From nobody Mon Sep 28 12:34:31 2026 Received: from mail-yw1-f182.google.com (mail-yw1-f182.google.com [209.85.128.182]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A5A6A49483B for ; Fri, 21 Aug 2026 16:13:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.182 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787328787; cv=none; b=oDAWE6hvVKHngww5VCPfjc/H6PB3K0RgEffxRJN+LZY7KCrLB9s3AhktSA2xhk+W5iT4RoAlAUg6cBFecmO2lRkdkNnD7pLM0Ss7/bPO574IMSnUa48VxSSIknP0iKxr1B2AzY/rXcmfd7doGNf8fJS0cZPS9B7104iEvMbW9dg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787328787; c=relaxed/simple; bh=bxejHnhZgOHZCx4l87xaSOkvIQXcM6SB6i/eoU6gds4=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=s4ZZL8mDnqBqkEnXgFVVahhuomPwm9VECwbPLsboPCzeVbrRpaKMqIglGSnlyoQLt6NMItPbNlDVuTi9yNKj0472lSxn0FaK4kkGGYJhZ7Afzu6+uWqSFdEt2VjiXYwbKLjuKWGGojM+wI382gznBU0NqPkc8DR8jvWLA+9C7j4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=cs.unc.edu; spf=pass smtp.mailfrom=cs.unc.edu; dkim=pass (2048-bit key) header.d=cs.unc.edu header.i=@cs.unc.edu header.b=CkM3QD3j; arc=none smtp.client-ip=209.85.128.182 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=cs.unc.edu Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=cs.unc.edu Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=cs.unc.edu header.i=@cs.unc.edu header.b="CkM3QD3j" Received: by mail-yw1-f182.google.com with SMTP id 00721157ae682-7ff05e5d009so16961667b3.1 for ; Fri, 21 Aug 2026 09:13:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cs.unc.edu; s=google; t=1787328784; x=1787933584; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=hnEZF2cF3IzXZwcXsx024q0uyKxWL8hRCsuHpl/rWC4=; b=CkM3QD3jObpWrzcYdjSKMuPbvm8v5VGNECtiCFRDH1cMW/7tZmdAQ3nejSy1bSobFr rh7bmAmoLAxoNeEJ3zFH2eZGU68ND1OkwzUCjaSSSiDRgV8POYwJMlJ+L2iAK9LIadou iTxdFbNn34x9vgt5VmcBMMwJOzjrpehaTUqdZwSuXD+ZQI3QTzeqkbpk9+zpL/jZpuKZ 7UYhYSq4fGzdKzGyZ6bIPhBF5rZlGA+q2eagPMGn8kMggNWGbfZnuMyVFqQYvGB84bS2 uvoGMJeGS/04dgBVz5E1mYQ3+bts0aEFv6wO84VD9L7F5e7eq1I/4UVrHuzyA5O/H11f Y8Lw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787328784; x=1787933584; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=hnEZF2cF3IzXZwcXsx024q0uyKxWL8hRCsuHpl/rWC4=; b=fY/13Xrc1k7y1WdVq7d9v+NXA8JQvfqQ5N+1zZuCKKNiT0jkI7zhT76AGo0LKzwpdc 2dOoEs0Sv2cC0sipCy8DRGndZXW6ouCYi1d38nwp3yvkiuFlFtAqmSTCY3NEOvBjSFdy j7YLAGD0AZYqS0LJLJ8P4PcAQIdPOnyLkXIeMWff+JpYwpznrStnN+oiQxcAMxpvS/y/ NM5F2OvPGVeUpM6PpmPA6axjS6U/+NI9aPxKKDPKxeUZuSgu21eLAOfZoR45lGVeGDD6 Jaso1bE7vHWZ+0SV/s7rkhru5XtKS9R6SMLTu7Z1YFO/sc/QC1+E5fAVBER6e1RycTHz pY8w== X-Forwarded-Encrypted: i=1; AHgh+RqS1yHbL3IogG0nmkUx2jv1nI1pENeafWJi2ks5DQY29NRgT9nnCKxmJpib01cjnMLuRRRJ8a1NyCKz71g=@vger.kernel.org X-Gm-Message-State: AFuF++kbuaZsX2M8+1yzkIuumWuGh+PkHLfNEOSLOOaExsk1VDoqaeAz jlRbP7/Iu+SEmNg3UYOvD/EANnmhhoiXRRJppS+5y5l6W03ND147eipZfAiDYBqscA== X-Gm-Gg: AR+sD13YWsFAfPoNSyBWLl1V11mfgJPjC0pfO76dWD/CZsRyIhKWHKnH+WkeBWVBgvd AuHpylK2xS4T+bME3JhRFd8Ot/hlLSNaFuFxbrfINm/mgnMKnv1Z5EIReF4/iNZj/8IXEdhzFFK 8OiKXMNxtcchGHPFjyzjYQxSVP1zo3VYNhMxRAsSfMIbfj2BtuMQwskXE74gr/Il5HMbj5ZVqKH Mousm7GFMFK2B+n9W/yqFTOS7whzxEj/erhTd5q7p8CYOND/PXpm+Uplqf/LvD7dk17rmnu8UYb