Thread (11 messages) 11 messages, 3 authors, 27d ago

Re: [RFC] connectat()/bindat() or an alternative design

From: John Ericson <hidden>
Date: 2026-06-30 20:22:48
Also in: linux-fsdevel

I'm bumping this and adding new recipients again in light of the
discussion happening elsewhere in
<https://lore.kernel.org/all/a49ce818-f38d-41b0-bbf7-80b8aad998b1@app.fastmail.com/ (local)>.
I don't want to count my chickens before they are hatched, but it is
looking to me like a consensus in that thread is building around the
ability to opt into intentionally empty/unusable root and working
directories (at least with nullfs, maybe but less likely with other
mechanisms instead).

That new functionality concretizes the motivation for what I am
proposing in this thread: in such a world, there is little to no point
binding listening sockets in the file system, because the containing
directory would have to be conveyed by file descriptor anyways --- might
as well just directly convey the socket to connect to by file
descriptor. Likewise, abstract sockets are not appealing, because the
abstract socket namespace is either too coarse-grained (leaking info in
the same way root/cwd would), or too cumbersome to keep it from leaking.

To recap (with some slight changes, like renames), my latest proposal (a
new version, not either of the two variations in the original email) is
new syscalls `bind_unix_anon` and `connectat`, supporting a workflow
like this:

    /* server */
    int lfd = socket(AF_UNIX, SOCK_STREAM | SOCK_CLOEXEC, 0);
    int addrfd = bind_unix_anon(
            lfd,
            /*flags, for the future*/0);
    listen(lfd, 64);

    /* client, handed `addrfd` */
    int cfd = socket(AF_UNIX, SOCK_STREAM | SOCK_CLOEXEC, 0);
    connectat(addrfd, cfd, AT_EMPTY_PATH);

Or, more radically, `bind_unix_anon` and `connectat` could let one skip
the initial `socket` calls by returning those new sockets directly:

    /* server */
    int fds[2];
    bind_unix_anon(
            SOCK_STREAM | SOCK_CLOEXEC,
            /*flags, for the future*/0,
            fds);
    int lfd = fds[0], addrfd = fds[1];
    listen(lfd, 64);

    /* client, handed `addrfd` */
    int cfd = connectat(
            addrfd,
            SOCK_STREAM | SOCK_CLOEXEC,
            AT_EMPTY_PATH);

(Note that in this variation `bind_unix_anon` would return *two* file
descriptors: one for the server, with the permission to listen, and the
other for clients, with just the privilege to `connectat`.) (Maybe
`bind_unix_anon` should furthermore `listen` right away on `lfd` too?)

Of course, it would be nice to have io_uring versions of these too. But
I don't know what the usual process is for that (regular first? io_uring
first? both at the same time?)

Thanks,

John

P.S. For anyone just getting CC'd now, the first message in this thread
is
<https://lore.kernel.org/all/b1af80fc-a57c-408d-bdfe-fa6bae26eaca@app.fastmail.com/ (local)>.
Hope that might save people a few keypresses :).
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help