Re: [PATCH RFC -next 07/12] LSM: pass struct path to the inode posix acl hooks
From: Casey Schaufler
Date: Tue Oct 06 2026 - 12:08:07 EST
On 9/24/2026 3:48 AM, Cai Xinchen wrote:
> The inode_set_acl, inode_get_acl and inode_remove_acl hooks are
> called from fs/posix_acl.c, whose helpers now hold a struct path and
> used to derive the idmap and dentry from it just for the hook calls.
>
> Convert the hooks and their SELinux, Smack, EVM and IMA
> implementations to take a const struct path. The implementations
> derive the idmap and dentry they still need from the path, so this
> is a purely mechanical change with no behavior change.
>
> Assisted-by: opencode: glm-5.3
> Signed-off-by: Cai Xinchen <caixinchen1@xxxxxxxxxx>
The Smack changes appear sane.
Acked-by: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
> ---
> fs/posix_acl.c | 6 ++---
> include/linux/lsm_hook_defs.h | 12 ++++-----
> include/linux/security.h | 20 +++++----------
> security/integrity/evm/evm_main.c | 14 +++++-----
> security/integrity/ima/ima_appraise.c | 8 +++---
> security/security.c | 32 ++++++++++-------------
> security/selinux/hooks.c | 19 +++++++-------
> security/smack/smack_lsm.c | 37 ++++++++++++---------------
> 8 files changed, 66 insertions(+), 82 deletions(-)
>
> diff --git a/fs/posix_acl.c b/fs/posix_acl.c
> index be1643e18a6a..72e77540a0e9 100644
> --- a/fs/posix_acl.c
> +++ b/fs/posix_acl.c
> @@ -1128,7 +1128,7 @@ int vfs_set_acl(const struct path *path, const char *acl_name,
> if (error)
> goto out_inode_unlock;
>
> - error = security_inode_set_acl(idmap, dentry, acl_name, kacl);
> + error = security_inode_set_acl(path, acl_name, kacl);
> if (error)
> goto out_inode_unlock;
>
> @@ -1184,7 +1184,7 @@ struct posix_acl *vfs_get_acl(const struct path *path, const char *acl_name)
> * The VFS has no restrictions on reading POSIX ACLs so calling
> * something like xattr_permission() isn't needed. Only LSMs get a say.
> */
> - error = security_inode_get_acl(idmap, dentry, acl_name);
> + error = security_inode_get_acl(path, acl_name);
> if (error)
> return ERR_PTR(error);
>
> @@ -1236,7 +1236,7 @@ int vfs_remove_acl(const struct path *path, const char *acl_name)
> if (error)
> goto out_inode_unlock;
>
> - error = security_inode_remove_acl(idmap, dentry, acl_name);
> + error = security_inode_remove_acl(path, acl_name);
> if (error)
> goto out_inode_unlock;
>
> diff --git a/include/linux/lsm_hook_defs.h b/include/linux/lsm_hook_defs.h
> index 3a3512a3ee91..45cf0ca24260 100644
> --- a/include/linux/lsm_hook_defs.h
> +++ b/include/linux/lsm_hook_defs.h
> @@ -160,14 +160,14 @@ LSM_HOOK(void, LSM_RET_VOID, inode_post_removexattr, struct dentry *dentry,
> const char *name)
> LSM_HOOK(int, 0, inode_file_setattr, struct dentry *dentry, struct file_kattr *fa)
> LSM_HOOK(int, 0, inode_file_getattr, struct dentry *dentry, struct file_kattr *fa)
> -LSM_HOOK(int, 0, inode_set_acl, struct mnt_idmap *idmap,
> - struct dentry *dentry, const char *acl_name, struct posix_acl *kacl)
> +LSM_HOOK(int, 0, inode_set_acl, const struct path *path,
> + const char *acl_name, struct posix_acl *kacl)
> LSM_HOOK(void, LSM_RET_VOID, inode_post_set_acl, struct dentry *dentry,
> const char *acl_name, struct posix_acl *kacl)
> -LSM_HOOK(int, 0, inode_get_acl, struct mnt_idmap *idmap,
> - struct dentry *dentry, const char *acl_name)
