From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f177.google.com (mail-pf1-f177.google.com [209.85.210.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8C7603D6D for ; Wed, 8 May 2024 17:11:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.177 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1715188299; cv=none; b=ELxBrYrG5ZTX8lPOZ5C47/u9dziqxVk7zRErGcdyXdOigrAXY2GnuX426j5wrMpqMm+LM1K1fkg93IpDLvU4/8HYTHOvuow/NYY0Bfg+SGEDbdZugRSqnBqOrlJ+rlio6pbvdoZYV1X8YPJsgYK6RdJ1ksbOWZiwWPxeWQ968Ag= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1715188299; c=relaxed/simple; bh=3H2Ex21607oQUraLy4a6ZebeomrW6qImqDFNkYN7KH4=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=CyUkGA+k8uBlK2Wg6KjqCe9VrNZKRZXiXkyf7yc9Uza8afhAYCuEWYYJtWrpsNpPL/pgSUHy1nYWPf1ok8T1f9f1XxrPrvWtitl0UN/wBzQaVp02XEqqRX1DY86WEnX7cryrX8ZASh+nQ3C/WiFdRNivKEbcHM7jp8K7HnBDDSk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=chromium.org; spf=pass smtp.mailfrom=chromium.org; dkim=pass (1024-bit key) header.d=chromium.org header.i=@chromium.org header.b=e/7av/64; arc=none smtp.client-ip=209.85.210.177 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=chromium.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=chromium.org Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=chromium.org header.i=@chromium.org header.b="e/7av/64" Received: by mail-pf1-f177.google.com with SMTP id d2e1a72fcca58-6f44b296e02so8766b3a.2 for ; Wed, 08 May 2024 10:11:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; t=1715188297; x=1715793097; darn=vger.kernel.org; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date:from:to :cc:subject:date:message-id:reply-to; bh=tSmrj41Qt+Se2fdGi7WeozvVj6AfH//AS3pb2zkquGg=; b=e/7av/64Dcgf3OMhlc/3aG68Cv9i0FKAXx1yap6cSbdW0nsJbcNd95Yo1lRWM4CXEO StJJA023SDun4hdxa5p+ZL91TWCTjhJqbT/I8537Y89y8wwXzIEuISflNf2v2IqVxAlb rwDXFcNsSy0ds4FxqMQiDgXwqp7u78CH/UbW0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1715188297; x=1715793097; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=tSmrj41Qt+Se2fdGi7WeozvVj6AfH//AS3pb2zkquGg=; b=s2Mlem06navbpndkDYEt7duIZKFKsy6z965eJgq5YYdzc7TS9+/SVi9Ed0DessnJaC MaH+vsvHZCIdeACATjhP4pQxaZU4h3MHRAWfsAv9O2BPdL2Ap5aN2cFqdB8fAAhISxuh j7PgfivQPjW/mPFpI/2Xs1ldgz8aKQ57W823aSQf0no1/wOmljd8sRaYVyqp4TLRQJk4 47xeeo3ixr9VN/wgaY8Ae6lm1ml9V2u7XOyVjWSv9gMDZ1gfLa8RXx52vn6OZy5ATRVk Y8X5d1Md7HFbDJRql/4qg3cumJVCfIyeetiEKvghzy9AoXvT1aOaxq34X9HgWr5vDkZp wltA== X-Forwarded-Encrypted: i=1; AJvYcCVgvfA9srKN076ob+zPdkuV7CEE4ntMAXI0QFv2cXVkL0UOzoaBl5pJbr8ApbMCL/dZs00S6XpjGxPH04nFWOd8frzm X-Gm-Message-State: AOJu0YzceyqXKOn3Z3O0Bfe962clRQ+ZtlXIZAGv9jKFz3wgDfPGxxg9 GU8ucGvjPj7QrRRVSYUkR9W56EMnSZ3SwjoyZkG7Xs0N+NNaUnZSuultjeuGbw== X-Google-Smtp-Source: AGHT+IHN8eeXE9OsgItxEKHR70nrrazwBAjav29jEzJB0wGGmdP+iVlP1VjtMYRBUjqpRzzzPBgYhQ== X-Received: by 2002:a05:6a20:c88b:b0:1a5:6a85:8ce9 with SMTP id adf61e73a8af0-1afc8d1b02amr3543639637.12.1715188296881; Wed, 08 May 2024 10:11:36 -0700 (PDT) Received: from www.outflux.net ([198.0.35.241]) by smtp.gmail.com with ESMTPSA id lp9-20020a056a003d4900b006f44ed124dfsm9245352pfb.160.2024.05.08.10.11.36 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 08 May 2024 10:11:36 -0700 (PDT) Date: Wed, 8 May 2024 10:11:35 -0700 From: Kees Cook To: Jakub Kicinski Cc: Thomas =?iso-8859-1?Q?Wei=DFschuh?