Linux Security Modules development
 help / color / mirror / Atom feed
From: Christian Brauner <brauner@kernel.org>
To: linux-fsdevel@vger.kernel.org
Cc: Alexander Viro <viro@zeniv.linux.org.uk>, Jan Kara <jack@suse.cz>,
	 Christoph Hellwig <hch@lst.de>,
	Seth Forshee <sforshee@kernel.org>,
	 Paul Moore <paul@paul-moore.com>,
	linux-security-module@vger.kernel.org,
	 Mimi Zohar <zohar@linux.ibm.com>,
	linux-integrity@vger.kernel.org,
	 Ilya Dryomov <idryomov@gmail.com>,
	ceph-devel@vger.kernel.org,  Carlos Maiolino <cem@kernel.org>,
	linux-xfs@vger.kernel.org,  Miklos Szeredi <miklos@szeredi.hu>,
	Amir Goldstein <amir73il@gmail.com>,
	 linux-unionfs@vger.kernel.org,
	Namjae Jeon <linkinjeon@kernel.org>,
	 linux-cifs@vger.kernel.org, linux-kernel@vger.kernel.org,
	 "Christian Brauner (Amutable)" <brauner@kernel.org>
Subject: [PATCH 04/27] fs: port fs{g,u}id helpers to const mnt_idmap
Date: Tue, 01 Sep 2026 14:14:29 +0200	[thread overview]
Message-ID: <20260901-work-idmap-const-v1-4-54ccd48e100b@kernel.org> (raw)
In-Reply-To: <20260901-work-idmap-const-v1-0-54ccd48e100b@kernel.org>

Convert to const struct mnt_idmap.

A mount's idmapping is immutable. The only thing that is allowed to be
modified afterwards is the reference count and that is hidden behind
mnt_idmap_get() and mnt_idmap_put(). Everything else only ever reads
from the idmapping. This is the same model that struct cred uses and the
idmapping is also rather sensitive.

So make the idmap argument const wherever we can. The conversion is done
from the bottom up so callers can continue to pass a non-const pointer
to a const parameter until the conversion is finished.

No functional changes.

Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
---
 fs/ceph/mds_client.h          |  2 +-
 fs/fuse/dir.c                 | 13 +++++++------
 fs/fuse/fuse_i.h              |  4 ++--
 fs/fuse/req.c                 |  8 +++++---
 include/linux/fs.h            |  6 +++---
 include/linux/mnt_idmapping.h |  4 ++--
 6 files changed, 20 insertions(+), 17 deletions(-)

diff --git a/fs/ceph/mds_client.h b/fs/ceph/mds_client.h
index 3c62e3c3530b..1ac8a7e08e5c 100644
--- a/fs/ceph/mds_client.h
+++ b/fs/ceph/mds_client.h
@@ -375,7 +375,7 @@ struct ceph_mds_request {
 	int r_fmode;        /* file mode, if expecting cap */
 	int r_request_release_offset;
 	const struct cred *r_cred;
-	struct mnt_idmap *r_mnt_idmap;
+	const struct mnt_idmap *r_mnt_idmap;
 	struct timespec64 r_stamp;
 
 	/* for choosing which mds to send this request to */
diff --git a/fs/fuse/dir.c b/fs/fuse/dir.c
index 0d297f74c663..7a204f55ca84 100644
--- a/fs/fuse/dir.c
+++ b/fs/fuse/dir.c
@@ -820,7 +820,7 @@ static void free_ext_value(struct fuse_args *args)
  * If the filesystem doesn't support this, then fall back to separate
  * 'mknod' + 'open' requests.
  */
-static int fuse_create_open(struct mnt_idmap *idmap, struct inode *dir,
+static int fuse_create_open(const struct mnt_idmap *idmap, struct inode *dir,
 			    struct dentry *entry, struct file *file,
 			    unsigned int flags, umode_t mode, u32 opcode)
 {
@@ -980,7 +980,7 @@ static int fuse_atomic_open(struct inode *dir, struct dentry *entry,
 /*
  * Code shared between mknod, mkdir, symlink and link
  */
-static struct dentry *create_new_entry(struct mnt_idmap *idmap, struct fuse_mount *fm,
+static struct dentry *create_new_entry(const struct mnt_idmap *idmap, struct fuse_mount *fm,
 				       struct fuse_args *args, struct inode *dir,
 				       struct dentry *entry, umode_t mode)
 {
@@ -1053,7 +1053,7 @@ static struct dentry *create_new_entry(struct mnt_idmap *idmap, struct fuse_moun
 	return ERR_PTR(err);
 }
 