> -LSM_HOOK(int, 0, inode_remove_acl, struct mnt_idmap *idmap,
> - struct dentry *dentry, const char *acl_name)
> +LSM_HOOK(int, 0, inode_get_acl, const struct path *path,
> + const char *acl_name)
> +LSM_HOOK(int, 0, inode_remove_acl, const struct path *path,
> + const char *acl_name)
> LSM_HOOK(void, LSM_RET_VOID, inode_post_remove_acl, struct mnt_idmap *idmap,
> struct dentry *dentry, const char *acl_name)
> LSM_HOOK(int, 0, inode_need_killpriv, struct dentry *dentry)
> diff --git a/include/linux/security.h b/include/linux/security.h
> index f5dc67a937bd..8b02b3bfe46d 100644
> --- a/include/linux/security.h
> +++ b/include/linux/security.h
> @@ -435,15 +435,12 @@ int security_inode_getattr(const struct path *path);
> int security_inode_setxattr(const struct path *path,
> const char *name, const void *value,
> size_t size, int flags);
> -int security_inode_set_acl(struct mnt_idmap *idmap,
> - struct dentry *dentry, const char *acl_name,
> - struct posix_acl *kacl);
> +int security_inode_set_acl(const struct path *path,
> + const char *acl_name, struct posix_acl *kacl);
> void security_inode_post_set_acl(struct dentry *dentry, const char *acl_name,
> struct posix_acl *kacl);
> -int security_inode_get_acl(struct mnt_idmap *idmap,
> - struct dentry *dentry, const char *acl_name);
> -int security_inode_remove_acl(struct mnt_idmap *idmap,
> - struct dentry *dentry, const char *acl_name);
> +int security_inode_get_acl(const struct path *path, const char *acl_name);
> +int security_inode_remove_acl(const struct path *path, const char *acl_name);
> void security_inode_post_remove_acl(struct mnt_idmap *idmap,
> struct dentry *dentry,
> const char *acl_name);
> @@ -1021,8 +1018,7 @@ static inline int security_inode_setxattr(const struct path *path,
> return cap_inode_setxattr(path, name, value, size, flags);
> }
>
> -static inline int security_inode_set_acl(struct mnt_idmap *idmap,
> - struct dentry *dentry,
> +static inline int security_inode_set_acl(const struct path *path,
> const char *acl_name,
> struct posix_acl *kacl)
> {
> @@ -1034,15 +1030,13 @@ static inline void security_inode_post_set_acl(struct dentry *dentry,
> struct posix_acl *kacl)
> { }
>
> -static inline int security_inode_get_acl(struct mnt_idmap *idmap,
> - struct dentry *dentry,
> +static inline int security_inode_get_acl(const struct path *path,
> const char *acl_name)
> {
> return 0;
> }
>
> -static inline int security_inode_remove_acl(struct mnt_idmap *idmap,
> - struct dentry *dentry,
> +static inline int security_inode_remove_acl(const struct path *path,
> const char *acl_name)
> {
> return 0;
> diff --git a/security/integrity/evm/evm_main.c b/security/integrity/evm/evm_main.c
> index 47ad39d64c76..c83befd32e99 100644
> --- a/security/integrity/evm/evm_main.c
> +++ b/security/integrity/evm/evm_main.c
> @@ -685,8 +685,7 @@ static inline int evm_inode_set_acl_change(struct mnt_idmap *idmap,
>
> /**
> * evm_inode_set_acl - protect the EVM extended attribute from posix acls
> - * @idmap: idmap of the idmapped mount
> - * @dentry: pointer to the affected dentry
> + * @path: pointer to the affected object
> * @acl_name: name of the posix acl
> * @kacl: pointer to the posix acls
> *
> @@ -696,10 +695,12 @@ static inline int evm_inode_set_acl_change(struct mnt_idmap *idmap,
> *
> * Return: zero on success, -EPERM on failure.
