From: Casey Schaufler <casey@schaufler-ca.com>
To: Christian Brauner <brauner@kernel.org>, linux-fsdevel@vger.kernel.org
Cc: Alexander Viro <viro@zeniv.linux.org.uk>, Jan Kara <jack@suse.cz>,
Christoph Hellwig <hch@lst.de>,
Seth Forshee <sforshee@kernel.org>,
Paul Moore <paul@paul-moore.com>,
linux-security-module@vger.kernel.org,
Mimi Zohar <zohar@linux.ibm.com>,
linux-integrity@vger.kernel.org,
Ilya Dryomov <idryomov@gmail.com>,
ceph-devel@vger.kernel.org, Carlos Maiolino <cem@kernel.org>,
linux-xfs@vger.kernel.org, Miklos Szeredi <miklos@szeredi.hu>,
Amir Goldstein <amir73il@gmail.com>,
linux-unionfs@vger.kernel.org,
Namjae Jeon <linkinjeon@kernel.org>,
linux-cifs@vger.kernel.org, linux-kernel@vger.kernel.org,
Casey Schaufler <casey@schaufler-ca.com>
Subject: Re: [PATCH 24/27] fs: port ->setattr() to pass const mnt_idmap
Date: Tue, 1 Sep 2026 08:53:42 -0700 [thread overview]
Message-ID: <d3656927-c39d-421f-8baa-f04c8d4eeff3@schaufler-ca.com> (raw)
In-Reply-To: <20260901-work-idmap-const-v1-24-54ccd48e100b@kernel.org>
On 9/1/2026 5:14 AM, Christian Brauner wrote:
> Convert to const struct mnt_idmap.
>
> A mount's idmapping is immutable. The only thing that is allowed to be
> modified afterwards is the reference count and that is hidden behind
> mnt_idmap_get() and mnt_idmap_put(). Everything else only ever reads
> from the idmapping. This is the same model that struct cred uses and the
> idmapping is also rather sensitive.
>
> So make the idmap argument const wherever we can. The conversion is done
> from the bottom up so callers can continue to pass a non-const pointer
> to a const parameter until the conversion is finished.
>
> No functional changes.
>
> Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
> ---
> Documentation/filesystems/locking.rst | 2 +-
> Documentation/filesystems/vfs.rst | 2 +-
> arch/powerpc/platforms/cell/spufs/inode.c | 2 +-
> fs/9p/v9fs_vfs.h | 2 +-
> fs/9p/vfs_inode.c | 2 +-
> fs/9p/vfs_inode_dotl.c | 2 +-
> fs/adfs/adfs.h | 2 +-
> fs/adfs/inode.c | 2 +-
> fs/affs/affs.h | 2 +-
> fs/affs/inode.c | 2 +-
> fs/afs/inode.c | 2 +-
> fs/afs/internal.h | 2 +-
> fs/anon_inodes.c | 2 +-
> fs/attr.c | 2 +-
> fs/bad_inode.c | 2 +-
> fs/btrfs/inode.c | 2 +-
> fs/ceph/inode.c | 2 +-
> fs/ceph/super.h | 2 +-
> fs/coda/coda_linux.h | 2 +-
> fs/coda/inode.c | 2 +-
> fs/configfs/configfs_internal.h | 2 +-
> fs/configfs/inode.c | 2 +-
> fs/debugfs/inode.c | 2 +-
> fs/ecryptfs/inode.c | 2 +-
> fs/efivarfs/inode.c | 2 +-
> fs/exfat/exfat_fs.h | 2 +-
> fs/exfat/file.c | 2 +-
> fs/ext2/ext2.h | 2 +-
> fs/ext2/inode.c | 2 +-
> fs/ext4/ext4.h | 2 +-
> fs/ext4/inode.c | 2 +-
> fs/f2fs/f2fs.h | 2 +-
> fs/f2fs/file.c | 2 +-
> fs/fat/fat.h | 2 +-
