From nobody Fri Oct 2 07:45:35 2026 Received: from mail-wm1-f42.google.com (mail-wm1-f42.google.com [209.85.128.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1779D3368BA for ; Mon, 3 Aug 2026 19:46:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.42 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785786390; cv=none; b=nOgBO5o6EJS0eIup/IhSXBh3rB++7YUlLLf7bvjW61CxF9a2ivV35Vb1sYZK8CET8Q6amMcnWgYMYGVwLO66Tl+jreak28YXPH104IJRsISjash2FCVggHy9jm/xyCHGqGXBntFv0LsFRDQgPsM6mFL+UW9ulrqkHFm/gd0//kA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785786390; c=relaxed/simple; bh=typ9Azzk008ITRlZw56fyhTb4AIIzw4bA/fCdMQJi0M=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:To:Cc; b=NFWQjzEf3t/EXpjyqc1rLg1BH4dln1TMkycdZ+pOGUgyR8LqVqlMoJ6A1y9fSWCYopnBnzXR2kYdOZFpya/w+hCoAll95vKBX4+w3JdJBxuvL2WOCHUbfeKL3bnO3hLCZB2mPlsu9mSk7Kv4Dwv0rXIn8ua2xZrpEy84UTsSii4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=TXJt9iHB; arc=none smtp.client-ip=209.85.128.42 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="TXJt9iHB" Received: by mail-wm1-f42.google.com with SMTP id 5b1f17b1804b1-498012a61f6so12855e9.0 for ; Mon, 03 Aug 2026 12:46:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1785786387; x=1786391187; darn=vger.kernel.org; h=cc:to:message-id:content-transfer-encoding:content-type :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=XYjmDiw2VbLsmJPIgyiXAfWmLhwTUZnrbCHzr6uykSs=; b=TXJt9iHBViOy+KtPBKoqQK75eo3IYqm1AQhs0eHrHRyyI5pRp4TWNFAY9Mvl89aQqX XEKJuT5arufSK3AQQEo/szq8SKExuP6nPcOhKozauFoU2spOmyXxkfc0vfl7WFcR+gTY hYvrPCLDLyQp9Y81UPkmyN/Z7QFQRkdqlr5EIT7QgYq7Tyw+dCTE3QK2avyBHdFUUecR zai1xeSabSU3rb8UWDndR8MQjqegLk7dMjNOtQFOfn9K2+5+mNgO/GR6a1HVFldDoY49 orCf6rfh+4YHUHOG2LXLXBHdUUsE5u0n4jWPus+hIuizYjVhJJ/jlibRzXgPeVS3o9MW bkAg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785786387; x=1786391187; h=cc:to:message-id:content-transfer-encoding:content-type :mime-version:subject:date:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=XYjmDiw2VbLsmJPIgyiXAfWmLhwTUZnrbCHzr6uykSs=; b=ooJK4KVluag/EOMH3MJCE1/Nd8Z0h4EkqQj1yzqXAm4dn4jY4SuWzRCA39hs+N/iAe xfgiWGtgvIjlRShFFYpnd1HEOutirMT+ynnyJQ6wVmtjxxKNj10lfypQXuDKnA6+P0xG AxGeLywe7ZPgYgXUpABy5n7XikoILq63yLBYdFAwQEMpVUYus+KN+4138szypsmyDT5X eO5bztWL6Dddm1qgDF0CUXb8+b54Dth2quY8BypQoxQBEzezhe0uOuviqm33BLmHY/oi om4tjt4QjdmUg+dbBxFYr8lk6NPy5VaDCOqh+n4r2z5qrXhmD9UrZav9YLdDR4bZoY0P ABFw== X-Forwarded-Encrypted: i=1; AHgh+Rpt/82WODvwBB8u/pHhPZ1CYb6stIIK6MKfMoFgPzHxwmRue2U+x4kE5SsSjWkxQKjLqkzmDPJiu1P9QYQ=@vger.kernel.org X-Gm-Message-State: AOJu0YzjsN5t1bWoZnMMnzsSOmBpSimX+Mqu6SQbdiwAl9843TEFfXzC OGcXQ3jXP144HK0brLod39LMX4tzP0eaZZidSBxN/VT+vfwlEH/l3VuLOWzKO2l+Ng== X-Gm-Gg: AR+sD12r5Hzp84XYJqx1ZWZjeuRBC0XWNVxk/xrIlqlOHLhMmJierZyp9pelVC0Rxq2 iAcMg7UEtJIiwP/NjJiRJaOk/J8to0iXm6z0nY4o4nUNRMnqKt7AGnLyTYlViwQKqdQXoPXw1CS VQ0VPtSjst0d6bNXaMIr/6WknG8uLurKdV7ePiqa+PjBNr5zxOYd1Ev6gQlXYcVoQh8FxMcD+pt VOazTcDGlrd6ztcIoQfspwSbofiZOsy4QaI1emF0uKfnR72JjaC2ugg2SyxFA2Ykh5VREOcYIh1 epnMHlU2u280dNKccubBUU0PrqrtRbTksFKdtXY1R7fNyQmRM2eEsTpIxP7SbaQXg+XZd7CSFfd 0iQD2mMaPxLLq3uak+Yq8++v6nU/Khf4QlYSrwo/H6OrXYhkPO5FxXw9BHzDG+nDfrt94xesmfK DM+STIcYjlmvyqd2kH0Btq1ZY6Bn+7jqDudyHcDrwQQEAzp7VzzWxQ6Hc8kIkoK++1SwFvopYRB c/KYfCfvZjz2PTjj3K5wTFdP5CRJh8xDLLkTYPiutXHbdc5m2Vgs6DHthI= X-Received: by 2002:a05:600d:101:b0:493:aca0:32e2 with SMTP