> */
> -static int evm_inode_set_acl(struct mnt_idmap *idmap, struct dentry *dentry,
> +static int evm_inode_set_acl(const struct path *path,
> const char *acl_name, struct posix_acl *kacl)
> {
> enum integrity_status evm_status;
> + struct dentry *dentry = path->dentry;
> + struct mnt_idmap *idmap = mnt_idmap(path->mnt);
>
> /* Policy permits modification of the protected xattrs even though
> * there's no HMAC key loaded
> @@ -738,8 +739,7 @@ static int evm_inode_set_acl(struct mnt_idmap *idmap, struct dentry *dentry,
>
> /**
> * evm_inode_remove_acl - Protect the EVM extended attribute from posix acls
> - * @idmap: idmap of the mount
> - * @dentry: pointer to the affected dentry
> + * @path: pointer to the affected object
> * @acl_name: name of the posix acl
> *
> * Prevent removing posix acls causing the EVM HMAC to be re-calculated
> @@ -748,10 +748,10 @@ static int evm_inode_set_acl(struct mnt_idmap *idmap, struct dentry *dentry,
> *
> * Return: zero on success, -EPERM on failure.
> */
> -static int evm_inode_remove_acl(struct mnt_idmap *idmap, struct dentry *dentry,
> +static int evm_inode_remove_acl(const struct path *path,
> const char *acl_name)
> {
> - return evm_inode_set_acl(idmap, dentry, acl_name, NULL);
> + return evm_inode_set_acl(path, acl_name, NULL);
> }
>
> static void evm_reset_status(struct inode *inode)
> diff --git a/security/integrity/ima/ima_appraise.c b/security/integrity/ima/ima_appraise.c
> index 58ba674bc172..518faf04ddde 100644
> --- a/security/integrity/ima/ima_appraise.c
> +++ b/security/integrity/ima/ima_appraise.c
> @@ -793,11 +793,11 @@ static int ima_inode_setxattr(const struct path *path,
> return result;
> }
>
> -static int ima_inode_set_acl(struct mnt_idmap *idmap, struct dentry *dentry,
> +static int ima_inode_set_acl(const struct path *path,
> const char *acl_name, struct posix_acl *kacl)
> {
> if (evm_revalidate_status(acl_name))
> - ima_reset_appraise_flags(d_backing_inode(dentry), -1);
> + ima_reset_appraise_flags(d_backing_inode(path->dentry), -1);
>
> return 0;
> }
> @@ -818,10 +818,10 @@ static int ima_inode_removexattr(const struct path *path,
> return result;
> }
>
> -static int ima_inode_remove_acl(struct mnt_idmap *idmap, struct dentry *dentry,
> +static int ima_inode_remove_acl(const struct path *path,
> const char *acl_name)
> {
> - return ima_inode_set_acl(idmap, dentry, acl_name, NULL);
> + return ima_inode_set_acl(path, acl_name, NULL);
> }
>
> static struct security_hook_list ima_appraise_hooks[] __ro_after_init = {
> diff --git a/security/security.c b/security/security.c
> index 3a8892d8ca5c..74bcd8c0502c 100644
> --- a/security/security.c
> +++ b/security/security.c
> @@ -1987,8 +1987,7 @@ int security_inode_setxattr(const struct path *path,
>
> /**
> * security_inode_set_acl() - Check if setting posix acls is allowed
> - * @idmap: idmap of the mount
> - * @dentry: file
> + * @path: file
> * @acl_name: acl name
> * @kacl: acl struct
> *
> @@ -1997,13 +1996,12 @@ int security_inode_setxattr(const struct path *path,
> *
> * Return: Returns 0 if permission is granted.
