Re: [PATCH v3 4/5] xfs: replace ns_capable_noaudit

Carlos Maiolino <[email protected]>
Newsgroups org.kernel.vger.linux-security-module,org.kernel.vger.linux-fsdevel,org.kernel.vger.linux-kernel,org.kernel.vger.linux-xfs
Message-ID <[email protected]>
On Thu, Jul 02, 2026 at 08:58:56AM -0700, Darrick J. Wong wrote:
> On Thu, Jul 02, 2026 at 11:33:23AM +0200, [email protected] wrote:
> > From: Carlos Maiolino <[email protected]>
> > 
> > Now that capable_noaudit() is available, we don't need to keep
> > using ns_capable_noaudit() and specifying the usernaspace every single
> > time.
> > 
> > Signed-off-by: Carlos Maiolino <[email protected]>
> > Cc: Jan Kara <[email protected]>
> > Cc: Christoph Hellwig <[email protected]>
> > Cc: Serge E. Hallyn <[email protected]>
> > Cc: Darrick J. Wong <[email protected]>
> > Cc: Dave Chinner <[email protected]>
> > Cc: Eric Sandeen <[email protected]>
> > Cc: Dr. Thomas Orgis" <[email protected]>
> > Cc: [email protected]
> > Cc: [email protected]
> > Cc: [email protected]
> > Cc: [email protected]
> > ---
> >  fs/xfs/xfs_fsmap.c | 3 +--
> >  fs/xfs/xfs_ioctl.c | 2 +-
> >  fs/xfs/xfs_iops.c  | 2 +-
> >  3 files changed, 3 insertions(+), 4 deletions(-)
> > 
> > diff --git a/fs/xfs/xfs_fsmap.c b/fs/xfs/xfs_fsmap.c
> > index 7c79fbe0a74c..041bb2105ec6 100644
> > --- a/fs/xfs/xfs_fsmap.c
> > +++ b/fs/xfs/xfs_fsmap.c
> > @@ -1174,8 +1174,7 @@ xfs_getfsmap(
> >  	if (!xfs_getfsmap_check_keys(&head->fmh_keys[0], &head->fmh_keys[1]))
> >  		return -EINVAL;
> >  
> > -	use_rmap = xfs_has_rmapbt(mp) &&
> > -		   ns_capable_noaudit(&init_user_ns, CAP_SYS_ADMIN);
> > +	use_rmap = xfs_has_rmapbt(mp) && capable_noaudit(CAP_SYS_ADMIN);
> >  	head->fmh_entries = 0;
> >  
> >  	/* Set up our device handlers. */
> > diff --git a/fs/xfs/xfs_ioctl.c b/fs/xfs/xfs_ioctl.c
> > index 1a8af827dde1..374b488f0416 100644
> > --- a/fs/xfs/xfs_ioctl.c
> > +++ b/fs/xfs/xfs_ioctl.c
> > @@ -647,7 +647,7 @@ xfs_ioctl_setattr_get_trans(
> >  		goto out_error;
> >  
> >  	error = xfs_trans_alloc_ichange(ip, NULL, NULL, pdqp,
> > -			ns_capable_noaudit(&init_user_ns, CAP_FOWNER), &tp);
> > +					capable_noaudit(CAP_FOWNER), &tp);
> 
> Not sure why the indentation changed, otherwise the patch looks fine to
> me.

Purely my screw up. I fixed it already to send to the next version. Was
just waiting for more comments

> 
> --D
> 
> >  	if (error)
> >  		goto out_error;
> >  
> > diff --git a/fs/xfs/xfs_iops.c b/fs/xfs/xfs_iops.c
> > index 205fe2dae732..ce9f8b8468fc 100644
> > --- a/fs/xfs/xfs_iops.c
> > +++ b/fs/xfs/xfs_iops.c
> > @@ -835,7 +835,7 @@ xfs_setattr_nonsize(
> >  	}
> >  
> >  	error = xfs_trans_alloc_ichange(ip, udqp, gdqp, NULL,
> > -					ns_capable_noaudit(&init_user_ns, CAP_FOWNER),
> > +					capable_noaudit(CAP_FOWNER),
> >  					&tp);
> >  	if (error)
> >  		goto out_dqrele;
> > -- 
> > 2.54.0
> > 
> > 
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.