= , Luis Chamberlain , Joel Granados , Eric Dumazet , Dave Chinner , linux-fsdevel@vger.kernel.org, netdev@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, linux-riscv@lists.infradead.org, linux-mm@kvack.org, linux-security-module@vger.kernel.org, bpf@vger.kernel.org, linuxppc-dev@lists.ozlabs.org, linux-xfs@vger.kernel.org, linux-trace-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, netfilter-devel@vger.kernel.org, coreteam@netfilter.org, kexec@lists.infradead.org, linux-hardening@vger.kernel.org, bridge@lists.linux.dev, lvs-devel@vger.kernel.org, linux-rdma@vger.kernel.org, rds-devel@oss.oracle.com, linux-sctp@vger.kernel.org, linux-nfs@vger.kernel.org, apparmor@lists.ubuntu.com Subject: Re: [PATCH v3 00/11] sysctl: treewide: constify ctl_table argument of sysctl handlers Message-ID: <202405080959.104A73A914@keescook> References: <20240423-sysctl-const-handler-v3-0-e0beccb836e2@weissschuh.net> <20240424201234.3cc2b509@kernel.org> Precedence: bulk X-Mailing-List: bpf@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <20240424201234.3cc2b509@kernel.org> On Wed, Apr 24, 2024 at 08:12:34PM -0700, Jakub Kicinski wrote: > On Tue, 23 Apr 2024 09:54:35 +0200 Thomas Weißschuh wrote: > > The series was split from my larger series sysctl-const series [0]. > > It only focusses on the proc_handlers but is an important step to be > > able to move all static definitions of ctl_table into .rodata. > > Split this per subsystem, please. I've done a few painful API transitions before, and I don't think the complexity of these changes needs a per-subsystem constification pass. I think this series is the right approach, but that patch 11 will need coordination with Linus. We regularly do system-wide prototype changes like this right at the end of the merge window before -rc1 comes out. The requirements are pretty simple: it needs to be a obvious changes (this certainly is) and as close to 100% mechanical as possible. I think patch 11 easily qualifies. Linus should be able to run the same Coccinelle script and get nearly the same results, etc. And all the other changes need to have landed. This change also has no "silent failure" conditions: anything mismatched will immediately stand out. So, have patches 1-10 go via their respective subsystems, and once all of those are in Linus's tree, send patch 11 as a stand-alone PR. (From patch 11, it looks like the seccomp read/write function changes could be split out? I'll do that now...) -Kees -- Kees Cook From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 3BF2AC04FFE for ; Wed, 8 May 2024 17:11:48 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:In-Reply-To:MIME-Version:References: Message-ID:Subject:Cc:To:From:Date:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=cIb4SNT51huMACfY3tMQ8U+zfhvHkRwL7d2a7k7ZBh8=; b=UqXMEkUR10b1Z6 Kr0VL6kVOYQj1YQISrDq6h5w1XRtM896vvH+UJJOGqOvfdmiOQNN7lHLYg05HxM2QYvqYOe2ErJoA ICEc5aPZSOZ3Fwt+Kz/TwmdENo+C+vgL6oBtIbpiRFD08aSdfasnPgMs8pWR1HoWrmABNA/iGEP1N gYKKlzhNCHLGYH6sEX/wc6Zb0SuoFGRpe9zYbcUaqniOJEgC8a9KBAUDqqSk3/y0rwLxDDgiE28jD 1m9Uo/3Z4Rb3Fv0sn5QXPzi6f2jZ4OZWzchoxkIEXXZnJXsjeBrxiGGqiGHObrKaxXB1aAkNMnZqP ubU95CX2f3pUHhFqbgxg==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.97.1 #2 (Red Hat Linux)) id 1s4kpX-0000000GJ1w-1Q3X; Wed, 08 May 2024 17:11:47 +0000 Received: from mail-pf1-x434.google.com ([2607:f8b0:4864:20::434]) by bombadil.infradead.org with esmtps (Exim 4.97.1 #2 (Red Hat Linux)) id 1s4kpQ-0000000GIzW-0kW1 for kexec@lists.infradead.org; Wed, 08 May 2024 17:11:42 +0000 Received: by mail-pf1-x434.google.com with SMTP id d2e1a72fcca58-6f45f1179c3so8623b3a.3 for ; Wed, 08 May 2024 10:11:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; t=1715188297; x=1715793097; darn=lists.infradead.org; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date:from:to :cc:subject:date:message-id:reply-to; bh=tSmrj41Qt+Se2fdGi7WeozvVj6AfH//AS3pb2zkquGg=; b=P1/Vk1ftAPZ/JGfIcL46RAevnIIRS6UDYW9YJ/cxP+SM2aHbg3EVccS5TsIPCAw3ay KrUP/+WSLA1KgcJppL/dLuokLaHqc3yLoAfkhLvX92l4rouz/CBAeopVjE09FSWWhHjD