[BUG] Landlock denies LANDLOCK_ACCESS_FS_EXECUTE despite a correctly-anchored PathBeneath rule (contradicts selftest layout1.execute)

Mickaël Salaün mic at digikod.net
Thu Jul 16 09:37:41 UTC 2026


Hi!

You should also get a look at the audit logs:
https://docs.kernel.org/admin-guide/LSM/landlock.html#audit

 Mickaël

On Wed, Jul 15, 2026 at 10:39:29AM +0200, Günther Noack wrote:
> Hello Ken!
> 
> (Also adding landlock at lists.linux.dev to CC)
> 
> On Tue, Jul 14, 2026 at 09:07:56PM +0000, Ken Grimes wrote:
> > Hey all, this is my first bug report for linux. The issue was discovered 
> > alongside llm-assisted coding on a downstream project. The 
> > investigation/testing of the bug was a mostly manual process so I could 
> > be sure this was something real. Please let me know if I can provide any
> > further details or assistance. Hope this is helpful, thank you for all of your
> > hard work!
> 
> Welcome and thanks for reporting your first issue!
> 
> I believe the issue you are observing is that the /bin/true program you are
> starting is a dynamically linked executable.  As such, executing it requires
> both the LANDLOCK_ACCESS_FS_EXECUTE right on the binary itself and on
> the system's dynamic loader binary, which usually lives in /lib/ld-linux.so.*
> (but there are symlinks and 32/64-bit differences at play as well, which
> influence the actual final location).
> 
> You can try this out with the following experiments:
> 
> (1) Compile a "true" program statically and try using that:
> 
>     $ echo 'int main() { return 0; }' > true.c
>     $ CFLAGS=-static make true
> 
>     This can be started with the test you have,
>     unlike the dynamically linked version.
> 
> (2) Alternatively, add execute permissions for the dynamic loader:
> 
>     Add an additional "path beneath" rule that allow-lists the execution
>     access right on /lib/ld-linux.so.2, /lib64/ld-linux-x86-64.so.2 or
>     wherever else your dynamic loader is.  (You can discover the actual
>     location using "ldd /bin/true".)
> 
> With either one of these two changes, your standalone reproducer program
> starts working again.  Or at least it does on my machine.  If it still doesn't
> work on your end that way, please let us know. :)
> 
> I admit that we should probably point this out in the Landlock documentation
> for the LANDLOCK_ACCESS_FS_EXECUTE right, as dynamic linking is common and it
> is a potential issue that many people might run into.
> 
> For background on the dynamic loading mechanism, see the man page ld.so(8) [1]
> and the LWN article "How programs get run: ELF binaries" [2] (specifically the
> section "Dynamically linked programs").
> 
> —Günther
> 
> 
> [1] https://man7.org/linux/man-pages/man8/ld.so.8.html
> [2] https://lwn.net/Articles/631631/
> 
> 



More information about the Linux-security-module-archive mailing list