id 5b1f17b1804b1-4994a33d363mr207745e9.4.1785786386648; Mon, 03 Aug 2026 12:46:26 -0700 (PDT) Received: from localhost ([2a00:79e0:288a:8:28e5:f164:de97:d72f]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4994a0f7b86sm17257885e9.10.2026.08.03.12.46.25 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 12:46:25 -0700 (PDT) From: Jann Horn Date: Mon, 03 Aug 2026 21:46:19 +0200 Subject: [PATCH] fs: document semantics of kstat::{uid,gid} fields Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260803-vfs-comment-stat-uid-v1-1-162d062b737c@google.com> X-B4-Tracking: v=1; b=H4sIAArwcGoC/yXMQQqDMBBA0avIrDuQqtjoVYqLmEzaKRglE0UQ7 260y7f4fwehyCTQFTtEWll4ChnPRwH2a8KHkF02lKpslFYVrl7QTuNIIaEkk3Bhh2Rap1+1b6t GQ07nSJ63e/vu/5Zl+JFN1wuO4wQ3aPwweAAAAA== X-Change-ID: 20260803-vfs-comment-stat-uid-ea9d874f9368 To: Alexander Viro , Christian Brauner Cc: Jan Kara , linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, Jann Horn X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1785786382; l=2128; i=jannh@google.com; s=20240730; h=from:subject:message-id; bh=typ9Azzk008ITRlZw56fyhTb4AIIzw4bA/fCdMQJi0M=; b=8eOftUoJmeL4qbf244FvXp4URGvEKeoGrpwx+VLB8M7Vv86w2G348lZxw23kLOz9sIGHJ7kaW cE1rf+DvnmHA+vcZ8T6KnvKV3oTf3C3OSlQbIPklE4C9zVFql8/hwmK X-Developer-Key: i=jannh@google.com; a=ed25519; pk=AljNtGOzXeF6khBXDJVVvwSEkVDGnnZZYqfWhP1V+C8= The uid stored in struct kstat is logically a vfsuid; file systems initialize it by converting a kuid (filesystem perspective) to a vfsuid (mount perspective), then use vfsuid_into_kuid(), which essentially just typecasts from vfsuid to kuid. For now, just add a comment to note this mismatch between C type and semantic type. Below are some notes for anyone who wants to refactor this in the future. There are probably two options to refactor this away: 1. Change the type of kstat::uid to vfsuid_t, and perform the conversion from vfsuid to userspace-uid in the VFS layer. This wouldn't change machine code, just be more semantically correct. 2. Change the semantics of kstat::uid to really be a kuid_t, and let the VFS layer take care of doing the translation from kuid to vfsuid that is currently done in filesystem code (or in generic_fillattr, on behalf of the filesystem code). Option 2 is probably neater since it moves more logic into the generic VFS layer, and this is something that is expected to work the same way in all file systems? The following coccinelle script: ``` virtual context @@ struct kstat *stat; @@ * stat->uid @@ struct kstat *stat; @@ * stat->gid @@ struct kstat stat; @@ * stat.uid @@ struct kstat stat; @@ * stat.gid ``` detects 43 field accesses to these uid/gid fields. Signed-off-by: Jann Horn Reviewed-by: Jan Kara --- include/linux/stat.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/include/linux/stat.h b/include/linux/stat.h index e3d00e7bb26d..9c5709132862 100644 --- a/include/linux/stat.h +++ b/include/linux/stat.h @@ -41,8 +41,8 @@ struct kstat { u64 ino; dev_t dev; dev_t rdev; - kuid_t uid; - kgid_t gid; + kuid_t uid; /* This is logically a vfsuid_t. */ + kgid_t gid; /* This is logically a vfsgid_t. */ loff_t size; struct timespec64 atime; struct timespec64 mtime; --- base-commit: 075b74841bd0065a3bda3440873c747938e69b68 change-id: 20260803-vfs-comment-stat-uid-ea9d874f9368 Best regards, -- =20 Jann Horn