[PATCH v6 0/8] lsm: Replace security_sb_mount with granular mount hooks
Song Liu
song at kernel.org
Tue Sep 29 06:21:11 UTC 2026
On Mon, Sep 28, 2026 at 3:35 PM Paul Moore <paul at paul-moore.com> wrote:
[...]
> >
> > There is another question here. These new hooks do not have any in-tree
> > user at the moment. This appears to violate the "New LSM Hooks" policy
> > in [2]. Could you please give more specific guidance on this?
>
> There are LSMs which implement mount level access controls, you've
> been updating those in your patchset :) I believe that some of those
> LSMs do have some (full? needs verification) coverage on the new mount
> API. I would expect that a patchset that adds, or modifies the
> existing, mount hooks would also update those LSMs accordingly. From
> what I've seen, you've done a good job updating the individual LSMs
> thus far, but if you have any questions or are unsure of what to do
> for any one LSM, please ask and I'm sure the associated devs will be
> happy to help.
I don't think the scope here, adding hooks for fsopen, fsconfig, fsmount,
fspick, open_tree, open_tree_attr and mount_setattr and using them
properly in all LSMs, is a reasonable ask for a single patchset. Given
how much time this simple refactoring patchset has taken, I don't foresee
this work landing in any reasonable timeframe.
Please consider reviewing this set and landing it before asking for more
work.
Thanks,
Song
More information about the Linux-security-module-archive
mailing list