cluster-devel.redhat.com archive mirror
 help / color / mirror / Atom feed
From: Andrew Morton <akpm@linux-foundation.org>
To: cluster-devel.redhat.com
Subject: [Cluster-devel] Re: [PATCH 00/25] move handling of setuid/gid bits from VFS into individual setattr functions (RESEND)
Date: Wed, 8 Aug 2007 09:48:53 -0700	[thread overview]
Message-ID: <20070808094853.8c27450c.akpm@linux-foundation.org> (raw)
In-Reply-To: <20070808085435.722f2b10.jlayton@redhat.com>

On Wed, 8 Aug 2007 08:54:35 -0400 Jeff Layton <jlayton@redhat.com> wrote:

> On Tue, 7 Aug 2007 17:15:01 -0700
> Andrew Morton <akpm@linux-foundation.org> wrote:
> 
> > On Mon, 6 Aug 2007 09:54:03 -0400
> > Jeff Layton <jlayton@redhat.com> wrote:
> > 
> > Is there any way in which we can prevent these problems?  Say
> > 
> > - rename something so that unconverted filesystems will reliably fail to
> >   compile?
> > 
> 
> I suppose we could rename the .setattr inode operation to something
> else, but then we'll be stuck with it for at least a while. That seems
> sort of kludgey too...

Sure.  We're changing the required behaviour of .setattr.  Changing its
name is a fine and reasonably reliable way to communicate that fact.

> > - leave existing filesystems alone, but add a new
> >   inode_operations.setattr_jeff, which the networked filesytems can
> >   implement, and teach core vfs to call setattr_jeff in preference to
> >   setattr?
> > 
> > Something else?
> 
> There's also the approach suggested by Miklos: Add a new inode flag that
> tells notify_change not to convert ATTR_KILL_S* flags into a mode
> change. Basically, allow filesystems to "opt out" of that behavior. 
> 
> I'd definitly pick that over a new inode op. That would also allow the
> default case be for the VFS to continue handling these flags.
> Everything would continue to work but filesystems that need to handle
> these flags differently would be able to do so.
> 

We should opt for whatever produces the best end state in the kernel tree. 
ie: if it takes more work and a larger patch to create a better result,
let's go for the better result.  We merge large patches all the time.  We
prefer to smash through, get it right whatever the transient cost.  But
quietly making out-of-tree filesystems less secure is a pretty high cost.

I'm suspecting that adding more flags and some code to test them purely to
minimise the size of the patch and to retain compatibility with the old
.setattr is not a good tradeoff, given that we'd carry the flags and tests
for evermore.

So I'd suggest s/setattr/something_else/g.



  reply	other threads:[~2007-08-08 16:48 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-08-06 13:54 [Cluster-devel] [PATCH 00/25] move handling of setuid/gid bits from VFS into individual setattr functions (RESEND) Jeff Layton
2007-08-07 20:49 ` [Cluster-devel] " Christoph Hellwig
2007-08-07 22:13   ` Jeff Layton
2007-08-08  0:15 ` Andrew Morton
2007-08-08  0:45   ` Trond Myklebust
2007-08-08  0:54     ` Andrew Morton
2007-08-10 20:47     ` Jeff Layton
2007-08-11  2:57       ` Christoph Hellwig
2007-08-13 12:01         ` Jeff Layton
2007-08-13 12:36           ` Jeff Layton
2007-08-08 12:54   ` Jeff Layton
2007-08-08 16:48     ` Andrew Morton [this message]
     [not found]       ` <Pine.LNX.4.64.0708082204210.10387@fbirervta.pbzchgretzou.qr>
2007-08-09 11:55         ` [Cluster-devel] Re: [fuse-devel] " Jeff Layton

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20070808094853.8c27450c.akpm@linux-foundation.org \
    --to=akpm@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).