uARbGkNXgEPUaBgPfItz+UMFQ109Ypyeax0n8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1715188297; x=1715793097; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=tSmrj41Qt+Se2fdGi7WeozvVj6AfH//AS3pb2zkquGg=; b=iTJglCeWauDbetih9x39VcPryJWzdXPYp4NmLGsIEGBWasJszJZogOLL3rnVHS20NM 8Scwmh1zsEsdnxQt/xs6kEyv4ot4NNk4QjB3Xd/GTDg0UC+k0U2eIWEo39AHWb4i9M5I suUDyi+XFYoqFsJ1yLTlHWPJ3hprjyAXHnWEU4mvaS/AzlZG6ABLRmZgWMtdhcAPfd34 RXyCqbS3cb0rGUZ/ZNL4JJ4ERDPxgp81bS5vM9eCWGz7lV49KFtSdRczo5Yzajejqyr2 AbDHhDGO2iUGZke3gt85Rvqve6wqbxUUA58jSFUR4yYPX1ZXkE7cl6smyJBwKiJsfaq0 0uUg== X-Forwarded-Encrypted: i=1; AJvYcCWcCxshPg5vblkV0LNb7DC1RzufGbBrQYmLtQ0AM8YxwgtC95WF14q5KnM95nDl/ZMggIlfR9/Cz8lyVYQlCfBf4sbtjlKCB6Nk X-Gm-Message-State: AOJu0YzOGhpfnMKs/W4HKnHk33YZsYcVdkcyUxJ0eQFduaPGiF68ZpBE BO4uKnbY6NR1+6igfhHc48F9d3AkKMQbSx0QTMQJoGB2NIS0z9kANdhauR2hZw== X-Google-Smtp-Source: AGHT+IHN8eeXE9OsgItxEKHR70nrrazwBAjav29jEzJB0wGGmdP+iVlP1VjtMYRBUjqpRzzzPBgYhQ== X-Received: by 2002:a05:6a20:c88b:b0:1a5:6a85:8ce9 with SMTP id adf61e73a8af0-1afc8d1b02amr3543639637.12.1715188296881; Wed, 08 May 2024 10:11:36 -0700 (PDT) Received: from www.outflux.net ([198.0.35.241]) by smtp.gmail.com with ESMTPSA id lp9-20020a056a003d4900b006f44ed124dfsm9245352pfb.160.2024.05.08.10.11.36 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 08 May 2024 10:11:36 -0700 (PDT) Date: Wed, 8 May 2024 10:11:35 -0700 From: Kees Cook To: Jakub Kicinski Cc: Thomas =?iso-8859-1?Q?Wei=DFschuh?= , Luis Chamberlain , Joel Granados , Eric Dumazet , Dave Chinner , linux-fsdevel@vger.kernel.org, netdev@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, linux-riscv@lists.infradead.org, linux-mm@kvack.org, linux-security-module@vger.kernel.org, bpf@vger.kernel.org, linuxppc-dev@lists.ozlabs.org, linux-xfs@vger.kernel.org, linux-trace-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, netfilter-devel@vger.kernel.org, coreteam@netfilter.org, kexec@lists.infradead.org, linux-hardening@vger.kernel.org, bridge@lists.linux.dev, lvs-devel@vger.kernel.org, linux-rdma@vger.kernel.org, rds-devel@oss.oracle.com, linux-sctp@vger.kernel.org, linux-nfs@vger.kernel.org, apparmor@lists.ubuntu.com Subject: Re: [PATCH v3 00/11] sysctl: treewide: constify ctl_table argument of sysctl handlers Message-ID: <202405080959.104A73A914@keescook> References: <20240423-sysctl-const-handler-v3-0-e0beccb836e2@weissschuh.net> <20240424201234.3cc2b509@kernel.org> MIME-Version: 1.0 Content-Disposition: inline In-Reply-To: <20240424201234.3cc2b509@kernel.org> X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20240508_101140_234502_23162D8D X-CRM114-Status: GOOD ( 15.52 ) X-BeenThere: kexec@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Sender: "kexec" Errors-To: kexec-bounces+kexec=archiver.kernel.org@lists.infradead.org On Wed, Apr 24, 2024 at 08:12:34PM -0700, Jakub Kicinski wrote: > On Tue, 23 Apr 2024 09:54:35 +0200 Thomas Wei=DFschuh wrote: > > The series was split from my larger series sysctl-const series [0]. > > It only focusses on the proc_handlers but is an important step to be > > able to move all static definitions of ctl_table into .rodata. > = > Split this per subsystem, please. I've done a few painful API transitions before, and I don't think the complexity of these changes needs a per-subsystem constification pass. I think this series is the right approach, but that patch 11 will need coordination with Linus. We regularly do system-wide prototype changes like this right at the end of the merge window before -rc1 comes out. The requirements are pretty simple: it needs to be a obvious changes (this certainly is) and as close to 100% mechanical as possible. I think patch 11 easily qualifies. Linus should be able to run the same