From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wr2-f1.google.com (mail-wr2-f1.google.com [74.125.225.65]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D34B5453A39 for ; Fri, 31 Jul 2026 16:32:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.65 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785515537; cv=none; b=ljnPTElwBHofgWRNwjfNDI8rRuRx5OiGQNjTaXYWlOCAJ8xWHs4J0vdTcUkmR1S3chZSUIFui5/jpUx5KGcNcl0JVVpDwYWYxkNGKj5PZXMKYhLCMTd4qlgRBb91PyIbOr1ud6YMbFYCF8+ry9kHQC9+ruMvG2pCdtWOYZiWumY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785515537; c=relaxed/simple; bh=9HFGiNNNAUH+NXm19RvmGJwmOISH+nDndQe11ccbYuw=; h=Mime-Version:Content-Type:Date:Message-Id:Cc:Subject:From:To: References:In-Reply-To; b=RoUvSwGmzkxqzA67t1cjCRCNVWAyzMfZLivG3SNv+sdyXkPenznWcUeXJVvRMsSUqjYEsTTH35oYf0Wv+kZao9iyvLgW/717hbzWSGQdfIwTlcbY6LN8DTh4z48cwS5xMEj6KsTDck5pKCXGpGtPBVZ81SqLi+24neFsy3hABXU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Yq2ri5FP; arc=none smtp.client-ip=74.125.225.65 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Yq2ri5FP" Received: by mail-wr2-f1.google.com with SMTP id ffacd0b85a97d-4700bd8aed1so47094f8f.1 for ; Fri, 31 Jul 2026 09:32:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785515534; x=1786120334; darn=vger.kernel.org; h=in-reply-to:references:to:from:subject:cc:message-id:date :content-type:content-transfer-encoding:mime-version:from:to:cc :subject:date:message-id:reply-to:content-type; bh=aUmR71V4eGCOh/F9b0SbwQJJGIMeqY66EO2STeKizkI=; b=Yq2ri5FPbQJ1F4uB/eXjU4yL6HWzrOTKf9c4Xq+kZsfcpu/XGsIrybdMN3YrtEJTKj goum9m7pj2R3M8ivlQ+VDMbDwl0OzIB3a1qavcLW97XEHUsv5K4woOUpGv/iSOuygqhh xhhGtT1l3wudfOMd/gYJYeox1zanwTegbFoe9CDDbokmy5HkjZVDv5+HMu8OXQwxtkVM VY7jxXSHg8kyEVizv7FOJfqgtA9IwI6Af3RuOXdG5pt2WLXvkUcWKchb0Al2Ogs3QLvb g/0tL/nwbmvLoQ+6/ao19dheXt0N4EVK6p57+Qmg9JDSjKXQeirDl1nnuiiYVF71e7db p4pg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785515534; x=1786120334; h=in-reply-to:references:to:from:subject:cc:message-id:date :content-type:content-transfer-encoding:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=aUmR71V4eGCOh/F9b0SbwQJJGIMeqY66EO2STeKizkI=; b=NvnR7bbojr+pkRbC9fihtYjnkywcLtM33X93MTt9rKJuD5NR8uFG1pc2wx1BhPNwYc GOQjGGPv6NwcY55jBXOgeHKqB4QFqr7MkmTrGf7nVC/KcYdDjkMmMdP2U0js5uVe2OjN XFDKKqDzBpiuApWAipcEzroa6o5ysHNtwwwjjEuVFstN88ed0MnkmKw4vHHtREAraWD7 wCBbJtJwSW8FgIzPBXoVh1FsiLc1a6BtaSWD1WeAVlPFYCwLUkqMqwoW5dEI34s160bX tUhluFoR5a3H1s4Tpq9P1mEMsnMhPzlVwzKgJqp3iic0jsdASxDGo15j9A+BTES+eEI3 FTfg== X-Forwarded-Encrypted: i=1; AHgh+RrVd30AyNAQOH0gZzIiJv2ZCtYogtz/sWYy/0KSUAs3KwEeOUBPO3Z6Iz+LkZr3J2C7OOdOfNva6z7Le7g=@vger.kernel.org X-Gm-Message-State: AOJu0YwQn5VWkZAI77TQW+QHQqOK48nxtk754uL179DgNMUvOdX0+2Qi 398j53Chsp8N0pj+WkBFu0XxQ/4JBB2OGs27VccO1h96zx0ZRno3phGK X-Gm-Gg: AR+sD10vdZSu3t74WtQvdVvzI1ViZv3UKGXF1G2lfwxzk1qtiDhxFCdID5SgjaxbHwT 3hGq3PDBc8a4vOSkm6p3hU1SgzykbqY3fIUa7C5c/9hEahI3V2AcCngn1MEn9BPE0Hn/2WiVC5N qUEDcnkI6Ed/Pv94yOQy/POO6h6ZkQPXfeMnJvIJqFM8DffhN0TzuPcbV1gVyk0aFksVisKOQ1R 5YkncD7D7ozXOBZJxKmEDfnIPMZifuOoJogmUey2TQU/yDAPMM6fIMtPZdd5dWpXmTXz4cOU28H QhnFOL8wkdKMWUT0VLCcZSP5luU6sFx10wpRUoa4H0OMRM8FN6VxKxO7hUh6IIPxh9G6OMwOBEk 1KJ6bZ8r1MaT7ghx/y6NwuSlWDdGBVnzhTFOztKj6xS2Ob2mfUxBfDBsc8++qA0rm43ESpdtiSp PEZXHReOyMDjriPPiocs7dYPVFwG55qArpYV9OIsZ/7XqWZNQlF+sysYPqVjGV3ypbzKI2JvQsh sxzrbYIh9cIgugKkOG1XpHnDfs0lohVZ0lp9mYEub1JuGus//ZIs6rk4zMpEyLrX6kzU2O0cu/A wPsvBN9ugkMVG0MTIc517gEeS3Q= X-Received: by 2002:a05:6000:481e:b0:47f:8cd3:4bed with SMTP id ffacd0b85a97d-47fd725b19fmr763298f8f.5.1785515534056; Fri, 31 Jul 2026 09:32:14 -0700 (PDT) Received: from localhost (nat-icclus-192-26-29-3.epfl.ch. [192.26.29.3]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47fd41e296csm6524909f8f.12.2026.07.31.09.32.13 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 