mbox series

[v4,0/5] virtiofsd xattr name mappings

Message ID 20201023165812.36028-1-dgilbert@redhat.com
Headers show
Series virtiofsd xattr name mappings | expand

Message

Dr. David Alan Gilbert Oct. 23, 2020, 4:58 p.m. UTC
From: "Dr. David Alan Gilbert" <dgilbert@redhat.com>

This is the 4th cut of an xattr name mapping option for virtiofsd.
It allows the user of virtiofsd to define a fairly flexible mapping
from the view of the xattr names the host fs has and the ones that the
guest sees.

  The hope is this allows things like:
    a) Different selinux attributes on host/guest
    b) separation of trusted. attributes that clash on overlayfs
    c) support for privileged xattr's in guests running with an
       unprivileged virtiofsd.

There's no apparent standard for this kind of mapping, so I made
it flexible by specifying a mapping rule in the option.

Prefix's can be added (selectively or globally), xattr's can be
dropped in either direction or passed through.

v4
  cleanups from Stefan and Vivek's reviews

Dave


Dr. David Alan Gilbert (5):
  tools/virtiofsd: xattr name mappings: Add option
  tools/virtiofsd: xattr name mappings: Map client xattr names
  tools/virtiofsd: xattr name mappings: Map server xattr names
  tools/virtiofsd: xattr name mapping examples
  tools/virtiofsd: xattr name mappings: Simple 'map'

 docs/tools/virtiofsd.rst         | 161 +++++++++++
 tools/virtiofsd/passthrough_ll.c | 474 ++++++++++++++++++++++++++++++-
 2 files changed, 632 insertions(+), 3 deletions(-)

Comments

Stefan Hajnoczi Oct. 26, 2020, 3:55 p.m. UTC | #1
On Fri, Oct 23, 2020 at 05:58:07PM +0100, Dr. David Alan Gilbert (git) wrote:
> From: "Dr. David Alan Gilbert" <dgilbert@redhat.com>

> 

> This is the 4th cut of an xattr name mapping option for virtiofsd.

> It allows the user of virtiofsd to define a fairly flexible mapping

> from the view of the xattr names the host fs has and the ones that the

> guest sees.

> 

>   The hope is this allows things like:

>     a) Different selinux attributes on host/guest

>     b) separation of trusted. attributes that clash on overlayfs

>     c) support for privileged xattr's in guests running with an

>        unprivileged virtiofsd.

> 

> There's no apparent standard for this kind of mapping, so I made

> it flexible by specifying a mapping rule in the option.

> 

> Prefix's can be added (selectively or globally), xattr's can be

> dropped in either direction or passed through.

> 

> v4

>   cleanups from Stefan and Vivek's reviews

> 

> Dave

> 

> 

> Dr. David Alan Gilbert (5):

>   tools/virtiofsd: xattr name mappings: Add option

>   tools/virtiofsd: xattr name mappings: Map client xattr names

>   tools/virtiofsd: xattr name mappings: Map server xattr names

>   tools/virtiofsd: xattr name mapping examples

>   tools/virtiofsd: xattr name mappings: Simple 'map'

> 

>  docs/tools/virtiofsd.rst         | 161 +++++++++++

>  tools/virtiofsd/passthrough_ll.c | 474 ++++++++++++++++++++++++++++++-

>  2 files changed, 632 insertions(+), 3 deletions(-)

> 

> -- 

> 2.28.0

> 


Reviewed-by: Stefan Hajnoczi <stefanha@redhat.com>
Dr. David Alan Gilbert Oct. 26, 2020, 5:30 p.m. UTC | #2
* Dr. David Alan Gilbert (git) (dgilbert@redhat.com) wrote:
> From: "Dr. David Alan Gilbert" <dgilbert@redhat.com>

> 

> This is the 4th cut of an xattr name mapping option for virtiofsd.

> It allows the user of virtiofsd to define a fairly flexible mapping

> from the view of the xattr names the host fs has and the ones that the

> guest sees.

> 

>   The hope is this allows things like:

>     a) Different selinux attributes on host/guest

>     b) separation of trusted. attributes that clash on overlayfs

>     c) support for privileged xattr's in guests running with an

>        unprivileged virtiofsd.

> 

> There's no apparent standard for this kind of mapping, so I made

> it flexible by specifying a mapping rule in the option.

> 

> Prefix's can be added (selectively or globally), xattr's can be

> dropped in either direction or passed through.

> 

> v4

>   cleanups from Stefan and Vivek's reviews

> 

> Dave


Queued

> 

> 

> Dr. David Alan Gilbert (5):

>   tools/virtiofsd: xattr name mappings: Add option

>   tools/virtiofsd: xattr name mappings: Map client xattr names

>   tools/virtiofsd: xattr name mappings: Map server xattr names

>   tools/virtiofsd: xattr name mapping examples

>   tools/virtiofsd: xattr name mappings: Simple 'map'

> 

>  docs/tools/virtiofsd.rst         | 161 +++++++++++

>  tools/virtiofsd/passthrough_ll.c | 474 ++++++++++++++++++++++++++++++-

>  2 files changed, 632 insertions(+), 3 deletions(-)

> 

> -- 

> 2.28.0

> 

> 

-- 
Dr. David Alan Gilbert / dgilbert@redhat.com / Manchester, UK