From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yx1-f45.google.com (mail-yx1-f45.google.com [74.125.224.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4F0703DFC6D for ; Wed, 5 Aug 2026 21:37:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.224.45 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965831; cv=none; b=s2hcZuopsyEzVxXzim8vrEF2Dcvfa4widEq04v8JL0PLssEeoF4cY3dkOMzJxyBp38pkNR/crklh35/QWoMkLYMwQAt3lOJUuB2+SRAL+YQKdwsHd8iCtBS3VYL6IfFOQ6Ch7Y8KoRr/0jcwKeTKj24+/ghjhwPMazeXVeyURmw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965831; c=relaxed/simple; bh=ybn3edS75210yGXHR8plER5wB6+bwq7DsJxlu+7rHU4=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=CQbnB9rGbKvxVtoNlXkyl5+BvMHgZeViBBgkrFDv9K4EpGrmAPAHdmraiFJWdCikDrDVdSliqMGrR7tyiLL4C/ANMuNaiKwaKHG8my9rhFTztaL6zaAqBe1N21QLmdwwn8Rf84HaAdQ5zSfa7I4EmYE+/hj9pgQShx5PRG10/Yc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Q3QAhSxu; arc=none smtp.client-ip=74.125.224.45 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Q3QAhSxu" Received: by mail-yx1-f45.google.com with SMTP id 956f58d0204a3-668432fe416so2104929d50.0 for ; Wed, 05 Aug 2026 14:37:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785965829; x=1786570629; darn=vger.kernel.org; h=in-reply-to:content-transfer-encoding:content-disposition :content-type:mime-version:references:message-id:subject:cc:to:from :date:from:to:cc:subject:date:message-id:reply-to:content-type; bh=eJ/f/QQNT6OWCbAu3IB8DxQ9ZnyppnwIAD+QIRJse9g=; b=Q3QAhSxuHwF7ThIMUDCku95Bjrooo3TnufEF2rcHFZ+wuvrYOiHwkbqZ1HoEY+coXz t14yH0GezNHRgvxBa+xE7pt3tmn/QamWFuad4SvsRCMsa8/PtKI5r9t3GkNGLSBdaOlg UTgA8AdytrBwtXeUWNueYCuez+ZP0YUzeRxpweA5dRcGQWGfXkBHxr9h/51vRw0V7f1w v52TUIBu7GWrdPpjU3tEEsjG0+2tm3Rk9yJoZKifXM50F5/IyH7hIfuBHPhPpsfPUDlT Qk8/SdPe3eb3Eg+J5i/e6wYyyNkqOtGCn1SgZfk7L8+ZbkdfxgLxzvwqPMjx2B3SqOp8 YW6w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785965829; x=1786570629; h=in-reply-to:content-transfer-encoding:content-disposition :content-type:mime-version:references:message-id:subject:cc:to:from :date:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=eJ/f/QQNT6OWCbAu3IB8DxQ9ZnyppnwIAD+QIRJse9g=; b=A5pKpxx/21a4DYMVB+DH77ylZ+rhFoqXVGaymlc46JFH0zz2n0pZoYAuGJZJID1KU5 g8WVDEN+Sy54d5Lk+QR1ZQj0v7fV+L9OM83xnboBLN6jIbiJ8ohTDtKV9TwEVdpdbtZD wjlO+hijVbzz5LTFvnFsfixK715gcwUGaV52RbFhERG0/Ay20KhOn3Xb4dE5ZZhWS9oX QKKkYdczUkJoZ0FJ+J6xwZTfhcKfvnh/kgGPZ/x4ju5nQuTi7/0o7BeGQfmuc+ZxUkfL yY0ab/uo6F6h30mGGvB5P/Hu7ROKeIxNeah0HhZbZHLKGzWlzg9wzkOAM8YBiURDZXsJ G18w== X-Forwarded-Encrypted: i=1; AHgh+Rr0ZjxaWhFNmx7zv4c2Dl4RbuzHYARVzR5sP+FeluJ2uePVeex1vgjvQ6fdcSH//YJpTs2iAaZwlbo+h7w=@vger.kernel.org X-Gm-Message-State: AOJu0YxYW0R13LTepS4YberaRYZcO8FJJRNt+PNuHU8GDDvq0yXAnIu9 