M+O0Qe7ErVekcNZuNpAI467IhrK7LuGIUFqGDlsmlnopzs+UEDvxHrw2EXIb3d1F+T6k92WFtV2 P4/3VkSO/sNhWXOs5pnzaQrDzmeA7N9Z2cbG8JgHqG6vrmB0tY83lmhGS/KTOUmUDXqct6Ya+Gi EoNnzyBG9exogaNEcaVUDdG7qpwNZ/XhWsnu6g7yly2AhPhz5shVxwcrkByfm54qtdCMlBwx9wt qfVQvEo7pygj99z X-Received: by 2002:a05:690c:9a86:b0:81f:3dab:372f with SMTP id 00721157ae682-849f1d8b2aemr37464177b3.12.1787328784469; Fri, 21 Aug 2026 09:13:04 -0700 (PDT) Received: from cobra01.cs.unc.edu (cobra01.cs.unc.edu. [152.2.130.143]) by smtp.gmail.com with ESMTPSA id 00721157ae682-84511abc12fsm43056607b3.1.2026.08.21.09.13.03 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 21 Aug 2026 09:13:04 -0700 (PDT) From: hengyul@cs.unc.edu To: chenyichong@uniontech.com, tj@kernel.org, dakr@kernel.org, gregkh@linuxfoundation.org Cc: driver-core@lists.linux.dev, linux-kernel@vger.kernel.org Subject: [PATCH] kernfs: preserve security xattrs without allocating iattrs Date: Fri, 21 Aug 2026 12:12:21 -0400 Message-ID: <20260821161221.1270292-1-hengyul@cs.unc.edu> X-Mailer: git-send-email 2.55.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Hengyu Liang Commit d5e81a5650b5 ("kernfs: avoid iattr allocation in listxattr") made kernfs_iop_listxattr() return an empty list when the kernfs node has no allocated kernfs_iattrs. However, this also skips security xattr names provided by simple_xattr_list(). As of now, applications can retrieve the SELinux label of a sysfs file with getxattr(), but cannot do it through listxattr(). A similar issue happened before in commit b09e0fa4b4ea ("tmpfs: implement g= eneric xattr support"). It was fixed by commit 8b0ba61df5a1c ("fs/xattr.c: fix simple_xattr_list to= always include security.* xattrs"). Perhaps this recent commit needs a fix as well. The issue can be reproduced with a simple python program: python3 - <<'PY' import os path =3D "/sys/kernel/warn_count" print("getxattr:", os.getxattr(path, "security.selinux")) print("listxattr:", os.listxattr(path)) PY Before commit d5e81a5650b5 ("kernfs: avoid iattr allocation in listxattr"), the result is: getxattr: b'system_u:object_r:sysfs_t:s0\x00' listxattr: ['security.selinux'] After that commit, the result is: getxattr: b'system_u:object_r:sysfs_t:s0\x00' listxattr: [] This patch will keep listxattr() consistent with getxattr() when security xattrs are available. Fixes: d5e81a5650b5 ("kernfs: avoid iattr allocation in listxattr") Signed-off-by: Hengyu Liang Acked-by: Tejun Heo --- fs/kernfs/inode.c | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/fs/kernfs/inode.c b/fs/kernfs/inode.c index 237dcdd73fc2..bc3c6b939b0e 100644 --- a/fs/kernfs/inode.c +++ b/fs/kernfs/inode.c @@ -142,10 +142,9 @@ ssize_t kernfs_iop_listxattr(struct dentry *dentry, ch= ar *buf, size_t size) struct kernfs_iattrs *attrs; =20 attrs =3D kernfs_iattrs_noalloc(kn); - if (!attrs) - return 0; =20 - return simple_xattr_list(d_inode(dentry), &attrs->xattrs, buf, size); + return simple_xattr_list(d_inode(dentry), + attrs ? &attrs->xattrs : NULL, buf, size); } =20 static inline void set_default_inode_attr(struct inode *inode, umode_t mod= e) --=20 2.55.0