Coccinelle script and get nearly the same results, etc. And all the other changes need to have landed. This change also has no "silent failure" conditions: anything mismatched will immediately stand out. So, have patches 1-10 go via their respective subsystems, and once all of those are in Linus's tree, send patch 11 as a stand-alone PR. (From patch 11, it looks like the seccomp read/write function changes could be split out? I'll do that now...) -Kees -- = Kees Cook _______________________________________________ kexec mailing list kexec@lists.infradead.org http://lists.infradead.org/mailman/listinfo/kexec From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id EBC82C25B4F for ; Wed, 8 May 2024 17:11:48 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:In-Reply-To:MIME-Version:References: Message-ID:Subject:Cc:To:From:Date:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=QhiZqIo4G5icb1NYQ0fJndE6qev3D3LjDLI2nPE0Ex8=; b=rD1a79NwEMTZ36 O4DbKsuxo66shnvM/sFx2O9B6LbX4W483VQEcMbA9YUuPpoF3yiwS3StIImqI4WRtv0iTQWwi1L+L /7K6m5DzDyoIkRcpW2/LxYSaU6hAJSB1MnZnxaDGZJtd3Ma7JkrxX6aY34WqGZnCy0C9FbcmI5Qz+ HPDbDXkiYueSJsoBn43SKd7Y/8hJ2kwuidkIQ6AkzmRpAFcK9l/GsQHyLWKcE8rkS4kCWq2tzDtOy 9BN7LbAXHbCIZOSRa2Kg8yK7gd63lASYde0rgCVQxsdeS/y80dDKX0btSri/URZ8LpoA4PpEWWY3/ skT0ggn53SPgWnQ59ndA==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.97.1 #2 (Red Hat Linux)) id 1s4kpU-0000000GJ1i-0CTc; Wed, 08 May 2024 17:11:44 +0000 Received: from mail-pf1-x435.google.com ([2607:f8b0:4864:20::435]) by bombadil.infradead.org with esmtps (Exim 4.97.1 #2 (Red Hat Linux)) id 1s4kpQ-0000000GIzX-0kf2 for linux-riscv@lists.infradead.org; Wed, 08 May 2024 17:11:42 +0000 Received: by mail-pf1-x435.google.com with SMTP id d2e1a72fcca58-6f45f1179c3so8624b3a.3 for ; Wed, 08 May 2024 10:11:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; t=1715188297; x=1715793097; darn=lists.infradead.org; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date:from:to :cc:subject:date:message-id:reply-to; bh=tSmrj41Qt+Se2fdGi7WeozvVj6AfH//AS3pb2zkquGg=; b=P1/Vk1ftAPZ/JGfIcL46RAevnIIRS6UDYW9YJ/cxP+SM2aHbg3EVccS5TsIPCAw3ay KrUP/+WSLA1KgcJppL/dLuokLaHqc3yLoAfkhLvX92l4rouz/CBAeopVjE09FSWWhHjD uARbGkNXgEPUaBgPfItz+UMFQ109Ypyeax0n8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1715188297; x=1715793097; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=tSmrj41Qt+Se2fdGi7WeozvVj6AfH//AS3pb2zkquGg=; b=KSEBzxSVx/L9ct18SNbx5wiNEVW0sx6U48dSq0N97nbdsJnXIY0KJCvx1QG8gWGRhF wVqMXfm+4a3oHVhVmODXHhiJhgBAEhSSb6lhXT8rPQg58TrS486rB6LtyGM/9DPcK8g7 8yjTYc7HV6eysaiP17z+KWaoJvvFVySJKr3T1XJghfPQs1R02ZPw0CHZz6z+0vFiigSN sX+QKDmhnHwwfkSvsErZ3m3ML6jwILbsvursgdfbBEuG7jFAmttSG1GoeoG9MasA+449 kdNVdYArUMvUOKy9hNQofclQLrYsTSPiM3yNdDwQJMzXp206ER6L5GEVSDsq60qKIuxH M5ew== X-Forwarded-Encrypted: i=1; AJvYcCVmtwUuwgPpgCTl/5dl/i5SmCciv/nmjCCls28b9M710xuDwGy9xwIByMWuxRzaAbq90MGzYAVkcqVwub34wkqNeTQzznWXIdo9SijLFNw3 X-Gm-Message-State: AOJu0YzwBnjenlOdrGHlZZO36hjRRCeisqjf0WbQV3P0Or0JgQiSdA9n Wmlv43eOLe5cN5C7GTnP9C+wypBqaF+Rq8M2jO4Yhc9sh8UrvO+XXO38Y6jpwA== X-Google-Smtp-Source: AGHT+IHN8eeXE9OsgItxEKHR70nrrazwBAjav29jEzJB0wGGmdP+iVlP1VjtMYRBUjqpRzzzPBgYhQ== X-Received: by 2002:a05:6a20:c88b:b0:1a5:6a85:8ce9 with SMTP id adf61e73a8af0-1afc8d1b02amr3543639637.12.1715188296881; Wed, 08 May 2024 10:11:36 -0700 (PDT) Received: from www.outflux.net ([198.0.35.241]) by smtp.gmail.com with ESMTPSA id lp9-20020a056a003d4900b006f44ed124dfsm9245352pfb.160.2024.05.08.10.11.36 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 08 May 2024 10:11:36 -0700 (PDT) Date: Wed, 8 May 2024 10:11:35 -0700 From: Kees Cook To: Jakub Kicinski Cc: Thomas =?iso-8859-1?Q?Wei=DFschuh?