From: Anthony G. Basile <blueness@gentoo.org>

This patch adds support for a restricted user-controlled namespace on
tmpfs filesystem used to house PaX flags.  The namespace must be of the
form user.pax.* and its value cannot exceed a size of 8 bytes.

This is needed even on all Gentoo systems so that XATTR_PAX flags
are preserved for users who might build packages using portage on
a tmpfs system with a non-hardened kernel and then switch to a
hardened kernel with XATTR_PAX enabled.

The namespace is added to any user with Extended Attribute support
enabled for tmpfs.  Users who do not enable xattrs will not have
the XATTR_PAX flags preserved.


--- a/include/uapi/linux/xattr.h	2022-11-22 05:56:58.175733644 -0500
+++ b/include/uapi/linux/xattr.h	2022-11-22 06:04:26.394834989 -0500
@@ -81,5 +81,9 @@
 #define XATTR_POSIX_ACL_DEFAULT  "posix_acl_default"
 #define XATTR_NAME_POSIX_ACL_DEFAULT XATTR_SYSTEM_PREFIX XATTR_POSIX_ACL_DEFAULT
 
+/* User namespace */
+#define XATTR_PAX_PREFIX XATTR_USER_PREFIX "pax."
+#define XATTR_PAX_FLAGS_SUFFIX "flags"
+#define XATTR_NAME_PAX_FLAGS XATTR_PAX_PREFIX XATTR_PAX_FLAGS_SUFFIX
 
 #endif /* _UAPI_LINUX_XATTR_H */
--- a/mm/shmem.c	2022-11-22 05:57:29.011626215 -0500
+++ b/mm/shmem.c	2022-11-22 06:03:33.165939400 -0500
@@ -3297,6 +3297,14 @@ static int shmem_xattr_handler_set(const
 	struct shmem_inode_info *info = SHMEM_I(inode);
 	int err;
 
+
+	if (!strncmp(name, XATTR_USER_PREFIX, XATTR_USER_PREFIX_LEN)) {
+		if (strcmp(name, XATTR_NAME_PAX_FLAGS))
+			return -EOPNOTSUPP;
+		if (size > 8)
+			return -EINVAL;
+	}
+
 	name = xattr_full_name(handler, name);
 	err = simple_xattr_set(&info->xattrs, name, value, size, flags, NULL);
 	if (!err) {
@@ -3312,6 +3320,12 @@ static const struct xattr_handler shmem_
 	.set = shmem_xattr_handler_set,
 };
 
+static const struct xattr_handler shmem_user_xattr_handler = {
+	.prefix = XATTR_USER_PREFIX,
+	.get = shmem_xattr_handler_get,
+	.set = shmem_xattr_handler_set,
+};
+
 static const struct xattr_handler shmem_trusted_xattr_handler = {
 	.prefix = XATTR_TRUSTED_PREFIX,
 	.get = shmem_xattr_handler_get,
@@ -3325,6 +3339,7 @@ static const struct xattr_handler *shmem
 #endif
 	&shmem_security_xattr_handler,
 	&shmem_trusted_xattr_handler,
+	&shmem_user_xattr_handler,
 	NULL
 };