[PATCH v6 0/8] lsm: Replace security_sb_mount with granular mount hooks

Paul Moore paul at paul-moore.com
Mon Sep 28 22:35:32 UTC 2026


On Mon, Sep 28, 2026 at 1:00 PM Song Liu <song at kernel.org> wrote:
>
> Hi Christian and Paul,
>
> Thanks for your replies.
>
> On Mon, Sep 28, 2026 at 8:46 AM Paul Moore <paul at paul-moore.com> wrote:
> >
> > On Mon, Sep 28, 2026 at 10:13 AM Christian Brauner <brauner at kernel.org> wrote:
> > > On Thu, Jul 23, 2026 at 11:19:30AM -0700, Song Liu wrote:
> > > > Hi Christian and folks,
> > > >
> > > > Could you please help review this set? Does this set address
> > > > concerns from earlier versions?
> > >
> > > I just realized something while looking at this. This doesn't cover the
> > > new mount api at all fsopen, fsconfig, fsmount, fspick, open_tree,
> > > open_tree_attr and mount_setattr. Without this the series is not very
> > > useful imho.
>
> Yes, I am fully aware that this does not cover the new mount APIs. I think
> those are orthogonal to the optimization here. This series is very useful
> without covering the new APIs. Users from multiple companies have
> repeatedly requested this change. ([1] and users requested this set).
>
> If we can land this set without covering the new APIs, I am more than
> happy to draft new patch set that covers the new APIs as a follow-up
> work. Therefore, could you please review this set as-is, and see whether
> we can land it without the orthogonal work covering the new mount APIs?
>
> > Thanks Christian.
> >
> > Song, I'm still open to reworking the LSM mount hooks, but any rework
> > should really take into account everything.
>
> There is another question here. These new hooks do not have any in-tree
> user at the moment. This appears to violate the "New LSM Hooks" policy
> in [2]. Could you please give more specific guidance on this?

There are LSMs which implement mount level access controls, you've
been updating those in your patchset :)  I believe that some of those
LSMs do have some (full? needs verification) coverage on the new mount
API.  I would expect that a patchset that adds, or modifies the
existing, mount hooks would also update those LSMs accordingly.  From
what I've seen, you've done a good job updating the individual LSMs
thus far, but if you have any questions or are unsure of what to do
for any one LSM, please ask and I'm sure the associated devs will be
happy to help.

-- 
paul-moore.com



More information about the Linux-security-module-archive mailing list