Re: [fuse-devel] [PATCH 01/25] VFS: move attr_kill logic from notify_change into helper function

Miklos Szeredi <[email protected]> Mon, 06 Aug 2007 21:37:00 +0200
Newsgroups gmane.linux.kernel,gmane.linux.file-systems,gmane.comp.file-systems.coda.general,gmane.linux.cluster.redhat.cluster.devel,gmane.comp.file-systems.reiserfs.general,gmane.comp.file-systems.fuse.devel,gmane.linux.file-systems.jffs,gmane.linux.uml.user,gmane.comp.file-systems.ext4,gmane.linux.file-systems.cifs,gmane.comp.file-systems.ocfs2.devel
Message-ID <[email protected]>
> > Your patch is changing the API in a very unsafe way, since there will
> > be no error or warning on an unconverted fs.  And that could lead to
> > security holes.
> > 
> > If we would rename the setattr method to setattr_new as well as
> > changing it's behavior, that would be fine.  But I guess we do not
> > want to do that.
> 
> Which "unconverted fses"? If we're talking out of tree stuff, then too
> bad: it is _their_ responsibility to keep up with kernel changes.

It is usually a good idea to not change the semantics of an API in a
backward incompatible way without changing the syntax as well.

This is true regardless of whether we care about out-of-tree code or
not (and we should care to some degree).  And especially true if the
change in question is security sensitive.

Miklos