Rp7OdXuJaO3IflqMsyl+n2nZYu7dYvRj55TC2PnPv5NNvN2Y+TyoKV4K X-Gm-Gg: AR+sD11Udl6A+0IcQGT283qYgrWabzzweUi1bxSP/jd57CLYgXq/iJb2ssqxmqplHPE Q0xo/qG1BDQ6BqnLZxk+g1sJeRpWhOr/F70p/x4VTQ/8IAbckIXpYqPcWw6V8uNzHUOlFYbw8EU A6JnWZ+GVBmSdZ7p4/qTWHc3aJ4PebLwQQL7lZQpSL5BPhdzX3MOuoRxrASCyd4ERGoBYyjYApV RQzhnnlWOFEt/j+umQHp5d4wWPjwcBR03G/Gkt2N2CEHK+oDSphTjgUoETs/HXqG3fmKpY2sPm6 47GYSfTYu77QJu2ruBdib3jiNm2MFRBoFOmFSx//FEMs8pmUuRaa6SgqPi6skLTxVP5B2WlfMNm OPDVhOls+pvi//BP3Xm2Qv+8FsxLfzwQ60GzkeoXTcCQYzWyxhWg3DlvIxMpcA51TRaXdCthPRY vD41mcEzwgKdLJ7pEhLIB0y6KXqYbJ++VOjPQZjxXfOaoSuuGlNRhk5lEF6p/jwZ4tO1BQp4Gq0 q+8ZX9IB6pQoNASO0QQF+VH+0nuTs/Mpg== X-Received: by 2002:a53:b427:0:b0:667:9d0c:5b80 with SMTP id 956f58d0204a3-6699ac4ef5amr4215598d50.28.1785965828960; Wed, 05 Aug 2026 14:37:08 -0700 (PDT) Received: from zenbox ([2600:1700:18fb:6011:7d5b:ac23:cde9:3664]) by smtp.gmail.com with ESMTPSA id 956f58d0204a3-669915f5a75sm3862542d50.11.2026.08.05.14.37.08 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 05 Aug 2026 14:37:08 -0700 (PDT) Date: Wed, 5 Aug 2026 17:37:07 -0400 From: Justin Suess To: Paul Moore Cc: ast@kernel.org, daniel@iogearbox.net, andrii@kernel.org, kpsingh@kernel.org, mic@digikod.net, viro@zeniv.linux.org.uk, brauner@kernel.org, kees@kernel.org, gnoack@google.com, jack@suse.cz, song@kernel.org, yonghong.song@linux.dev, martin.lau@linux.dev, m@maowtm.org, bpf@vger.kernel.org, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org Subject: Re: [PATCH bpf-next 00/13] BPF interface for applying Landlock rulesets Message-ID: References: <20260731022047.189137-1-utilityemal77@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: On Fri, Jul 31, 2026 at 04:30:39PM -0400, Paul Moore wrote: > On Thu, Jul 30, 2026 at 10:21 PM Justin Suess wrote: > [...] > As you may, or may not have seen, there is currently an ongoing debate > regarding the location of LSM kfuncs that will impact this patchset. > Sadly, we don't appear to be approaching an agreement on this issue > which introduces some additional risk to this patchset. We'll have to > see how that ends up, but I just wanted you to be aware of the > situation. Quick aside question: Would security/bpf/ be a better place for these type of kfuncs? security/bpf/bpf_lsm_kfuncs.c could be for LSM framework kfuncs, and each LSM could maintain their own security/bpf/_kfuncs.c for kfuncs dealing with lsm-specific types. One issue with just security/ is it's not CONFIG_SECURITY_BPF. But security/bpf is. Right now security/bpf only has hooks.c so it's free real estate. That way things are more greppable... (important!) and we can have proper MAINTAINERS entries per file so emails get routed properly. (linux-security-module, bpf, and whatever lsm list) Justin