From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yw1-f177.google.com (mail-yw1-f177.google.com [209.85.128.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CCA3448F859 for ; Fri, 21 Aug 2026 13:15:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.177 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787318144; cv=none; b=g3sqoKS1I+QBPQxSAL8vr0t2DGhzErygTKfJg6otXzSRmtl4uoPMRt3/IV/QCsCUGPhCvhoUh/HnKO668M2B3+IC/EVRBM8gR77c5oVAXtQ01p6GgCaQ+W7BivlUV8crTkCDwPSsDpho8KWv19B/YmmpvxPgCI7zsMC8cfGjnEQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787318144; c=relaxed/simple; bh=TOgYQZ829UyU2jOilwn5+g3K5dTtN7xU+CJosTc4jVc=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=hPkxjXweAX1sk0aQ6zwvLib65Pk1/hwUZe0JrYyJLwiAjBKmLHHaynLtA5rJzNP6OyibISfep/2ShjcJN3MDgVuSThYBOaUbJjA20rONhG7mmUS8Syvmtc0qY1CQyWeqb/fojReuSAabC2xlnVwBQBy6doCsFyj4beqXgVd6VgE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=aMv6j9VU; arc=none smtp.client-ip=209.85.128.177 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="aMv6j9VU" Received: by mail-yw1-f177.google.com with SMTP id 00721157ae682-836d2861a39so14422447b3.2 for ; Fri, 21 Aug 2026 06:15:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787318133; x=1787922933; darn=vger.kernel.org; h=in-reply-to:content-transfer-encoding:content-disposition :content-type:mime-version:references:message-id:subject:cc:to:from :date:from:to:cc:subject:date:message-id:reply-to:content-type; bh=vH94uxfMfesjNr68TvUP5/weYC42qiuv499mvdY0TYU=; b=aMv6j9VUq+cFb/uq0Z438I+ZDp6BJvKZ/zxEsEacDqFOpbbz0pKLicmDd476xMtN5k SBcT83qoMKjq44cW68L3Jf3nbgoQ6TxhsJhH5gph+M/75MknsCC3gkgoBrb6DInYZ98m Fa2fYIeVkObfP+CTDRbIRMk/veMmwiFxXgXrKhhNFyuVlwp9uqAqEWrUmbLS/xxT2h54 qAF4wkt3KgyrdLHBm18jcqX4HjFLPb7xEvqK1VurXTjP+jZVztuUb+08uvRIY4j1C8Uc +yC1u315UvFgitDEq4DfCotXT/hUs0qWJOqiNJSRVx2z1c467oHbEGuojGQWLct0CKZ9 WmBQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787318133; x=1787922933; h=in-reply-to:content-transfer-encoding:content-disposition :content-type:mime-version:references:message-id:subject:cc:to:from :date:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=vH94uxfMfesjNr68TvUP5/weYC42qiuv499mvdY0TYU=; b=hjcgQMgvlA8Mntq55YvETDU0psBj28kuTEwP3m2086YV0DuNDKriFZJfb3rJA0R7sy 0bxYggJMxShlHzTdNYtjU0YPLcdmJuexZpYybZabG2xjatcJlxtmbprfkcZu6QbopWlD wtOJiaeD2RxKnD8/sNp6vmyT6foI+Gr3gFtB0aIYhHeSQOU8YQlXSZYVNAtXfScr+iko +Wnkv1DDNSK34fpmlJGP7Ofj6uvzJxJDKV9G1dnPwiyGg01MDz3J10JGF7xjwo54xZVE 3y+XCuBPOp93TJ6yqr/oc3Go5IkwLkJ8+TnBDu3+pgbgmzaFFcB5IsqCGGi3UW8meAqV oE5A== X-Forwarded-Encrypted: i=1; AHgh+RqgU98xLCRRC1FEVtHTV/6kGKO650jedfsvfNBJAjy+vFn5ngerWurjJ33ZiPRbdVVD1rpM+GOOJYswZrk=@vger.kernel.org X-Gm-Message-State: AFuF++lcu2ULz/e4vAYxst3F+GFQv69hNq+Lb9+F1M5Wts2ONSZ09Pm+ K7sg89Q4E7terFABCambpUlgUeSuMCXeteUvSBAamTSEaClnhkOo20jLUJfp5Q== X-Gm-Gg: AR+sD138DNSmjf1PJAPsJ1ZyHqbVvPLhvDSnYo+UMarx0r1fgaLlHRHjFNe6gKetsE8 