[PATCH bpf-next 0/4] Introduce bpf_kernfs_read_xattr

Song Liu songliubraving at meta.com
Thu Jun 19 15:31:32 UTC 2025



> On Jun 19, 2025, at 1:48 AM, Christian Brauner <brauner at kernel.org> wrote:
> 
> On Wed, Jun 18, 2025 at 02:43:34PM -1000, Tejun Heo wrote:
>> Hello,
>> 
>> On Wed, Jun 18, 2025 at 04:37:35PM -0700, Song Liu wrote:
>>> Introduce a new kfunc bpf_kernfs_read_xattr, which can read xattr from
>>> kernfs nodes (cgroupfs, for example). The primary users are LSMs, for
>>> example, from systemd. sched_ext could also use xattrs on cgroupfs nodes.
>>> However, this is not allowed yet, because bpf_kernfs_read_xattr is only
>>> allowed from LSM hooks. The plan is to address sched_ext later (or in a
>>> later revision of this set).
>> 
>> I don't think kernfs is the name we should be exposing to BPF users. This is
>> an implementation detail which may change in the future. I'd rather make it
>> a generic interface or a cgroup specific one. The name "kernfs" doesn't
> 
> cgroup specific, please. That's what I suggested to Daan.

I guess there was some misunderstanding. I will make this cgroup specific 
in v2. 

Thanks,
Song



More information about the Linux-security-module-archive mailing list