-static int create_new_nondir(struct mnt_idmap *idmap, struct fuse_mount *fm,
+static int create_new_nondir(const struct mnt_idmap *idmap, struct fuse_mount *fm,
 			     struct fuse_args *args, struct inode *dir,
 			     struct dentry *entry, umode_t mode)
 {
@@ -1256,9 +1256,10 @@ static int fuse_rmdir(struct inode *dir, struct dentry *entry)
 	return err;
 }
 
-static int fuse_rename_common(struct mnt_idmap *idmap, struct inode *olddir, struct dentry *oldent,
-			      struct inode *newdir, struct dentry *newent,
-			      unsigned int flags, int opcode, size_t argsize)
+static int fuse_rename_common(const struct mnt_idmap *idmap, struct inode *olddir,
+			      struct dentry *oldent, struct inode *newdir,
+			      struct dentry *newent, unsigned int flags,
+			      int opcode, size_t argsize)
 {
 	int err;
 	struct fuse_rename2_in inarg;
diff --git a/fs/fuse/fuse_i.h b/fs/fuse/fuse_i.h
index c8d4c5f3af7e..a07c75377a30 100644
--- a/fs/fuse/fuse_i.h
+++ b/fs/fuse/fuse_i.h
@@ -1003,7 +1003,7 @@ void __exit fuse_ctl_cleanup(void);
 /*
  * Simple request sending that does request allocation and freeing
  */
-ssize_t __fuse_simple_request(struct mnt_idmap *idmap,
+ssize_t __fuse_simple_request(const struct mnt_idmap *idmap,
 			      struct fuse_mount *fm,
 			      struct fuse_args *args);
 
@@ -1012,7 +1012,7 @@ static inline ssize_t fuse_simple_request(struct fuse_mount *fm, struct fuse_arg
 	return __fuse_simple_request(&invalid_mnt_idmap, fm, args);
 }
 
-static inline ssize_t fuse_simple_idmap_request(struct mnt_idmap *idmap,
+static inline ssize_t fuse_simple_idmap_request(const struct mnt_idmap *idmap,
 						struct fuse_mount *fm,
 						struct fuse_args *args)
 {
diff --git a/fs/fuse/req.c b/fs/fuse/req.c
index a01ee743d31e..a133b012d041 100644
--- a/fs/fuse/req.c
+++ b/fs/fuse/req.c
@@ -3,7 +3,8 @@
 #include "dev.h"
 #include "fuse_i.h"
 
-static int fuse_fill_creds(struct fuse_mount *fm, struct fuse_args *args, struct mnt_idmap *idmap)
+static int fuse_fill_creds(struct fuse_mount *fm, struct fuse_args *args,
+			   const struct mnt_idmap *idmap)
 {
 	struct fuse_conn *fc = fm->fc;
 	bool no_idmap = !fm->sb || (fm->sb->s_iflags & SB_I_NOIDMAP);
@@ -49,7 +50,8 @@ static int fuse_fill_creds(struct fuse_mount *fm, struct fuse_args *args, struct
 	return 0;
 }
 
-static int fuse_req_prep(struct fuse_mount *fm, struct fuse_args *args, struct mnt_idmap *idmap)
+static int fuse_req_prep(struct fuse_mount *fm, struct fuse_args *args,
+			 const struct mnt_idmap *idmap)
 {
 	if (!args->force && fm->fc->conn_error)
 		return -ECONNREFUSED;
@@ -57,7 +59,7 @@ static int fuse_req_prep(struct fuse_mount *fm, struct fuse_args *args, struct m
 	return fuse_fill_creds(fm, args, idmap);
 }
 
