From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 42C95EB64DC for ; Wed, 14 Jun 2023 07:07:36 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S242751AbjFNHHf (ORCPT ); Wed, 14 Jun 2023 03:07:35 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:34248 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S231878AbjFNHHc (ORCPT ); Wed, 14 Jun 2023 03:07:32 -0400 Received: from bombadil.infradead.org (bombadil.infradead.org [IPv6:2607:7c80:54:3::133]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 57ED6129; Wed, 14 Jun 2023 00:07:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=infradead.org; s=bombadil.20210309; h=In-Reply-To:Content-Type:MIME-Version :References:Message-ID:Subject:Cc:To:From:Date:Sender:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description; bh=X8oBK+aRsv2PFyfDBYhfNAVfWjSHoTIQiIy5LeMUfN4=; b=33E5p1Vw1VdYhD/NFwTO5yeNlb K4jAHC1Q76zWb2ppdkIud463PzyGPIfUXXqIVT8m+p25tmvV/DYRTw51fCV41bQfLkQeaNNFWbiiW ocYtuxT+tqfjnZYx5iaBWCW6whn1r6IG89n+7EkFAgQhyjvkJrl69egFWdPlsrnIAlLGchrQBKgd7 wqcwjMVUS17hetS/ehOnwx1sdVIcoTUic5MbWAOqcY1L/VIUOsNAZP6Z69ZbZrYQcHxZn/gJhrfxE I0iJfP8HWav/h5hjrf0oLArlM8WKYPM3Rb0mXQeCZoMzkCK3jae9qofDqKDch0b5lP3RN6QJvXlUZ +RrBd48g==; Received: from hch by bombadil.infradead.org with local (Exim 4.96 #2 (Red Hat Linux)) id 1q9KbG-00Aavt-35; Wed, 14 Jun 2023 07:07:26 +0000 Date: Wed, 14 Jun 2023 00:07:26 -0700 From: Christoph Hellwig To: Christian Brauner Cc: Jan Kara , Colin Walters , Bart Van Assche , Jens Axboe , linux-block@vger.kernel.org, Christoph Hellwig , Dmitry Vyukov , Theodore Ts'o , yebin , linux-fsdevel@vger.kernel.org Subject: Re: [PATCH] block: Add config option to not allow writing to mounted devices Message-ID: References: <20230612161614.10302-1-jack@suse.cz> <20230612162545.frpr3oqlqydsksle@quack3> <2f629dc3-fe39-624f-a2fe-d29eee1d2b82@acm.org> <20230613113448.5txw46hvmdjvuoif@quack3> <20230614-talent-davor-e447eb7bcd93@brauner> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20230614-talent-davor-e447eb7bcd93@brauner> X-SRS-Rewrite: SMTP reverse-path rewritten from by bombadil.infradead.org. See http://www.infradead.org/rpr.html Precedence: bulk List-ID: X-Mailing-List: linux-fsdevel@vger.kernel.org On Wed, Jun 14, 2023 at 09:05:41AM +0200, Christian Brauner wrote: > > I kind of like the flexibility of device cgroups but it does not seem to > > Let's not bring in device cgroups here just yet. They're an optional LSM > security measure while your change is more fundamental which is the > right thing to do imho. Yes. That last thing we need is hiding fundamentally security tradeoffs in weird optional corners of the kernel.