= , Luis Chamberlain , Joel Granados , Eric Dumazet , Dave Chinner , linux-fsdevel@vger.kernel.org, netdev@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, linux-riscv@lists.infradead.org, linux-mm@kvack.org, linux-security-module@vger.kernel.org, bpf@vger.kernel.org, linuxppc-dev@lists.ozlabs.org, linux-xfs@vger.kernel.org, linux-trace-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, netfilter-devel@vger.kernel.org, coreteam@netfilter.org, kexec@lists.infradead.org, linux-hardening@vger.kernel.org, bridge@lists.linux.dev, lvs-devel@vger.kernel.org, linux-rdma@vger.kernel.org, rds-devel@oss.oracle.com, linux-sctp@vger.kernel.org, linux-nfs@vger.kernel.org, apparmor@lists.ubuntu.com Subject: Re: [PATCH v3 00/11] sysctl: treewide: constify ctl_table argument of sysctl handlers Message-ID: <202405080959.104A73A914@keescook> References: <20240423-sysctl-const-handler-v3-0-e0beccb836e2@weissschuh.net> <20240424201234.3cc2b509@kernel.org> MIME-Version: 1.0 Content-Disposition: inline In-Reply-To: <20240424201234.3cc2b509@kernel.org> X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20240508_101140_232762_F1A0C9E8 X-CRM114-Status: GOOD ( 14.93 ) X-BeenThere: linux-riscv@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Sender: "linux-riscv" Errors-To: linux-riscv-bounces+linux-riscv=archiver.kernel.org@lists.infradead.org On Wed, Apr 24, 2024 at 08:12:34PM -0700, Jakub Kicinski wrote: > On Tue, 23 Apr 2024 09:54:35 +0200 Thomas Wei=DFschuh wrote: > > The series was split from my larger series sysctl-const series [0]. > > It only focusses on the proc_handlers but is an important step to be > > able to move all static definitions of ctl_table into .rodata. > = > Split this per subsystem, please. I've done a few painful API transitions before, and I don't think the complexity of these changes needs a per-subsystem constification pass. I think this series is the right approach, but that patch 11 will need coordination with Linus. We regularly do system-wide prototype changes like this right at the end of the merge window before -rc1 comes out. The requirements are pretty simple: it needs to be a obvious changes (this certainly is) and as close to 100% mechanical as possible. I think patch 11 easily qualifies. Linus should be able to run the same Coccinelle script and get nearly the same results, etc. And all the other changes need to have landed. This change also has no "silent failure" conditions: anything mismatched will immediately stand out. So, have patches 1-10 go via their respective subsystems, and once all of those are in Linus's tree, send patch 11 as a stand-alone PR. (From patch 11, it looks like the seccomp read/write function changes could be split out? I'll do that now...) -Kees -- = Kees Cook _______________________________________________ linux-riscv mailing list linux-riscv@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-riscv From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from lists.ozlabs.org (lists.ozlabs.org [112.213.38.117]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id D47B3C04FFE for ; Wed, 8 May 2024 17:12:29 +0000 (UTC) Authentication-Results: lists.ozlabs.org; dkim=fail reason="signature verification failed" (1024-bit key; unprotected) header.d=chromium.org header.i=@chromium.org header.a=rsa-sha256 header.s=google header.b=RMFR4Xy+; dkim-atps=neutral Received: from boromir.ozlabs.org (localhost [IPv6:::1]) by lists.ozlabs.org (Postfix) with ESMTP id 4VZMCJ3DBMz3cTd for ; Thu, 9 May 2024 03:12:28 +1000 (AEST) Authentication-Results: lists.ozlabs.org; dmarc=pass (p=none dis=none) header.from=chromium.org Authentication-Results: lists.ozlabs.org; dkim=pass (1024-bit key; unprotected) header.d=chromium.org header.i=@chromium.org header.a=rsa-sha256 header.s=google header.b=RMFR4Xy+; dkim-atps=neutral Authentication-Results: lists.