[PATCH 01/27] userns: pass const uid_gid_map in lookup helpers

Jan Kara jack at suse.cz
Wed Sep 2 14:06:21 UTC 2026


On Tue 01-09-26 14:14:26, Christian Brauner wrote:
> map_id_down(), map_id_up() and map_id_range_up() search the extents
> of an idmapping and never modify it. Let all relevant helpers pass a
> const struct uid_gid_map. Callers can now pass pass struct mnt_idmap as
> const and pass down &idmap->uid_map and &idmap->gid_map.
> 
> No functional changes.
> 
> Signed-off-by: Christian Brauner (Amutable) <brauner at kernel.org>

Looks good. Feel free to add:

Reviewed-by: Jan Kara <jack at suse.cz>

								Honza

> ---
>  include/linux/uidgid.h  | 12 ++++++------
>  kernel/user_namespace.c | 28 ++++++++++++++--------------
>  2 files changed, 20 insertions(+), 20 deletions(-)
> 
> diff --git a/include/linux/uidgid.h b/include/linux/uidgid.h
> index 2dc767e08f54..02403629b49f 100644
> --- a/include/linux/uidgid.h
> +++ b/include/linux/uidgid.h
> @@ -130,9 +130,9 @@ static inline bool kgid_has_mapping(struct user_namespace *ns, kgid_t gid)
>  	return from_kgid(ns, gid) != (gid_t) -1;
>  }
>  
> -u32 map_id_down(struct uid_gid_map *map, u32 id);
> -u32 map_id_up(struct uid_gid_map *map, u32 id);
> -u32 map_id_range_up(struct uid_gid_map *map, u32 id, u32 count);
> +u32 map_id_down(const struct uid_gid_map *map, u32 id);
> +u32 map_id_up(const struct uid_gid_map *map, u32 id);
> +u32 map_id_range_up(const struct uid_gid_map *map, u32 id, u32 count);
>  
>  #else
>  
> @@ -182,17 +182,17 @@ static inline bool kgid_has_mapping(struct user_namespace *ns, kgid_t gid)
>  	return gid_valid(gid);
>  }
>  
> -static inline u32 map_id_down(struct uid_gid_map *map, u32 id)
> +static inline u32 map_id_down(const struct uid_gid_map *map, u32 id)
>  {
>  	return id;
>  }
>  
> -static inline u32 map_id_range_up(struct uid_gid_map *map, u32 id, u32 count)
> +static inline u32 map_id_range_up(const struct uid_gid_map *map, u32 id, u32 count)
>  {
>  	return id;
>  }
>  
> -static inline u32 map_id_up(struct uid_gid_map *map, u32 id)
> +static inline u32 map_id_up(const struct uid_gid_map *map, u32 id)
>  {
>  	return id;
>  }
> diff --git a/kernel/user_namespace.c b/kernel/user_namespace.c
> index 0bed462e9b2a..55b6bd75624b 100644
> --- a/kernel/user_namespace.c
> +++ b/kernel/user_namespace.c
> @@ -278,8 +278,8 @@ static int cmp_map_id(const void *k, const void *e)
>   * map_id_range_down_max - Find idmap via binary search in ordered idmap array.
>   * Can only be called if number of mappings exceeds UID_GID_MAP_MAX_BASE_EXTENTS.
>   */
> -static struct uid_gid_extent *
> -map_id_range_down_max(unsigned extents, struct uid_gid_map *map, u32 id, u32 count)
> +static const struct uid_gid_extent *
> +map_id_range_down_max(unsigned extents, const struct uid_gid_map *map, u32 id, u32 count)
>  {
>  	struct idmap_key key;
>  
> @@ -296,8 +296,8 @@ map_id_range_down_max(unsigned extents, struct uid_gid_map *map, u32 id, u32 cou
>   * Can only be called if number of mappings is equal or less than
>   * UID_GID_MAP_MAX_BASE_EXTENTS.
>   */
> -static struct uid_gid_extent *
> -map_id_range_down_base(unsigned extents, struct uid_gid_map *map, u32 id, u32 count)
> +static const struct uid_gid_extent *
> +map_id_range_down_base(unsigned extents, const struct uid_gid_map *map, u32 id, u32 count)
>  {
>  	unsigned idx;
>  	u32 first, last, id2;
> @@ -315,9 +315,9 @@ map_id_range_down_base(unsigned extents, struct uid_gid_map *map, u32 id, u32 co
>  	return NULL;
>  }
>  
> -static u32 map_id_range_down(struct uid_gid_map *map, u32 id, u32 count)
> +static u32 map_id_range_down(const struct uid_gid_map *map, u32 id, u32 count)
>  {
> -	struct uid_gid_extent *extent;
> +	const struct uid_gid_extent *extent;
>  	unsigned extents = map->nr_extents;
>  	smp_rmb();
>  
> @@ -335,7 +335,7 @@ static u32 map_id_range_down(struct uid_gid_map *map, u32 id, u32 count)
>  	return id;
>  }
>  
> -u32 map_id_down(struct uid_gid_map *map, u32 id)
> +u32 map_id_down(const struct uid_gid_map *map, u32 id)
>  {
>  	return map_id_range_down(map, id, 1);
>  }
> @@ -345,8 +345,8 @@ u32 map_id_down(struct uid_gid_map *map, u32 id)
>   * Can only be called if number of mappings is equal or less than
>   * UID_GID_MAP_MAX_BASE_EXTENTS.
>   */
> -static struct uid_gid_extent *
> -map_id_range_up_base(unsigned extents, struct uid_gid_map *map, u32 id, u32 count)
> +static const struct uid_gid_extent *
> +map_id_range_up_base(unsigned extents, const struct uid_gid_map *map, u32 id, u32 count)
>  {
>  	unsigned idx;
>  	u32 first, last, id2;
> @@ -368,8 +368,8 @@ map_id_range_up_base(unsigned extents, struct uid_gid_map *map, u32 id, u32 coun
>   * map_id_up_max - Find idmap via binary search in ordered idmap array.
>   * Can only be called if number of mappings exceeds UID_GID_MAP_MAX_BASE_EXTENTS.
>   */
> -static struct uid_gid_extent *
> -map_id_range_up_max(unsigned extents, struct uid_gid_map *map, u32 id, u32 count)
> +static const struct uid_gid_extent *
> +map_id_range_up_max(unsigned extents, const struct uid_gid_map *map, u32 id, u32 count)
>  {
>  	struct idmap_key key;
>  
> @@ -381,9 +381,9 @@ map_id_range_up_max(unsigned extents, struct uid_gid_map *map, u32 id, u32 count
>  		       sizeof(struct uid_gid_extent), cmp_map_id);
>  }
>  
> -u32 map_id_range_up(struct uid_gid_map *map, u32 id, u32 count)
> +u32 map_id_range_up(const struct uid_gid_map *map, u32 id, u32 count)
>  {
> -	struct uid_gid_extent *extent;
> +	const struct uid_gid_extent *extent;
>  	unsigned extents = map->nr_extents;
>  	smp_rmb();
>  
> @@ -401,7 +401,7 @@ u32 map_id_range_up(struct uid_gid_map *map, u32 id, u32 count)
>  	return id;
>  }
>  
> -u32 map_id_up(struct uid_gid_map *map, u32 id)
> +u32 map_id_up(const struct uid_gid_map *map, u32 id)
>  {
>  	return map_id_range_up(map, id, 1);
>  }
> 
> -- 
> 2.53.0
> 
-- 
Jan Kara <jack at suse.com>
SUSE Labs, CR



More information about the Linux-security-module-archive mailing list