lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Fri,  5 Jan 2024 13:49:30 +0100
From: Christian Brauner <brauner@...nel.org>
To: Linus Torvalds <torvalds@...ux-foundation.org>
Cc: Christian Brauner <brauner@...nel.org>,
	linux-fsdevel@...r.kernel.org,
	linux-kernel@...r.kernel.org
Subject: [GIT PULL] vfs rw updates

Hey Linus,

Based on the discussions at Maintainer's Summit I've encouraged relevant people
to provide pulls if they feel comfortable doing so. So this contains a pull
from Amir for read-write backing file helpers for stacking filesystems such as
overlayfs.

/* Summary */
* Fanotify is currently in the process of introducing pre content events.
  Roughly, a new permission event will be added indicating that it is safe to
  write to the file being accessed. These events are used by hierarchical
  storage managers to e.g., fill the content of files on first access.

  During that work we noticed that our current permission checking is
  inconsistent in rw_verify_area() and remap_verify_area(). Especially in the
  splice code permission checking is done multiple times. For example, one time
  for the whole range and then again for partial ranges inside the iterator.

  In addition, we mostly do permission checking before we call
  file_start_write() except for a few places where we call it after. For
  pre-content events we need such permission checking to be done before
  file_start_write(). So this is a nice reason to clean this all up.

  After this series, all permission checking is done before file_start_write().

  As part of this cleanup we also massaged the splice code a bit. We got rid of
  a few helpers because we are alredy drowning in special read-write helpers.
  We also cleaned up the return types for splice helpers.

* Introduce generic read-write helpers for backing files. This lifts some
  overlayfs code to common code so it can be used by the FUSE passthrough work
  coming in over the next cycles. Make Amir and Miklos the maintainers for this
  new subsystem of the vfs.

/* Testing */
clang: Debian clang version 16.0.6 (19)
gcc: (Debian 13.2.0-7) 13.2.0

All patches are based on v6.7-rc1 and have been sitting in linux-next.
No build failures or warnings were observed.

/* Conflicts */
At the time of creating this PR no merge conflicts were reported from
linux-next and no merge conflicts showed up doing a test-merge with
current mainline.

The following changes since commit b85ea95d086471afb4ad062012a4d73cd328fa86:

  Linux 6.7-rc1 (2023-11-12 16:19:07 -0800)

are available in the Git repository at:

  git@...olite.kernel.org:pub/scm/linux/kernel/git/vfs/vfs tags/vfs-6.8.rw

for you to fetch changes up to c39e2ae3943d4ee278af4e1b1dcfd5946da1089b:

  fs: fix __sb_write_started() kerneldoc formatting (2023-12-28 11:40:40 +0100)

Please consider pulling these changes from the signed vfs-6.8.rw tag.

Happy New Year!
Christian

----------------------------------------------------------------
vfs-6.8.rw

----------------------------------------------------------------
Amir Goldstein (29):
      scsi: target: core: add missing file_{start,end}_write()
      ovl: add permission hooks outside of do_splice_direct()
      splice: remove permission hook from do_splice_direct()
      splice: move permission hook out of splice_direct_to_actor()
      splice: move permission hook out of splice_file_to_pipe()
      splice: remove permission hook from iter_file_splice_write()
      remap_range: move permission hooks out of do_clone_file_range()
      remap_range: move file_start_write() to after permission hook
      btrfs: move file_start_write() to after permission hook
      coda: change locking order in coda_file_write_iter()
      fs: move file_start_write() into vfs_iter_write()
      fs: move permission hook out of do_iter_write()
      fs: move permission hook out of do_iter_read()
      fs: move kiocb_start_write() into vfs_iocb_iter_write()
      fs: create __sb_write_started() helper
      fs: create file_write_started() helper
      fs: create {sb,file}_write_not_started() helpers
      fs: fork splice_file_range() from do_splice_direct()
      fs: move file_start_write() into direct_splice_actor()
      fs: use do_splice_direct() for nfsd/ksmbd server-side-copy
      splice: return type ssize_t from all helpers
      fs: use splice_copy_file_range() inline helper
      fsnotify: split fsnotify_perm() into two hooks
      fsnotify: assert that file_start_write() is not held in permission hooks
      fsnotify: optionally pass access range in file permission hooks
      fs: prepare for stackable filesystems backing file helpers
      fs: factor out backing_file_{read,write}_iter() helpers
      fs: factor out backing_file_splice_{read,write}() helpers
      fs: factor out backing_file_mmap() helper

Christian Brauner (1):
      Merge tag 'ovl-vfs-6.8' of ssh://gitolite.kernel.org/pub/scm/linux/kernel/git/overlayfs/vfs

Vegard Nossum (1):
      fs: fix __sb_write_started() kerneldoc formatting

 MAINTAINERS                  |   9 ++
 drivers/block/loop.c         |   2 -
 fs/Kconfig                   |   4 +
 fs/Makefile                  |   1 +
 fs/backing-file.c            | 336 +++++++++++++++++++++++++++++++++++++++++++
 fs/btrfs/ioctl.c             |  12 +-
 fs/cachefiles/io.c           |   5 +-
 fs/ceph/file.c               |  13 +-
 fs/coda/file.c               |   2 -
 fs/fuse/file.c               |   5 +-
 fs/internal.h                |   8 +-
 fs/nfs/nfs4file.c            |   5 +-
 fs/nfsd/vfs.c                |   7 +-
 fs/open.c                    |  42 +-----
 fs/overlayfs/Kconfig         |   1 +
 fs/overlayfs/copy_up.c       |  30 +++-
 fs/overlayfs/file.c          | 247 +++++--------------------------
 fs/overlayfs/overlayfs.h     |   8 +-
 fs/overlayfs/super.c         |  11 +-
 fs/read_write.c              | 235 ++++++++++++++++--------------
 fs/readdir.c                 |   4 +
 fs/remap_range.c             |  45 +++---
 fs/smb/client/cifsfs.c       |   5 +-
 fs/splice.c                  | 243 +++++++++++++++++++------------
 include/linux/backing-file.h |  42 ++++++
 include/linux/fs.h           |  71 +++++++--
 include/linux/fsnotify.h     |  50 +++++--
 include/linux/splice.h       |  51 ++++---
 io_uring/splice.c            |   4 +-
 security/security.c          |  10 +-
 30 files changed, 941 insertions(+), 567 deletions(-)
 create mode 100644 fs/backing-file.c
 create mode 100644 include/linux/backing-file.h

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