zvFmpdj2BtuuYv21IufrztUCBJrJzcXk1oXj9dSfMGD55VjwkN5VycV7qi4Nv6zXkmxJqZQsIh4 YToHs2dxxPvollVM/f+rdJM/IpdD+emH7oSUL+uQT3YDi91URcSTQiTMYCgBtPmmSzEQHOAQOb3 k1JDjtXmg971/o2BTMxL/OPyDO3lAC+QUWTmzS1cBhmzeyq88smf2gJpcmy5mIa3EjpyMx6fE8L XtbDZ43GKymE3ungQkcVrMKD9TBYxPNkiYN5DOah82H+/vLXz8c7PQYuvhuKCesvfEA8dQXfSvS 8ISWyKD21YZXQvmCknzIPdu87IuKhLUbl5o475UIXzU/tC4PSuXFthOIeo97RhjisSySRT//yGT DRAn0P6q1GCcGvf2Pq2ncqrZCRDA8DOq+y+vbqkjv06CyeXIq8dVNrEzsnAsYBwVuSjutbDDx9R BGl7dUxoiaTR9qtYeD4cg== X-Received: by 2002:a05:690c:2702:b0:833:a89f:6cab with SMTP id 00721157ae682-849f0145609mr29244477b3.2.1787318132623; Fri, 21 Aug 2026 06:15:32 -0700 (PDT) Received: from zenbox ([2600:1700:18fb:6011:350e:631:3b2c:9519]) by smtp.gmail.com with ESMTPSA id 00721157ae682-84512762addsm39350687b3.15.2026.08.21.06.15.32 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 21 Aug 2026 06:15:32 -0700 (PDT) Date: Fri, 21 Aug 2026 09:15:31 -0400 From: Justin Suess To: =?utf-8?Q?G=C3=BCnther?= Noack Cc: mic@digikod.net, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org Subject: Re: [PATCH v2 3/6] landlock: Bump ABI for LANDLOCK_SCOPE_SYSV_MSG_QUEUE Message-ID: References: <20260727230833.138165-1-utilityemal77@gmail.com> <20260727230833.138165-4-utilityemal77@gmail.com> <20260821.ad614a879e61@gnoack.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <20260821.ad614a879e61@gnoack.org> On Fri, Aug 21, 2026 at 02:38:15PM +0200, Günther Noack wrote: > On Mon, Jul 27, 2026 at 07:08:30PM -0400, Justin Suess wrote: > > Bump the ABI version for Landlock SysV message queue scoping. > > > > Signed-off-by: Justin Suess > > The ABI bump is normally put into the same commit as the > implementation for easier backporting. Otherwise, looks good. I'll squash them. > Thanks, I did wonder about if we need to use the landlock_object here? I'm pretty sure SysV message queues stay open after process exit, which could cause the domain to be pinned by landlock_cred_security, if programs are lazy and don't close them. So it probably needs to be a weak reference. But it's unclear what should be the behavior there when the domain is dropped: 1. Should it become inaccessible and belong to *nobody's* domain? (i.e when owning domain is dropped, the queue belongs to no domain and is inaccessible to all LANDLOCK_SCOPE_SYSV_MSG_QUEUE scoped domains) 2. Should it be moved to the parent's domain? (i.e when owning domain is dropped, the parent domain is the new scope, and then it's parent, so on and so forth, more complicated, but more correct) 3. Or be kept as is. (i.e Allow an open sysv message queue to pin a domain for it's lifetime) Either way this almost certainly needs to be rebased since it's been a little bit and there were significant refactorings of the domain and ruleset structures since the tracepoints series. Justin > –Günther