[PATCH v6 00/12] vfs: add O_CREAT|O_DIRECTORY to open*(2)

From: Jori Koolstra

Date: Sun Sep 13 2026 - 14:49:25 EST


Hi Christian/Neil,

Finally got back from holiday. I know Neil is also attempting to make
changes to the same code paths as the O_CREAT|O_DIRECTORY series touch,
so I hope, now that I have a bit more time, that I can push this
forwards before I have to do more rebasing.

This series implements new semantics for the O_CREAT|O_DIRECTORY flag
combination for open*(2): perform a mkdir and open the resulting
directory; return a pinning fd (which mkdir does not).

Most of the work happens in "vfs: add O_CREAT|O_DIRECTORY to open*(2),"
as may be expected. Before that there is some clean-up work and
preparation. The "vfs: short-circuit MAY_WRITE access for O_DIRECTORY
opens" patch is also worth paying extra attention to as it
short-circuits doomed opening of directories as writable. This check (to
prevent one from opening directories as writable) is currently done very
late in do_open(), after an inode has been obtained. However, when
introducing O_CREAT|O_DIRECTORY this is unacceptable as it would create
the directory and then still fail. This patch does however change some
user visible error codes.

Moreover, "vfs: change ->create/->mkdir operations unavailable errno"
also changes the ->create and ->mkdir unavailable errnos to -EOPNOTSUPP.
A previous attempt to do this more widely stranded before.[1] However,
that regression was only for vfat and does seem specific to changing the
return code from vfs_symlink(). We can drop this patch if needed, but it
would be _really_ ugly.

Changes from vn to v(n+1):
v5: https://lore.kernel.org/linux-fsdevel/20260823160706.358293-1-jkoolstra@xxxxxxxxx/
- Uniformize ->create and ->mkdir unavailable errnos to -EOPNOTSUPP.
- Return -EOPNOTSUPP instead of -ENOENT when O_CREAT|O_DIRECTORY is
not supported by a ->atomic_open filesystem.
- Added test cases for dangling symlink and sticky directory
behaviour, and a test that verifies O_TMPFILE|O_CREAT is still
-EINVAL.
- Split off "vfs: lookup_open(): lock the parent as I_MUTEX_PARENT"
as a separate patch.
- Fixed the issues pointed out by Brauner in v5.
v4: https://lore.kernel.org/linux-fsdevel/20260712175539.1565444-1-jkoolstra@xxxxxxxxx/
- rebased on 7.2, which includes my changes to auditing in
lookup_open() as well as Neil Brown's changes to the same function
for the implementation of vfs_lookup_open().
v3: https://lore.kernel.org/linux-fsdevel/20260704164149.3480051-1-jkoolstra@xxxxxxxxx/
- address the inconsistency in calling audit_inode_child() in
lookup_open() versus vfs_create() in a separate series.
- fclog.c selftest header fix moved to separate patch.
- add a "with trailing slash test" success test to the included
selftests.
- pass struct qstr by pointer to trailing_slashes() and add a comment
on what it does
- changed commit message of "vfs: add O_CREAT|O_DIRECTORY to
open*(2)" to address comments of Brauner

[1]: https://lore.kernel.org/linux-fsdevel/90228c39-04e7-41ef-ad91-84a8bb866650@xxxxxxxxxxxxx/

Jori Koolstra (12):
fs/namei.c: use trailing_slashes()
vfs: prepare vfs_creat|mkdir_no_perm for reuse in lookup_open()
vfs: lookup_open(): move setting FMODE_CREATED down
vfs: move ->create check in lookup_open() to before try_break_deleg()
vfs: lookup_open(): use vfs_create_no_perm()
vfs: lookup_open(): lock the parent as I_MUTEX_PARENT
vfs: add O_CREAT|O_DIRECTORY to open*(2)
vfs: change ->create/->mkdir operations unavailable errno
vfs: move O_IS_MKDIR check from lookup_open() into individual
filesystems
vfs: refuse O_CREAT for directories through a dangling symlink
vfs: short-circuit MAY_WRITE access for O_DIRECTORY opens
selftest: add tests for open*(O_CREAT|O_DIRECTORY)

fs/9p/vfs_inode.c | 5 +
fs/9p/vfs_inode_dotl.c | 5 +
fs/ceph/file.c | 5 +
fs/fuse/dir.c | 5 +
fs/gfs2/inode.c | 5 +
fs/namei.c | 247 ++++++++++-----
fs/nfs/dir.c | 10 +
fs/open.c | 32 +-
fs/smb/client/dir.c | 5 +
fs/vboxsf/dir.c | 5 +
include/linux/fcntl.h | 6 +
include/uapi/asm-generic/errno.h | 2 +-
.../testing/selftests/filesystems/.gitignore | 1 +
tools/testing/selftests/filesystems/Makefile | 2 +-
.../filesystems/open_o_creat_o_dir.c | 296 ++++++++++++++++++
.../testing/selftests/filesystems/wrappers.h | 11 +
16 files changed, 554 insertions(+), 88 deletions(-)
create mode 100644 tools/testing/selftests/filesystems/open_o_creat_o_dir.c


base-commit: 2f0c1cf72f4682178506f513bbf015e591b1aa4a
--
2.55.0