[PATCH 01/14] VFS: Add additional RESOLVE_* flags [ver #18]
dhowells at redhat.com
Tue Mar 10 07:25:05 UTC 2020
Linus Torvalds <torvalds at linux-foundation.org> wrote:
> > > Also make openat2() handle RESOLVE_NO_TRAILING_SYMLINKS.
> No, please let's not do this.
> We have O_NOFOLLOW, and we can't get rid of it.
> So adding RESOLVE_NO_TRAILING_SYMLINKS isn't a cleanup. It's just
> extra complexity for absolutely zero gain.
Okay. So what's the equivalent of AT_SYMLINK_NOFOLLOW in RESOLVE_* flag
terms? RESOLVE_NO_SYMLINKS is not equivalent, though O_NOFOLLOW is. The
reason I ask is that RESOLVE_* flags can't be easily extended to non-open
syscalls that don't take O_* flags without it. Would you prefer that new
non-open syscalls continue to take AT_* and ignore RESOLVE_* flags? That
would be fine by me.
More information about the Linux-security-module-archive