> fs/fat/file.c | 2 +-
> fs/fuse/dir.c | 2 +-
> fs/gfs2/inode.c | 2 +-
> fs/hfs/hfs_fs.h | 2 +-
> fs/hfs/inode.c | 2 +-
> fs/hfsplus/inode.c | 2 +-
> fs/hostfs/hostfs_kern.c | 2 +-
> fs/hpfs/hpfs_fn.h | 2 +-
> fs/hpfs/inode.c | 2 +-
> fs/hugetlbfs/inode.c | 2 +-
> fs/inode.c | 2 +-
> fs/internal.h | 2 +-
> fs/jffs2/fs.c | 2 +-
> fs/jffs2/os-linux.h | 2 +-
> fs/jfs/file.c | 2 +-
> fs/jfs/jfs_inode.h | 2 +-
> fs/kernfs/inode.c | 2 +-
> fs/kernfs/kernfs-internal.h | 2 +-
> fs/libfs.c | 4 ++--
> fs/minix/file.c | 2 +-
> fs/nfs/inode.c | 2 +-
> fs/nfs/namespace.c | 2 +-
> fs/nilfs2/inode.c | 2 +-
> fs/nilfs2/nilfs.h | 2 +-
> fs/ntfs/file.c | 2 +-
> fs/ntfs/inode.h | 2 +-
> fs/ntfs3/file.c | 2 +-
> fs/ntfs3/ntfs_fs.h | 2 +-
> fs/ocfs2/dlmfs/dlmfs.c | 2 +-
> fs/ocfs2/file.c | 2 +-
> fs/ocfs2/file.h | 2 +-
> fs/omfs/file.c | 2 +-
> fs/orangefs/inode.c | 2 +-
> fs/orangefs/orangefs-kernel.h | 2 +-
> fs/overlayfs/inode.c | 2 +-
> fs/overlayfs/overlayfs.h | 2 +-
> fs/pidfs.c | 2 +-
> fs/proc/base.c | 2 +-
> fs/proc/generic.c | 2 +-
> fs/proc/internal.h | 2 +-
> fs/proc/proc_sysctl.c | 2 +-
> fs/ramfs/file-nommu.c | 4 ++--
> fs/smb/client/cifsfs.h | 2 +-
> fs/smb/client/inode.c | 2 +-
> fs/tracefs/event_inode.c | 2 +-
> fs/tracefs/inode.c | 2 +-
> fs/ubifs/file.c | 2 +-
> fs/ubifs/ubifs.h | 2 +-
> fs/udf/file.c | 2 +-
> fs/ufs/inode.c | 2 +-
> fs/ufs/ufs.h | 2 +-
> fs/vboxsf/utils.c | 2 +-
> fs/vboxsf/vfsmod.h | 2 +-
> fs/xfs/xfs_iops.c | 2 +-
> fs/zonefs/super.c | 2 +-
> include/linux/fs.h | 6 +++---
> include/linux/lsm_hook_defs.h | 4 ++--
> include/linux/nfs_fs.h | 2 +-
> include/linux/security.h | 8 ++++----
> mm/secretmem.c | 2 +-
> mm/shmem.c | 2 +-
> net/socket.c | 2 +-
> security/integrity/evm/evm_main.c | 4 ++--
> security/integrity/ima/ima_appraise.c | 2 +-
> security/security.c | 4 ++--
> security/selinux/hooks.c | 2 +-
> security/smack/smack_lsm.c | 2 +-
> virt/kvm/guest_memfd.c | 2 +-
> 102 files changed, 112 insertions(+), 112 deletions(-)
...
> diff --git a/security/smack/smack_lsm.c b/security/smack/smack_lsm.c
> index df4fc6ff26aa..bb78569b3d5b 100644
> --- a/security/smack/smack_lsm.c
> +++ b/security/smack/smack_lsm.c
> @@ -1270,7 +1270,7 @@ static int smack_inode_permission(struct inode *inode, int mask)
> *
> * Returns 0 if access is permitted, an error code otherwise
> */
> -static int smack_inode_setattr(struct mnt_idmap *idmap, struct dentry *dentry,
> +static int smack_inode_setattr(const struct mnt_idmap *idmap, struct dentry *dentry,
> struct iattr *iattr)
Please keep to 80 columns.
+static int smack_inode_setattr(const struct mnt_idmap *idmap,
+ struct dentry *dentry, struct iattr *iattr)
Note that the above may get whitespace mangled.