> */
> -int security_inode_set_acl(struct mnt_idmap *idmap,
> - struct dentry *dentry, const char *acl_name,
> - struct posix_acl *kacl)
> +int security_inode_set_acl(const struct path *path,
> + const char *acl_name, struct posix_acl *kacl)
> {
> - if (unlikely(IS_PRIVATE(d_backing_inode(dentry))))
> + if (unlikely(IS_PRIVATE(d_backing_inode(path->dentry))))
> return 0;
> - return call_int_hook(inode_set_acl, idmap, dentry, acl_name, kacl);
> + return call_int_hook(inode_set_acl, path, acl_name, kacl);
> }
>
> /**
> @@ -2025,8 +2023,7 @@ void security_inode_post_set_acl(struct dentry *dentry, const char *acl_name,
>
> /**
> * security_inode_get_acl() - Check if reading posix acls is allowed
> - * @idmap: idmap of the mount
> - * @dentry: file
> + * @path: file
> * @acl_name: acl name
> *
> * Check permission before getting osix acls, the posix acls are identified by
> @@ -2034,18 +2031,16 @@ void security_inode_post_set_acl(struct dentry *dentry, const char *acl_name,
> *
> * Return: Returns 0 if permission is granted.
> */
> -int security_inode_get_acl(struct mnt_idmap *idmap,
> - struct dentry *dentry, const char *acl_name)
> +int security_inode_get_acl(const struct path *path, const char *acl_name)
> {
> - if (unlikely(IS_PRIVATE(d_backing_inode(dentry))))
> + if (unlikely(IS_PRIVATE(d_backing_inode(path->dentry))))
> return 0;
> - return call_int_hook(inode_get_acl, idmap, dentry, acl_name);
> + return call_int_hook(inode_get_acl, path, acl_name);
> }
>
> /**
> * security_inode_remove_acl() - Check if removing a posix acl is allowed
> - * @idmap: idmap of the mount
> - * @dentry: file
> + * @path: file
> * @acl_name: acl name
> *
> * Check permission before removing posix acls, the posix acls are identified
> @@ -2053,12 +2048,11 @@ int security_inode_get_acl(struct mnt_idmap *idmap,
> *
> * Return: Returns 0 if permission is granted.
> */
> -int security_inode_remove_acl(struct mnt_idmap *idmap,
> - struct dentry *dentry, const char *acl_name)
> +int security_inode_remove_acl(const struct path *path, const char *acl_name)
> {
> - if (unlikely(IS_PRIVATE(d_backing_inode(dentry))))
> + if (unlikely(IS_PRIVATE(d_backing_inode(path->dentry))))
> return 0;
> - return call_int_hook(inode_remove_acl, idmap, dentry, acl_name);
> + return call_int_hook(inode_remove_acl, path, acl_name);
> }
>
> /**
> diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
> index 5d98ec73df9f..45ece734463e 100644
> --- a/security/selinux/hooks.c
> +++ b/security/selinux/hooks.c
> @@ -3498,23 +3498,22 @@ static int selinux_inode_setxattr(const struct path *path,
> &ad);
> }
>
> -static int selinux_inode_set_acl(struct mnt_idmap *idmap,
> - struct dentry *dentry, const char *acl_name,
> - struct posix_acl *kacl)
> +static int selinux_inode_set_acl(const struct path *path,
> + const char *acl_name, struct posix_acl *kacl)
> {
> - return dentry_has_perm(current_cred(), dentry, FILE__SETATTR);
> + return dentry_has_perm(current_cred(), path->dentry, FILE__SETATTR);
> }
>
> -static int selinux_inode_get_acl(struct mnt_idmap *idmap,
> - struct dentry *dentry, const char *acl_name)
> +static int selinux_inode_get_acl(const struct path *path,
> + const char *acl_name)
> {
> - return dentry_has_perm(current_cred(), dentry, FILE__GETATTR);
> + return dentry_has_perm(current_cred(), path->dentry, FILE__GETATTR);
> }
>
> -static int selinux_inode_remove_acl(struct mnt_idmap *idmap,