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=chromium.org (client-ip=2607:f8b0:4864:20::432; helo=mail-pf1-x432.google.com; envelope-from=keescook@chromium.org; receiver=lists.ozlabs.org) Received: from mail-pf1-x432.google.com (mail-pf1-x432.google.com [IPv6:2607:f8b0:4864:20::432]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by lists.ozlabs.org (Postfix) with ESMTPS id 4VZMBS41pYz2y70 for ; Thu, 9 May 2024 03:11:44 +1000 (AEST) Received: by mail-pf1-x432.google.com with SMTP id d2e1a72fcca58-6f45f1179c3so8628b3a.3 for ; Wed, 08 May 2024 10:11:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; t=1715188297; x=1715793097; darn=lists.ozlabs.org; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date:from:to :cc:subject:date:message-id:reply-to; bh=tSmrj41Qt+Se2fdGi7WeozvVj6AfH//AS3pb2zkquGg=; b=RMFR4Xy+QSMwTa7z5J8MNqqFUn26K8/AwJNx5voGQj7msRRhVbwC3LFGpz58qsV07K 9pt93sI2EIt+9aggLffLWNorEyIm68H8BjioTQ+PsNphG1ON8ZmVPy2gUqbIDN+1XtRa z5xYuwC3veQ/2pszXuDPfR2/v8wewkTs8dRcc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1715188297; x=1715793097; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=tSmrj41Qt+Se2fdGi7WeozvVj6AfH//AS3pb2zkquGg=; b=INIht8tuF1X/9IBEdfi9x0DE23Uc5hbd53i4jrd2IKPoJlxYX87qUD7T5MXAh/25p1 MdDeKCRoE9wWGJzKE+Bs5S4AHSrtXhdeBI5fyP9e2yCB1yM874iSjbsUSKiix9cNeb2R YKP9iDpTLYmb1IY48RQClETn64lFv3oWUt3K7wGtdQ3ltU4Ig9gfe8CyZmV6ZAlZeiOc BC3UCZ5eHGayabhuA5xErzZzlnhview/gc3s33gurbwxIDdX9Hh05qFS0z8DikrUEmDj 8+y7s6qjduPO9I1+wTEiuuKlOsfK72Qz+0vHiZcWj3p93AWfCr+mxDf/cc/VPufZUcUc kzvg== X-Forwarded-Encrypted: i=1; AJvYcCUne5qT3JxwGG3Meh3qTvGB5YP5wf7/pF2qRV8JsrYPjILIcxvkRJd0X9Pht++XQ2QoGgvbmXexPs3KF10giZbTUz0lv9jBK+toOr4Crw== X-Gm-Message-State: AOJu0YymZ4Yi+5TSVPJBZQdhM4gALJFYocDk6CgL2Qgebuwz3nqV00hm suL4IIiagGgCQSbm/CJUXoIS1byFl+kMX7slsacI74dd7C3+0F1U1glNDMvzFg== X-Google-Smtp-Source: AGHT+IHN8eeXE9OsgItxEKHR70nrrazwBAjav29jEzJB0wGGmdP+iVlP1VjtMYRBUjqpRzzzPBgYhQ== X-Received: by 2002:a05:6a20:c88b:b0:1a5:6a85:8ce9 with SMTP id adf61e73a8af0-1afc8d1b02amr3543639637.12.1715188296881; Wed, 08 May 2024 10:11:36 -0700 (PDT) Received: from www.outflux.net ([198.0.35.241]) by smtp.gmail.com with ESMTPSA id lp9-20020a056a003d4900b006f44ed124dfsm9245352pfb.160.2024.05.08.10.11.36 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 08 May 2024 10:11:36 -0700 (PDT) Date: Wed, 8 May 2024 10:11:35 -0700 From: Kees Cook To: Jakub Kicinski Subject: Re: [PATCH v3 00/11] sysctl: treewide: constify ctl_table argument of sysctl handlers Message-ID: <202405080959.104A73A914@keescook> References: <20240423-sysctl-const-handler-v3-0-e0beccb836e2@weissschuh.net> <20240424201234.3cc2b509@kernel.org> MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <20240424201234.3cc2b509@kernel.org> X-BeenThere: linuxppc-dev@lists.ozlabs.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Linux on PowerPC Developers Mail List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Joel Granados , Dave Chinner , linux-kernel@vger.kernel.org, linux-mm@kvack.org, Eric Dumazet , linux-hardening@vger.kernel.org, linux-riscv@lists.infradead.org, linux-s390@vger.kernel.org, rds-devel@oss.oracle.com, linux-rdma@vger.kernel.org, Luis Chamberlain , linux-sctp@vger.kernel.org, lvs-devel@vger.kernel.org, coreteam@netfilter.org, linux-trace-kernel@vger.kernel.org, bridge@lists.linux.dev, apparmor@lists.ubuntu.com, linux-xfs@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-nfs@vger.kernel.org, netdev@vger.kernel.org, kexec@lists.infradead.org, Thomas =?iso-8859-1?Q?Wei=DFschuh?