> {
> struct smk_audit_info ad;
>
next prev parent reply other threads:[~2026-09-01 16:14 UTC|newest]
Thread overview: 62+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-01 12:14 [PATCH 00/27] fs: port to const struct mnt_idmap Christian Brauner
2026-09-01 12:14 ` [PATCH 01/27] userns: pass const uid_gid_map in lookup helpers Christian Brauner
2026-09-02 14:06 ` Jan Kara
2026-09-01 12:14 ` [PATCH 02/27] fs: port mnt_idmap_{get,put}() to const mnt_idmap Christian Brauner
2026-09-02 14:08 ` Jan Kara
2026-09-01 12:14 ` [PATCH 03/27] fs: port vfs{g,u}id helpers " Christian Brauner
2026-09-02 14:11 ` Jan Kara
2026-09-01 12:14 ` [PATCH 04/27] fs: port fs{g,u}id " Christian Brauner
2026-09-02 14:13 ` Jan Kara
2026-09-01 12:14 ` [PATCH 05/27] fs: port i_{g,u}id_into_vfs{g,u}id() " Christian Brauner
2026-09-02 14:14 ` Jan Kara
2026-09-01 12:14 ` [PATCH 06/27] fs: port i_{g,u}id_{needs_}update() " Christian Brauner
2026-09-02 14:15 ` Jan Kara
2026-09-01 12:14 ` [PATCH 07/27] quota: port " Christian Brauner
2026-09-02 14:16 ` Jan Kara
2026-09-01 12:14 ` [PATCH 08/27] fs: port privilege checking helpers " Christian Brauner
2026-09-02 14:17 ` Jan Kara
2026-09-01 12:14 ` [PATCH 09/27] fs: port inode_owner_or_capable() " Christian Brauner
2026-09-02 14:18 ` Jan Kara
2026-09-01 12:14 ` [PATCH 10/27] fs: port inode_init_owner() " Christian Brauner
2026-09-02 14:20 ` Jan Kara
2026-09-01 12:14 ` [PATCH 11/27] fs: port acl " Christian Brauner
2026-09-02 14:22 ` Jan Kara
2026-09-02 19:34 ` Paul Moore
2026-09-01 12:14 ` [PATCH 12/27] fs: port ->permission() to pass " Christian Brauner
2026-09-02 15:38 ` Jan Kara
2026-09-02 19:34 ` Paul Moore
2026-09-01 12:14 ` [PATCH 13/27] fs: port xattr to " Christian Brauner
2026-09-02 15:42 ` Jan Kara
2026-09-02 19:34 ` Paul Moore
2026-09-01 12:14 ` [PATCH 14/27] fs: port ->fileattr_set() to pass " Christian Brauner
2026-09-02 15:43 ` Jan Kara
2026-09-01 12:14 ` [PATCH 15/27] fs: port ->set_acl() " Christian Brauner
2026-09-02 15:45 ` Jan Kara
2026-09-01 12:14 ` [PATCH 16/27] fs: port ->get_acl() " Christian Brauner
2026-09-02 15:45 ` Jan Kara
2026-09-01 12:14 ` [PATCH 17/27] fs: port ->tmpfile() " Christian Brauner
2026-09-02 15:47 ` Jan Kara
2026-09-02 19:34 ` Paul Moore
2026-09-01 12:14 ` [PATCH 18/27] fs: port ->mknod() " Christian Brauner
2026-09-02 15:49 ` Jan Kara
2026-09-02 19:34 ` Paul Moore
2026-09-01 12:14 ` [PATCH 19/27] fs: port ->rename() " Christian Brauner
2026-09-02 15:50 ` Jan Kara
2026-09-01 12:14 ` [PATCH 20/27] fs: port ->mkdir() " Christian Brauner
2026-09-02 15:52 ` Jan Kara
2026-09-01 12:14 ` [PATCH 21/27] fs: port ->symlink() " Christian Brauner
2026-09-02 15:53 ` Jan Kara
2026-09-01 12:14 ` [PATCH 22/27] fs: port ->create() " Christian Brauner
2026-09-02 15:55 ` Jan Kara
2026-09-01 12:14 ` [PATCH 23/27] fs: port ->getattr() " Christian Brauner
2026-09-02 15:58 ` Jan Kara
2026-09-01 12:14 ` [PATCH 24/27] fs: port ->setattr() " Christian Brauner
2026-09-01 15:53 ` Casey Schaufler [this message]
2026-09-02 16:01 ` Jan Kara
2026-09-02 19:34 ` Paul Moore
2026-09-01 12:14 ` [PATCH 25/27] fs: port vfs_*() helpers to " Christian Brauner
2026-09-02 16:02 ` Jan Kara
2026-09-01 12:14 ` [PATCH 26/27] fs: port mnt_idmap() and file_mnt_idmap() " Christian Brauner
2026-09-02 16:06 ` Jan Kara
2026-09-01 12:14 ` [PATCH 27/27] fs: make nop_mnt_idmap and invalid_mnt_idmap const Christian Brauner
2026-09-02 16:07 ` Jan Kara
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=d3656927-c39d-421f-8baa-f04c8d4eeff3@schaufler-ca.com \
--to=casey@schaufler-ca.com \
--cc=amir73il@gmail.com \
--cc=brauner@kernel.org \
--cc=cem@kernel.org \
--cc=ceph-devel@vger.kernel.org \
--cc=hch@lst.de \
--cc=idryomov@gmail.com \
--cc=jack@suse.cz \
--cc=linkinjeon@kernel.org \
--cc=linux-cifs@vger.kernel.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=linux-unionfs@vger.kernel.org \
--cc=linux-xfs@vger.kernel.org \
--cc=miklos@szeredi.hu \
--cc=paul@paul-moore.com \
--cc=sforshee@kernel.org \
--cc=viro@zeniv.linux.org.uk \
--cc=zohar@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox