR_openat, dfd, pathname, + flags | O_DIRECTORY | O_CREAT, mode); +} + #endif --=20 2.55.0