From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from relay.hostedemail.com (smtprelay0015.hostedemail.com [216.40.44.15]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 326B3430CF9; Thu, 6 Aug 2026 22:30:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=216.40.44.15 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786055450; cv=none; b=d0oP1xstUqxydulVYvyB7mEP9EB/cNPcX6va4YADQqxsILVhrRfjqhpsooCYbbHUTFrGvi9RH1zydPwAttj9WHuuwtz2j63q7riywcsiXCAPCV0v2JtHzUgYp+xPwEWOMyme6HuYSlWT9m1ceW4GfGJo0n/1yIaDLHMACfr9cP8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786055450; c=relaxed/simple; bh=qyHVJJ1Np197evupjuCDw3AOO9nsqP38d1h6nU3H+Dw=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=gtBw831YBIhMWzPXWIBg8NkvEDdk9OzIC+llQ+y+i/lnHyvm9AwJXNAT22sM44fH/CKjnyVhUQYiHoTSK20/ToY3cXyT1AbaI0F0M7x4u1Z9M7wM8GwB4U+FNvE7mgXFycwyqqxZdA4a2TzqKDW1bhGVM7IgIJ+dU2tArq4xgnY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=groves.net; spf=pass smtp.mailfrom=groves.net; arc=none smtp.client-ip=216.40.44.15 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=groves.net Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=groves.net Received: from omf15.hostedemail.com (lb01a-stub [10.200.18.249]) by unirelay04.hostedemail.com (Postfix) with ESMTP id DC8A01A0558; Thu, 6 Aug 2026 22:30:43 +0000 (UTC) Received: from [HIDDEN] (Authenticated sender: john@groves.net) by omf15.hostedemail.com (Postfix) with ESMTPA id B1F551B; Thu, 6 Aug 2026 22:30:27 +0000 (UTC) Date: Thu, 6 Aug 2026 17:30:26 -0500 From: John Groves To: "Darrick J. Wong" Cc: John Groves , Miklos Szeredi , Dan Williams , Bernd Schubert , Alison Schofield , John Groves , Jonathan Corbet , Jake Edge , Shuah Khan , Vishal Verma , Dave Jiang , Matthew Wilcox , Jan Kara , Alexander Viro , David Hildenbrand , Christian Brauner , Randy Dunlap , Jeff Layton , Amir Goldstein , Jonathan Cameron , Stefan Hajnoczi , Joanne Koong , Josef Bacik , Bagas Sanjaya , Chen Linxuan , James Morse , Fuad Tabba , Sean Christopherson , Shivank Garg , Ackerley Tng , Gregory Price , Andrew Morton , Namjae Jeon , Lorenzo Stoakes , Greg Kroah-Hartman , Ira Weiny , Pasha Tatashin , Haren Myneni , Pratyush Yadav , Giovanni Cabiddu , Jiri Slaby , Ethan Nelson-Moore , Gabriel Whigham , Aravind Ramesh , Ajay Joshi , "venkataravis@micron.com" , "linux-doc@vger.kernel.org" , "linux-kernel@vger.kernel.org" , "nvdimm@lists.linux.dev" , "linux-cxl@vger.kernel.org" , "linux-fsdevel@vger.kernel.org" , "fuse-devel@lists.linux.dev" Subject: Re: [PATCH V12 10/12] famfs: Add runtime operation-permission (opts) framework Message-ID: References: <0100019fc572ca94-ec363dd7-3a77-484b-b4b7-f2503a0931a6-000000@email.amazonses.com> <20260803022950.75930-1-john@jagalactic.com> <0100019fc574dabe-572d99fc-3bb0-421a-afec-05432de2a757-000000@email.amazonses.com> <20260806053100.GJ3560084@frogsfrogsfrogs> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20260806053100.GJ3560084@frogsfrogsfrogs> X-Stat-Signature: bw5em5g91hg913xpaesgugrouo4wrfn9 X-Rspamd-Server: rspamout06 X-Rspamd-Queue-Id: B1F551B X-Session-Marker: 6A6F686E4067726F7665732E6E6574 X-Session-ID: U2FsdGVkX19JCa/3povowe+DVCaTZremTyrvXzE9dnQ= X-HE-Tag: 1786055427-275828 X-HE-Meta: U2FsdGVkX19kEufDJVAy1gAj6uX2nDLCMmpAAN6usy3i1o+xi9PabxL+EioG4DkZXPut0+l8QSWoMAI3GpyQVamkZYvkiIf0/ZrhbwCamP2Bn7uXlbwx/m0WCdq5TaB/klmYruBqb+w85tYTPKSaW2J4uznKsgho/Y0ChfhKuc6JRG21vYVJGSZPvtvGXKIIrbMDgyuEVaYAS9AQ0VXNOOW9fUKpE2pboIcdZpuZaIDcguVWUExVC3d1axI8+sUl2q6zUhaJYeCKCRWI5FrXSnExsHx7SqBaOguD71asvanO+3QVIDwcfV3OxywzVd3pRmdY5gx/oUx601TQ5cF27dxii60aVlQ8DcTrGrRchmAN9zlorO5H1Eu7Nf9fXjkk On 26/08/05 10:31PM, Darrick J. Wong wrote: > On Mon, Aug 03, 2026 at 02:29:57AM +0000, John Groves wrote: > > From: John Groves > > > > famfs denies most namespace, attribute and data operations by default > > because the userspace log, not the kernel, is authoritative for a famfs > > instance. Earlier commits already guard each such operation with a > > famfs_opt_enabled(fsi, FAMFS_OPT_x) check backed by a permissive stub. This > > commit defines the permission bitmap and makes those checks live. > > Why would it ever be acceptable for user programs to mess with the > directory tree and file attributes? There's nothing here that would > seem to write to the userspace log. Or am I mistaken, and only the > program that maintains the userspace log (e.g. the famfs server) can do > these kinds of operations? > > --D Mostly it's the code that maintains the log that needs to create stub files and then pass in fmaps (MAP_CREATE). Changes made via the "front door" of a mount are ephemeral, but allowing them can have practical value (e.g. allowing chown/chmod, which people actually seem to need to do sometimes. Also at one point a user sent me a patch enabling symlink creation, because some software needed that.) But you're right that any changes we do allow are ephemeral (not logged). Thanks! John