> - struct dentry *dentry, const char *acl_name)
> +static int selinux_inode_remove_acl(const struct path *path,
> + const char *acl_name)
> {
> - return dentry_has_perm(current_cred(), dentry, FILE__SETATTR);
> + return dentry_has_perm(current_cred(), path->dentry, FILE__SETATTR);
> }
>
> static void selinux_inode_post_setxattr(struct dentry *dentry, const char *name,
> diff --git a/security/smack/smack_lsm.c b/security/smack/smack_lsm.c
> index 4adb2fd9cf70..7889f63ec739 100644
> --- a/security/smack/smack_lsm.c
> +++ b/security/smack/smack_lsm.c
> @@ -1548,62 +1548,59 @@ static int smack_inode_removexattr(const struct path *path,
> *
> * Returns 0 if access is permitted, an error code otherwise
> */
> -static int smack_inode_set_acl(struct mnt_idmap *idmap,
> - struct dentry *dentry, const char *acl_name,
> - struct posix_acl *kacl)
> +static int smack_inode_set_acl(const struct path *path,
> + const char *acl_name, struct posix_acl *kacl)
> {
> struct smk_audit_info ad;
> int rc;
>
> smk_ad_init(&ad, __func__, LSM_AUDIT_DATA_DENTRY);
> - smk_ad_setfield_u_fs_path_dentry(&ad, dentry);
> + smk_ad_setfield_u_fs_path_dentry(&ad, path->dentry);
>
> - rc = smk_curacc(smk_of_inode(d_backing_inode(dentry)), MAY_WRITE, &ad);
> - rc = smk_bu_inode(d_backing_inode(dentry), MAY_WRITE, rc);
> + rc = smk_curacc(smk_of_inode(d_backing_inode(path->dentry)), MAY_WRITE, &ad);
> + rc = smk_bu_inode(d_backing_inode(path->dentry), MAY_WRITE, rc);
> return rc;
> }
>
> /**
> * smack_inode_get_acl - Smack check for getting posix acls
> - * @idmap: idmap of the mnt this request came from
> - * @dentry: the object
> + * @path: the object
> * @acl_name: name of the posix acl
> *
> * Returns 0 if access is permitted, an error code otherwise
> */
> -static int smack_inode_get_acl(struct mnt_idmap *idmap,
> - struct dentry *dentry, const char *acl_name)
> +static int smack_inode_get_acl(const struct path *path,
> + const char *acl_name)
> {
> struct smk_audit_info ad;
> int rc;
>
> smk_ad_init(&ad, __func__, LSM_AUDIT_DATA_DENTRY);
> - smk_ad_setfield_u_fs_path_dentry(&ad, dentry);
> + smk_ad_setfield_u_fs_path_dentry(&ad, path->dentry);
>
> - rc = smk_curacc(smk_of_inode(d_backing_inode(dentry)), MAY_READ, &ad);
> - rc = smk_bu_inode(d_backing_inode(dentry), MAY_READ, rc);
> + rc = smk_curacc(smk_of_inode(d_backing_inode(path->dentry)), MAY_READ, &ad);
> + rc = smk_bu_inode(d_backing_inode(path->dentry), MAY_READ, rc);
> return rc;
> }
>
> /**
> * smack_inode_remove_acl - Smack check for getting posix acls
> - * @idmap: idmap of the mnt this request came from
> - * @dentry: the object
> + * @path: the object
> * @acl_name: name of the posix acl
> *
> * Returns 0 if access is permitted, an error code otherwise
> */
> -static int smack_inode_remove_acl(struct mnt_idmap *idmap,
> - struct dentry *dentry, const char *acl_name)
> +static int smack_inode_remove_acl(const struct path *path,
> + const char *acl_name)
> {
> struct smk_audit_info ad;
> int rc;
>
> smk_ad_init(&ad, __func__, LSM_AUDIT_DATA_DENTRY);
> - smk_ad_setfield_u_fs_path_dentry(&ad, dentry);
> + smk_ad_setfield_u_fs_path_dentry(&ad, path->dentry);
>
> - rc = smk_curacc(smk_of_inode(d_backing_inode(dentry)), MAY_WRITE, &ad);
> - rc = smk_bu_inode(d_backing_inode(dentry), MAY_WRITE, rc);
> + rc = smk_curacc(smk_of_inode(d_backing_inode(path->dentry)), MAY_WRITE, &ad);
> + rc = smk_bu_inode(d_backing_inode(path->dentry), MAY_WRITE, rc);
> return rc;
> }
>