-ssize_t __fuse_simple_request(struct mnt_idmap *idmap, struct fuse_mount *fm,
+ssize_t __fuse_simple_request(const struct mnt_idmap *idmap, struct fuse_mount *fm,
 			      struct fuse_args *args)
 {
 	struct fuse_conn *fc = fm->fc;
diff --git a/include/linux/fs.h b/include/linux/fs.h
index f9d1e05e8ae6..959c747ef75a 100644
--- a/include/linux/fs.h
+++ b/include/linux/fs.h
@@ -1544,7 +1544,7 @@ static inline void i_gid_update(struct mnt_idmap *idmap,
  * an idmapped mount map the caller's fsuid according to @idmap.
  */
 static inline void inode_fsuid_set(struct inode *inode,
-				   struct mnt_idmap *idmap)
+				   const struct mnt_idmap *idmap)
 {
 	inode->i_uid = mapped_fsuid(idmap, i_user_ns(inode));
 }
@@ -1558,7 +1558,7 @@ static inline void inode_fsuid_set(struct inode *inode,
  * an idmapped mount map the caller's fsgid according to @idmap.
  */
 static inline void inode_fsgid_set(struct inode *inode,
-				   struct mnt_idmap *idmap)
+				   const struct mnt_idmap *idmap)
 {
 	inode->i_gid = mapped_fsgid(idmap, i_user_ns(inode));
 }
@@ -1575,7 +1575,7 @@ static inline void inode_fsgid_set(struct inode *inode,
  * Return: true if fsuid and fsgid is mapped, false if not.
  */
 static inline bool fsuidgid_has_mapping(struct super_block *sb,
-					struct mnt_idmap *idmap)
+					const struct mnt_idmap *idmap)
 {
 	struct user_namespace *fs_userns = sb->s_user_ns;
 	kuid_t kuid;
diff --git a/include/linux/mnt_idmapping.h b/include/linux/mnt_idmapping.h
index b16f52d27ba0..6656aea23be2 100644
--- a/include/linux/mnt_idmapping.h
+++ b/include/linux/mnt_idmapping.h
@@ -225,7 +225,7 @@ static inline kgid_t vfsgid_into_kgid(vfsgid_t vfsgid)
  *
  * Return: the caller's current fsuid mapped up according to @idmap.
  */
-static inline kuid_t mapped_fsuid(struct mnt_idmap *idmap,
+static inline kuid_t mapped_fsuid(const struct mnt_idmap *idmap,
 				  struct user_namespace *fs_userns)
 {
 	return from_vfsuid(idmap, fs_userns, VFSUIDT_INIT(current_fsuid()));
@@ -244,7 +244,7 @@ static inline kuid_t mapped_fsuid(struct mnt_idmap *idmap,
  *
  * Return: the caller's current fsgid mapped up according to @idmap.
  */
-static inline kgid_t mapped_fsgid(struct mnt_idmap *idmap,
+static inline kgid_t mapped_fsgid(const struct mnt_idmap *idmap,
 				  struct user_namespace *fs_userns)
 {
 	return from_vfsgid(idmap, fs_userns, VFSGIDT_INIT(current_fsgid()));

-- 
2.53.0


  parent reply	other threads:[~2026-09-01 12:15 UTC|newest]