31 Jul 2026 09:32:13 -0700 (PDT) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=UTF-8 Date: Fri, 31 Jul 2026 18:32:13 +0200 Message-Id: Cc: "David Windsor" , "Alexei Starovoitov" , "Daniel Borkmann" , "Andrii Nakryiko" , "Martin KaFai Lau" , "Eduard Zingerman" , "Song Liu" , "Yonghong Song" , "John Fastabend" , "KP Singh" , "Jiri Olsa" , "Emil Tsalapatis" , "Matt Bobrowski" , "James Morris" , "Serge E . Hallyn" , "Casey Schaufler" , "Stephen Smalley" , "Ondrej Mosnacek" , "Mimi Zohar" , "Roberto Sassu" , "Dmitry Kasatkin" , "Eric Snowberg" , "Alexander Viro" , "Christian Brauner" , "Jan Kara" , "Shuah Khan" , , , , , , , Subject: Re: [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling From: "Kumar Kartikeya Dwivedi" To: "Paul Moore" X-Mailer: aerc 0.21.0 References: <20260730234533.1912709-1-dwindsor@gmail.com> <20260730234533.1912709-4-dwindsor@gmail.com> In-Reply-To: On Fri Jul 31, 2026 at 6:02 PM CEST, Paul Moore wrote: > On Fri, Jul 31, 2026 at 11:44=E2=80=AFAM Kumar Kartikeya Dwivedi > wrote: >> On Fri Jul 31, 2026 at 5:30 PM CEST, David Windsor wrote: >> > On Fri, Jul 31, 2026 at 11:17=E2=80=AFAM Paul Moore wrote: >> >> >> >> >> >> Okay, it looks like there was some confusion/misunderstanding. >> >> >> >> My understanding of Kumar's comments was that he was referring to the >> >> exisiting LSM related kfuncs that are located in fs/bpf_fs_kfuncs.c, >> >> not necessarily the new kfunc you are proposing in this patchset. >> >> Kumar is welcome to correct either one or both of us, if we read that >> >> wrong :) >> >> >> > >> > Yes, after another reading, that does appear to be the case =3D). >> > >> > We'll need v7 anyway to fix the ocfs-related UAF the bot found. >> > >> >> Since there is confusion, let me clear it up. >> >> I meant it for all of them. I don't think it makes sense to keep this on= e in >> security/ when others are in fs/bpf_fs_kfuncs.c. That confusing limbo st= ate is >> worse than just placing it where others already are. >> >> As I already said, the discussion around whether all of them they should= go in >> security/ is orthogonal and should be done separately; it isn't producti= ve to >> repeatedly bring it up in the context of this patch set. >> >> I honestly don't get the urgency; it will be a mechanical change if we n= eed to >> make such changes. The worst outcome would be stalling David's work over= it. >> >> As for landing this stuff, we can let Paul take the patches touching sec= urity/ >> and route the rest (3-4) through bpf-next after the merge window. We nee= d them >> to go through BPF CI anyway to ensure nothing breaks. > > Some existing LSM kfuncs are located in the wrong files. I'm not > suggesting that David needs to fix the existing problems, but there is > no reason to keep making the same mistakes. The new LSM kfunc must go > in security/bpf_lsm_kfuncs.c; if that isn't acceptable to the BPF > developers then David will need to find a new way that doesn't involve > kfuncs. What "mistakes"? Really? It's just code organization bureaucracy. Calling i= t a mistake is just blowing things out of proportion. I don't think you can simply decide this unilaterally either. Do you take f= ull responsibility that kfuncs going there won't introduce BPF side regressions= ? Who makes sure patches touching the new location run through BPF CI? All of thi= s needs to be thought through before we decide upon anything. Thus, I am simply asking you to be reasonable: let's help David make progre= ss, and get the changes landed. FS, BPF, and LSM folks can then decide on where= to copy paste the existing kfuncs later. So David, please send the v7 once you've address Sashiko's concern. We are almost there, and you've been at it for a long time.