= , linux-perf-users@vger.kernel.org, linux-security-module@vger.kernel.org, netfilter-devel@vger.kernel.org, linux-fsdevel@vger.kernel.org, bpf@vger.kernel.org, linuxppc-dev@lists.ozlabs.org Errors-To: linuxppc-dev-bounces+linuxppc-dev=archiver.kernel.org@lists.ozlabs.org Sender: "Linuxppc-dev" On Wed, Apr 24, 2024 at 08:12:34PM -0700, Jakub Kicinski wrote: > On Tue, 23 Apr 2024 09:54:35 +0200 Thomas Weißschuh wrote: > > The series was split from my larger series sysctl-const series [0]. > > It only focusses on the proc_handlers but is an important step to be > > able to move all static definitions of ctl_table into .rodata. > > Split this per subsystem, please. I've done a few painful API transitions before, and I don't think the complexity of these changes needs a per-subsystem constification pass. I think this series is the right approach, but that patch 11 will need coordination with Linus. We regularly do system-wide prototype changes like this right at the end of the merge window before -rc1 comes out. The requirements are pretty simple: it needs to be a obvious changes (this certainly is) and as close to 100% mechanical as possible. I think patch 11 easily qualifies. Linus should be able to run the same Coccinelle script and get nearly the same results, etc. And all the other changes need to have landed. This change also has no "silent failure" conditions: anything mismatched will immediately stand out. So, have patches 1-10 go via their respective subsystems, and once all of those are in Linus's tree, send patch 11 as a stand-alone PR. (From patch 11, it looks like the seccomp read/write function changes could be split out? I'll do that now...) -Kees -- Kees Cook From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id F066BC04FFE for ; Wed, 8 May 2024 17:11:59 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:In-Reply-To:MIME-Version:References: Message-ID:Subject:Cc:To:From:Date:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=4lKuE8/RkpKdWTXYMQUQrb+E3yi/jt2NVV07ACtaUu8=; b=WPDBPaYKykhmUu nnAMEPDRA8rCq7XjRhVdDOBvRlG0WOXAUhfK4HPkjKMw3mArnJ2YOI/0T9vffzBbwLtGPRnLUy/4R o+rE5U3lj7sBfPfoLmzV8k22s0nicGSZSFiZu/raDe+UzwMxIjYHrXSXNZZbblW6ReoereNC9Fe+m FWqVnjZMy7BUtOp+q1EKmDAV0eA3dVuX781HsHotzEz0WeA+kJst28drasZ+xQwseNmDgEC/1WhO0 YgOzvGeJmF/KmS8eU4Orr29Lc+hdpJMTr//CNdG2ltAgbJiw+H//n7Xu1euzvzhP3noPED8Zib7YW PSmtT8KKXnP0PkdP5zpw==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.97.1 #2 (Red Hat Linux)) id 1s4kpX-0000000GJ2l-3tCY; Wed, 08 May 2024 17:11:47 +0000 Received: from mail-pf1-x433.google.com ([2607:f8b0:4864:20::433]) by bombadil.infradead.org with esmtps (Exim 4.97.1 #2 (Red Hat Linux)) id 1s4kpQ-0000000GIza-0klB for linux-arm-kernel@lists.infradead.org; Wed, 08 May 2024 17:11:42 +0000 Received: by mail-pf1-x433.google.com with SMTP id d2e1a72fcca58-6f447260f9dso28635b3a.0 for ; Wed, 08 May 2024 10:11:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; t=1715188297; x=1715793097; darn=lists.infradead.org; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date:from:to :cc:subject:date:message-id:reply-to; bh=tSmrj41Qt+Se2fdGi7WeozvVj6AfH//AS3pb2zkquGg=; b=P1/Vk1ftAPZ/JGfIcL46RAevnIIRS6UDYW9YJ/cxP+SM2aHbg3EVccS5TsIPCAw3ay KrUP/+WSLA1KgcJppL/dLuokLaHqc3yLoAfkhLvX92l4rouz/CBAeopVjE09FSWWhHjD uARbGkNXgEPUaBgPfItz+UMFQ109Ypyeax0n8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1715188297; x=1715793097; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=tSmrj41Qt+Se2fdGi7WeozvVj6AfH//AS3pb2zkquGg=; b=CMQ1/HDXPibUBfHVFJ37GzPM7JPny1vE3GEe0QwZb/atEBPfQf7C6cdkUZqapHNyZl NZbLCT0cy7U/NjTHq5j6DSh0XsbsRtHhYrtErS5i9+ezDIGjr5PaglvCONuxxWndR1B8 VbHKEQe0z2DNfrBHKEu28s5Jc06bPdsJTOeMJ43SMtlVgHeqZkp7ni/6z9H0ayOUHdmf CVYdEecBEoFDUDGfzCqFkI2zsV6duxP+cYJ9h+0GELlMXdy4kVp2g0k07Ij2Ptdb6pan 