The Linux Kernel Mailing List
 help / color / mirror / Atom feed
From: "Mickaël Salaün" <mic@digikod.net>
To: Paul Moore <paul@paul-moore.com>
Cc: "Christian Brauner" <brauner@kernel.org>,
	"Günther Noack" <gnoack@google.com>,
	"Serge E . Hallyn" <serge@hallyn.com>,
	"Daniel Durning" <danieldurning.work@gmail.com>,
	"Jonathan Corbet" <corbet@lwn.net>,
	"Justin Suess" <utilityemal77@gmail.com>,
	"Lennart Poettering" <lennart@poettering.net>,
	"Mikhail Ivanov" <ivanov.mikhail1@huawei-partners.com>,
	"Nicolas Bouchinet" <nicolas.bouchinet@oss.cyber.gouv.fr>,
	"Shervin Oloumi" <enlightened@google.com>,
	"Tingmao Wang" <m@maowtm.org>,
	kernel-team@cloudflare.com, linux-fsdevel@vger.kernel.org,
	linux-kernel@vger.kernel.org,
	linux-security-module@vger.kernel.org
Subject: Re: [PATCH v2 1/9] security: add LSM blob and hooks for namespaces
Date: Fri, 24 Jul 2026 11:25:52 +0200	[thread overview]
Message-ID: <20260724.raec1Roo6iox@digikod.net> (raw)
In-Reply-To: <CAHC9VhSrYUWkt0_kbOdEuoeKdj+oSaFcY0Fg8t2SuUwH-=MJXA@mail.gmail.com>

On Fri, Jul 10, 2026 at 04:42:58PM -0400, Paul Moore wrote:
> On Thu, Jul 9, 2026 at 11:58 AM Mickaël Salaün <mic@digikod.net> wrote:
> > On Thu, Jul 09, 2026 at 09:03:58AM -0400, Paul Moore wrote:
> > > On Thu, Jul 9, 2026 at 5:12 AM Mickaël Salaün <mic@digikod.net> wrote:
> > > > On Wed, Jul 08, 2026 at 11:22:17PM -0400, Paul Moore wrote:
> > > > > On May 27, 2026 =?UTF-8?q?Micka=C3=ABl=20Sala=C3=BCn?= <mic@digikod.net> wrote:
> 
> ...
> 
> > > I'm aware of the new hook guidance, I was the one who documented it :)
> >
> > I know.  I guess that means you're ok with that?
> 
> Yes.

Thanks.  I applied your suggestions wrt comments and patch split for v3.

> 
> Just a heads-up, and some of this depends on timing, but as we've got
> multiple patchsets (there is a SELinux patchset that depends on these
> hooks) I'll want to take this hook additions via the LSM tree.  I can
> take the associated Landlock patches too if you like, or you base the
> Landlock tree off the LSM branch; no worries either way, we can sort
> out the details once the patchset is ready for merging.

If it's all right with you, I'd prefer to carry the LSM hook patches in
the Landlock tree this cycle, so the whole namespace/capability series
stays a single consistent set of commits.  I also have ongoing Landlock
work (e.g. tracepoints) that needs to build on these hooks, which is
easier to manage with them on landlock-next.

That shouldn't hold up the SELinux side: if those patches aren't in a
hurry, letting the hooks stay in the -next branch until the next merge
window also give them some time to get a broader set of checks.  Happy
to revisit if the timing gets tight on your end.

  reply	other threads:[~2026-07-24  9:26 UTC|newest]

Thread overview: 22+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-05-27 18:11 [PATCH v2 0/9] Landlock: Namespace and capability control Mickaël Salaün
2026-05-27 18:11 ` [PATCH v2 1/9] security: add LSM blob and hooks for namespaces Mickaël Salaün
2026-06-05 15:06   ` Mickaël Salaün
2026-06-05 18:08     ` Paul Moore
2026-07-09  3:22   ` Paul Moore
2026-07-09  9:12     ` Mickaël Salaün
2026-07-09 13:03       ` Paul Moore
2026-07-09 15:58         ` Mickaël Salaün
2026-07-10  6:55           ` Christian Brauner
2026-07-24  9:24             ` Mickaël Salaün
2026-07-10 20:42           ` Paul Moore
2026-07-24  9:25             ` Mickaël Salaün [this message]
2026-05-27 18:11 ` [PATCH v2 2/9] security: Add LSM_AUDIT_DATA_NS for namespace audit records Mickaël Salaün
2026-05-27 18:11 ` [PATCH v2 3/9] landlock: Wrap per-layer access masks in struct layer_config Mickaël Salaün
2026-05-27 18:11 ` [PATCH v2 4/9] landlock: Enforce namespace use restrictions Mickaël Salaün
2026-05-27 18:11 ` [PATCH v2 5/9] landlock: Enforce capability restrictions Mickaël Salaün
2026-05-27 18:11 ` [PATCH v2 6/9] selftests/landlock: Add namespace restriction tests Mickaël Salaün
2026-05-27 18:11 ` [PATCH v2 7/9] selftests/landlock: Add capability " Mickaël Salaün
2026-05-27 18:11 ` [PATCH v2 8/9] samples/landlock: Add capability and namespace restriction support Mickaël Salaün
2026-05-27 18:11 ` [PATCH v2 9/9] landlock: Add documentation for capability and namespace restrictions Mickaël Salaün
2026-06-01  9:37   ` Günther Noack
2026-07-24  9:26     ` Mickaël Salaün

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260724.raec1Roo6iox@digikod.net \
    --to=mic@digikod.net \
    --cc=brauner@kernel.org \
    --cc=corbet@lwn.net \
    --cc=danieldurning.work@gmail.com \
    --cc=enlightened@google.com \
    --cc=gnoack@google.com \
    --cc=ivanov.mikhail1@huawei-partners.com \
    --cc=kernel-team@cloudflare.com \
    --cc=lennart@poettering.net \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=m@maowtm.org \
    --cc=nicolas.bouchinet@oss.cyber.gouv.fr \
    --cc=paul@paul-moore.com \
    --cc=serge@hallyn.com \
    --cc=utilityemal77@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox