Received: by 2002:a05:6500:1b8f:b0:1fa:5c73:8e2d with SMTP id df15csp1093879lqb; Wed, 29 May 2024 23:07:55 -0700 (PDT) X-Forwarded-Encrypted: i=3; AJvYcCVkNZZQJqxwoCNTgozVpTXsRbiJLvoV3JhoXkUiXfoSV2Xb9R9V87IjFTYu7pGZqMPKASkb/tdnIdJ2dmuCJ7aBg0MFCpK43j3kV/W1sw== X-Google-Smtp-Source: AGHT+IHmfS1qVyxgRNTuQSuC3c9hzXoj5B4x9F3g9OzGsa7DOnXa3nqzoUqLZYUDVjb9yye+L3lS X-Received: by 2002:a17:906:f897:b0:a63:4e95:5639 with SMTP id a640c23a62f3a-a65e9102b1fmr58153966b.47.1717049275561; Wed, 29 May 2024 23:07:55 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1717049275; cv=pass; d=google.com; s=arc-20160816; b=ycoDDu0Qjqq3ualmnocTjjr9bCdY4bfsEUkbGvKYHk0qWtcfJ+rztyO1vPMhL/yDtB oq/rJseFOX/0E1YqNAWa4aJKsKtMtwwmeHkS6z4jane6pAy/6BUwo5CCwbnxf38p3aZ8 NqwpEhKGUkGE2JyLlBpuRPI+jVA77ZhHEUrCKlRltZZy+E2XJ3FAWjKZUYVws/BqZ/tv pLFiZe1Qis1Zh+SBrPcwi7GlwxbxBETJ7qGNMNkysJWKKnfEdbUyqWEFj0p3G62pLq8e jpFM4GEh+oJlDUAYNxL/EaKDrg7L9YbKrj4Xvy+eNlDN9H4LiRTQd0CB8YdCTEgWu9Ca Nz1w== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=in-reply-to:references:to:from:subject:cc:message-id:date :content-transfer-encoding:mime-version:list-unsubscribe :list-subscribe:list-id:precedence:dkim-signature; bh=s0v8RLFjGsAdUbVrAJwy/LJycIrYxMESvCHfg8Cgp9o=; fh=xqT1BQ0CCxsNKDaL/yReYeQm+G/5TctFBhTu1xJ9Pvo=; b=QhXofdUcy3KJz2DUSoWaGwuqIF3bEcOvJeu6nxJKt57wh5L44YU3XJHTtmKD8RFX1h WqPq1fTzecjTymJeZ4pPgFssX4Ovw+GG4rlaTh+7K8SKEXkeOpVhLpWihqZWiYl2NECo zo0irwEBFTUVWn3F+7yuZHUzsYZtYXszGVKL5EcPKJUCM97fXKnI9wo4EUL1bI0U0Cz2 rd1tpKXqPpBA8uoNFmct2/gfDU+e2AFYJY4r9ulqPjt0oOqO3r2MKK+4qrVZiuIvF6+9 D8VBfuuOzj6JEf70z2Y9k3v7bWG3I2eVHg9yrMgEnE5MvDA9ps7xuWyJXQnYX7/WQ6QS RZ4g==; dara=google.com ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=X4GcpmJv; arc=pass (i=1 dkim=pass dkdomain=kernel.org); spf=pass (google.com: domain of linux-kernel+bounces-194978-linux.lists.archive=gmail.com@vger.kernel.org designates 147.75.80.249 as permitted sender) smtp.mailfrom="linux-kernel+bounces-194978-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from am.mirrors.kernel.org (am.mirrors.kernel.org. [147.75.80.249]) by mx.google.com with ESMTPS id a640c23a62f3a-a626cdd2b91si721645266b.991.2024.05.29.23.07.55 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 29 May 2024 23:07:55 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel+bounces-194978-linux.lists.archive=gmail.com@vger.kernel.org designates 147.75.80.249 as permitted sender) client-ip=147.75.80.249; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=X4GcpmJv; arc=pass (i=1 dkim=pass dkdomain=kernel.org); spf=pass (google.com: domain of linux-kernel+bounces-194978-linux.lists.archive=gmail.com@vger.kernel.org designates 147.75.80.249 as permitted sender) smtp.mailfrom="linux-kernel+bounces-194978-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by am.mirrors.kernel.org (Postfix) with ESMTPS id 4F4E61F22EBA for ; Thu, 30 May 2024 06:07:50 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 271BA14375B; Thu, 30 May 2024 