5PcsTHbGajWhAQ7vnh65yvghiuKAGcvGuD37fLx+8Olekwu88vd8xIN6vrb/eQMBefUh PqWg== X-Forwarded-Encrypted: i=1; AJvYcCXj5JV1UFWJPA+ZnVHTJzPoiXcs45cNNHdR8S3LfNGUC2l0M1tFMJ44mb27zyFB86FwB9dzxa5FiZx26jl1btVqtSbvxzDm64P2DBCFN30Oksvx6qU= X-Gm-Message-State: AOJu0Yz3XG4Y0OszmGD4AZylIbwQ/YpYTOZLcUbXWr4Rfyyu+44L2Lsn lYc89EsdmfTA53WAcsre0Od319X2bWIQBM5LdM0hdXrB5jfvn418rHBj4E50jw== X-Google-Smtp-Source: AGHT+IHN8eeXE9OsgItxEKHR70nrrazwBAjav29jEzJB0wGGmdP+iVlP1VjtMYRBUjqpRzzzPBgYhQ== X-Received: by 2002:a05:6a20:c88b:b0:1a5:6a85:8ce9 with SMTP id adf61e73a8af0-1afc8d1b02amr3543639637.12.1715188296881; Wed, 08 May 2024 10:11:36 -0700 (PDT) Received: from www.outflux.net ([198.0.35.241]) by smtp.gmail.com with ESMTPSA id lp9-20020a056a003d4900b006f44ed124dfsm9245352pfb.160.2024.05.08.10.11.36 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 08 May 2024 10:11:36 -0700 (PDT) Date: Wed, 8 May 2024 10:11:35 -0700 From: Kees Cook To: Jakub Kicinski Cc: Thomas =?iso-8859-1?Q?Wei=DFschuh?= , Luis Chamberlain , Joel Granados , Eric Dumazet , Dave Chinner , linux-fsdevel@vger.kernel.org, netdev@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, linux-riscv@lists.infradead.org, linux-mm@kvack.org, linux-security-module@vger.kernel.org, bpf@vger.kernel.org, linuxppc-dev@lists.ozlabs.org, linux-xfs@vger.kernel.org, linux-trace-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, netfilter-devel@vger.kernel.org, coreteam@netfilter.org, kexec@lists.infradead.org, linux-hardening@vger.kernel.org, bridge@lists.linux.dev, lvs-devel@vger.kernel.org, linux-rdma@vger.kernel.org, rds-devel@oss.oracle.com, linux-sctp@vger.kernel.org, linux-nfs@vger.kernel.org, apparmor@lists.ubuntu.com Subject: Re: [PATCH v3 00/11] sysctl: treewide: constify ctl_table argument of sysctl handlers Message-ID: <202405080959.104A73A914@keescook> References: <20240423-sysctl-const-handler-v3-0-e0beccb836e2@weissschuh.net> <20240424201234.3cc2b509@kernel.org> MIME-Version: 1.0 Content-Disposition: inline In-Reply-To: <20240424201234.3cc2b509@kernel.org> X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20240508_101140_232796_CF905B9C X-CRM114-Status: GOOD ( 16.45 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org On Wed, Apr 24, 2024 at 08:12:34PM -0700, Jakub Kicinski wrote: > On Tue, 23 Apr 2024 09:54:35 +0200 Thomas Wei=DFschuh wrote: > > The series was split from my larger series sysctl-const series [0]. > > It only focusses on the proc_handlers but is an important step to be > > able to move all static definitions of ctl_table into .rodata. > = > Split this per subsystem, please. I've done a few painful API transitions before, and I don't think the complexity of these changes needs a per-subsystem constification pass. I think this series is the right approach, but that patch 11 will need coordination with Linus. We regularly do system-wide prototype changes like this right at the end of the merge window before -rc1 comes out. The requirements are pretty simple: it needs to be a obvious changes (this certainly is) and as close to 100% mechanical as possible. I think patch 11 easily qualifies. Linus should be able to run the same Coccinelle script and get nearly the same results, etc. And all the other changes need to have landed. This change also has no "silent failure" conditions: anything mismatched will immediately stand out. So, have patches 1-10 go via their respective subsystems, and once all of those are in Linus's tree, send patch 11 as a stand-alone PR. (From patch 11, it looks like the seccomp read/write function changes could be split out? I'll do that now...) -Kees -- = Kees Cook _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel