From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-4.0 required=3.0 tests=BAYES_00, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 22537C433DF for ; Mon, 10 Aug 2020 22:29:07 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by mail.kernel.org (Postfix) with ESMTP id 072002076C for ; Mon, 10 Aug 2020 22:29:07 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726789AbgHJW3B (ORCPT ); Mon, 10 Aug 2020 18:29:01 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:44472 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726705AbgHJW3A (ORCPT ); Mon, 10 Aug 2020 18:29:00 -0400 Received: from ZenIV.linux.org.uk (zeniv.linux.org.uk [IPv6:2002:c35c:fd02::1]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 65B31C06174A; Mon, 10 Aug 2020 15:29:00 -0700 (PDT) Received: from viro by ZenIV.linux.org.uk with local (Exim 4.92.3 #3 (Red Hat Linux)) id 1k5GHW-00DHrJ-VN; Mon, 10 Aug 2020 22:28:39 +0000 Date: Mon, 10 Aug 2020 23:28:38 +0100 From: Al Viro To: David Laight Cc: =?iso-8859-1?Q?Micka=EBl_Sala=FCn?= , Kees Cook , Andrew Morton , "linux-kernel@vger.kernel.org" , Aleksa Sarai , Alexei Starovoitov , Andy Lutomirski , Christian Brauner , Christian Heimes , Daniel Borkmann , Deven Bowers , Dmitry Vyukov , Eric Biggers , Eric Chiang , Florian Weimer , James Morris , Jan Kara , Jann Horn , Jonathan Corbet , Lakshmi Ramasubramanian , Matthew Garrett , Matthew Wilcox , Michael Kerrisk , Mimi Zohar , Philippe =?iso-8859-1?Q?Tr=E9buchet?= , Scott Shell , Sean Christopherson , Shuah Khan , Steve Dower , Steve Grubb , Tetsuo Handa , Thibaut Sautereau , Vincent Strubel , "kernel-hardening@lists.openwall.com" , "linux-api@vger.kernel.org" , "linux-integrity@vger.kernel.org" , "linux-security-module@vger.kernel.org" , "linux-fsdevel@vger.kernel.org" Subject: Re: [PATCH v7 0/7] Add support for O_MAYEXEC Message-ID: <20200810222838.GF1236603@ZenIV.linux.org.uk> References: <20200723171227.446711-1-mic@digikod.net> <202007241205.751EBE7@keescook> <0733fbed-cc73-027b-13c7-c368c2d67fb3@digikod.net> <20200810202123.GC1236603@ZenIV.linux.org.uk> <30b8c003f49d4280be5215f634ca2c06@AcuMS.aculab.com> MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <30b8c003f49d4280be5215f634ca2c06@AcuMS.aculab.com> Sender: linux-integrity-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-integrity@vger.kernel.org On Mon, Aug 10, 2020 at 10:09:09PM +0000, David Laight wrote: > > On Mon, Aug 10, 2020 at 10:11:53PM +0200, Mickaël Salaün wrote: > > > It seems that there is no more complains nor questions. Do you want me > > > to send another series to fix the order of the S-o-b in patch 7? > > > > There is a major question regarding the API design and the choice of > > hooking that stuff on open(). And I have not heard anything resembling > > a coherent answer. > > To me O_MAYEXEC is just the wrong name. > The bit would be (something like) O_INTERPRET to indicate > what you want to do with the contents. ... which does not answer the question - name of constant is the least of the worries here. Why the hell is "apply some unspecified checks to file" combined with opening it, rather than being an independent primitive you apply to an already opened file? Just in case - "'cuz that's how we'd done it" does not make a good answer...