Thread overview: 62+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-01 12:14 [PATCH 00/27] fs: port to const struct mnt_idmap Christian Brauner
2026-09-01 12:14 ` [PATCH 01/27] userns: pass const uid_gid_map in lookup helpers Christian Brauner
2026-09-02 14:06   ` Jan Kara
2026-09-01 12:14 ` [PATCH 02/27] fs: port mnt_idmap_{get,put}() to const mnt_idmap Christian Brauner
2026-09-02 14:08   ` Jan Kara
2026-09-01 12:14 ` [PATCH 03/27] fs: port vfs{g,u}id helpers " Christian Brauner
2026-09-02 14:11   ` Jan Kara
2026-09-01 12:14 ` Christian Brauner [this message]
2026-09-02 14:13   ` [PATCH 04/27] fs: port fs{g,u}id " Jan Kara
2026-09-01 12:14 ` [PATCH 05/27] fs: port i_{g,u}id_into_vfs{g,u}id() " Christian Brauner
2026-09-02 14:14   ` Jan Kara
2026-09-01 12:14 ` [PATCH 06/27] fs: port i_{g,u}id_{needs_}update() " Christian Brauner
2026-09-02 14:15   ` Jan Kara
2026-09-01 12:14 ` [PATCH 07/27] quota: port " Christian Brauner
2026-09-02 14:16   ` Jan Kara
2026-09-01 12:14 ` [PATCH 08/27] fs: port privilege checking helpers " Christian Brauner
2026-09-02 14:17   ` Jan Kara
2026-09-01 12:14 ` [PATCH 09/27] fs: port inode_owner_or_capable() " Christian Brauner
2026-09-02 14:18   ` Jan Kara
2026-09-01 12:14 ` [PATCH 10/27] fs: port inode_init_owner() " Christian Brauner
2026-09-02 14:20   ` Jan Kara
2026-09-01 12:14 ` [PATCH 11/27] fs: port acl " Christian Brauner
2026-09-02 14:22   ` Jan Kara
2026-09-02 19:34   ` Paul Moore
2026-09-01 12:14 ` [PATCH 12/27] fs: port ->permission() to pass " Christian Brauner
2026-09-02 15:38   ` Jan Kara
2026-09-02 19:34   ` Paul Moore
2026-09-01 12:14 ` [PATCH 13/27] fs: port xattr to " Christian Brauner
2026-09-02 15:42   ` Jan Kara
2026-09-02 19:34   ` Paul Moore
2026-09-01 12:14 ` [PATCH 14/27] fs: port ->fileattr_set() to pass " Christian Brauner
2026-09-02 15:43   ` Jan Kara
2026-09-01 12:14 ` [PATCH 15/27] fs: port ->set_acl() " Christian Brauner
2026-09-02 15:45   ` Jan Kara
2026-09-01 12:14 ` [PATCH 16/27] fs: port ->get_acl() " Christian Brauner
2026-09-02 15:45   ` Jan Kara
2026-09-01 12:14 ` [PATCH 17/27] fs: port ->tmpfile() " Christian Brauner
2026-09-02 15:47   ` Jan Kara
2026-09-02 19:34   ` Paul Moore
2026-09-01 12:14 ` [PATCH 18/27] fs: port ->mknod() " Christian Brauner
2026-09-02 15:49   ` Jan Kara
2026-09-02 19:34   ` Paul Moore
2026-09-01 12:14 ` [PATCH 19/27] fs: port ->rename() " Christian Brauner
2026-09-02 15:50   ` Jan Kara
2026-09-01 12:14 ` [PATCH 20/27] fs: port ->mkdir() " Christian Brauner
2026-09-02 15:52   ` Jan Kara
2026-09-01 12:14 ` [PATCH 21/27] fs: port ->symlink() " Christian Brauner
2026-09-02 15:53   ` Jan Kara
2026-09-01 12:14 ` [PATCH 22/27] fs: port ->create() " Christian Brauner
2026-09-02 15:55   ` Jan Kara
2026-09-01 12:14 ` [PATCH 23/27] fs: port ->getattr() " Christian Brauner
2026-09-02 15:58   ` Jan Kara
2026-09-01 12:14 ` [PATCH 24/27] fs: port ->setattr() " Christian Brauner
2026-09-01 15:53   ` Casey Schaufler
2026-09-02 16:01   ` Jan Kara
2026-09-02 19:34   ` Paul Moore
2026-09-01 12:14 ` [PATCH 25/27] fs: port vfs_*() helpers to " Christian Brauner
2026-09-02 16:02   ` Jan Kara
2026-09-01 12:14 ` [PATCH 26/27] fs: port mnt_idmap() and file_mnt_idmap() " Christian Brauner
2026-09-02 16:06   ` Jan Kara
2026-09-01 12:14 ` [PATCH 27/27] fs: make nop_mnt_idmap and invalid_mnt_idmap const Christian Brauner
2026-09-02 16:07   ` Jan Kara

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260901-work-idmap-const-v1-4-54ccd48e100b@kernel.org \
    --to=brauner@kernel.org \
    --cc=amir73il@gmail.com \
    --cc=cem@kernel.org \
    --cc=ceph-devel@vger.kernel.org \
    --cc=hch@lst.de \
    --cc=idryomov@gmail.com \
    --cc=jack@suse.cz \
    --cc=linkinjeon@kernel.org \
    --cc=linux-cifs@vger.kernel.org \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-integrity@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=linux-unionfs@vger.kernel.org \
    --cc=linux-xfs@vger.kernel.org \
    --cc=miklos@szeredi.hu \
    --cc=paul@paul-moore.com \
    --cc=sforshee@kernel.org \
    --cc=viro@zeniv.linux.org.uk \
    --cc=zohar@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox