Re: [PATCH v3 00/12] vfs: change inode->i_ino from unsigned long to u64
Jeff Layton <[email protected]> Mon, 09 Mar 2026 16:50:22 -0400
| Newsgroups | org.kernel.vger.autofs,dev.linux.lists.fsverity,dev.linux.lists.netfs,dev.linux.lists.ntfs3,dev.linux.lists.nvdimm,dev.linux.lists.ocfs2-devel,dev.linux.lists.v9fs,net.sourceforge.lists.linux-f2fs-devel,org.freedesktop.lists.amd-gfx,org.freedesktop.lists.dri-devel,org.infradead.lists.linux-mtd,org.kernel.vger.audit,org.kernel.vger.bpf,org.kernel.vger.ceph-devel,org.kernel.vger.ecryptfs,org.kernel.vger.linux-bluetooth,org.kernel.vger.linux-can,org.kernel.vger.linux-cifs,org.kernel.vger.linux-ext4,org.kernel.vger.linux-fscrypt,org.kernel.vger.linux-fsdevel,org.kernel.vger.linux-hams,org.kernel.vger.linux-integrity,org.kernel.vger.linux-kernel,org.kernel.vger.linux-media,org.kernel.vger.linux-nfs,org.kernel.vger.linux-nilfs,org.kernel.vger.linux-perf-users,org.kernel.vger.linux-sctp,org.kernel.vger.linux-security-module,org.kernel.vger.linux-trace-kernel,org.kernel.vger.linux-unionfs,org.kernel.vger.linux-x25,org.kernel.vger.linux-xfs,org.kernel.vger.netdev,org.kernel.vger.selinux,org.kvack.linux-mm |
|---|---|
| Message-ID | <[email protected]> |
On Mon, 2026-03-09 at 16:11 -0400, Mimi Zohar wrote: > On Mon, 2026-03-09 at 15:33 -0400, Jeff Layton wrote: > > On Mon, 2026-03-09 at 15:00 -0400, Mimi Zohar wrote: > > > On Mon, 2026-03-09 at 13:59 -0400, Jeff Layton wrote: > > > > On Mon, 2026-03-09 at 13:47 -0400, Mimi Zohar wrote: > > > > > [ I/O socket time out. Trimming the To list.] > > > > >=20 > > > > > On Wed, 2026-03-04 at 10:32 -0500, Jeff Layton wrote: > > > > > > This version squashes all of the format-string changes and the = i_ino > > > > > > type change into the same patch. This results in a giant 600+ l= ine patch > > > > > > at the end of the series, but it does remain bisectable. Becau= se the > > > > > > patchset was reorganized (again) some of the R-b's and A-b's ha= ve been > > > > > > dropped. > > > > > >=20 > > > > > > The entire pile is in the "iino-u64" branch of my tree, if anyo= ne is > > > > > > interested in testing this. > > > > > >=20 > > > > > > https://git.kernel.org/pub/scm/linux/kernel/git/jlayton/lin= ux.git/ > > > > > >=20 > > > > > > Original cover letter follows: > > > > > >=20 > > > > > > ----------------------8<----------------------- > > > > > >=20 > > > > > > Christian said [1] to "just do it" when I proposed this, so her= e we are! > > > > > >=20 > > > > > > For historical reasons, the inode->i_ino field is an unsigned l= ong, > > > > > > which means that it's 32 bits on 32 bit architectures. This has= caused a > > > > > > number of filesystems to implement hacks to hash a 64-bit ident= ifier > > > > > > into a 32-bit field, and deprives us of a universal identifier = field for > > > > > > an inode. > > > > > >=20 > > > > > > This patchset changes the inode->i_ino field from an unsigned l= ong to a > > > > > > u64. This shouldn't make any material difference on 64-bit host= s, but > > > > > > 32-bit hosts will see struct inode grow by at least 4 bytes. Th= is could > > > > > > have effects on slabcache sizes and field alignment. > > > > > >=20 > > > > > > The bulk of the changes are to format strings and tracepoints, = since the > > > > > > kernel itself doesn't care that much about the i_ino field. The= first > > > > > > patch changes some vfs function arguments, so check that one ou= t > > > > > > carefully. > > > > > >=20 > > > > > > With this change, we may be able to shrink some inode structure= s. For > > > > > > instance, struct nfs_inode has a fileid field that holds the 64= -bit > > > > > > inode number. With this set of changes, that field could be eli= minated. > > > > > > I'd rather leave that sort of cleanups for later just to keep t= his > > > > > > simple. > > > > > >=20 > > > > > > Much of this set was generated by LLM, but I attributed it to m= yself > > > > > > since I consider this to be in the "menial tasks" category of L= LM usage. > > > > > >=20 > > > > > > [1]: https://lore.kernel.org/linux-fsdevel/20260219-portrait-wi= nkt-959070cee42f@brauner/ > > > > > >=20 > > > > > > Signed-off-by: Jeff Layton <[email protected]> > > > > >=20 > > > > > Jeff, missing from this patch set is EVM. In hmac_add_misc() EVM= copies the > > > > > i_ino and calculates either an HMAC or file meta-data hash, which= is then > > > > > signed.=20 > > > > >=20 > > > > >=20 > > > >=20 > > > > Thanks Mimi, good catch. > > > >=20 > > > > It looks like we should just be able to change the ino field to a u= 64 > > > > alongside everything else. Something like this: > > > >=20 > > > > diff --git a/security/integrity/evm/evm_crypto.c b/security/integri= ty/evm/evm_crypto.c > > > > index c0ca4eedb0fe..77b6c2fa345e 100644 > > > > --- a/security/integrity/evm/evm_crypto.c > > > > +++ b/security/integrity/evm/evm_crypto.c > > > > @@ -144,7 +144,7 @@ static void hmac_add_misc(struct shash_desc *de= sc, struct inode *inode, > > > > char type, char *digest) > > > > { > > > > struct h_misc { > > > > - unsigned long ino; > > > > + u64 ino; > > > > __u32 generation; > > > > uid_t uid; > > > > gid_t gid; > > > >=20 > > >=20 > > > Agreed. > > >=20 > > > >=20 > > > > That should make no material difference on 64-bit hosts. What's the > > > > effect on 32-bit? Will they just need to remeasure everything or wo= uld > > > > the consequences be more dire? Do we have any clue whether anyone i= s > > > > using EVM in 32-bit environments? > > >=20 > > > All good questions. Unfortunately I don't know the answer to most of = them. What > > > we do know: changing the size of the i_ino field would affect EVM fil= e metadata > > > verification and would require relabeling the filesystem. Even packa= ges > > > containing EVM portable signatures, which don't include or verify the= i_ino > > > number, would be affected. > > >=20 > >=20 > > Ouch. Technically, I guess this is ABI... > >=20 > > While converting to u64 seems like the ideal thing to do, the other > > option might be to just keep this as an unsigned long for now. > >=20 > > No effect on 64-bit, but that could keep things working 32-bit when the > > i_ino casts properly to a u32. ext4 would be fine since they don't > > issue inode numbers larger than UINT_MAX. xfs and btrfs are a bit more > > iffy, but worst case they'd just need to be relabeled (which is what > > they'll need to do anyway). > >=20 > > If we do that, then we should probably add a comment to this function > > explaining why it's an unsigned long. >=20 > Agreed. >=20 For now, I think that's the best approach. I'll spin up a patch to add the comment. > >=20 > > Thoughts? >=20 > My concern would be embedded/IoT devices, but I don't have any insight in= to who > might be using it on 32 bit. >=20 Yep. This LWN article on Arnd's talk lays out the state of things: https://lwn.net/Articles/1035727/ The upshot is that it's hard to buy 32-bit CPUs these days, and will only get harder. But, there are still a fair number of 32-bit devices out in the field and will be for some time. The big question is how many of those EVM users that intend to run new kernels. I have no idea how to answer that. --=20 Jeff Layton <[email protected]>