From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm2-f9.google.com (mail-wm2-f9.google.com [74.125.225.137]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2F7D546984C for ; Fri, 31 Jul 2026 23:35:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.137 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785540940; cv=none; b=fiHTRp55vZ5ZBcNiI6JRfpFiIZYV5x82KnolEdaSLxf2hyWjz0zuZODb47wGHNxFpsbqAKI5KyjJ0oVqKOkUcstY4XKmMOU0q/MlGTAfRP+jkJi5fL17LYWLgsSuVgTKBqN6W6a3xwrOwygqs5Pm8bYheM1M0NiXesSnYFbV/ps= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785540940; c=relaxed/simple; bh=E7AD1CY3Sv52g2oANantVmZ5L4EPUbRo2OwSiRw2zRo=; h=Mime-Version:Content-Type:Date:Message-Id:From:To:Cc:Subject: References:In-Reply-To; b=qvjZeBGx25RQrUH24HGFCK3R6exCaW8wHbO/dG7VKiwXpH9b7wBfCVkytXnrmv3hZz36Wq7DUVjh7fl/8Q47xu1qU0V69sTk/kyR5cTTGJwrfkmhw2+pVwyf/MpO6dpxuwkm47uaocZZbkm85uw8B51JybIwFDS2j36/V/WhyjM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=hRMc5/Hk; arc=none smtp.client-ip=74.125.225.137 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="hRMc5/Hk" Received: by mail-wm2-f9.google.com with SMTP id 5b1f17b1804b1-49553da76dcso1195565e9.1 for ; Fri, 31 Jul 2026 16:35:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785540936; x=1786145736; darn=vger.kernel.org; h=in-reply-to:references:subject:cc:to:from:message-id:date :content-type:content-transfer-encoding:mime-version:from:to:cc :subject:date:message-id:reply-to:content-type; bh=NAH7LZBWSLN1vfCOZsndZVsDBYzJNfOag1t/z/WjVS0=; b=hRMc5/HkH7EAo3d6JMqtf1CusAWagPmDZh1+2bIF4ntX3h9LCW+ETsiJ1lTyPABKoE FCXSkciHGOZ0F0WUP1p8DSuAI4xTYQ7AwIqATxrEhnKMX4gwUwJEzhoRrSqDKGNYDnBO PeBn/yXq0sXOmzbZ7tAQo1qGbC98+acngNaysJSaa/22qoz7xMKiIfQtvAYUdbMS3gK3 XPD4U0KrXX2sr/uucqyMh1J0uaJDVEcaRGXhKBIOXBi0TLMMP1ETP09G+IA74ifDLJ+a LQVnXKmc6qDNeWa3TjMDTHWOUSWmz+THeOpAHC2C3mjuK9ZRIH058RGDTH+qwMa0Y5sI LqSQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785540936; x=1786145736; h=in-reply-to:references:subject:cc:to:from:message-id:date :content-type:content-transfer-encoding:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=NAH7LZBWSLN1vfCOZsndZVsDBYzJNfOag1t/z/WjVS0=; b=KohurKR6kmPH5J9VDDdalcrtxP/lT8f1gPtBnr7Slx/voL2TaeZfPJz9KvJn02jrIE nNHN7uq6zIt2FiAwBSH6npBlIQmoRaEwTcmmA4WKj61xHTyPlcat+pCdM3uqrVSXCpyd EDMVQdmCPB4OBV9JRIGuXT1QqBpufqNMNLLEq6MEWMZWAuPO+NXKK462nxlyLQcvFn+n jRGW9d/dP6zF4Yy9OZ1eQi9pdGQZnBWsbwlk7usqGRJtyNwsLJiAq1As+iN0kLAPMrJd 8xoNYm2XSdm3vz2TzYYdqBvxpxuHffv0H+uQsWMbfm+eX6vRqlP72nDR88Ged55a5HkS WCnQ== X-Forwarded-Encrypted: i=1; AHgh+RoO9xw3D01P/xF/o/tcgcWQT9UtHiHy5A42vvcjbjRvsNQZmTzKiqO1NaKzHoIdLFXJmA7C8J53/NXJGY4QSNQ=@vger.kernel.org X-Gm-Message-State: AOJu0Yzz8S10AigfilwoLAWvs60QnNgqegi9QbTr155cqGfu7NNikV5r MZsRkWTovcjlwXobGJxGc+MvBDQefOI0jSjhy/lQ9FTyLi2/lXchGGMM X-Gm-Gg: AR+sD11rW3/ZkCRyuegm+NiSwdiM0krmb+xX4/milKjFx4JtY0XH6wJIoE21wp8wfej Em06nIt//ZOi12EVByGsoK1UBmkUYRhIzipdfbl7TrBytwQ0+jbLX6fNOcWXzsq/Cgy8OO9TnUa qKCJKMrCHrJLbZQsoR82QdSy5LXfPDnmxeR3rRDa5c0UKCeLHHuykxScw034TVPuzAaRRJuZb1s o2OJ9+MDoiWDyAB3/NQwu0a2CXa0WPQcjBj7yolIPIA/R08pkw/VnAbhoDLVoJsasCNPeQolC5V PU6X76ULL2Q2V3lpfE40lHW4EI0m/4VvU2EskAK048yFcG4kQg9+PCED7I8SRkSUAbYe11pCRxu Gp0oswpflQHRta3vu/Qfi6tFJ1vaJZyodXahwxuVcG2Gh09H58GRe/SM+X/kPg4QfP9tto7PQrt IlMAQonU2QtINGidGEGfqH93Z8k4W7iBx2D7sP65V14rAkttj0a2RQ9jxPWb7cOFBTM9u0nckgL 0hw4KFs3DEc1SKtXkgrFUY63hZdytFI9KAzmhpFz6HTbB9eU9dzjYaH34Bpv0kNfL+5XohLMd2V g2BCRMS+JV/FgN1WM+lWAQQ1yV3t/Zhdtib/nw== X-Received: by 2002:a05:600c:4292:b0:495:406f:dff6 with SMTP id 5b1f17b1804b1-4980c68e114mr998445e9.33.1785540936415; Fri, 31 Jul 2026 16:35:36 -0700 (PDT) Received: from localhost (nat-icclus-192-26-29-3.epfl.ch. [192.26.29.3]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47fd41d1756sm10260172f8f.4.2026.07.31.16.35.36 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 31 Jul 2026 16:35:36 -0700 (PDT) Precedence: bulk X-Mailing-List: linux-kselftest@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=UTF-8 Date: Sat, 01 Aug 2026 01:35:35 +0200 Message-Id: From: "Kumar Kartikeya Dwivedi" To: "David Windsor" , "Paul Moore" Cc: "Alexei Starovoitov" , "Daniel Borkmann" , "Andrii Nakryiko" , "Martin KaFai Lau" , "Eduard Zingerman" , "Song Liu" , "Yonghong Song" , "John Fastabend" , "KP Singh" , "Jiri Olsa" , "Emil Tsalapatis" , "James Morris" , "Serge E . Hallyn" , "Casey Schaufler" , "Stephen Smalley" , "Ondrej Mosnacek" , "Mimi Zohar" , "Roberto Sassu" , "Dmitry Kasatkin" , "Eric Snowberg" , "Alexander Viro" , "Christian Brauner" , "Jan Kara" , "Shuah Khan" , , , , , , , Subject: Re: [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling X-Mailer: aerc 0.21.0 References: <20260730234533.1912709-1-dwindsor@gmail.com> <20260730234533.1912709-4-dwindsor@gmail.com> In-Reply-To: On Sat Aug 1, 2026 at 1:34 AM CEST, Kumar Kartikeya Dwivedi wrote: > On Sat Aug 1, 2026 at 1:11 AM CEST, David Windsor wrote: >> On Fri, Jul 31, 2026 at 6:23=E2=80=AFPM Paul Moore = wrote: >>> >>> On Fri, Jul 31, 2026 at 6:04=E2=80=AFPM Kumar Kartikeya Dwivedi >>> wrote: >>> > On Fri Jul 31, 2026 at 11:49 PM CEST, Paul Moore wrote: >>> > > On Fri, Jul 31, 2026 at 5:29=E2=80=AFPM Kumar Kartikeya Dwivedi >>> > > wrote: >>> > >> On Fri Jul 31, 2026 at 10:48 PM CEST, Paul Moore wrote: >>> > >> > On Fri, Jul 31, 2026 at 4:16=E2=80=AFPM Kumar Kartikeya Dwivedi >>> > >> > wrote: >>> > >> >> On Fri