[PATCH v3 0/4] pidfd: add task path ioctls
flat view
WARM1d
From: Chen Linxuan via B4 Relay <devnull+me.black-desk.cn@kernel.org>
Date: 2026-10-10 10:21:20
Also in:
b4-sent, linux-fsdevel, linux-mm, linux-security-module, lkml
Revision v3 of 2 in this series.
Revisions (2)
- v2 [diff vs current]
- v3 current
Obtaining a target task's executable, working directory, or root currently requires walking procfs symlinks such as /proc/<pid>/exe, /proc/<pid>/cwd, and /proc/<pid>/root. That makes the operation depend on procfs being mounted and visible to the caller, even when it already holds a pidfd for the target. This series adds PIDFD_GET_EXE, PIDFD_GET_CWD, and PIDFD_GET_ROOT. Each ioctl takes no argument and returns a close-on-exec O_PATH file descriptor referencing the corresponding task path. The new ioctls use the same ptrace permission check and nonzero-argument rejection as the existing pidfd namespace ioctls. The target task is sampled while holding its exec_update_lock. This keeps the access decision and the task-state read in the same exec critical section, preventing a concurrent execve() from changing the credentials or target state between the check and the use. Since pidfds can cross pid namespace boundaries, the first patch restricts the existing namespace ioctls to targets visible in the caller's active pid namespace, failing with -EREMOTE like PIDFD_GET_INFO. The second patch factors out helpers for acquiring referenced task paths and reuses them in procfs and AppArmor. The third patch introduces scoped cleanup for privileged pidfd task access, carries the visibility check into the shared task acquisition helper, and separates namespace lookup from namespace fd creation. The final patch uses these pieces to implement the three new ioctls. --- Changes in v3: - Restrict the pidfd task access ioctls to targets visible in the caller's pid namespace, failing with -EREMOTE consistent with PIDFD_GET_INFO, following review feedback from Jann Horn and Christian Brauner. - Document that get_task_exe_path() leaves the output path unchanged on failure, as suggested by Jann Horn. - Link to v2: https://patch.msgid.link/20260831-pidfd-get-paths-v2-0-c59ea6a21b72@black-desk.cn (local) Changes in v2: - Make pidfd_get_task_locked() own the task reference until it is transferred to the pidfd_task_locked cleanup class. - Link to v1: https://patch.msgid.link/20260820-pidfd-get-paths-v1-0-ac3eee4003d5@black-desk.cn (local) To: Alexander Viro <viro@zeniv.linux.org.uk> To: Christian Brauner <brauner@kernel.org> To: Jan Kara <jack@suse.cz> To: Andrew Morton <akpm@linux-foundation.org> To: David Hildenbrand <david@kernel.org> To: Lorenzo Stoakes <ljs@kernel.org> To: "Liam R. Howlett" <liam@infradead.org> To: Vlastimil Babka <vbabka@kernel.org> To: Mike Rapoport <rppt@kernel.org> To: Suren Baghdasaryan <surenb@google.com> To: Michal Hocko <mhocko@suse.com> To: Ingo Molnar <mingo@redhat.com> To: Peter Zijlstra <peterz@infradead.org> To: Juri Lelli <juri.lelli@redhat.com> To: Vincent Guittot <vincent.guittot@linaro.org> To: Dietmar Eggemann <dietmar.eggemann@arm.com> To: Steven Rostedt <rostedt@goodmis.org> To: Ben Segall <bsegall@google.com> To: Mel Gorman <mgorman@suse.de> To: Valentin Schneider <vschneid@redhat.com> To: K Prateek Nayak <kprateek.nayak@amd.com> To: Kees Cook <kees@kernel.org> To: John Johansen <john.johansen@canonical.com> To: Georgia Garcia <georgia.garcia@canonical.com> To: Paul Moore <paul@paul-moore.com> To: James Morris <jmorris@namei.org> To: "Serge E. Hallyn" <serge@hallyn.com> To: Jann Horn <jannh@google.com> Cc: linux-fsdevel@vger.kernel.org Cc: linux-kernel@vger.kernel.org Cc: linux-mm@kvack.org Cc: apparmor@lists.ubuntu.com Cc: linux-security-module@vger.kernel.org Cc: linux-api@vger.kernel.org --- Chen Linxuan (4): pidfd: restrict task access ioctls to the caller's pid namespace fs: Introduce task path helpers pidfd: Use scoped cleanup for task access pidfd: Add task path ioctls fs/fs_struct.c | 44 +++++++++++++ fs/pidfs.c | 158 +++++++++++++++++++++++++++++++++------------ fs/proc/base.c | 34 +--------- include/linux/fs_struct.h | 3 + include/linux/mm.h | 1 + include/uapi/linux/pidfd.h | 7 ++ kernel/fork.c | 22 +++++++ security/apparmor/task.c | 12 +--- 8 files changed, 198 insertions(+), 83 deletions(-) --- base-commit: cee9395acd8043be0644b25c34bfa86623f2b935 change-id: 20260819-pidfd-get-paths-59640d8cd1ee Best regards, -- Chen Linxuan [off-list ref]