06:07:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="X4GcpmJv" Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2C6C5DDA0; Thu, 30 May 2024 06:07:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1717049255; cv=none; b=EsN6BWTlBM1+RiFBoFtLWBLfVs5WXDHLsK4BjVHGL1CWOyXMjyH4MUPgQbrCKtUKsn8SS/LGU6NB5vf6bh1BGJrlGZwC1xXp7r7wCWtE2f6u7n0c6tLZZasYGaUXU1K4JvmPRFbQOCNFw9r7vlXsZQQDejBusscL+ox7Xk8tWQM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1717049255; c=relaxed/simple; bh=HaYt2U+ot0lKNo1rF40NupQyMsZE36x8bEub+oPge68=; h=Mime-Version:Content-Type:Date:Message-Id:Cc:Subject:From:To: References:In-Reply-To; b=YkZDzgewZvFaMSWBw1JkmDnpSjiJEEBT/csUtkXc1h0qssRlp28LSCcaxzQdCOZc0S0JKwzhBIa/DBhJPCg1AzNB4ztek238s8ihFN/xd13JQOUwxMCZDw2ncMUfuCC8lOIoSfwZ4+OL8gYWMyq+sjYQ1P6ipjNwUgkXPsJDDbs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=X4GcpmJv; arc=none smtp.client-ip=10.30.226.201 Received: by smtp.kernel.org (Postfix) with ESMTPSA id 13DA5C2BBFC; Thu, 30 May 2024 06:07:26 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1717049254; bh=HaYt2U+ot0lKNo1rF40NupQyMsZE36x8bEub+oPge68=; h=Date:Cc:Subject:From:To:References:In-Reply-To:From; b=X4GcpmJvZMxWDq6XgjQ+3KSTg09v76vgBVwMhHmZP4Nt66NUtlSyl3oHkCN+hw06W b4itoI0WYrjUXTKQiemhkWpnGsgW8X0Q6pG9lgN55PVktBGlQwzZFGjbWM379Ios7i rCw9NjP260KHm1E8qo8ucC1JdZQgRS5fc7FRCg4RHMDwwrpOIFFZUUFwjn8H3U4lvZ nEm5BRe67LkkPwku7fd5GgDeFSlkhd9niY9AyXd0muMdgKwJitk23OALnKQV2/zZKT 2995hxrL5vWBkdAlNGEGAOIK1/VDVv4dxjSrzqE5k6RUe7TKc+mAzfnrPmQtDkKnu3 7zjcAmr+cMtWQ== Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=UTF-8 Date: Thu, 30 May 2024 09:07:23 +0300 Message-Id: Cc: "Paul Moore" , "Fan Wu" , , , , , , , , , , , , , , , , , , , "Deven Bowers" Subject: Re: [PATCH v19 15/20] fsverity: expose verified fsverity built-in signatures to LSMs From: "Jarkko Sakkinen" To: "Eric Biggers" X-Mailer: aerc 0.17.0 References: <1716583609-21790-16-git-send-email-wufan@linux.microsoft.com> <06bb61dc838eeff63bb5f11cea6d4b53@paul-moore.com> <20240530060120.GB29189@sol.localdomain> In-Reply-To: <20240530060120.GB29189@sol.localdomain> On Thu May 30, 2024 at 9:01 AM EEST, Eric Biggers wrote: > On Thu, May 30, 2024 at 08:51:21AM +0300, Jarkko Sakkinen wrote: > > On Thu May 30, 2024 at 4:44 AM EEST, Paul Moore wrote: > > > > + err =3D security_inode_setintegrity(inode, > > > > + LSM_INT_FSVERITY_BUILTINSIG_VALID, > > > > + signature, > > > > + le32_to_cpu(sig_size)); > > > > > > I like this much better without the explicit inode cast :) > >=20 > > Would be nice btw if that was 'ret' or 'rc' because err is such > > a common name for exception handler alike goto-labels... Looks > > confusing just because of that :-) > >=20 > > A lot of kernel code, including the rest of fs/verity/, uses the conventi= on that > "0 or negative errno" return values are named 'err' (and return values th= at > aren't necessarily an errno are named something else). So it's fine as-i= s. Right, just hadn't seen such naming convention before. BR, Jarkko