Jul 31, 2026 at 10:01 PM CEST, Paul Moore wrote: >>> > >> >> > On Fri, Jul 31, 2026 at 3:20=E2=80=AFPM Kumar Kartikeya Dwive= di >>> > >> >> > wrote: >>> > >> >> >> On Fri Jul 31, 2026 at 9:05 PM CEST, Paul Moore wrote: >>> > >> >> >> > On Fri, Jul 31, 2026 at 2:50=E2=80=AFPM Kumar Kartikeya Dw= ivedi >>> > >> >> >> > wrote: >>> > >> >> >> >> On Fri Jul 31, 2026 at 8:42 PM CEST, Paul Moore wrote: >>> > >> >> >> >> > On Fri, Jul 31, 2026 at 2:18=E2=80=AFPM Kumar Kartikeya= Dwivedi >>> > >> >> >> >> > wrote: >>> > >> >> >> >> >> On Fri Jul 31, 2026 at 6:59 PM CEST, Paul Moore wrote: >>> > >> >> >> >> >> > On Fri, Jul 31, 2026 at 12:32=E2=80=AFPM Kumar Karti= keya Dwivedi >>> > >> >> >> >> >> > wrote: >>> > >> >> >> >> >> >> On Fri Jul 31, 2026 at 6:02 PM CEST, Paul Moore wro= te: >>> > >> >> >> >> >> >> > On Fri, Jul 31, 2026 at 11:44=E2=80=AFAM Kumar Ka= rtikeya Dwivedi >>> > >> >> >> >> >> >> > wrote: >>> > >> >> >> >> >> >> >> On Fri Jul 31, 2026 at 5:30 PM CEST, David Winds= or wrote: >>> > >> >> >> >> >> >> >> > On Fri, Jul 31, 2026 at 11:17=E2=80=AFAM Paul = Moore wrote: >>> >>> ... >>> >>> > As a consequence, everyone suffers because they first need to satisfy= your whims >>> > on how all code and kfuncs written thus far are wrong, and need to be= moved >>> > around ASAP, including the one being proposed. >>> >>> That's not a reasonble or truthful summary of things, I've only >>> requested that David locate his proposed kfunc in >>> security/bpf_lsm_kfuncs.c, I never suggested he move any others. >>> >> >> Looking at what's left of the kfunc itself, it's basically nothing. >> Everything meaningful has been moved into security/ already. >> >> Aside from bpf dynptr ops, what's left is: >> >> if (!name__str) >> return -EINVAL; >> > > You can actually lose this one, the verifier should prevent passing NULL = for > name__str. Other functions don't check it either. Feel free to check it, = or add .. and I meant, feel free to double check that passing NULL indeed fails ju= st in case. > a negative test in case you're worried about it. > >> if (strncmp(name__str, XATTR_BPF_LSM_SUFFIX, sizeof(XATTR_BPF_LSM_SUFFIX= ) - 1)) >> return -EPERM; >> >> if (!xattrs->xattrs) >> return -EOPNOTSUPP; >> >> ... then a call to security_lsmxattr_add. Why not move this chunk into >> security_lsmxattr_add, and leave the remaining bits, which are pure >> bpf, in fs/ for now, and litigate the total placement of all of them >> once v7 lands? >> > > I wouldn't bother, everything LSM specific is already where it belongs. = That > said, your question is a good demonstration of the absurdity of the ask h= ere. > >>> -- >>> paul-moore.com