propagate_umount(): only surviving overmounts should be reparented
authorAl Viro <viro@zeniv.linux.org.uk>
Fri, 15 Aug 2025 03:32:26 +0000 (23:32 -0400)
committerAl Viro <viro@zeniv.linux.org.uk>
Tue, 19 Aug 2025 16:00:07 +0000 (12:00 -0400)
commitda025cdb97a23c1916d8491925b878f3e1de0bca
tree63cec32b7b9a1211bc67df47e6837f556fc87828
parent0ddfb62f5d018edcb571a3d8ea30ad5332cf2a69
propagate_umount(): only surviving overmounts should be reparented

... as the comments in reparent() clearly say.  As it is, we reparent
*all* overmounts of the mounts being taken out, including those that
are taken out themselves.  It's not only a potentially massive slowdown
(on a pathological setup we might end up with O(N^2) time for N mounts
being kicked out), it can end up with incorrect ->overmount in the
surviving mounts.

Fixes: f0d0ba19985d "Rewrite of propagate_umount()"
Reviewed-by: Christian Brauner <brauner@kernel.org>
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
fs/pnode.c